Cross-Perimeter Data Audit Trail Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack an effective mechanism for generating a data audit trail during cross-perimeter data transfers, particularly from an encrypted perimeter to an unencrypted perimeter, which is essential for auditing malicious activity and ensuring the security of sensitive information.

Innovation Solution

A computing device with multiple perimeters generates a data audit trail that includes an identifier, timestamp, and user ID, encrypts and decrypts data as needed, and stores the audit trail until a predetermined condition is met before sending it to a server for analysis, ensuring secure cross-perimeter data transfers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is transferred from an encrypted perimeter to an unencrypted perimeter, then data accessibility and usability are improved, but security control and audit capability deteriorate

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by generating an audit trail record before the actual data transfer occurs. The record is created with all necessary metadata (identifiers, timestamps, user IDs) in advance, ensuring security auditing is prepared before the security boundary is crossed and data becomes accessible in the unencrypted perimeter.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The audit trail record serves as an intermediary mechanism between the encrypted and unencrypted perimeters. It captures and preserves security-relevant information about the data transfer, acting as a mediator that maintains security control and audit capability even as data moves across the security boundary.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive audit trail information is collected for all data transfers, then security monitoring capability is improved, but system complexity and storage requirements worsen

Engineering Contradiction:
Improveaudit trail completenessVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The audit trail record is segmented into distinct, standardized fields (first identifier, second identifier, timestamp, user ID). This segmentation organizes complex audit information into manageable, structured components that are easier to process, store, and analyze individually while maintaining comprehensive monitoring capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes parameters by standardizing the audit trail data into specific fields with defined purposes. By transforming raw transfer information into structured parameters (identifiers, timestamps, user IDs), the system reduces complexity while maintaining measurement precision for security monitoring.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If audit trail data is stored locally until predetermined conditions are met, then data integrity and security are improved, but storage space and potential security risks worsen

Engineering Contradiction:
Improvedata integrityVSAvoidstorage space
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system implements periodic action by storing audit trail records locally until predetermined conditions are met, then transmitting them to the server. This periodic transmission cycle maintains data integrity during storage while periodically reducing local storage requirements and distributing security risk.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system performs preliminary local storage of audit records before transmission to the server. This preliminary action ensures data integrity is maintained during the initial storage phase, and only after conditions are met does the system proceed with transmission, balancing storage requirements with security considerations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9298930B2Generating a data audit trail for cross perimeter data transfer
Publication Date: 2016.03.29 MALIKIE INNOVATIONS LTD
  • US9298930B2 patent drawing
  • US9298930B2 patent drawing
  • US9298930B2 patent drawing

AI summary

A computing device is disclosed having two or more perimeters, where each perimeter is a logical separation of computing resources. A computing device and method are also disclosed for generating a data audit trail for data transfers between two perimeters.