SE1050902A1 - Electronic encryption device and method - Google Patents

Electronic encryption device and method Download PDF

Info

Publication number
SE1050902A1
SE1050902A1 SE1050902A SE1050902A SE1050902A1 SE 1050902 A1 SE1050902 A1 SE 1050902A1 SE 1050902 A SE1050902 A SE 1050902A SE 1050902 A SE1050902 A SE 1050902A SE 1050902 A1 SE1050902 A1 SE 1050902A1
Authority
SE
Sweden
Prior art keywords
eller
ett
andra
datafiler
nämnda
Prior art date
Application number
SE1050902A
Other languages
Swedish (sv)
Inventor
Rolf Andersson
Roger Eriksson
Fredrik Olsson
Original Assignee
Business Security Ol Ab
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Business Security Ol Ab filed Critical Business Security Ol Ab
Priority to SE1050902A priority Critical patent/SE1050902A1/en
Priority to PCT/SE2011/051062 priority patent/WO2012030296A2/en
Publication of SE1050902A1 publication Critical patent/SE1050902A1/en

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/71Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
    • G06F21/72Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in cryptographic circuits
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/602Providing cryptographic facilities or services
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/78Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
    • G06F21/79Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data in semiconductor storage media, e.g. directly-addressable memories
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/82Protecting input, output or interconnection devices
    • G06F21/85Protecting input, output or interconnection devices interconnection devices, e.g. bus-connected or in-line devices
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0894Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
    • H04L9/0897Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage involving additional devices, e.g. trusted platform module [TPM], smartcard or USB

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Physics & Mathematics (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mathematical Physics (AREA)
  • Storage Device Security (AREA)

Abstract

100902 P:\l868 Business Security\P\ll2\Pl8680ll2_l0090l__patent applicationßocx 19 ABSTRACT An electronic encryption device and method for encryption of data files,comprising a crypto module (113) configured to read one or more unencrypted data filesstored in a first files system on a first external memory device (l07); encrypt the one ormore unencrypted data files into one or more encrypted data files; and Write the one ormore encrypted data files to a second file system on a second external memory device (108). To be published With Figure 2.

Description

100902 P:\1B68 Business Security\P\112\P18680l12_l0090l_patent applicatiomdocx l ELECTRONIC ENCRYPTION DEVICE AND METHOD Technical FieldThe present invention relates generally to the field of electronic encryptiondevices, and more particularly, it relates to an electronic encryption device and method for encryption of data files.
Background Universal Serial Bus (USB) is a specification to establish communicationbetween devices and a host controller, such as PCs (personal computers).
USB can connect computer peripherals such as mice, keyboards, digitalcameras, printers, personal media players, flash drives, and external hard drives.Although, USB was designed for personal computers, it has become commonplace onother devices such as smartphones, PDAs and video game consoles. For many of thosedevices, USB has become the standard connection method.
A USB flash drive consists of a flash memory data storage device integratedwith a USB interface, and is typically removable and rewritable.
Since USB flash drives are portable they can also easily be lost or stolen.Therefore, USB flash drives may have their contents encrypted using third party diskencryption software or programs which can use encrypted archives such as ZIP andRAR. The executable files can be stored on the USB drive, together with the encryptedfile image. The encrypted paitition can then be accessed on any computer running thecorrect Operating system, although it may require the user to have administrative rightson the host computer to access data. A problem with this is that the encryption softwareor programs have to be installed on specific PC and doe require specific operatingsystems.
Some vendors have produced USB flash drives which use hardware basedencryption as part of the design, thus removing the need for third-party encryptionsoftware. Other flash drives allow the user to configure secure and public partitions ofdifferent sizes, and offer hardware encryption. However, a problem with encrypted partitions is lack of transparency for the host computer. 100902 P;\1868 Business Security\P\112\Pl8680112_l00901_pacent applicationxiocx 2 Another approach to provide encrypted information on portable memorydevices, such as USB flash drives, is a crypto pass-through dangle disclosed in US2007/033320. The crypto pass-through dangle enables various memory devices WithUSB interface, such as a flash memory card or a flash memory storage device, to beconveniently inserted into or removed from With encryption/decryption function, Acontroller With USB interface and data encryption and decryption ability executes theencryption/decryption function to generate an identity code for the flash memorydevice. If an encrypted flash memory device being directly plugged into the USB portof a host computer that can not recognize the identity code, the computer can not accessthe data of the encrypted flash memory device, and therefore, the data of the flashmemory device can be protected. However, if the encrypted flash memory device beingplugged into the crypto pass-through dangle, the controller can recognize the identitycode and execute the decrypting function for the data, and therefore, the computer canaccess the data of the encrypted flash memory device. Even this approach lackstransparency for the host computer.
Another disadvantage with the prior art approaches is non-existent or unsafekey management.
Therefore, there is a need for improved electronic crypto device.
Summary lt should be emphasized that the term “comprises/comprising” when used inthis specification is taken to specify the presence of stated features, integers, steps, orcomponents, but does not preclude the presence or addition of one or more otherfeatures, integers, steps, components, or groups thereof.
It is an object of the invention to obviate at least some of the abovedisadvantages and to provide an improved electronic encryption device.
According to a first aspect of the invention, this is achieved by an electronicencryption device for encryption of data files. The electronic encryption device ischaracterized by a crypto module configured to read one or more unencrypted data files stored in a first files system on a first external memory device; encrypt the one or more 100902 P;\l868 Business Security\P\1l2\P18680l12_l00901__patent applicatiomdocx 3 unencrypted data files into one or more encrypted data files; and Write the one or moreencrypted data files to a second file system on a second external memory device.
In some embodiments, the device may further comprise a first connectoroperatively connected to the crypto module via a first file system driver for transferringthe one or more unencrypted data files read from the first external memory device to thecrypto module; and a second connector operatively connected to the crypto modulevia a second file system driver for transferring the one or more encrypted data filesencrypted by the crypto module to the second file system on the second externalmemory device. ln some embodiments, the crypto module is configured to read the one ormore unencrypted data files from a first external USB memory device.
In some embodiments the crypto module is configured to Write the one ormore encrypted data files to the second file system on a second external USB memorydevice.
In some embodiments the crypto module is configured to read the oneor more unencrypted data files from the second file system on the second memorydevice of an external computer.
The crypto module may in some embodiments be configured to read the oneor more unencrypted data files from the second file system on a hard disk, a CD-ROMstation, a RAM (Random Access Memory), a ROM (Read Only Memory), a flashmemory, optical storage device, or magnetic storage device.
The electronic encryption device of claims l or 2, Wherein the crypto module(113) is configured to write the one or more encrypted data files to the second filesystem on a hard disk, a CD-ROM station, a RAM (Random Access Memory), a ROM (Read Only Memory), a flash memory, optical storage device, or magnetic storage device.The electronic encryption device may in some embodiments further comprise a key interface operatively connected to the crypto module for loadingencryption keys for encryption of the one or more unencrypted data files.Accodrding to a second aspect of the invention, this is achieved by a method of for encryption of data. The method is characterized by the steps ofz: lO 100902 P:\lB68 Business Securicy\P\1l2\P18680l12_100901_patent application.docx 4 reading one or more unencrypted data files stored in a first files system on a firstexternal memory device; encrypting the one or more unencrypted data files into one or more encrypteddata files; and writing the one or more encrypted data files to a second file system on a secondexternal memory device.
In some embodiinents, the second aspect of the invention may additionallyhave features identical with or corresponding to any of the various features as explainedabove for the first aspect of the invention.
An advantage of some embodiments of the invention is that the encryptiondevice understands the file system of memory devices storing unencrypted as well asencrypted data files, wherein the encryption device is virtually transparent. Thereby, theelectronic encryption device enables unlimited creation/deletion of files and directories,and reading/writing of files on the various memory devices, as well as formatting of anymemory device connected to the electronic encryption device.
Another advantage of some embodiments of the invention is that a hostcomputer and the file encryption device may interact by means of file system calls, i.e open, read, write, and close.
Brief Description of the Drawings Further objects, features and advantages of the invention will appear from thefollowing detailed description of embodiments of the invention, with reference beingmade to the accompanying drawings, in which: FIG. lA illustrates an electronic file encryption device for encryption anddecryption of data files according to some embodiments of the invention; FIG. IB illustrates a general block diagram of an electronic encryption devicein an operating environment according to some embodiments of the invention; FIG. 2 illustrates a block diagram of the electronic file encryption device inFIG. l according to some embodiments of the invention; FIG. 3A illustrates a schematic drawing in a front view of an embodiment of the electronic encryption device; 100902 P:\l868 Business Security\P\1l2\P18680l12__l00901_patent applicatioimdocx 5 FIG. 3B illustrates a schematic drawing in a rear view of an embodiment of theelectronic encryption device; FIG. 4 is a flow diagram illustrating steps in a method for encryption/decryption of data files by the electronic encryption device; FIG. 5 illustrates a block diagram of an electronic file copy encryption deviceaccording to some embodiments of the invention; FIG, 6A illustrates an electronic file encryption device for encryption anddecryption of data files according to some embodiments of the invention; FIG. 6B illustrates a general block diagram of an electronic encryption devicein an operating environment according to some embodiments of the invention; FIG. 7 illustrates a block diagram of an electronic file server encryption deviceaccording to some embodiments of the invention; FIG. 8A illustrates a hardware architecture of the file encryption deviceaccording to some embodiments of the invention; FIG. 8B illustrates an FPGA block diagram of the file encryption deviceaccording to some embodiments of the invention; FIG. 9 illustrates a block diagram of the electronic file encryption deviceaccording to some embodiments of the invention; and FIG. 10 illustrates a block diagram of an electronic file server encryption device according to some embodiments of the invention.
Detailed Description Embodiments of the invention will be described with reference to Figures 1-10,which all illustrate schematically an example arrangement according to someembodiments of the invention. The same reference signs are used for correspondingfeatures in different figures.
FIG. 1A illustrates an electronic file encryption device 100 for encryption anddecryption of data files according to one embodiment of the present invention in anoperating environment. A general block diagram of the electronic file encryption device 100 is shown in FIG lB, which may comprise a housing 101, a printed circuit board 100902 P:\l868 Business Security\P\1l2\Pl8680l12_l00901_patent applicatiomdocx 6 102, a first connector 103, and a second connector 104, an MMI (Man MachineInterface) 105, and a key interface 106.
The printed circuit board 102 is disposed within the housing 101 for conveyingthe first connector 103 for input and output of unencrypted information, and the secondconnector 104 for input and output of encrypted information.
The first and second connectors 103 and 104 may be USB interface slots forconnecting various memory devices, including but not limited to USB memory devices,such as USB flash drives.
As shown in FIG 1A, a first USB memory device 107 with a USB interfaceconnector may store unencrypted files for encryption by the electronic crypto device100, when it is connected to the first connector 103 of the electronic crypto device. Asecond USB memory device 108 with a USB interface connector may be connected tothe second connector 104 for receiving and storing files encrypted by the electronic fileencryption device 100.
The a key interface 106 may be but is not limited to a smart card interface forloading encryption keys to be used in the encryption/decryption of files passing theelectronic file encryption device 100.
The USB memory devices 107 and 108 may be flash drives, each comprising asmall printed circuit board carrying the circuit elements and a USB connector, insulatedelectrically and protected inside a plastic, metal, or rubberized case. The USB connectormay be protected by a removable cap or by retracting into the body of the drive,although it is not likely to be damaged if unprotected. The flash drives may have astandard type-A USB connection allowing plugging into a port on the electronicencryption device or a personal computer.
The electronic file encryption device 100 is provided with "RED/BLACKseparation", i.e. maintaining distance or installing shielding between circuits andequipment used to handle plaintext classified or sensitive information (RED signals)and normal unsecured circuits and equipment (BLACK), the latter including those carrying encrypted or cipher text signals (BLACK signals). 100902 P:\1868 Business Security\P\l12\Pl8680l12_l0090l_patent applicatioimdocx 7 The RED/BLACK separation is achieved by means of two separate sets of eachmodule except the crypto module of the electronic encryption device. One exampleembodiment of the electronic file encryption device 100 is shown in FIG. 2.
The printed circuit board 102 has disposed thereon a first USB driver 109connected to the first connector 103 for handling the communication between theelectronic encryption device 100 and the first USB memory device 107 on the “REDside” when it is inserted into the USB interface slot 103. A first FS (file system) driver110 disposed on the printed circuit board and operatively connected to the first USBdriver 109 is adapted to handle information on a file system level, because it is only thecontent of the data files which is encrypted.
On the “BLACK side”, the printed circuit board 102 has a second USB driver111 disposed thereon and connected to the second connector 104 for handling thecommunication between the electronic file encryption device 100 and the second USBmemory device 108 for storing encrypted files when it is inserted into the second USBinterface slot 104. A second FS driver 112 operatively connected to the second USBdriver 111, which is also adapted to handle information on a file system level.
A crypto module 113 is provided, which has data file encryption anddecryption ability and provide authentication control of data files passing the electronicfile encryption device 100.
The crypto module 113 is disposed on the printed circuit board 102 andoperatively coupled to the first connector 103 and the second connector 104. The cryptomodule 113 is a controller configured for receiving plaintext data files from the firstconnector 103 and executing encryption of the plaintext data files into ciphertext datafiles for transmission as output on the second connector 104.
Similarly, the crypto module 113 is also configured for receiving ciphertextdata files from the second connector 104 and executing decryption of the ciphertext datafiles into plaintext data files for transmission as output on the first connector 103.
Each plaintext data file stored on the first USB memory device 107 may beread and separately encrypted by the crypto module 113 when the USB memory deviceis inserted into the first USB interface slot 103. Data files of any size may be read by streaming and may be encrypted and output on the second connector 104 and stored as 100902 P;\1868 Business Security\P\ll2\Pl8680l12wl0090l__patent applicatiomdocx 8 cipheitext files on the second USB memory device 108 When it is inserted into thesecond USB interface slot 104.
The crypto module 113 executes the encryption/decryption function accordingto, but is not limited to, AES-GCM, which is an authenticated encryption algorithmdesigned to provide both authentication and privacy.
FIG. 3A illustrates a schematic drawing in a front view of an embodiment ofthe electronic encryption device 102. The MMI 105 may comprise, but is not limited to,a display 105 a and a set of keys 105b for controlling the encryption/decryption functionand other functions of the device. According to an alternative embodiment the MMI 105may comprise a touch screen display for controlling the functions of the device.
FIG. 3B illustrates a schematic drawing in a rear view of an embodiment of theelectronic encryption device 102. In addition to the first and second connectors 103, and104, the electronic encryption device 102 may have a third connector 114 forconnection to a host computer. The third connector may be, but is not limited to, a USBinterface slot. Moreover, the electronic encryption device 102 may comprise a powerconnection 115 for main voltage supply. Alternatively, the electronic encryption device102 may be powered by a host computer connected to the first connector 103 or thethird connector 114 if it is provided.
FIG. 4 is a flow diagram illustrating steps in a method for encryption]decryption of data files that are input/output on the two connectors 103 and 104 of theelectronic encryption device 102. In a first step 200 the electronic encryption device 102is powered on. The electronic encryption device 102 goes through a boot process andthe operating system of the device takes over the control in step 201. The electronicencryption device 102 has turned into an operational mode to be responsive tocommands entered via the MMI 105, and to communicate with any USB memorydevice plugged into any of the USB interface slots 103 and 104.
The USB memory device 107 is plugged into and received by the USBinterface slot 103 in step 202 and the USB memory device 108 is plugged into andreceived by the USB interface slot 104 of the electronic encryption device in step 203.A user may plug in the USB memory devices into its respective USB interface slots either at the same time or one after the other in any order. In response to the USB 100902 P;\l86B Business Security\P\ll2\Pl8680ll2__l0090l_patent applicatiomdocx 9 memory device 103 is plugged in, the crypto module 113 establishes connection bysignalling with the first USB memory device 103 in step 204, accesses information offiles stored in an ordinary file system on the USB memory device, and display theinformation about the files and/or file directories in a file menu on the display 105a. Inresponse to the USB memory device 104 is plugged in, the crypto module 113establishes connection by signalling with the USB memory device 104 in step 205 andif there are any files and/or file directories already stored in an ordinary file system onthe USB memory device 104, accesses information of the files and/or file directories,and in that case displays the information about the files and/or file directories in a filemenu on the display l05a.
A selected encryption/decryption key or set of keys is loaded into the electronicencryption device 102, in response to a user inserting a smartcard 116 into the smartcardinterface 106 in step 206 together With an authentication of the user, for example, butnot limited to entering in step 207 a PIN (Personal Identification Number) code validfor the particular smartcard. The crypto module 113 reads the encryption key from thesmart card and authenticate the user With the PIN code in step 208.
A user may select through the MMI 105 one or more plaintext or unencryptedfiles and/or file directories stored on the first USB memory device 103 in step 209 andcopy the plaintext files to the second USB memory device 104, for example by, but notlimited to, drag and drop on the display 105a in step 210. ln response signals generatedin response to the copy of the selected one or more files and/or file directories from thefirst USB memory device 103 to the second USB memory device 104, the cryptomodule 114 enables the encryption function by generating access signals to read theselected one or more files and/or file directories from the first USB memory device 103in step 211. The one or more selected plaintext files and/or file directories are encryptedinto cipher text or encrypted files by the crypto module 113 in step 212 by means of theencryption algorithm using the loaded encryption key(s). The crypto module stores theone or more encrypted files in an ordinary file system on the second USB memorydevice 104.
FIG. 5 illustrates a block diagram of another embodiment of a file encryption device 100” for file copy of unencrypted data files, Wherein the unencrypted files are 100902 P:\l868 Business Security\P\112\Pl8680ll2_l0090l_patent applicatiomdocx lO read, encrypted, and stored as encrypted data files by the file encryption device 100°tothe second file system on the second memory device 108.The printed Circuit board 102has disposed thereon the first USB driver 109 connected to the first connector 103 forhandling the communication between the electronic encryption device 100 and the firstUSB memory device 107 on the “RED side” when it is inserted into the USB interfaceslot 103. The first FS (file system) driver 110 disposed on the printed circuit board andoperatively connected to the first USB driver 109 is adapted to handle information on afile system level, because it is only the content of the data files which is encrypted.
On the “BLACK side”, the printed circuit board 102 has the second USB driver111 disposed thereon and connected to the second connector 104 for handling thecommunication between the electronic file encryption device 100 and the second USBmemory device 108 for storing encrypted files when it is inseited into the second USBinterface slot 104. The second FS driver 112 is operatively connected to the secondUSB driver 111, which is also adapted to handle information on a file system level.The crypto module comprises two blocks, a file copy application block 120 and a filesystem encryption block (CRYPTFS) 122. The file copy application block 120 isconnected between the first file system driver 110 and the file system encryption block120 and is configured to read the one or more unencrypted data files from the firstexternal USB memory device 107.
The file system crypto block 122 has the data file encryption and decryptionability and provide authentication control of data files passing the electronic fileencryption device 100”. The file system crypto block 122 is connected to the file copyapplication block 120 and the second file system driver 112.
Both the file copy application block 120 and the file system crypto block aredisposed on the printed circuit board 102. The file system crypto block 120 is acontroller configured for receiving plaintext data files from the first connector 103 viathe file copy application block 120 and executing encryption of the plaintext data filesinto ciphertext data files for transmission as output on the second connector 104.
Similarly, the file system crypto block 122 is also configured for receiving ciphertext data files from the second connector 104 and executing decryption of the 100902 1.7:\l868 Business Security\P\ll2\Pl86801l2_100901_patent applicatioimdocx ll ciphertext data files into plaintext data files for transmission via the file copyapplication 120 as output on the first connector 103.
Each plaintext data file stored on the first USB memory device 107 may becopied by the file copy application block 120 and separately encrypted by the filesystem crypto block 120 when the USB memory device is inserted into the first USBinterface slot 103, Data files of any size may be read by streaming and may beencrypted and output on the second connector 104 and stored as cipheitext files on thesecond USB memory device 108 when it is inserted into the second USB interface slot104.
The file system crypto block 122 executes the encryption/decryption functionaccording to, but is not limited to, AES-GCM, which is an authenticated encryptionalgorithm designed to provide both authentication and privacy.
FlGs. 6A and 6B illustrate an electronic file server encryption device 100” forencryption and decryption of data files according to one embodiment of the presentinvention in an operating environment. The first and second connectors 103 and 104may be USB interface slots for connecting various memory devices, including but notlimited to a general purpose computer 124 and the USB memory device 108. Theelectronic encryption device 100” is in this embodiment configured to encrypt one ormore data files stored in a file system on the internal or external memory of thecomputer, into one or more encrypted data files; and Write the one or more encrypteddata files to the external USB memory device 108.
FIG. 7 illustrates a block diagram of the electronic file server encryption device100” according to some embodiments of the invention. An electronic file serverencryption device 100” can be implemented With, but is not limited to a Linux basedcomputer. The computer 124 has Windows stack 125 in this embodiment, comprisingan application 126, an SMB/CIFS 127 file system implementation, TCP/IP 128, RNDISDriver 129, and an USB host 130.
The file server encryption device 100” comprises, but is not limited to, a USBperipheral 109” for connection and transfer of unencrypted data files to/from thecomputer 124 With a Windows stack 125, a RNDIS Driver 131, a TCP/IP 132operatively connected to the SMB/CIFS file system module 133 for implementation of 100902 P=\1868 Business Security\P\l12\P18680112_100901_patent applicationxíocx 12 the file system. A USB host 111' is provided for connection and transfer of encrypteddata files to/from the USB memory device 108 via the file system driver 112”. Theencryption module 122” encrypts/decrypts the unencrypted/encrypted data files on a filesystem level between the computer 124 and the USB memory device 108.
Hence, the SMB/CIFS module 133 and the encryption module 122”implements a virtual encrypted file system on top of the physical file system and maythereby transparently encrypt the data files with the encryption key loaded through thekey interface 106.
The electronic file server encryption device 100” is operated by means of theMMI 105, which is implemented as an application that starts when the device is booted.
FIG. 8A illustrates a hardware architecture of the file encryption deviceaccording to some embodiments of the invention.
The design may be based on, but is not limited to, an ACME FOX G20 LinuxEmbedded Single Board Computer, in this embodiment. A daughter board (FED Board)is attached to the computer. The Foxg20 System may be based on an ATMELAT9lSAM9G20 micro controller, that may have an ARM926 processor (MCU) withMMU, instruction and data chaches, two USB host ports, a USB device port, a SPIcontroller, UARTs, a real time clock, fast Ethernet MAC, and features supportingDRAM, power supply, Micro SD FLASH socket.
The daughter board (FED Board) may have an FPGA module with clockgenerator, various buttons, a smartcard interface circuitry, a J TAG, debug connector,and a display module.
The Fox board may handle most of the functionality. Communication with thedaughter board may be handled by SPI communication for the smartcard controller.RS232 may be used for display and button interfaces. The display may be, but is notlimited to OLED. The software within the smart display unit may be customized and/orupgraded.
The FPGA may be, but is not limited to, a Lattice XP2 device. The design maybe divided into, but is not limited to, two main data paths. The SPI to smartcard path,and the MMI path as shown in FIG. 8B. There are a contextual difference betweencryptographic keys and physical keys (buttons) that can be pressed by the user. 100902 P:\l868 Business Security\P\l12\Pl86BOll2_10090l_patent applicationxiocx 13 The SPI to smartcard path may allow the host MUC to access a smartcard overits SPI interface. It may comprise an SPI slave, control logic With register and asmartcard control block.
The SPI slave may basically be, but is not limited to, two eight shift registers,Which may be clocked by SPCK. The SPI clock may be asynchronous to the mainclock. Hence the ready strobe from the slave may be captured (synchronised) andretimed before data is stored in the SC-Control block.
In SC-control commands, status as well as key data may be shifted in/out, butis not limited to, 8 bits a time.
The largest block may be the smartcard controller. It may handel both thesmartcard protocol and the NBK card specific details.
The MMI path may have a number of keys (buttons). Key inputs are de-bounced and information about key press events and Which keys that are pressed, maybe sent to the host serially With UART. LEDs can optionally be turned on, by signallingin the opposite direction.
The serial connection from the host to the display may just be routedelectrically through the FPGA.
The external clock input (33 MHz in this embodíment) is routed to a PLL,Which is configured to divide by 3 in order to generate a main clock of ll MHz in thisexample embodiment. Other external clock frequencies and main clock frequencies maybe used in other embodiments. The SPI slave block may not be driven by the clock.
A reset may be generated as an or-not function of the external reset input andthe PLL lock signal.
FIG. 9 illustrates a block diagram of the electronic file encryption deviceaccording to some embodiments of the invention, Wherein the crypto module 113 '” is aseparate hardware module FIG. 10 illustrates a block diagram of an electronic file server encryptiondevice according to some embodiments of the invention, Wherein encryption module 122” is a separate hardware module. l0 100902 P:\l868 Business Security\P\1l2\P18680l12_10090l_patent applicatiomdocx 14 The electronic encryption device lOO may comprise a digital electroniccomputer or computer apparatus and processes performed in a computer apparatus orsystem. The computer apparatus may comprises a data processing system, including acomputer processor including the crypto module l l3 for processing data, and storagemeans connected to the computer processor for storing data on a storage medium.
The electronic encryption device may be embodied as an electronic device withtamper protection, i.e involve prevention of access to the electronic circuitry of thecrypto device, any information comprised in the electronic circuitry (such as programcode or configurations of the circuitry), or any internal signals generated by theelectronic circuitry. Additionally or alternatively, tamper protection of the electronicencryption device may involve that attempts to access the electronic circuitry,information, or signals are detected.
The invention has been described herein with reference to variousembodiments. However, a person skilled in the art would recognize numerous Variationsto the described embodiments that would still fall within the scope of the invention. Forexample, it should be noted that in the description of embodiments of the invention, thepartition of functional blocks into particular units is by no means limiting to theinvention. Contrarily, these partitions are merely examples. Functional blocks describedherein as one unit may be split into two or more units. In the same manner, functionalblocks that are described herein as being implemented as two or more units may beimplemented as a single unit without departing from the scope of the invention.
Hence, it should be understood that the limitations of the describedembodiments are merely for illustrative purpose and by no means limiting. instead, thescope of the invention is defined by the appended claims rather than by the description,and all Variations that fall within the range of the claims are intended to be embracedtherein.
The present invention may be embodied as a method in a device, device, orsystem with a computer program product. Accordingly, the present invention may takethe form of an entirely hardware embodiment, or an embodiment combining software and hardware aspects all generally referred to herein as a unit, component or device.
Furthermore, the software of the present invention may take the form of a computer 100902 P;\l868 Business Security\P\1l2\Pl8680ll2__10090l__patent applicatiormdocx program product. The computer program product may be stored on a computer-usablestorage medium having computer-usable program code embodied in the medium. Theembodiments of the invention described with reference to the drawings comprise acomputer apparatus and processes performed in the computer apparatus. The programmay be in the form of source code, object code a code suitable for use in theimplementation of the method according to the invention. The carrier can be any entityor device capable of carrying the program. For example the carrier may be a recordmedium, computer memory, read-only memory or an electrical carrier signal.Embodiments according to the invention may be carried out when the computerprogram product is loaded and run in a system having computer capabilities.
Although, the invention has been described with reference to embodimentsconfigured for USB memory devices, other embodiments of the electronic encryptiondevice may be configured for operating on any suitable computer readable mediumincluding hard disks, CD-ROMs, a RAM (Random Access Memory), a ROM (ReadOnly Memory), a flash memory, optical storage devices, or magnetic storage devicesexternally connected to the electronic encryption device directly or indirectly via forexample a computer apparatus.
Embodiments of the present invention have been described herein withreference to flowchart and/or block diagrams. lt will be understood that some or all ofthe illustrated blocks may be implemented by computer program instructions. Thesecomputer program instructions may be provided to a processor of a general purposecomputer, special purpose computer, or other programmable data processing apparatusto produce a machine, such that the instructions when executed create means forimplementing the functions/acts specified in the flowchart otherwise described.
It is to be understood that the functions/acts noted in the flowchart may occurout of the order noted in the operational illustrations. For example, two blocks shown insuccession may in fact be executed substantially concurrently or the blocks maysometimes be executed in the reverse order, depending upon the functionality/actsinvolved. Although some of the diagrams include arrows on communication paths toshow a primary direction of communication, it is to be understood that communicationmay occur in the opposite direction to the depicted arrows.
A computer program product may comprise computer program code portionsfor executing the method, as described in the description and the claims, for providingcontrol data when the computer program code portions are run by an electronic device having computer capabilities. 100902 P;\1868 Business Security\P\ll2\Pl8680l12_l0090l_pat:ent application.docx 16 A computer readable medium having stored thereon a computer programproduct may comprise computer program code portions for executing the method, asdescribed in the description and the claims, for providing control data when thecomputer program code portions are run by an electronic device having computercapabilities.
The many features and advantages of the invention are apparent from thedetailed specification, and thus, it is intended by the appended claims to cover all suchfeatures and advantages of the invention, which fall within the scope of the invention.However, although embodiments of the method and apparatus of the invention has beenillustrated in the accompanying drawings and described in the foregoing detaileddescription, the disclosure is illustrative only and changes, modifications andsubstitutions may be made without departing from the scope of the invention as set forth and defined by the following claims.
Terminology: CIF S Common Internet File System GPIO General Purpose Input/ Output J TAG Joint Test Action Group MAC Medium Access Controller MCU Micro Controller Unit MMI Man Machine Interface NBK Key card OLED Organic Light Emitting DiodRNDIS Remote Network Driver Interface SpecificationSD Secure Digital SMB Server Messge Block (same as CIFS)SPI Serial Peripheral Interface UART Universal Asynehronous Receiver and TransmitterVHDL VHSIC Hardware Description Language VHSIC Very High Speed Integrated Circuit

Claims (9)

1. Elektronisk krypteringsapparat för kryptering av datafiler, kännetecknadav en kryptomodul (113) konfigurerad att läsa en eller fler okrypterade datafiler lagradei ett första filsystem på ett första externt minne (107); kryptera nämnda en eller fleradatafiler till en eller fler krypterade datafiler på filsystemnlvå och skriva nämnda eneller flera krypterade datafiler till ett andra filsystem på ett andra externt minne (108).
2. Elektronisk krypteringsapparat enligt krav 1, innefattande: en första anslutning (103) operativt förbunden med kryptomodulen (113) via enforsta filsystemenhet (110) fór överföring av nämnda en eller flera okrypterade datafiler,lästa från det första externa minnet (107), till kryptomodulen (1 13); och en andra anslutning (104) operativt förbunden med kryptomodulen (113) via enandra filsystemenhet (112) för överföring av nämnda en eller flera krypterade filerkrypterade av kryptomodulen (113) till det andra filsystemet på det andra extemaminnet (108).
3. Elektronisk krypteringsapparat enligt krav 1 eller 2, varvid krypto-modulen (113) är konfigurerad att läsa nämnda en eller flera okrypterade datafiler frånen första extern USB-minnesenhet (107).
4. Elektronisk krypteringsapparat enligt krav 1 till 3, varvid kryptomodulen(113) är konfigurerad att skriva nämnda en eller flera datafiler till det andra filsystemetpå en andra extern USB-minnesenhet (108).
5. Elektronisk krypteringsapparat enligt krav leller 2, varvid krypto-modulen (113) är konfigurerad att läsa nämnda en eller flera okrypterade datafiler från det andra filsystemet på det andra externa minnet på en extern dator (124).
6. Elektronisk krypteringsapparat enligt krav 1 eller 2, varvid krypto-modulen (113) är konfigurerad att läsa nämnda en eller flera okrypterade datafiler fråndet andra filsystemet på en hårddisk, en CD-ROM-station, ett RAM (Random AccessMemory), ett ROM (Read Only Memory), ett flashminne, en anordning för optisklagring eller en anordning för magnetisk lagring. 15 0817 I : \Patrawin\TEMP\GT\~Pl8660ll2_lst:_amended_claims_SE_marked . 2 0150817044 8157354 .docx 17
7. Elektronisk krypteringsapparat enligt krav 1 eller 2, varvid krypto-modulen (113) är konfigurerad att skriva nämnda en eller flera krypterade datafiler tilldet andra filsystemet på den andra externa minnesanordningen på en hårddisk, en CD-ROM-station, ett RAM (Random Access Memory), ett ROM (Read Only Memory), ett flashminne, en anordning for optisk lagring eller en anordning for magnetisk lagring.
8. Elektronisk krypteringsapparat enligt krav 1 till 7, vidare innefattande ettnyckelgränssnitt (106) operativt förbundet med kryptomodulen (113) for att laddakrypteringsnycklar for kryptering av nämnda en eller flera okrypterade filer.
9. Metod for kryptering av data, kännetecknad av stegen att: läsa en eller fler okrypterade datafiler lagrad i ett forsta filsystem på ett forstaexternt minne (107); kryptera nämnda en eller flera okrypterade filer på filsysterrggvåfl till en ellerfler krypterade datafiler; och skriva nämnda en eller flera krypterade filer till ett andra filsystem på ett andra externt minne (108).
SE1050902A 2010-09-02 2010-09-02 Electronic encryption device and method SE1050902A1 (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
SE1050902A SE1050902A1 (en) 2010-09-02 2010-09-02 Electronic encryption device and method
PCT/SE2011/051062 WO2012030296A2 (en) 2010-09-02 2011-09-02 Electronic encryption device and method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
SE1050902A SE1050902A1 (en) 2010-09-02 2010-09-02 Electronic encryption device and method

Publications (1)

Publication Number Publication Date
SE1050902A1 true SE1050902A1 (en) 2012-03-03

Family

ID=45420932

Family Applications (1)

Application Number Title Priority Date Filing Date
SE1050902A SE1050902A1 (en) 2010-09-02 2010-09-02 Electronic encryption device and method

Country Status (2)

Country Link
SE (1) SE1050902A1 (en)
WO (1) WO2012030296A2 (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11574057B2 (en) * 2020-10-29 2023-02-07 Dell Products L.P. Encryption as a service with request pattern anomaly detection

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
IL161027A0 (en) * 2001-09-28 2004-08-31 High Density Devices As Method and device for encryption/decryption of data on mass storage device
US20070033320A1 (en) 2005-08-05 2007-02-08 Wu Victor C Crypto pass-through dangle
US7962755B2 (en) * 2006-04-28 2011-06-14 Ceelox, Inc. System and method for biometrically secured, transparent encryption and decryption
US7908476B2 (en) * 2007-01-10 2011-03-15 International Business Machines Corporation Virtualization of file system encryption
GB0808341D0 (en) * 2008-05-08 2008-06-18 Michael John P External storage security and encryption device

Also Published As

Publication number Publication date
WO2012030296A2 (en) 2012-03-08
WO2012030296A3 (en) 2012-04-26

Similar Documents

Publication Publication Date Title
US20240354265A1 (en) System and method for securely connecting to a peripheral device
AU2019245506B2 (en) Secured computer system
US8615656B2 (en) Secure remote peripheral encryption tunnel
US8341087B2 (en) Method for implementing and application of a secure processor stick (SPS)
EP3391276B1 (en) Hardware integrity check
US20150178504A1 (en) Virtual machine assurances
US10013565B2 (en) System and method for secure transport of data from an operating system to a pre-operating system environment
CN100464313C (en) A mobile storage device and method for accessing encrypted data in the mobile storage device
WO2019209630A1 (en) File processing method and system, and data processing method
US9674336B2 (en) Portable processing unit add on for mobile devices
CN103268206B (en) A kind of seal equipment based on printing technique
US10523427B2 (en) Systems and methods for management controller management of key encryption key
WO2016024838A1 (en) Method and system for providing cloud-based application security service
SE1050902A1 (en) Electronic encryption device and method
Loftus et al. Android 7 file based encryption and the attacks against it
KR101043255B1 (en) USB hub security device and data security method using the same
KR20110050631A (en) Method and system for improving control and efficiency of input / output in encrypted file system
CN106325710A (en) Mobile terminal control method, device and mobile terminal
WO2013129987A1 (en) Electronic encryption device and method
WO2023135477A1 (en) System and method for secure copy-and-paste opertions between hosts through a peripheral sharing device
McCune Reducing the trusted computing base for applications on commodity systems
US20220108041A1 (en) External secure and encrypted ssd device and a secure operating system on an external ssd device
CN110489386A (en) Information processing method, device, storage medium and electronic equipment
Balmer Framework for a high-assurance security extension to commercial network clients
Gao et al. The research and design of embed RSA encryption algorithm network encryption card driver

Legal Events

Date Code Title Description
NAV Patent application has lapsed