Dynamic Data Concealment via Randomized File Relocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security measures are inadequate in preventing unauthorized access and cryptographic attacks, as attackers can still identify and target encrypted data within secure networks, even with perimeter security in place, due to the limitations of static security techniques and the potential for insider threats.

Innovation Solution

A continuous concealment process that obfuscates and dynamically moves data across a distributed data store, creating multiple obfuscated data files that are randomly renamed and distributed across multiple computing devices, making it impractically difficult for attackers to identify and access the target data, even if they gain access to the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static security measures such as firewalls and encryption are used, then data protection is provided, but attackers can still identify and target encrypted data within the network

Engineering Contradiction:
Improvedata protectionVSAvoiddata identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements dynamic data concealment by continuously moving encrypted data files to different locations and randomly renaming them. This transforms the static security approach into a dynamic system where data location and identity constantly change, making it extremely difficult for attackers to identify and target specific encrypted files even when they have network access

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by pre-obfuscating data files with random names and continuously moving them to different locations before attackers can identify them. This proactive concealment ensures that even if attackers gain network access, the target data remains hidden and unidentifiable

Inventive Principle:
Principle #10Preliminary action

2Reliability

If data is encrypted and stored in a data store, then data security is improved, but attackers can still locate and target the encrypted data files

Engineering Contradiction:
Improvedata securityVSAvoiddata targeting
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies the principle of color changes by randomly renaming data files with unpredictable identifiers that change over time. This is analogous to changing the visual appearance of an object to prevent recognition. The random names act as changing identifiers that make it impossible for attackers to recognize or target specific data files based on their names or locations

Inventive Principle:
Principle #32Color changes

3Reliability

If perimeter security is implemented, then unauthorized entry is prevented, but inside attackers with authorized access can still obtain sensitive data

Engineering Contradiction:
Improveperimeter securityVSAvoidinsider threats
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent segments the data protection strategy into multiple independent layers: encryption of data content, continuous random renaming of files, and frequent relocation to different storage locations. This segmentation ensures that even if one layer (perimeter security) is compromised by insider attackers, the other layers (dynamic concealment and encryption) remain intact and continue to protect the data

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10642786B2Security via data concealment using integrated circuits
Publication Date: 2020.05.05 CRYPTOMOVE INC
  • US10642786B2 patent drawing
  • US10642786B2 patent drawing
  • US10642786B2 patent drawing

AI summary

Methods, apparatuses, and embodiments related to improving security of data that is stored and distributed over a data network. In an example, source data to be protected is partitioned into multiple files, and each file is obfuscated, such as by being encrypted, to created multiple obfuscated data files. Information as to how each obfuscated data file was obfuscated is stored in an associated trace file. The multiple obfuscated data files are moved around a data network via a data movement process that includes sending each of the multiple obfuscated data files to a different randomly selected computer, where the computer further obfuscates the obfuscated data the trace file, and sends the further obfuscated data and trace file to a next randomly selected computer. In an example, the various operations for improving security may be performed by an integrated circuit, such as a system-on-chip (SoC) or application-specific integrated circuit (ASIC).