Portable USB Key Security Circuit Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing peripherals such as USB keys, MMC cards, and SD cards lack cost-effective solutions for securing data access and storage, relying on specific and costly components for encryption and decryption.
Innovation Solution
A method and device that utilize distinct and independent access and securing means within a portable electronic entity, allowing encrypted data to be decrypted only after user authentication, and encrypting data before storage, without data exchange between these means, enabling secure data management using non-specific components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If specific encryption and decryption components are integrated into peripherals, then data security is improved, but device cost increases significantly
Solution Approach 1:
The system separates security functions into a dedicated security circuit independent of the mass memory controller. The security circuit handles encryption/decryption operations while the mass memory controller manages data storage and retrieval, allowing each component to be optimized independently and reducing overall system cost.
Solution Approach 2:
The security circuit is designed to work with multiple types of mass memory devices (USB keys, MMC cards, SD cards) without requiring device-specific customization. This universal approach allows the same security infrastructure to protect data across different peripheral types, reducing development and manufacturing costs.
2Reliability
If encryption and decryption functions are integrated into the peripheral, then data protection is enhanced, but device complexity increases
Solution Approach 1:
The system architecture divides the peripheral into distinct functional blocks: a mass memory controller for data management and a separate security circuit for cryptographic operations. This segmentation reduces the complexity of each individual component while maintaining comprehensive data protection capabilities.
Solution Approach 2:
The host station acts as an intermediary that coordinates between the user authentication process and the security circuit operations. The host station manages the authentication flow and triggers encryption/decryption operations based on authentication results, simplifying the control logic within the peripheral itself.
3Reliability
If authentication is required before data access, then data security is improved, but access time increases
Solution Approach 1:
The system performs authentication checks before initiating data access operations. By verifying user credentials in advance and establishing authentication state, the system ensures that subsequent data operations can proceed efficiently without repeated authentication overhead, reducing the perceived access time for authorized users.
4Ease of manufacture
If separate access means and securing means are used, then manufacturing flexibility is improved, but device complexity increases
Solution Approach 1:
The peripheral device is designed with separate access means (mass memory controller) and securing means (security circuit) that communicate through standardized interfaces. This modular architecture allows each component to be manufactured independently using different manufacturing processes, improving manufacturing flexibility while maintaining a clear separation of concerns.
Solution Approach 2:
The security circuit is designed as a universal component that can be integrated with various types of mass memory devices through standard communication protocols. This universal design approach allows the same security circuit to work with different mass memory controllers, reducing the complexity of creating device-specific security implementations.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The method involves receiving encrypted data by an access unit i.e. memory controller(110), of a portable electronic entity i.e. universal serial buskey (100), where the access unit permits access to a mass memory comprising the encrypted data, and the electronic entity is connected to a host station i.e. computer. The received encrypted data is transmitted to a securization unit for decryption of the encrypted data, where the access unit and the securization unit are separate and independent of each other. The decrypted data is received in the host station. Independent claims are also included for the following: (1) a method for storing encrypted data in a mass memory of a portable electronic entity (2) a device for accessing encrypted data previously stored in a mass memory of a portable electronic entity.