Encrypted Search Configuration File Directing Uninstalled Search Agent
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for searching and collecting electronically stored information in legal proceedings are costly, technically demanding, and risk modifying or destroying evidence, particularly due to the need for extensive technical expertise and potential tampering concerns when installing search applications on target computer systems.
Innovation Solution
A method and system that utilize a search configuration application to generate an encrypted search configuration file, which directs a search agent that operates without installation on the target computer system, ensuring minimal user interaction and preventing unauthorized access to search parameters and results through encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a search application is installed on the target computer system to search for electronically stored information, then the search can be performed with full access to the system, but the system is modified which may constitute tampering with evidence and increases the risk of destroying original data
Solution Approach 1:
The patent creates a duplicate copy of the target computer system's storage device and performs the search on the copy rather than the original. This allows full search capability while preserving the original evidence unchanged, eliminating the tampering risk associated with installing search applications on the target system.
Solution Approach 2:
The patent introduces an intermediary imaging process that acts as a buffer between the search application and the original evidence. The search is performed on the image/copy rather than directly on the original system, mediating the interaction to prevent modification of the original data.
2Reliability
If imaging tools are used to create duplicates of storage devices for searching, then the original system remains unmodified, but extensive technical expertise is required which increases costs
Solution Approach 1:
The patent implements automated imaging and search capabilities that can be performed without requiring extensive technical expertise. The system provides self-service functionality through automated processes that reduce the need for skilled operators, thereby reducing costs while maintaining evidence integrity.
Solution Approach 2:
The patent performs preliminary automated preparation of search environments and configurations before the actual search begins. This preliminary action includes setting up the imaging process and search parameters in advance, which simplifies the subsequent search operation and reduces the technical expertise needed during execution.
3Measurement precision
If multiple people are involved in the process (one to create images, another to search), then specialized skills are utilized, but costs increase
Solution Approach 1:
The patent creates a multi-functional system that combines both imaging and search capabilities in a single integrated tool. This allows one person to perform both functions rather than requiring separate specialists, improving cost efficiency while maintaining search capability through the universal design of the search application.
4Reliability
If the target computer system is imaged for searching, then the original evidence is protected from modification, but the targeted computer system may be temporarily rendered inoperative
Solution Approach 1:
The patent applies local quality by performing the imaging operation only on the storage device rather than the entire computer system. This allows the search to be conducted on the imaged storage device while the target computer system remains operational for other purposes, maintaining system availability while protecting evidence integrity.
Data Source
AI summary
A method and system for searching and collecting electronically stored information are described. Consistent with an embodiment of the invention, configuration and execution of a search are separated in time and location. For example, a search configuration application executing at a first computer system is utilized to generate a search configuration file, which controls the operation of a search agent when the search agent is executing at a target computer system and performing a search of storage devices act of the target computer system. Encryption is utilized to prevent unauthorized access to the search configuration file as well as the search results file generated by the search agent.


