Adaptive Enterprise Data Protection via Root of Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection systems lack comprehensive, multi-layered security measures to effectively address emerging and persistent threats across enterprise environments, assuming a secure IT infrastructure and focusing on specific data flows rather than holistic protection.

Innovation Solution

A modular, adaptive data protection platform integrating distributed Hardware- and Software-based Root of Trust technologies with multi-dimensional data binding, real-time monitoring, and machine-learning-powered anomaly detection, utilizing permissioned blockchain for secure data access control and trust channel establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing data protection systems assume secure IT infrastructure and focus on specific data flows, then device complexity is reduced, but data protection reliability is insufficient against emerging threats

Engineering Contradiction:
Improvedata protection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments data protection into multiple layers: device-level protection via Root of Trust, data-level protection through encryption, and behavioral-level protection via monitoring agents. Each layer operates independently to provide comprehensive security without requiring complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nested security mechanisms where Root of Trust anchors are embedded within devices, encryption keys are nested within secure enclaves, and monitoring agents operate within the data plane while the control plane remains separate. This nested structure provides multi-layered protection while maintaining manageable complexity.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Measurement precision

If multi-layer, multi-domain real-time monitoring is implemented, then threat detection capability is improved, but use of energy and computational resources increases

Engineering Contradiction:
Improvethreat detection precisionVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The monitoring system implements partial monitoring by focusing on specific high-risk data flows and behaviors rather than monitoring all system activity uniformly. Machine learning models analyze only relevant features and anomalies, reducing computational overhead while maintaining high detection precision for critical threats.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

Lightweight agents are introduced as intermediaries between monitoring functions and system resources. These agents collect and filter data locally, performing preliminary analysis before transmitting only essential information to central analysis components, thereby reducing overall computational resource consumption.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If distributed Root of Trust technologies are coupled with multi-dimensional data binding, then data access control reliability is improved, but device complexity increases

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidsecurity module complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The Root of Trust anchors are designed as universal security primitives that can be deployed across diverse device types (mobile devices, servers, IoT devices) with varying capabilities. The same RoT mechanism provides authentication, encryption key management, and integrity verification across different platforms, reducing the need for device-specific security implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses cryptographic copies and representations of trust anchors rather than requiring physical duplication of security hardware. Digital certificates, cryptographic keys, and trust anchors are replicated through secure channels and verified through mathematical proofs, enabling distributed trust without physical complexity.

Inventive Principle:
Principle #26Copying

4Loss of time

If autonomous response to security risks is implemented, then response time is reduced, but automation extent increases system complexity

Engineering Contradiction:
Improvesecurity response timeVSAvoidautonomous control takeover
Core Design Contradiction:
Loss of timeVSExtent of automation

Solution Approach 1:

The system performs preliminary configuration of response actions during secure boot and initialization phases. Pre-defined response playbooks are established beforehand for common threat scenarios, allowing the system to execute predetermined countermeasures immediately upon threat detection without requiring complex real-time decision-making algorithms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The autonomous response system implements feedback loops where the results of automated actions are continuously monitored and fed back to the control plane. This allows for adaptive adjustment of response strategies and provides human operators with visibility into automated actions, reducing the perceived complexity through transparent feedback mechanisms.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3948608B1Adaptive, multi-layer enterprise data protection & resiliency platform
Publication Date: 2023.04.26 RAYTHEON CO
  • EP3948608B1 patent drawingFigure 1
  • EP3948608B1 patent drawingFigure 2
  • EP3948608B1 patent drawingFigure 3

AI summary

A system for data protection includes a first computing device comprising a security module; and a storage device coupled to the first computing device via a network interface. The security module comprises at least one of Software Root of Trust (SRoT) and Hardware Root of Trust (HRoT). The security module is further configured to: establish a trust channel between the first computing device and the storage device or storage service; monitor the first computing device and the storage device; create and enforce multi-dimensional data access control by tightly binding data access and permissions to authorized computing devices, users, applications, system services, networks, locations, and access time windows; and take over control of the storage device or storage service in response to a security risk to the system.