TPM-Based Backup Data Verification for Information Processing Apparatus
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information processing apparatuses face challenges in ensuring the validity and integrity of backup data stored on external storage units, particularly in scenarios where the SD card is replaced or tampered with, leading to potential security breaches and operational failures.
Innovation Solution
The apparatus employs a trusted platform module (TPM) to encrypt data encryption keys, verifies the validity of external storage units through identification information, and performs multiple verification steps to ensure the integrity of backup data, including TPM access keys, internal keys, and encrypted data encryption keys, thereby preventing unauthorized access and ensuring data security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the SD card is replaced or tampered with, then the apparatus can potentially access unauthorized data or keys, but this compromises data security and integrity
Solution Approach 1:
The system performs preliminary verification of the SD card's identification information and validates the integrity of backup data (TPM access key, TPM internal key, EDEK) before allowing any operations. This preliminary check prevents unauthorized access by detecting tampered or incorrect SD cards before they can compromise security.
Solution Approach 2:
The verification process provides feedback by comparing the SD card's identification information against stored valid information and checking the integrity of backup data. This feedback mechanism allows the system to detect and reject unauthorized or tampered SD cards, maintaining security while allowing legitimate replacements.
2Reliability
If multiple verification steps are performed to ensure data integrity, then security is improved, but the operation time and complexity increase
Solution Approach 1:
The system performs verification of SD card identification information and backup data integrity as preliminary actions before main operations. By checking the identification information and validating backup data (TPM access key, TPM internal key, EDEK) in advance, the system ensures security and data integrity are established before critical operations begin, preventing time loss during actual data processing.
Data Source
AI summary
There is provided an information processing apparatus. An internal storage unit encrypts a data encryption key used for encryption of data to an encrypted data encryption key and stores the encrypted key. A first verification unit verifies validity of its own external storage unit on the basis of identification information acquired from the external storage unit that stores backup data regarding the EDEK and the identification information of the external storage unit. Another verification unit verifies validity of the backup data stored in the external storage unit.


