Decoy Data Encryption for Secure Physical Media Transfers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need to secure physical-storage-media data transfers, particularly for large or sensitive data that may be at risk of leakage during network transfers, requiring effective methods to ensure information security and prevent unauthorized access.

Innovation Solution

The solution involves combining source data with bulk decoy data, encrypting the combined dataset, and using physical media for transfer, where decoy data is generated and identified to enhance security, and physical-storage-media identifiers are used to manage and authenticate the transfer process, ensuring only authorized data is written to approved storage media.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical storage media are used for data transfer, then information security is improved, but data leakage risks increase

Engineering Contradiction:
Improveinformation securityVSAvoiddata leakage risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-registering physical storage media identifiers with a computing system before data transfer. The system maintains a log of approved media identifiers, and only pre-registered media can be used for secure data transfer. This preliminary registration and authorization process ensures that only authenticated physical media are accepted, preventing unauthorized data leakage while maintaining information security through controlled physical transfer channels.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If decoy data is combined with source data, then security against brute force attacks is improved, but data transfer complexity increases

Engineering Contradiction:
Improvesecurity against brute force attacksVSAvoiddata transfer complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses decoy data as an intermediary element that is combined with source data before encryption and transfer. The decoy data acts as a protective layer that increases the computational complexity of brute force attacks, as attackers must distinguish and discard fake data from real data. The computing system manages the decoy data through metadata catalogs that identify which portions are authentic, thereby enhancing security while maintaining manageable transfer complexity through systematic data organization.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If physical storage media are approved and tracked by identifiers, then data security is improved, but ease of operation decreases

Engineering Contradiction:
Improvedata securityVSAvoidease of physical media usage
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling the computing system to automatically verify physical storage media identifiers against its log of approved identifiers. When physical media is inserted, the system autonomously checks the identifier, determines authorization status, and either permits or denies data transfer without manual intervention. This automated self-verification process maintains high data security through strict identifier validation while improving ease of operation by eliminating manual approval steps for authorized media.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10613777B2Ensuring information security in data transfers by utilizing decoy data
Publication Date: 2020.04.07 BANK OF AMERICA CORP
  • US10613777B2 patent drawing
  • US10613777B2 patent drawing
  • US10613777B2 patent drawing

AI summary

Aspects of the disclosure relate to ensuring information security in data transfers by utilizing decoy data. A computing platform may receive, from a data source computing device, a source data collection for a secure physical-storage-media data transfer and may identify one or more transmission parameters associated with the secure physical-storage-media data transfer. Subsequently, the computing platform may generate decoy data and may produce a secure dataset for the secure physical-storage-media data transfer by combining the decoy data with the source data collection received from the data source computing device. Then, the computing platform may encrypt the secure dataset based on the one or more transmission parameters to produce an encrypted dataset for the secure physical-storage-media data transfer. After encrypting the secure dataset based on the one or more transmission parameters to produce the encrypted dataset, the computing platform may store the encrypted dataset on one or more physical media.