Portable Device Data Destruction via Agent-Driven Overwriting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security methods, such as user IDs and passwords, and data encryption, are inadequate in preventing unauthorized access to sensitive information on lost or stolen portable devices, and data erasure techniques leave behind recoverable vestiges of data.

Innovation Solution

A system comprising a client, a central controller server, and a communications link, with an embedded agent that implements security rules for encryption, data destruction, and monitoring, which detects compromised devices and initiates rapid, targeted destruction of sensitive information using encryption, overwriting, and hardware disablement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data encryption is used to conceal electronic information, then data security is improved, but encryption keys may be discovered by computer driven trial and error processes

Engineering Contradiction:
Improvedata securityVSAvoidkey discovery risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing multiple encryption layers and distributing key fragments before any potential breach occurs. The hierarchical encryption structure is pre-configured with multiple key levels, and the system proactively monitors for breach attempts, resetting key material before compromise can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption system is segmented into multiple hierarchical levels with separate key material for each layer. Instead of a single encryption key, the system uses multiple keys distributed across different encryption layers, so that compromise of one key does not expose all data. This segmentation prevents single-point failure from key discovery.

Inventive Principle:
Principle #1Segmentation

2Reliability

If data erasure is performed to remove files, then data access is restricted, but vestiges of erased files remain on storage devices allowing reconstruction

Engineering Contradiction:
Improvedata protectionVSAvoiddata reconstruction risk
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system changes the parameters of data destruction by moving from simple deletion to multi-pass overwriting with different patterns. The destruction process varies parameters such as overwrite patterns (sequential, random, reverse), number of passes (multiple), and data patterns (zeros, ones, random) to ensure complete eradication of data vestiges.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The data destruction process maintains continuity by performing multiple sequential overwriting operations rather than a single deletion. The system continuously overwrites data multiple times with different patterns, ensuring that no recoverable vestiges remain after the complete destruction sequence.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS7543144B2System and method for lost data destruction of electronic data stored on portable electronic devices
Publication Date: 2009.06.02 BEACHHEAD SOLUTIONS
  • US7543144B2 patent drawing
  • US7543144B2 patent drawing
  • US7543144B2 patent drawing

AI summary

A data security system and method protects stored data from unauthorized access. According to one aspect of the invention, a client computing device communicates periodically with a server. If communications is note established between the client and the server for a selected activation interval and a subsequent grace period, the data is determined to be lost, and programmed security rules are automatically executed. Rules relating to encryption, as well as other security procedures, can be defined and entered by an administrator with access to the server, and then disseminated to each of a plurality of clients that access the server.