WO2011006533A1 - Stackable cryptographic adapter - Google Patents

Stackable cryptographic adapter Download PDF

Info

Publication number
WO2011006533A1
WO2011006533A1 PCT/EP2009/058987 EP2009058987W WO2011006533A1 WO 2011006533 A1 WO2011006533 A1 WO 2011006533A1 EP 2009058987 W EP2009058987 W EP 2009058987W WO 2011006533 A1 WO2011006533 A1 WO 2011006533A1
Authority
WO
WIPO (PCT)
Prior art keywords
adapter
data
storage device
decryption
kit
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/EP2009/058987
Other languages
French (fr)
Inventor
Andreas Ripke
Jens Klaas
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
NEC Europe Ltd
Original Assignee
NEC Europe Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by NEC Europe Ltd filed Critical NEC Europe Ltd
Priority to PCT/EP2009/058987 priority Critical patent/WO2011006533A1/en
Publication of WO2011006533A1 publication Critical patent/WO2011006533A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/78Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
    • G06F21/80Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data in storage media based on magnetic or optical technology, e.g. disks with sectors
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/602Providing cryptographic facilities or services
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/71Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
    • G06F21/72Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in cryptographic circuits
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/78Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/82Protecting input, output or interconnection devices
    • G06F21/85Protecting input, output or interconnection devices interconnection devices, e.g. bus-connected or in-line devices
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2153Using hardware token as a secondary aspect

Definitions

  • the invention relates to an adapter for a computer system to encrypt and decrypt data. Further, the invention is directed to an adapter kit comprising two or more adapters to encrypt and decrypt data. Furthermore, a method for encrypting and decrypting data is provided.
  • the data to be encrypted or decrypted is data to be transmitted to or received from a data storage device.
  • a data storage device may be a removable media to store data separately from a computer system.
  • the storage media may contain sensitive or confidential data so that high levels of security are needed to avoid public access.
  • the storage device is connected to a computer system and then a software is used to decrypt the ciphered data received from the storage device.
  • the same or another software is used to cipher data from the computer system before they are transmitted to the storage device.
  • the encryption and decryption steps each require a particular password/keyfile or a encryption key: without using the correct password, the data stored on the storage device cannot be read or the data to be transmitted to the storage device cannot become encrypted.
  • a software as the cryptographic key for encryption and/or decryption of, for example, confidential data has several drawbacks: for example, the software can be easily duplicated or manipulated so that this kind of software keys bears the risk that unauthorized persons may read the confidential data or may hinder originally authorized users to obtain access to the data. Further, the requirement of a password also bears the risk of easy duplication of the password by unauthorized persons. The duplication of the software and/or the password is often not recognized by the authorized user so that necessary steps to avert any violation are usually taken to late.
  • the present invention is directed to an adapter for a computer system.
  • a data storage device connected to the computer system via the adapter may contain ciphered data which have to be decrypted by the adapter before any reading by a user.
  • data from the computer system may be transmitted to the storage device and is encrypted by the adapter before storage.
  • an adapter kit is provided, comprising two or more adapters as discussed above.
  • the invention is also related to a method for encrypting and decrypting data by using the above adapter and/or adapter kit.
  • an adapter for a computer system is provided.
  • the adapter is configured to provide encryption and decryption of data to be transmitted to or received from a data storage device.
  • the data storage device is connected via the adapter to the computer system.
  • the adapter maybe any kind of connecting piece removably attachable/connectable to the computer system and removably attachable/connectable to the data storage media.
  • the adapter may be an adapter providing at least two USB ports for connecting the storage device indirectly to the computer system.
  • the connection between the storage device and the computer system is indirect in contrast to (direct) connections between the storage device and the computer system without using any removable connecting piece.
  • the (data) storage device may be any media for storing data, for example, a mass storage device or a flash device.
  • the storage device may be a removable/external storage media adapted to be connected to further devices or systems via one or more ports, hi a particular embodiment, the storage device is a USB storage media.
  • the storage media may be connected/attached to the adapter via a particular port, for example, via an external port (provided at the casing of the storage device, and not provided inside the casing), for example, a USB port/plug.
  • a USB port/plug of a storage device is usually applied to connect peripheral devices to computer system and, hi the present invention, for example, to an adapter.
  • USB storage media may be used as storage media and may also be referred to as "USB stick” or “USB drive”. These storage media may be removable storage media, in particular, removable USB storage media. Removable media are meant herein to be configured for being attached/connected to an external port of the computer system.
  • the confidential data maybe readable only by the user to which the adapter belongs.
  • these ciphered data may be securely stored in the storage device.
  • the adapter may contain a firmware enabling the encryption and decryption.
  • Firmware is a program to internally control the functionality of electronic devices, for example, of an adapter.
  • the expression “firmware” is contrasted with “hardware” and “software” which are well-known terms in this technical field.
  • Firmware may be a microcode which cannot be manipulated or changed by a user.
  • firmware denotes anything ROM-resident, hi a particular embodiment, the functionality of the adapter cannot be manipulated or changed by a user.
  • the adapter containing a firmware enabling/initiating the functionality of the adapter (encryption/decryption of data) may fulfil the function of a cryptographic key and may thus be useful for making ciphered data readable to a user and/or ciphering data before storing them externally.
  • the encryption is an on-the-fly encryption and the decryption is a on-the-fly decryption.
  • On-the-fly encryption/decryption means that data is automatically encrypted/decrypted right before it is saved/loaded, without any user intervention.
  • the adapter comprises two USB ports.
  • USB Universal serial bus
  • a USB port may provide a USB plug or may provide a USB socket/receptacle.
  • USB may be used to connect a computer system to external devices, for example digital cameras, flash drives, and external hard drives.
  • the first of the USB ports of the adapter provides a plug and the second USB port provides a socket/receptacle.
  • the computer system may be connected to the adapter via the USB plug of the adapter, and the adapter may be connected to the data storage device via the receptacle of the adapter.
  • the computer system provides a USB receptacle to receive the adapter's USB plug, and the data storage device provides a USB plug to be plugged into the receptacle of the adapter.
  • USB may provide a plug-and-socket connection which is easy to handle and which may easily be used with every common computer system and data storage devices.
  • the adapter is configured to provide encryption upon a USB write command. hi this case, as soon as the write command is issued/initiated, the data to be transmitted to the data storage device are encrypted by the adapter.
  • the issuance/initiation of the USB write command may be realized by a particular input of a user without any need for a password or particular key or may, alternatively, start automatically upon (physical) connection between the data storage device and the computer system via the adapter.
  • the user may have chosen the particular data (in the computer system) to be transmitted to the data storage device, and upon connection to the data storage device via the adapter, the data are automatically encrypted before they are stored in the storage device.
  • Providing encryption upon a USB write command also avoids any intervention of a user, since inputting a password to encrypt the data to be transmitted to the storage device is not necessary anymore.
  • the adapter is configured to provide decryption upon a USB read command.
  • the data received from the data storage device are decrypted by the adapter before the data is received by the computer system.
  • the issuance/initiation of the USB read command may be realized by a particular input of a user without any need for a password or particular key or may, alternatively, start automatically upon (physical) connection between the data storage device and the computer system via the adapter.
  • the (ciphered) data are automatically transmitted to the computer system via the adapter, and the adapter decrypts these data "on-the-fly", without any further intervention by a user.
  • the data storage device is a USB RBC class device.
  • USB RBC class devices are storage devices that use the reduced block commands (RBC)(subclass OxOl) protocol.
  • the Reduced Block Commands standard defines a minimal command set for logical block addressable storage devices including removable media devices.
  • the RBC set is designed to provide very efficient initiator-to-target operation of input/output logical units (disks, tapes, printers, etc.) by an operating system.
  • the adapter and/or the computer system "understands" the RBC version, that means that they are RBC compatible.
  • an adapter kit comprising at least two of the adapter as discussed above, hi particular, the plug of the second adapter is connectable to the receptacle of the first adapter.
  • the kit is adapted to have the data storage device connected to the computer system via the receptacle of the second adapter.
  • the two adapters are stacked, wherein the USB plug of the second adapter is plugged in the receptacle of the first adapter.
  • an adapter system is provided, wherein the adapter system has two free USB ports, the plug of the first adapter and the receptacle of the second adapter.
  • the USB plug of a storage device may be connected to the receptacle of the adapter system, and the plug of the adapter system may be connected to the receptacle of the computer system to provide the (indirect) connection between computer system and data storage device.
  • the adapters are configured to provide encryption and decryption due to their connection.
  • the storage device may be connected to the computer system via the kit of stacked adapters.
  • a kit of adapters to encrypt data to be transmitted to a storage device is advantageous, since all adapters of the kit are needed to encrypt the data. Theft or loss of any one of the adapters of the kit would not enable the unauthorized person to get any access to the confidential data. Thus, additional security is provided.
  • each of the adapters contains a firmware.
  • the firmware of the first adapter and the firmware of the second adapter complement each other so as to enable the encryption and decryption.
  • each of the adapters contains a firmware, and each of the adapters may be configured to decrypt and encrypt data as discussed above.
  • the data from the computer system to the storage device is encrypted by the first adapter and then further encrypted by the second adapter, hi order to provide decryption, for example, the data from the storage device has to be firstly transmitted to the second adapter (where a first decryption takes place) and then to the first adapter (where the second decryption takes place).
  • the adapters of the adapter kit are connected to each other in a pre-defined order when the data is decrypted, depending on the order of the adapters of the adapter kit during the encryption of the data.
  • each adapter of the adapter kit is configured to provide encryption and decryption of the data, wherein the adapter kit is configured to provide decryption of the data if and only if the order of the adapters is identical during decryption and encryption.
  • the firmware of the adapters of the adapter kit are inter- coordinated so that the encryption and decryption may only be provided (as a synergistic effect) if both adapters are stacked and (indirectly) connect the computer system to the storage device. If one of the adapters is not available, no encryption can take place.
  • the encryption is an on-the-fly encryption and the decryption is an on-the-fly decryption.
  • on-the-fly encryption/decryption means that data is automatically encrypted/decrypted right before it is saved/loaded, without any user intervention.
  • Providing the encryption and decryption "on-the-fly" may avoid the possibility of any violation of the transmission of confidential data between the computer system and the data storage device and thus further enhances security of the data transmission via the adapter kit.
  • the data storage device is a USB RBC class device.
  • a system of at least two adapter kits is provided, wherein one of the adapter kits is an adapter kit as discussed above with reference to the particular embodiment teaching that each of the adapters contains a firmware and that the firmware of the first adapter and the firmware of the second adapter complement each other so as to enable the encryption and decryption.
  • the other adapter kit of the system is an adapter kit as discussed above with reference to an alternative embodiment teaching that each of the adapters contains a firmware, and each of the adapters is configured to decrypt and encrypt data, and wherein the adapter kit is configured to provide decryption of the data if and only if the order of the adapters is identical during decryption and encryption.
  • a method for encrypting and decrypting data to be transmitted to or received from a data storage device comprises the steps of (a) connecting the data storage device via an adapter or adapter kit to a computer system; (b') encrypting the data to be transmitted to the data storage device upon initiating a USB write command; and/or (b") decrypting the data received from a data storage device upon initiating a USB read command.
  • the same definitions and particular embodiments as discussed above with reference to the adapter and/or the adapter kit may also be applied to the above-recited method according the present application.
  • FIG. 1 schematically shows a computer system connected to a storage device via an adapter according to a particular embodiment of the present invention
  • Fig.2 schematically shows a computer system connected to a storage device via an adapter kit according to a particular embodiment of the present invention
  • Fig.3 schematically shows a computer system connected to a storage device via an adapter kit according to a particular embodiment of the present invention.
  • Fig. 1 shows a computer system 10 connected to a data storage device 20 via an adapter 30.
  • data 31 to be transmitted from the computer system 10 to the storage device 20 is received by the adapter 30, where the data is being encrypted 32.
  • the encrypted/ciphered data 33 is then transmitted to the storage device 20.
  • ciphered data 34 is received by the adapter 30 from the storage device 20.
  • Li the adapter 30, the data is being decrypted 35, and then the decrypted data 36 is transmitted to the computer system 10.
  • Fig.2 shows a computer system 10 connected to a data storage device 20 via an adapter kit of two adapters 30, 40.
  • data 31 to be transmitted from the computer 10 to the storage device 20 is received by the adapter kit, where the data is being encrypted 42.
  • the encryption takes only place if the two adapters 30, 40 of the kit are stacked. Otherwise the functionalities (for example provided by a particular firmware) of the adapters 30, 40 cannot complement each other to provide the needed synergistic effect resulting in the encryption.
  • the ciphered data 43 is further transmitted to the storage device 20.
  • ciphered data 34 is received by the adapter kit of two adapters 30, 40 from the storage device 20. hi the adapter kit, the data is being decrypted 45, and then - l i
  • the decrypted data 46 is further transmitted to the computer system 10. Similar to the first embodiment of Fig. 2, the decryption takes only place if the adapter kit is complete, that means that the adapters 30, 40 of the adapter kit are stacked. Only if the adapters 30, 40 are stacked, their functionality (for example, provided by a particular firmware) is able to provide decryption as a synergistic effect.
  • Fig. 3 shows a computer system 10 connected to a data storage device 20 via an adapter kit of two adapters 30, 40.
  • each of the adapters 30, 40 of the adapter kit is configured to provide encryption and decryption of data.
  • Lti Lti a first embodiment, data 31 to be transmitted from the computer 10 to the storage device 20 is received by the first adapter 30 of the adapter kit, where the data is being encrypted 42a.
  • the encrypted data 42a is transmitted to the second adapter 40, where the data 42a is further encrypted 42b.
  • the ciphered data 43 is further transmitted to the storage device 20.
  • the ciphered data 34 which was encrypted as explained above (by encryption 42a and 42b) is received by the adapter kit of two adapters 30, 40 from the storage device 20. In the adapter kit, the data is being decrypted 45b by the second adapter 40.
  • the data 45b is transmitted to the first adapter 30 to be further decrypted 45a, and then the decrypted data 46 is further transmitted to the computer system 10.
  • the decryption takes only place if the adapter kit is complete and the two adapters 30, 40 are stacked/connected in the same order as during encryption.
  • a system of at least two adapter kits is provided, wherein one of the adapter kits is the adapter kit shown in Fig. 2 and the other adapter kit is the adapter kit shown in Fig. 3.
  • a secure means i.e. the adapter or the adapter kit
  • encryption and decryption of data to be transmitted to or received from a storage device connected to a computer system via the adapter/adapter kit. Due to the physical possession of the device, additional security is provided to the authorized user, since a theft or a loss of the adapter would be recognized immediately. Hence measures necessary to avert any violation in regard to the confidential content of the storage device can also be taken immediately. Further, the use of the adapter/adapter kit to encrypt and decrypt data does not require the need of inputting a password bearing several risks as discussed above.
  • the firmware of the adapters may be configured to complement each other in order to provide functionality of the adapter kit.
  • the encryption/decryption only works if all necessary adapters are stacked so that the security of the encryption/decryption is further enhanced.
  • the present invention is advantageous for any safe handling of information in general, for example, for providing a safe personal mobile health card.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Mathematical Physics (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Storage Device Security (AREA)

Abstract

The invention provides for a an adapter for a computer system. The adapter is configured to provide encryption and decryption of data to be transmitted to or received from a data storage device. The data storage device is connected via the adapter to the computer system. Further, the invention provides for an adapter kit comprising at least two of the adapter as discussed above. In particular, the plug of the second adapter is connectable to the receptacle of the first adapter. Furthermore, the invention provides a method for encrypting and decrypting data to be transmitted to or received from a data storage device. The method comprises the steps of (a) connecting the data storage device via an adapter or adapter kit to a computer system; (b') encrypting the data to be transmitted to the data storage device upon initiating a USB write command; and/or (b") decrypting the data received from a data storage device upon initiating a USB read command.

Description

Stackable cryptographic adapter
The invention relates to an adapter for a computer system to encrypt and decrypt data. Further, the invention is directed to an adapter kit comprising two or more adapters to encrypt and decrypt data. Furthermore, a method for encrypting and decrypting data is provided. In one embodiment, the data to be encrypted or decrypted is data to be transmitted to or received from a data storage device.
A data storage device may be a removable media to store data separately from a computer system. For example, the storage media may contain sensitive or confidential data so that high levels of security are needed to avoid public access. In order to allow access to the data, usually the storage device is connected to a computer system and then a software is used to decrypt the ciphered data received from the storage device. Alternatively, the same or another software is used to cipher data from the computer system before they are transmitted to the storage device. Usually the encryption and decryption steps each require a particular password/keyfile or a encryption key: without using the correct password, the data stored on the storage device cannot be read or the data to be transmitted to the storage device cannot become encrypted.
However, the use of a software as the cryptographic key for encryption and/or decryption of, for example, confidential data has several drawbacks: for example, the software can be easily duplicated or manipulated so that this kind of software keys bears the risk that unauthorized persons may read the confidential data or may hinder originally authorized users to obtain access to the data. Further, the requirement of a password also bears the risk of easy duplication of the password by unauthorized persons. The duplication of the software and/or the password is often not recognized by the authorized user so that necessary steps to avert any violation are usually taken to late.
Hence, a need exists to provide secure means enabling data transmission to or from a storage device, wherein the data is ciphered, but readable for an authorized user, or is to be ciphered before storage.
The above objects maybe achieved with the features of the claims. In particular, the present invention is directed to an adapter for a computer system. A data storage device connected to the computer system via the adapter may contain ciphered data which have to be decrypted by the adapter before any reading by a user. Further, data from the computer system may be transmitted to the storage device and is encrypted by the adapter before storage. Additionally, an adapter kit is provided, comprising two or more adapters as discussed above. Furthermore, the invention is also related to a method for encrypting and decrypting data by using the above adapter and/or adapter kit.
According to the present invention, an adapter for a computer system is provided. The adapter is configured to provide encryption and decryption of data to be transmitted to or received from a data storage device. The data storage device is connected via the adapter to the computer system.
The adapter maybe any kind of connecting piece removably attachable/connectable to the computer system and removably attachable/connectable to the data storage media. For example, the adapter may be an adapter providing at least two USB ports for connecting the storage device indirectly to the computer system. According to the present invention the connection between the storage device and the computer system is indirect in contrast to (direct) connections between the storage device and the computer system without using any removable connecting piece. The (data) storage device may be any media for storing data, for example, a mass storage device or a flash device. The storage device may be a removable/external storage media adapted to be connected to further devices or systems via one or more ports, hi a particular embodiment, the storage device is a USB storage media. For instance, the storage media may be connected/attached to the adapter via a particular port, for example, via an external port (provided at the casing of the storage device, and not provided inside the casing), for example, a USB port/plug. A USB port/plug of a storage device is usually applied to connect peripheral devices to computer system and, hi the present invention, for example, to an adapter.
For example, Universal Serial Bus (USB) storage media maybe used as storage media and may also be referred to as "USB stick" or "USB drive". These storage media may be removable storage media, in particular, removable USB storage media. Removable media are meant herein to be configured for being attached/connected to an external port of the computer system.
For example, due to the decryption of (ciphered) data, the confidential data maybe readable only by the user to which the adapter belongs. Further, due to the encryption of the data, these ciphered data may be securely stored in the storage device.
In a particular embodiment, the adapter may contain a firmware enabling the encryption and decryption.
Firmware is a program to internally control the functionality of electronic devices, for example, of an adapter. The expression "firmware" is contrasted with "hardware" and "software" which are well-known terms in this technical field. Firmware may be a microcode which cannot be manipulated or changed by a user. For example, in general terms, firmware denotes anything ROM-resident, hi a particular embodiment, the functionality of the adapter cannot be manipulated or changed by a user. The adapter containing a firmware enabling/initiating the functionality of the adapter (encryption/decryption of data) may fulfil the function of a cryptographic key and may thus be useful for making ciphered data readable to a user and/or ciphering data before storing them externally.
In a particular embodiment, the encryption is an on-the-fly encryption and the decryption is a on-the-fly decryption.
On-the-fly encryption/decryption means that data is automatically encrypted/decrypted right before it is saved/loaded, without any user intervention.
Providing the encryption and decryption "on-the-fly" lets the need for any further access of an authorized user to the computer system become redundant and may thus avoid the possibility of any violation of the transmission of confidential data between the computer system and the data storage device. hi a particular embodiment, the adapter comprises two USB ports.
Universal serial bus (USB) is a serial bus standard to connect devices to a host computer and is well-known in the art of information technology. A USB port may provide a USB plug or may provide a USB socket/receptacle. USB may be used to connect a computer system to external devices, for example digital cameras, flash drives, and external hard drives. In a particular embodiment, the first of the USB ports of the adapter provides a plug and the second USB port provides a socket/receptacle. hi this embodiment, the computer system may be connected to the adapter via the USB plug of the adapter, and the adapter may be connected to the data storage device via the receptacle of the adapter. Particularly, the computer system provides a USB receptacle to receive the adapter's USB plug, and the data storage device provides a USB plug to be plugged into the receptacle of the adapter.
Using USB may provide a plug-and-socket connection which is easy to handle and which may easily be used with every common computer system and data storage devices. hi a particular embodiment, the adapter is configured to provide encryption upon a USB write command. hi this case, as soon as the write command is issued/initiated, the data to be transmitted to the data storage device are encrypted by the adapter. The issuance/initiation of the USB write command may be realized by a particular input of a user without any need for a password or particular key or may, alternatively, start automatically upon (physical) connection between the data storage device and the computer system via the adapter. For example, before connection to the data storage device, the user may have chosen the particular data (in the computer system) to be transmitted to the data storage device, and upon connection to the data storage device via the adapter, the data are automatically encrypted before they are stored in the storage device. Providing encryption upon a USB write command also avoids any intervention of a user, since inputting a password to encrypt the data to be transmitted to the storage device is not necessary anymore. hi a particular embodiment, the adapter is configured to provide decryption upon a USB read command.
Similar to the above encryption, in this case, as soon as the read command is issued/initiated, the data received from the data storage device are decrypted by the adapter before the data is received by the computer system. The issuance/initiation of the USB read command may be realized by a particular input of a user without any need for a password or particular key or may, alternatively, start automatically upon (physical) connection between the data storage device and the computer system via the adapter. For example, as soon as the data storage device is connected via the adapter to the computer system, the (ciphered) data are automatically transmitted to the computer system via the adapter, and the adapter decrypts these data "on-the-fly", without any further intervention by a user.
In a particular embodiment, the data storage device is a USB RBC class device.
USB RBC class devices are storage devices that use the reduced block commands (RBC)(subclass OxOl) protocol. The Reduced Block Commands standard defines a minimal command set for logical block addressable storage devices including removable media devices. The RBC set is designed to provide very efficient initiator-to-target operation of input/output logical units (disks, tapes, printers, etc.) by an operating system. hi a particular embodiment, the adapter and/or the computer system "understands" the RBC version, that means that they are RBC compatible.
According to the present invention, an adapter kit is provided, comprising at least two of the adapter as discussed above, hi particular, the plug of the second adapter is connectable to the receptacle of the first adapter.
The same definitions and particular embodiments as discussed above with reference to the adapter may also be applied to the adapter kit according to the present invention. ha a particular embodiment, the kit is adapted to have the data storage device connected to the computer system via the receptacle of the second adapter. hi particular, the two adapters are stacked, wherein the USB plug of the second adapter is plugged in the receptacle of the first adapter. In doing so, an adapter system is provided, wherein the adapter system has two free USB ports, the plug of the first adapter and the receptacle of the second adapter. In this case, the USB plug of a storage device may be connected to the receptacle of the adapter system, and the plug of the adapter system may be connected to the receptacle of the computer system to provide the (indirect) connection between computer system and data storage device. hi a particular embodiment, the adapters are configured to provide encryption and decryption due to their connection.
In this case, an encryption cannot take place without having all adapters of the kit stacked. The storage device may be connected to the computer system via the kit of stacked adapters.
Using a kit of adapters to encrypt data to be transmitted to a storage device is advantageous, since all adapters of the kit are needed to encrypt the data. Theft or loss of any one of the adapters of the kit would not enable the unauthorized person to get any access to the confidential data. Thus, additional security is provided.
In a particular embodiment, each of the adapters contains a firmware. The firmware of the first adapter and the firmware of the second adapter complement each other so as to enable the encryption and decryption.
As defined above, firmware cannot be manipulated or changed by a user, and the firmware controls the functionality of the adapter. In an alternative embodiment, each of the adapters contains a firmware, and each of the adapters may be configured to decrypt and encrypt data as discussed above.
For example, due to the connection between the adapters, the data from the computer system to the storage device is encrypted by the first adapter and then further encrypted by the second adapter, hi order to provide decryption, for example, the data from the storage device has to be firstly transmitted to the second adapter (where a first decryption takes place) and then to the first adapter (where the second decryption takes place). Hence, in this example, the adapters of the adapter kit are connected to each other in a pre-defined order when the data is decrypted, depending on the order of the adapters of the adapter kit during the encryption of the data.
To summarize, hi the alternative embodiment, each adapter of the adapter kit is configured to provide encryption and decryption of the data, wherein the adapter kit is configured to provide decryption of the data if and only if the order of the adapters is identical during decryption and encryption.
If the order of the adapters of the adapter kit during decryption is different from the order during encryption, no decryption of the data can take place in this particular embodiment. The above discussed alternative embodiment further increases the safety of the data transmission, since even a loss of the whole adapter kit would not enable an unauthorized person to decrypt encrypted data without knowing the correct order of the adapters.
In a particular embodiment, the firmware of the adapters of the adapter kit are inter- coordinated so that the encryption and decryption may only be provided (as a synergistic effect) if both adapters are stacked and (indirectly) connect the computer system to the storage device. If one of the adapters is not available, no encryption can take place. hi a particular embodiment, the encryption is an on-the-fly encryption and the decryption is an on-the-fly decryption.
As defined above, on-the-fly encryption/decryption means that data is automatically encrypted/decrypted right before it is saved/loaded, without any user intervention. Providing the encryption and decryption "on-the-fly" may avoid the possibility of any violation of the transmission of confidential data between the computer system and the data storage device and thus further enhances security of the data transmission via the adapter kit.
In a particular embodiment, the data storage device is a USB RBC class device.
In a particular embodiment, a system of at least two adapter kits is provided, wherein one of the adapter kits is an adapter kit as discussed above with reference to the particular embodiment teaching that each of the adapters contains a firmware and that the firmware of the first adapter and the firmware of the second adapter complement each other so as to enable the encryption and decryption. The other adapter kit of the system is an adapter kit as discussed above with reference to an alternative embodiment teaching that each of the adapters contains a firmware, and each of the adapters is configured to decrypt and encrypt data, and wherein the adapter kit is configured to provide decryption of the data if and only if the order of the adapters is identical during decryption and encryption.
According to the present invention, a method for encrypting and decrypting data to be transmitted to or received from a data storage device is provided. The method comprises the steps of (a) connecting the data storage device via an adapter or adapter kit to a computer system; (b') encrypting the data to be transmitted to the data storage device upon initiating a USB write command; and/or (b") decrypting the data received from a data storage device upon initiating a USB read command. The same definitions and particular embodiments as discussed above with reference to the adapter and/or the adapter kit may also be applied to the above-recited method according the present application.
In the following, the above and other aspects of the invention will be apparent from and exemplified with reference to the embodiments described hereafter. Fig. 1 schematically shows a computer system connected to a storage device via an adapter according to a particular embodiment of the present invention; Fig.2 schematically shows a computer system connected to a storage device via an adapter kit according to a particular embodiment of the present invention;
Fig.3 schematically shows a computer system connected to a storage device via an adapter kit according to a particular embodiment of the present invention.
Fig. 1 shows a computer system 10 connected to a data storage device 20 via an adapter 30. La a first embodiment, data 31 to be transmitted from the computer system 10 to the storage device 20 is received by the adapter 30, where the data is being encrypted 32. The encrypted/ciphered data 33 is then transmitted to the storage device 20. hi a second embodiment, ciphered data 34 is received by the adapter 30 from the storage device 20. Li the adapter 30, the data is being decrypted 35, and then the decrypted data 36 is transmitted to the computer system 10. Fig.2 shows a computer system 10 connected to a data storage device 20 via an adapter kit of two adapters 30, 40.
hi a first embodiment, data 31 to be transmitted from the computer 10 to the storage device 20 is received by the adapter kit, where the data is being encrypted 42. The encryption takes only place if the two adapters 30, 40 of the kit are stacked. Otherwise the functionalities (for example provided by a particular firmware) of the adapters 30, 40 cannot complement each other to provide the needed synergistic effect resulting in the encryption. After encryption, the ciphered data 43 is further transmitted to the storage device 20. hi a second embodiment, ciphered data 34 is received by the adapter kit of two adapters 30, 40 from the storage device 20. hi the adapter kit, the data is being decrypted 45, and then - l i
the decrypted data 46 is further transmitted to the computer system 10. Similar to the first embodiment of Fig. 2, the decryption takes only place if the adapter kit is complete, that means that the adapters 30, 40 of the adapter kit are stacked. Only if the adapters 30, 40 are stacked, their functionality (for example, provided by a particular firmware) is able to provide decryption as a synergistic effect.
Fig. 3 shows a computer system 10 connected to a data storage device 20 via an adapter kit of two adapters 30, 40. hi this particular embodiment, each of the adapters 30, 40 of the adapter kit is configured to provide encryption and decryption of data.
Lti a first embodiment, data 31 to be transmitted from the computer 10 to the storage device 20 is received by the first adapter 30 of the adapter kit, where the data is being encrypted 42a. hi a next step, the encrypted data 42a is transmitted to the second adapter 40, where the data 42a is further encrypted 42b. After the second encryption, the ciphered data 43 is further transmitted to the storage device 20. hi a second embodiment, the ciphered data 34 which was encrypted as explained above (by encryption 42a and 42b) is received by the adapter kit of two adapters 30, 40 from the storage device 20. In the adapter kit, the data is being decrypted 45b by the second adapter 40. After the first decryption, the data 45b is transmitted to the first adapter 30 to be further decrypted 45a, and then the decrypted data 46 is further transmitted to the computer system 10. hi this embodiment, the decryption takes only place if the adapter kit is complete and the two adapters 30, 40 are stacked/connected in the same order as during encryption. hi a particular embodiment, a system of at least two adapter kits is provided, wherein one of the adapter kits is the adapter kit shown in Fig. 2 and the other adapter kit is the adapter kit shown in Fig. 3.
Due to the above discussed invention, it maybe possible to provide a secure means, i.e. the adapter or the adapter kit, for encryption and decryption of data to be transmitted to or received from a storage device connected to a computer system via the adapter/adapter kit. Due to the physical possession of the device, additional security is provided to the authorized user, since a theft or a loss of the adapter would be recognized immediately. Hence measures necessary to avert any violation in regard to the confidential content of the storage device can also be taken immediately. Further, the use of the adapter/adapter kit to encrypt and decrypt data does not require the need of inputting a password bearing several risks as discussed above.
Furthermore, by stacking two or more adapters belonging, for example, to different users, the firmware of the adapters may be configured to complement each other in order to provide functionality of the adapter kit. In this case, the encryption/decryption only works if all necessary adapters are stacked so that the security of the encryption/decryption is further enhanced.
The present invention is advantageous for any safe handling of information in general, for example, for providing a safe personal mobile health card.
While the invention has been illustrated and described in detail in the foregoing description, such illustration and description are to be considered illustrative or exemplary and non- restrictive; the invention is thus not limited to the disclosed embodiments. Features mentioned in connection with one embodiment described herein may also be advantageous as features of another embodiment described herein without explicitly showing these features. Variations to the disclosed embodiments can be understood and effected by those skilled in the art and practicing the claimed invention, from a study of the disclosure and the appended claims, hi the claims, the word "comprising" does not exclude other elements or steps, and the indefinite article "a" or "an" does not exclude a plurality. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures can not be used to advantage.

Claims

1. Adapter kit for a computer system comprising at least two adapters, wherein each of the adapters comprises a first and a second USB port, the first USB port of each adapter provides a plug and the second USB port of each adapter provides a receptacle, wherein the plug of the second adapter is connectable to the receptacle of the first adapter, and the adapter kit is configured to provide encryption and decryption of data to be transmitted to or received from a data storage device connected via the adapter kit to the computer system.
2. Adapter kit of claim 1 , wherein the adapters are configured to provide encryption and decryption due to their connection.
3. Adapter kit of claim 1 or 2, wherein each of the adapters contains a firmware, and wherein the firmware of the first adapter and the firmware of the second adapter complement each other so as to enable the encryption and decryption.
4. Adapter kit of claim 1 or 2 or 3, wherein the encryption is on-the-fly encryption and the decryption is on-the-fly decryption.
5. Adapter kit of any one of claims 1 - 4, wherein the data storage device is a USB RBC class device.
6. Adapter kit of any one of claims 1 - 5, wherein the kit is configured to provide encryption upon a USB write command and/or to provide decryption upon a USB read command.
7. System of at least two adapter kits, wherein one adapter kit is the adapter kit of claim 3 and the other adapter kit is the adapter of claim 1 with its adapters containing a firmware, and wherein the other adapter kit is configured to provide decryption of the data if and only if the order of the adapters is identical during decryption and encryption.
8. Adapter for a computer system configured to provide encryption and decryption of data to be transmitted to or received from a data storage device connected via the adapter to the computer system.
9. Adapter of claim 8, wherein the adapter contains a firmware enabling the encryption and decryption.
10. Adapter of claim 8 or 9, wherein the encryption is on-the-fly encryption and the decryption is on-the-fly decryption.
11. Adapter of claim 8 or 9 or 10, wherein the adapter comprises two USB ports.
12. Adapter of claim 11, wherein the first of the USB ports provides a plug and the second USB port provides a receptacle.
13. Adapter of any one of claims 8 - 12, wherein the adapter is configured to provide encryption upon a USB write command.
14. Adapter of any one claims 8 - 13, wherein the adapter is configured to provide decryption upon a USB read command.
15. Adapter of any one of claims 8 - 14, wherein the data storage device is aUSB RBC class device.
16. Method for encrypting and decrypting data to be transmitted to or received from a data storage device, comprising the steps of: connecting the data storage device via an adapter or adapter kit to a computer system; encrypting the data to be transmitted to the data storage device upon initiating a USB write command; and/or decrypting the data received from a data storage device upon initiating a USB read command.
PCT/EP2009/058987 2009-07-14 2009-07-14 Stackable cryptographic adapter Ceased WO2011006533A1 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/EP2009/058987 WO2011006533A1 (en) 2009-07-14 2009-07-14 Stackable cryptographic adapter

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/EP2009/058987 WO2011006533A1 (en) 2009-07-14 2009-07-14 Stackable cryptographic adapter

Publications (1)

Publication Number Publication Date
WO2011006533A1 true WO2011006533A1 (en) 2011-01-20

Family

ID=41210414

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/EP2009/058987 Ceased WO2011006533A1 (en) 2009-07-14 2009-07-14 Stackable cryptographic adapter

Country Status (1)

Country Link
WO (1) WO2011006533A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11833038B2 (en) 2013-01-08 2023-12-05 Medtronic, Inc. Valve prosthesis and method for delivery

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070033320A1 (en) * 2005-08-05 2007-02-08 Wu Victor C Crypto pass-through dangle

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070033320A1 (en) * 2005-08-05 2007-02-08 Wu Victor C Crypto pass-through dangle

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11833038B2 (en) 2013-01-08 2023-12-05 Medtronic, Inc. Valve prosthesis and method for delivery

Similar Documents

Publication Publication Date Title
CN103020493B (en) A kind of software protection of anti-copy and running gear and method
US8694799B2 (en) System and method for protection of content stored in a storage device
CN107563213B (en) A security and confidentiality control device for preventing data extraction from storage equipment
GB2462442A (en) A remote server centrally controls access to data stored in a data container in an encrypted form
CN102831346B (en) A kind of file protecting system carries out the method for file encryption-decryption
US8689011B2 (en) System and method for content protection
US12255879B2 (en) Secure application processing systems and methods
CN105247833A (en) Self-authentication device and method
CN102270182B (en) Encrypted mobile storage equipment based on synchronous user and host machine authentication
US11531626B2 (en) System and method to protect digital content on external storage
TW201738802A (en) A removable security device and a method to prevent unauthorized exploitation and control access to files
US20090024844A1 (en) Terminal And Method For Receiving Data In A Network
US20210367780A1 (en) Adapter apparatus and processing method
KR101043255B1 (en) USB hub security device and data security method using the same
WO2011006533A1 (en) Stackable cryptographic adapter
KR101276217B1 (en) Data recovery system and method for hard disk using encryption scheme
JP2008005408A (en) Recording data processing device
US20140223195A1 (en) Encrypted Storage Device for Personal Information
CN101478538A (en) Storage method, apparatus or system for safety management device
JPH0498552A (en) Electronic filing device
JP4574108B2 (en) Data protection device
TWI892774B (en) Self-encrypting storage device and operation method thereof
CN101324866A (en) Data access method for preventing password from being cracked
CN201965622U (en) Encryption adapter for data storage equipment
KR20200082187A (en) Secure usb dongle for usb memory without security

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09780564

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 25/04/2012)

122 Ep: pct application non-entry in european phase

Ref document number: 09780564

Country of ref document: EP

Kind code of ref document: A1