Appliance Secure Data Storage and Ownership Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional IoT architectures are vulnerable to data breaches and lack owner control, as data is stored remotely in the cloud, making it susceptible to unauthorized access and alteration during ownership transfers.
Innovation Solution
An appliance with a processor, memory, and state monitoring sensors that securely stores and manages ownership, behavioral, and historical data using encryption keys, allowing owners to control access and transfer ownership while ensuring data integrity and privacy by encrypting data with symmetric keys and digitally signing it to prevent alteration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored remotely in the cloud, then data accessibility is improved, but data security and owner control deteriorate
Solution Approach 1:
The patent segments data storage across multiple locations: locally in the appliance, at edge servers, and in the cloud. Each segment serves a specific purpose - local storage provides security and owner control, edge storage enables fast retrieval, and cloud storage provides backup and long-term retention. This segmentation resolves the contradiction by allowing data to be accessible (through distributed storage) while maintaining security (through local encryption and control).
Solution Approach 2:
The patent applies preliminary action through pre-encryption of data before storage and pre-establishment of encryption keys in the appliance. Data is encrypted with owner-specific keys before being stored anywhere, and the appliance stores these keys locally to maintain control. This preliminary security measure ensures that even if cloud storage is compromised, the data remains secure and accessible only to authorized owners.
2Quantity of substance
If data is stored in the cloud, then storage capacity is improved, but data integrity and protection from alteration deteriorate
Solution Approach 1:
The patent applies preliminary anti-action by implementing digital signatures and hash verification mechanisms before data is stored in the cloud. Each data entry is cryptographically signed by the appliance, creating an immutable record. When data is retrieved, the signature is verified to ensure integrity. This preliminary protective measure prevents unauthorized alteration even though data is stored in the cloud with large capacity.
3Adaptability or versatility
If ownership transfer is enabled, then device versatility is improved, but data security and access control worsen
Solution Approach 1:
The patent implements dynamic access control through cryptographic key management that adapts to ownership changes. The appliance dynamically generates and manages encryption keys that are tied to specific owners. When ownership transfers, the cryptographic relationships are updated - the new owner receives appropriate access credentials while the appliance maintains the ability to control and audit access. This dynamic system enables versatile ownership transfer while maintaining security through cryptographic protection.
4Device complexity
If centralized cloud management is used, then system simplicity is improved, but owner control and data privacy deteriorate
Solution Approach 1:
The patent implements self-service through the appliance's autonomous cryptographic operations. The appliance independently generates encryption keys, encrypts data, manages ownership transfers, and verifies data integrity without requiring centralized cloud management for these critical functions. The cloud provides storage capacity but not control - the appliance serves itself in maintaining security and owner control, thus reducing system complexity in terms of control architecture while enhancing owner control capabilities.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
A second device associated with a second user provides, to an appliance that encrypts users private data to form encrypted users private data and stores the encrypted users private data, and that is separate from the second device, a decryption request for transfer data stored in the appliance. The transfer data includes an encrypted second key formed by encrypting a second key, wherein the second key was encrypted by a first device separate from the appliance and associated with a first user, using a public key obtained from the second device and transmitted by the first device to the appliance, wherein the first device accessed the encrypted users private data using the second key. The second device receives the transfer data from the appliance and decrypts, using a private key of the second device, the encrypted second key that was included in the transfer data received from the appliance to recover the second key, wherein the second key is capable of accessing the encrypted users private data on the appliance. The second device decrypts the encrypted users private data with the second key. The second device generates a symmetric key pair including a first symmetric key and a second symmetric key and provides the first symmetric key and the second symmetric key to the appliance. The first symmetric key is used to encrypt data only viewable by the second user of the second device while the appliance is being used by the second user.