TPM-Based Backup Data Verification for Information Processing Apparatus

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information processing apparatuses face challenges in ensuring the validity and integrity of backup data stored on external storage units, particularly in scenarios where the SD card is replaced or tampered with, leading to potential security breaches and operational failures.

Innovation Solution

The apparatus employs a trusted platform module (TPM) to encrypt data encryption keys, verifies the validity of external storage units through identification information, and performs multiple verification steps to ensure the integrity of backup data, including TPM access keys, internal keys, and encrypted data encryption keys, thereby preventing unauthorized access and ensuring data security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the SD card is replaced or tampered with, then the apparatus can potentially access unauthorized data or keys, but this compromises data security and integrity

Engineering Contradiction:
ImproveReplaceability of SD cardVSAvoidData security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary verification of the SD card's identification information and validates the integrity of backup data (TPM access key, TPM internal key, EDEK) before allowing any operations. This preliminary check prevents unauthorized access by detecting tampered or incorrect SD cards before they can compromise security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The verification process provides feedback by comparing the SD card's identification information against stored valid information and checking the integrity of backup data. This feedback mechanism allows the system to detect and reject unauthorized or tampered SD cards, maintaining security while allowing legitimate replacements.

Inventive Principle:
Principle #23Feedback

2Reliability

If multiple verification steps are performed to ensure data integrity, then security is improved, but the operation time and complexity increase

Engineering Contradiction:
ImproveData integrityVSAvoidVerification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs verification of SD card identification information and backup data integrity as preliminary actions before main operations. By checking the identification information and validating backup data (TPM access key, TPM internal key, EDEK) in advance, the system ensures security and data integrity are established before critical operations begin, preventing time loss during actual data processing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10657268B2Information processing apparatus, information processing method, and non-transitory computer readable medium to verify validity of backup data
Publication Date: 2020.05.19 FUJIFILM BUSINESS INNOVATION CORP
  • US10657268B2 patent drawing
  • US10657268B2 patent drawing
  • US10657268B2 patent drawing

AI summary

There is provided an information processing apparatus. An internal storage unit encrypts a data encryption key used for encryption of data to an encrypted data encryption key and stores the encrypted key. A first verification unit verifies validity of its own external storage unit on the basis of identification information acquired from the external storage unit that stores backup data regarding the EDEK and the identification information of the external storage unit. Another verification unit verifies validity of the backup data stored in the external storage unit.