Portable USB Key Security Circuit Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing peripherals such as USB keys, MMC cards, and SD cards lack cost-effective solutions for securing data access and storage, relying on specific and costly components for encryption and decryption.

Innovation Solution

A method and device that utilize distinct and independent access and securing means within a portable electronic entity, allowing encrypted data to be decrypted only after user authentication, and encrypting data before storage, without data exchange between these means, enabling secure data management using non-specific components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If specific encryption and decryption components are integrated into peripherals, then data security is improved, but device cost increases significantly

Engineering Contradiction:
Improvedata securityVSAvoiddevice cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system separates security functions into a dedicated security circuit independent of the mass memory controller. The security circuit handles encryption/decryption operations while the mass memory controller manages data storage and retrieval, allowing each component to be optimized independently and reducing overall system cost.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security circuit is designed to work with multiple types of mass memory devices (USB keys, MMC cards, SD cards) without requiring device-specific customization. This universal approach allows the same security infrastructure to protect data across different peripheral types, reducing development and manufacturing costs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If encryption and decryption functions are integrated into the peripheral, then data protection is enhanced, but device complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidcomponent integration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system architecture divides the peripheral into distinct functional blocks: a mass memory controller for data management and a separate security circuit for cryptographic operations. This segmentation reduces the complexity of each individual component while maintaining comprehensive data protection capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The host station acts as an intermediary that coordinates between the user authentication process and the security circuit operations. The host station manages the authentication flow and triggers encryption/decryption operations based on authentication results, simplifying the control logic within the peripheral itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication is required before data access, then data security is improved, but access time increases

Engineering Contradiction:
Improvedata securityVSAvoidaccess time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs authentication checks before initiating data access operations. By verifying user credentials in advance and establishing authentication state, the system ensures that subsequent data operations can proceed efficiently without repeated authentication overhead, reducing the perceived access time for authorized users.

Inventive Principle:
Principle #10Preliminary action

4Ease of manufacture

If separate access means and securing means are used, then manufacturing flexibility is improved, but device complexity increases

Engineering Contradiction:
Improvemanufacturing flexibilityVSAvoidcomponent architecture
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The peripheral device is designed with separate access means (mass memory controller) and securing means (security circuit) that communicate through standardized interfaces. This modular architecture allows each component to be manufactured independently using different manufacturing processes, improving manufacturing flexibility while maintaining a clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security circuit is designed as a universal component that can be integrated with various types of mass memory devices through standard communication protocols. This universal design approach allows the same security circuit to work with different mass memory controllers, reducing the complexity of creating device-specific security implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2131300B1Securing method and device for a portable electronic entity
Publication Date: 2018.08.01 IDEMIA FRANCE SAS
  • EP2131300B1 patent drawingFigure 1~2
  • EP2131300B1 patent drawingFigure 3
  • EP2131300B1 patent drawingFigure 4

AI summary

The method involves receiving encrypted data by an access unit i.e. memory controller(110), of a portable electronic entity i.e. universal serial buskey (100), where the access unit permits access to a mass memory comprising the encrypted data, and the electronic entity is connected to a host station i.e. computer. The received encrypted data is transmitted to a securization unit for decryption of the encrypted data, where the access unit and the securization unit are separate and independent of each other. The decrypted data is received in the host station. Independent claims are also included for the following: (1) a method for storing encrypted data in a mass memory of a portable electronic entity (2) a device for accessing encrypted data previously stored in a mass memory of a portable electronic entity.