Digital Artifact Segmentation for Secure Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure server systems face vulnerabilities in tracking and managing access to digital artifacts, as compromised servers can exploit disk allocation methods to identify artifacts, and encryption strategies can be weakened, leading to potential disclosure of sensitive information, along with difficulties in tracing access origins and authenticity verification.

Innovation Solution

A system that partitions digital artifacts into segments with varying sensitivity levels, encrypts each segment accordingly, and randomly stores them across multiple storage units, using a multidimensional approach to obscure content and track access through unique access points and context identifiers, ensuring secure storage and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital artifacts are stored in encrypted files on secure servers, then security is improved, but tracking and managing access becomes difficult

Engineering Contradiction:
ImprovesecurityVSAvoidaccess tracking complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides digital artifacts into multiple segments and stores them as separate encrypted files on the secure server. Each segment is associated with metadata including context identifiers and access tracking information. This segmentation allows the system to maintain security through encryption while enabling granular tracking of access to individual segments, resolving the contradiction between security and access tracking capability.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If disk allocation and file tracking methods are used to manage secure servers, then file management is improved, but security is worsened because these methods can be exploited to identify artifacts

Engineering Contradiction:
Improvefile managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies different quality characteristics to different parts of the storage system. Encrypted artifact segments are stored with obfuscated filenames that do not reveal artifact identities, while metadata files containing access tracking information are stored separately with different access controls. This local differentiation allows efficient file management through metadata while maintaining security by preventing filename-based identification of artifacts.

Inventive Principle:
Principle #3Local quality

3Reliability

If encryption strategies are used to protect artifact contents, then security is improved, but vulnerability to focused attacks increases

Engineering Contradiction:
ImprovesecurityVSAvoidfocused attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

By dividing artifacts into multiple encrypted segments and distributing them across the storage system, the patent increases the effort required for focused attacks. An attacker would need to compromise multiple storage locations and decrypt multiple segments to reconstruct the full artifact, rather than targeting a single encrypted file. This segmentation multiplies the security defenses against focused attacks.

Inventive Principle:
Principle #1Segmentation

4Loss of information

If redaction is used to disclose artifact contents, then information control is improved, but inadvertent disclosure risk increases

Engineering Contradiction:
Improveinformation controlVSAvoiddisclosure security
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent extracts sensitive information control into a separate layer through metadata associated with each artifact segment. The metadata includes context identifiers and access permissions that control disclosure without requiring redaction of the actual content. This separation allows the system to maintain information control through structured metadata while reducing the risks associated with manual redaction processes.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9245137B2Management of digital information
Publication Date: 2016.01.26 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9245137B2 patent drawing
  • US9245137B2 patent drawing
  • US9245137B2 patent drawing

AI summary

According to an embodiment of the present invention, a system provides secure access to a digital item and includes at least one processor. The system partitions the digital item into a plurality of segments each containing a portion of the digital item and associated with a corresponding sensitivity level. The portion of the digital item within each segment is encrypted in accordance with the corresponding sensitivity level, and the plurality of segments are randomly stored among a plurality of storage units. Embodiments of the present invention further include a method and computer program product for providing secure access to a digital item in substantially the same manner described above.