Distributed Data Memory Unit Authentication and Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing distributed data storage systems face challenges in securing data across multiple storage units, particularly in preventing unauthorized access and ensuring that access to one storage unit does not compromise others, especially in highly secure environments like the financial sector.

Innovation Solution

A distributed data storage device design where unique electronic keys are stored in the authentication device, and an access control module manages access through a defined communication path, with an allocation table separating data units and relationships, and encryption modules securing communication between components, ensuring only authorized access and maximum protection against unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is distributed across multiple storage units to increase storage capacity and access performance, then the system can handle larger data volumes and simultaneous access requests, but the security risk increases because each storage unit becomes a potential access point that could compromise the entire system

Engineering Contradiction:
Improvedata storage capacity and access performanceVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the data storage system into multiple independent storage units, each with its own access control mechanisms. The allocation table separates data units from their relationships, and unique electronic keys are distributed to different components. This segmentation ensures that compromising one storage unit does not provide direct access to others, as each unit is isolated by cryptographic authentication barriers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an authentication device as an intermediary between access requests and storage units. This intermediary verifies unique electronic keys and manages authentication without exposing direct access paths. The sequence control acts as another intermediary that coordinates access requests through the authentication device, preventing direct communication between storage units and potential attackers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If direct access to storage units is allowed to improve access speed and reduce latency, then data retrieval is faster, but unauthorized access and manipulation become more likely

Engineering Contradiction:
Improvedata access speedVSAvoidunauthorized access and manipulation
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication actions through unique electronic keys stored in the authentication device and sequence control. Before any data access can occur, the accessing module must present valid authentication credentials. This preliminary security check is performed without significantly impacting subsequent data access speed, as the authentication overhead occurs only once per session rather than per data operation.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If allocation tables and relationship data are stored with data units in the same storage location to simplify management, then system complexity is reduced, but security is compromised because accessing one data unit reveals relationships to other units

Engineering Contradiction:
Improvesystem management complexityVSAvoiddata protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent extracts the allocation table and relationship data from the storage units and stores them separately in the sequence control. This separation ensures that even if storage units are compromised, the relationship structure remains protected. The authentication device and sequence control manage these extracted allocation data independently, maintaining security while allowing efficient data management through centralized control.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If multiple access control points are implemented to enhance security, then unauthorized access is better prevented, but system complexity and authentication overhead increase

Engineering Contradiction:
Improveaccess securityVSAvoidaccess control structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication mechanism using unique electronic keys that serve multiple functions across different storage units and access points. Rather than implementing separate access control systems for each storage unit, the same authentication device and key management structure is used universally throughout the distributed system. This multi-functional approach enhances security while avoiding the complexity of multiple independent access control implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2272199B1Distributed data memory unit
Publication Date: 2017.10.18 KISTERS FRIEDRICH
  • EP2272199B1 patent drawing
  • EP2272199B1 patent drawing
  • EP2272199B1 patent drawing

AI summary

The invention relates to a distributed data memory unit (1) comprising a plurality of memory units (2), each having memory means (15) and an access controller (14), an authentication unit (9) comprising memory means (11) and a validation unit (47), an execution controller (4) comprising an execution controller module (13) and an access verification unit (6), the execution controller (4) communicating with the memory units (2) and the authentication unit (9). At least one unambiguous electronic cipher (12) is stored in the memory means (11) of the authentication unit (9), the access verification unit (6) has an access controller module (7) and a memory unit (8). A first unambiguous cipher (10), which corresponds to a stored cipher (12) of the authentication unit (9) is stored in the memory unit (2) and an assignment table (26) is stored in the memory means (18) of the memory unit (8). The invention also relates to a method for operating a distributed data memory unit (1).