Timed Key Table for Secure Government Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for providing government agencies with access to locked devices and secure communications introduce high risks of unauthorized access and abuse, and existing key escrow solutions are deemed insecure, necessitating a low-risk method for vendors to grant access while verifying agency possession of the device.

Innovation Solution

A method involving key wrapping and data access keys, where a data protection key is encrypted and stored on the device, allowing vendors to decrypt and verify possession through unique device identification, eliminating the need for key escrow and ensuring secure, low-risk access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If key escrow solutions are used to provide government access to locked devices, then access capability is improved, but security risk increases due to potential unauthorized access and abuse

Engineering Contradiction:
Improveaccess capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a secure enclave as an intermediary component that mediates between the government's need for device access and the requirement for security. The secure enclave contains cryptographic materials and controls the unlocking process, ensuring that access is granted only through verified legal authority while preventing unauthorized access. This intermediary architecture resolves the contradiction by enabling access capability through controlled key release while maintaining security through the enclave's protective boundaries and verification mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strong cryptography and cryptographic key management are used to secure device access, then security is improved, but access capability deteriorates for legitimate government investigations

Engineering Contradiction:
ImprovesecurityVSAvoidaccess capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the cryptographic key management into distinct components: the secure enclave that holds and protects cryptographic materials, the operating system that implements the key management policy, and the government access mechanism that operates through the enclave. This segmentation allows strong cryptography to protect device security while enabling government access through the controlled enclave interface, resolving the contradiction by separating security enforcement from access control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic key management where the secure enclave can adaptively control key release based on verification of legal authority. The system transitions from static encryption to dynamic key release mechanisms that respond to government access requests through verified warrants or court orders. This dynamic approach maintains strong cryptography for general security while enabling conditional access for legitimate investigations.

Inventive Principle:
Principle #15Dynamics

3Loss of time

If golden keys are created to provide immediate government access to devices, then access speed is improved, but security risk increases due to potential abuse and unintended use

Engineering Contradiction:
Improveaccess speedVSAvoidsecurity risk
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where the secure enclave verifies government identity and legal authority before releasing cryptographic keys. The system provides immediate feedback on whether access should be granted based on verification of warrants, court orders, or other legal authority. This feedback loop enables fast access when authority is verified while preventing abuse when verification fails, resolving the contradiction between access speed and security risk.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary verification of legal authority and device ownership before releasing access keys. The secure enclave checks warrants, court orders, or other legal documentation in advance of key release, ensuring that only authorized government entities can obtain access. This preliminary action prevents abuse and unintended use while maintaining the ability to provide immediate access when verification succeeds.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11363454B2Providing low risk exceptional access with verification of device possession
Publication Date: 2022.06.14 OZZIE RAYMOND EDWARD
  • US11363454B2 patent drawing
  • US11363454B2 patent drawing
  • US11363454B2 patent drawing

AI summary

A method for providing access to a communication includes generating a timed key table in device nonvolatile memory, storing archival copies of the timed key table within enterprise environments, encrypting a master secret with the currently applicable key of the timed key table, generating an encrypted timed key table by encrypting the timed key table with a public key, sending data on an encrypted session from a communication device to a server over a network, sending the encrypted master secret and encrypted timed key table from the communication device over the network, decrypting the encrypted timed key table with a private key, decrypting the encrypted master secret sent from the communication device using at least a subset of an unencrypted timed key table to obtain the master secret, and decrypting the encrypted data sent from the communication device using the unencrypted master secret. The timed key table includes information that identifies a locked communication device such that the information, which includes one or more of an IMEI, a WiFi MAC address, and a BT MAC address, is used to verify physical possession of the locked communication device.