Appliance Secure Data Storage and Ownership Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional IoT architectures are vulnerable to data breaches and lack owner control, as data is stored remotely in the cloud, making it susceptible to unauthorized access and alteration during ownership transfers.

Innovation Solution

An appliance with a processor, memory, and state monitoring sensors that securely stores and manages ownership, behavioral, and historical data using encryption keys, allowing owners to control access and transfer ownership while ensuring data integrity and privacy by encrypting data with symmetric keys and digitally signing it to prevent alteration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is stored remotely in the cloud, then data accessibility is improved, but data security and owner control deteriorate

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments data storage across multiple locations: locally in the appliance, at edge servers, and in the cloud. Each segment serves a specific purpose - local storage provides security and owner control, edge storage enables fast retrieval, and cloud storage provides backup and long-term retention. This segmentation resolves the contradiction by allowing data to be accessible (through distributed storage) while maintaining security (through local encryption and control).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action through pre-encryption of data before storage and pre-establishment of encryption keys in the appliance. Data is encrypted with owner-specific keys before being stored anywhere, and the appliance stores these keys locally to maintain control. This preliminary security measure ensures that even if cloud storage is compromised, the data remains secure and accessible only to authorized owners.

Inventive Principle:
Principle #10Preliminary action

2Quantity of substance

If data is stored in the cloud, then storage capacity is improved, but data integrity and protection from alteration deteriorate

Engineering Contradiction:
Improvestorage capacityVSAvoiddata integrity
Core Design Contradiction:
Quantity of substanceVSStability of the object's composition

Solution Approach 1:

The patent applies preliminary anti-action by implementing digital signatures and hash verification mechanisms before data is stored in the cloud. Each data entry is cryptographically signed by the appliance, creating an immutable record. When data is retrieved, the signature is verified to ensure integrity. This preliminary protective measure prevents unauthorized alteration even though data is stored in the cloud with large capacity.

Inventive Principle:
Principle #9Preliminary anti-action

3Adaptability or versatility

If ownership transfer is enabled, then device versatility is improved, but data security and access control worsen

Engineering Contradiction:
Improveownership transfer capabilityVSAvoidaccess control security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic access control through cryptographic key management that adapts to ownership changes. The appliance dynamically generates and manages encryption keys that are tied to specific owners. When ownership transfers, the cryptographic relationships are updated - the new owner receives appropriate access credentials while the appliance maintains the ability to control and audit access. This dynamic system enables versatile ownership transfer while maintaining security through cryptographic protection.

Inventive Principle:
Principle #15Dynamics

4Device complexity

If centralized cloud management is used, then system simplicity is improved, but owner control and data privacy deteriorate

Engineering Contradiction:
Improvesystem architecture simplicityVSAvoidowner control
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent implements self-service through the appliance's autonomous cryptographic operations. The appliance independently generates encryption keys, encrypts data, manages ownership transfers, and verifies data integrity without requiring centralized cloud management for these critical functions. The cloud provides storage capacity but not control - the appliance serves itself in maintaining security and owner control, thus reducing system complexity in terms of control architecture while enhancing owner control capabilities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3873024B1Device using secure storage and retrieval of data
Publication Date: 2024.09.11 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP3873024B1 patent drawingFigure 1
  • EP3873024B1 patent drawingFigure 2A
  • EP3873024B1 patent drawingFigure 2B

AI summary

A second device associated with a second user provides, to an appliance that encrypts users private data to form encrypted users private data and stores the encrypted users private data, and that is separate from the second device, a decryption request for transfer data stored in the appliance. The transfer data includes an encrypted second key formed by encrypting a second key, wherein the second key was encrypted by a first device separate from the appliance and associated with a first user, using a public key obtained from the second device and transmitted by the first device to the appliance, wherein the first device accessed the encrypted users private data using the second key. The second device receives the transfer data from the appliance and decrypts, using a private key of the second device, the encrypted second key that was included in the transfer data received from the appliance to recover the second key, wherein the second key is capable of accessing the encrypted users private data on the appliance. The second device decrypts the encrypted users private data with the second key. The second device generates a symmetric key pair including a first symmetric key and a second symmetric key and provides the first symmetric key and the second symmetric key to the appliance. The first symmetric key is used to encrypt data only viewable by the second user of the second device while the appliance is being used by the second user.