Information Asset Encryption With Component-Level Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information storage solutions lack long-term security, fail to provide independent encryption for individual components of assets, and are susceptible to compromise if any connected internet element is compromised, lacking discretion in access control and longevity.
Innovation Solution
An information security system that uses genuine random numbers to generate unique encryption keys, applies different security to each asset component, and stores these keys securely, independent of cloud service integrity, enabling long-term protection and discretion in access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DRM technology-based solutions are used for information storage, then security requirements such as zero-knowledge systems and individualized secure encryption are met, but the solutions are designed only for audio-video information files and do not provide long-term security across generations of computing technology
Solution Approach 1:
The patent segments information assets into separate components that can be independently encrypted and secured. Each component can have its own encryption key and access controls, allowing long-term security management where individual components can be updated or re-encrypted without affecting the entire asset, thus providing adaptability across computing generations while maintaining security
Solution Approach 2:
The patent implements dynamic key management systems that can adapt to changing security requirements and computing environments over time. Encryption keys can be rotated, updated, and managed independently for different asset components, enabling the system to maintain security viability across multiple generations of computing technology
2Reliability
If DRM technology-based solutions are applied, then access controls are enforced, but the solutions do not permit parcelling of information assets into parts with different security levels and discretionary access rules
Solution Approach 1:
The patent divides information assets into discrete components or parcels, each of which can be independently secured with different encryption levels and access rules. This segmentation enables fine-grained discretionary access control where different users can have different permissions for different components of the same asset, while maintaining overall access control security
Solution Approach 2:
The patent applies different security properties and encryption levels to different local components of information assets based on their sensitivity and access requirements. Each component can have customized security parameters, enabling discretionary access control tailored to specific parts of the asset while maintaining overall system security
3Reliability
If Public-Private Key (PPK) encryption is used for information storage, then zero-knowledge security and discretionary access management are provided, but the system has single points of failure and is not readily usable for end-consumers without additional functionality
Solution Approach 1:
The patent combines PPK encryption with additional security functionalities including asset parcelling, dynamic key management, and integrated access control systems. This merging creates a comprehensive security platform that maintains the zero-knowledge properties of PPK while adding consumer-friendly features such as simplified key management and multiple access control mechanisms, making it readily usable for end-consumers
4Ease of operation
If cloud-based storage systems are used, then information can be stored and shared, but the systems do not provide complete independent security protection and are susceptible to compromise if the provider's security is breached
Solution Approach 1:
The patent extracts the encryption and key management functions from the cloud storage provider's control and places them under user control. Encryption keys are generated and managed by the user's client device, and encrypted asset components are stored in the cloud without the provider having access to decryption capabilities. This extraction provides complete independent security protection while maintaining cloud-based storage and sharing convenience
Data Source
AI summary
Embodiments of the present disclosure provide a system and a method of providing information security to information assets of a user. The information security system provides a more secure way of collecting, retrieving and storing data in one place to the users for their own use as well as for curating and sharing their most precious information assets such as, but not limited to, personal memories and precious information with selected friends and family, both now and in the future. The information security system includes a service management system, an encryption engine, a random data source, a secure third-party storage system, and a distribution and delivery device. The information security system is hack proof as it has high cryptographic strength and maintains high security and also usability/workability for potentially many years and decades in between uses.


