Air-Gapped Data Storage with Ruggedized Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for protecting and securing data are inadequate as they often rely on internet-connected systems that are vulnerable to hacking, hardware failures, and physical damage, with individual components having distinct vulnerabilities.

Innovation Solution

An air-gapped computer system is used in conjunction with ruggedized and encrypted on-site and portable storage, where data is transferred offline using a ruggedized flash drive, and only accessible with a unique encryption key, ensuring no internet connection is made during transfer, and previous versions of information are retained.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is stored on internet-connected systems for easy access, then ease of operation is improved, but vulnerability to hacking and network compromises increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidhacking vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system divides data storage into two separate segments: an air-gapped secure storage system that is physically isolated from networks, and a network-connected interface system that handles user interactions. This segmentation allows data to be accessible through the network interface while the actual sensitive data remains protected in the isolated environment, resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary air-gapped computer system that acts as a mediator between the network-connected user interface and the secure offline storage. This intermediary transfers data through physical media (USB drives, external hard drives) rather than direct network connections, enabling ease of operation through network interfaces while maintaining security through physical isolation, thus resolving the vulnerability to hacking.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If standard storage devices are used for portability, then ease of operation is improved, but vulnerability to physical damage and loss increases

Engineering Contradiction:
ImproveportabilityVSAvoidresistance to physical damage
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent employs composite protective enclosures that combine multiple materials with different properties - shock-absorbing materials, water-resistant coatings, and mechanically strong structures. This composite approach creates storage devices that maintain the portability of standard USB drives while adding comprehensive protection against physical damage, fire, flood, and mechanical force, thus resolving the contradiction between portability and reliability.

Inventive Principle:
Principle #40Composite materials

3Object-affected harmful factors

If encryption is applied to protect data, then security is improved, but ease of operation deteriorates due to key management complexity

Engineering Contradiction:
Improvedata protectionVSAvoidaccess complexity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system implements self-service automated key management where the air-gapped computer system automatically generates, stores, and manages encryption keys without requiring user intervention. The system handles key distribution through secure physical media transfer and automatically manages key rotation and retrieval processes. This automation maintains strong encryption protection while eliminating the operational complexity that would otherwise burden users, resolving the contradiction between security and ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11196718B2Method of secure data storage and transfer
Publication Date: 2021.12.07 HELLER PATRICK SCOTT
  • US11196718B2 patent drawing
  • US11196718B2 patent drawing
  • US11196718B2 patent drawing

AI summary

A method of secure data transfer and storage using a removable storage device storing encrypted information. The method uses a host that stores and transfers encrypted sensitive information and a customer that desires the information to be securely stored. The customer chooses a unique encryption code to encrypt sensitive information and places the encrypted files on the removable storage device, then physically transfers the information to the host. The encrypted sensitive information travels physically between the host and customer outside of any computer network. The host has a gapped area that remains disconnected from any network. The host takes the sensitive information and copies it to the designated armored storage unit.