Digital Artifact Segmentation for Secure Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure server systems face vulnerabilities in tracking and managing access to digital artifacts, as compromised servers can exploit disk allocation methods to identify artifacts, and encryption strategies can be weakened, leading to potential disclosure of sensitive information, along with difficulties in tracing access origins and authenticity verification.
Innovation Solution
A system that partitions digital artifacts into segments with varying sensitivity levels, encrypts each segment accordingly, and randomly stores them across multiple storage units, using a multidimensional approach to obscure content and track access through unique access points and context identifiers, ensuring secure storage and access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital artifacts are stored in encrypted files on secure servers, then security is improved, but tracking and managing access becomes difficult
Solution Approach 1:
The patent divides digital artifacts into multiple segments and stores them as separate encrypted files on the secure server. Each segment is associated with metadata including context identifiers and access tracking information. This segmentation allows the system to maintain security through encryption while enabling granular tracking of access to individual segments, resolving the contradiction between security and access tracking capability.
2Ease of operation
If disk allocation and file tracking methods are used to manage secure servers, then file management is improved, but security is worsened because these methods can be exploited to identify artifacts
Solution Approach 1:
The patent applies different quality characteristics to different parts of the storage system. Encrypted artifact segments are stored with obfuscated filenames that do not reveal artifact identities, while metadata files containing access tracking information are stored separately with different access controls. This local differentiation allows efficient file management through metadata while maintaining security by preventing filename-based identification of artifacts.
3Reliability
If encryption strategies are used to protect artifact contents, then security is improved, but vulnerability to focused attacks increases
Solution Approach 1:
By dividing artifacts into multiple encrypted segments and distributing them across the storage system, the patent increases the effort required for focused attacks. An attacker would need to compromise multiple storage locations and decrypt multiple segments to reconstruct the full artifact, rather than targeting a single encrypted file. This segmentation multiplies the security defenses against focused attacks.
4Loss of information
If redaction is used to disclose artifact contents, then information control is improved, but inadvertent disclosure risk increases
Solution Approach 1:
The patent extracts sensitive information control into a separate layer through metadata associated with each artifact segment. The metadata includes context identifiers and access permissions that control disclosure without requiring redaction of the actual content. This separation allows the system to maintain information control through structured metadata while reducing the risks associated with manual redaction processes.
Data Source
AI summary
According to an embodiment of the present invention, a system provides secure access to a digital item and includes at least one processor. The system partitions the digital item into a plurality of segments each containing a portion of the digital item and associated with a corresponding sensitivity level. The portion of the digital item within each segment is encrypted in accordance with the corresponding sensitivity level, and the plurality of segments are randomly stored among a plurality of storage units. Embodiments of the present invention further include a method and computer program product for providing secure access to a digital item in substantially the same manner described above.


