Distributed Data Fragmentation for Secure User Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing distributed and decentralized systems face challenges in maintaining user data security and privacy, particularly in scenarios where user computing devices are lost, corrupted, or accessed maliciously, as they often require trusting third-party service providers with sensitive credentials.

Innovation Solution

A method where user data is split into fragments and stored across multiple nodes, with only the user device initially possessing the complete data, allowing secure re-assembly on demand, even with device replacement or user death, ensuring no single entity has complete knowledge of the data and maintaining user control over their information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user data is stored in a centralized location for easy access, then ease of operation is improved, but security and privacy are worsened because third parties must be trusted with complete credentials

Engineering Contradiction:
Improveease of data accessVSAvoidsecurity risk from third-party access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent divides user credentials into multiple separate fragments and distributes them across different storage nodes. Each fragment alone is insufficient to reconstruct the complete credential, eliminating the security risk of centralized storage while maintaining accessibility through distributed retrieval mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted computing device as an intermediary that temporarily holds and manages credential fragments during authentication operations. This intermediary enables secure data access without requiring users to directly trust storage providers with complete credentials, as the trusted device controls fragment reconstruction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If credential fragments are distributed across multiple storage nodes, then security is improved, but device complexity increases due to the need for fragment management and re-assembly

Engineering Contradiction:
Improvesecurity against malicious attacksVSAvoidcomplexity of fragment management
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the system automatically handles fragment distribution, retrieval, and re-assembly operations without requiring manual user intervention. The trusted computing device autonomously manages the complex coordination of multiple fragments, reducing the perceived complexity for users while maintaining high security.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If complete user data is stored on a single device, then ease of operation is improved, but reliability is worsened because loss or corruption of the device results in permanent data loss

Engineering Contradiction:
Improvesimplicity of data storageVSAvoiddata continuity upon device loss
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

By segmenting credentials into multiple fragments stored at different locations, the patent ensures that loss or corruption of a single device does not result in complete data loss. The remaining fragments can be retrieved and re-assembled to restore credentials, significantly improving reliability while maintaining operational simplicity through automated processes.

Inventive Principle:
Principle #1Segmentation

4Loss of information

If cryptographic credentials are stored in user devices, then privacy is improved, but security is worsened because loss or malicious attacks on the device compromise access rights

Engineering Contradiction:
Improveuser privacy protectionVSAvoidvulnerability to device attacks
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent segments cryptographic credentials into multiple fragments distributed across different storage nodes, ensuring that compromise of a single device does not expose complete credentials. This segmentation maintains user privacy by limiting what any single entity can access while reducing vulnerability to attacks through distributed storage architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by storing different fragments of credentials at different locations with different security characteristics. Each storage location holds only a portion of the credential data, and the trusted computing device selectively retrieves and combines specific fragments based on authentication needs, optimizing both privacy protection and attack resistance.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11750380B2Storing and retrieving user data using joint, non-correlative, irreversible and private indexical expressions
Publication Date: 2023.09.05 SAFELISHARE INC
  • US11750380B2 patent drawing
  • US11750380B2 patent drawing
  • US11750380B2 patent drawing

AI summary

In accordance a method for storing a dataset, the dataset may be split into fragments that are distributed among different nodes of a network for storage. The fragments may then be retrieved as and when needed and re-assembled. The method allows multiple different fragments to be stored and re-assembled on demand. The dataset is initially stored in a user computing device in communication with a data storage system and a custodial entity. The fragments are stored so that no single computing entity in the storage system or the custodian ever contains or gains knowledge of all the fragments. Additionally, the user computing device that was initially in possession of the dataset and which caused the fragments to be stored in the storage system may be replaced with different user computing devices without losing the capability of storing and re-assembling the user data on demand by the replacement user computing device.