Data Security via Physical Separation of User Data and Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security methods, such as encryption and passwords, are inefficient and vulnerable to unauthorized access due to social engineering and exploitation of bugs or backdoors, failing to effectively limit access to electronic data.

Innovation Solution

A system that separates user data and its corresponding metadata onto distinct electronic devices, requiring communication between these devices to access and utilize the data, thereby conditioning access on physical possession and correct passwords, and specific communication paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data and metadata are stored on the same device, then ease of operation is improved, but data security deteriorates

Engineering Contradiction:
Improveease of data accessVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides data into two separate components: data content stored on a first device and metadata stored on a second device. This segmentation prevents unauthorized access because an attacker would need to compromise both devices simultaneously, thereby resolving the contradiction between ease of access and data security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If encryption and passwords are used, then data security is improved, but vulnerability to social engineering and exploits worsens

Engineering Contradiction:
Improvedata securityVSAvoidvulnerability to social engineering
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

By segmenting data and metadata across separate devices with different authentication mechanisms, the system eliminates the single point of failure that exists in traditional encryption systems. Even if one device's security is compromised through social engineering, the other device remains protected, resolving the vulnerability issue.

Inventive Principle:
Principle #1Segmentation

3Reliability

If data is separated from metadata, then data security is improved, but device complexity worsens

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a communication system as an intermediary that automatically manages the interaction between the two devices. This mediator handles the complexity of coordination, authentication, and data reconstruction, thereby resolving the contradiction by isolating the user from the system's inherent complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11288396B2Data security through physical separation of data
Publication Date: 2022.03.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11288396B2 patent drawing
  • US11288396B2 patent drawing
  • US11288396B2 patent drawing

AI summary

A data security method may include storing user data to a first device and storing metadata corresponding to the user data to a second device. The method may further include making a first determination that at least one device selected from the group of the first device and the second device is not in communication with a third device. The method may further include disabling utilization of the user data in response to the first determination.