Digital Evidence Chain of Custody via Intermediary Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Public safety agencies face challenges in preserving the chain of custody for digital evidence when transferring data from portable devices to storage servers, due to limited storage and network capabilities, and the risk of data tampering or loss during reassignment of devices.
Innovation Solution
A method involving a portable device, an intermediary storage device, and a cloud server, where digitally signed metadata with a data integrity code is used to authenticate and validate the transfer of digital evidence, ensuring it is stored securely and not deleted until acknowledged by the server, thus maintaining the chain of custody.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital evidence is transferred from portable devices to storage servers, then the evidence can be stored and accessed centrally, but the chain of custody may be compromised due to limited storage and network capabilities of portable devices
Solution Approach 1:
The patent introduces an intermediary storage device that acts as a bridge between portable evidence collection devices and central cloud servers. This intermediary device with enhanced storage and network capabilities receives evidence from portable devices, performs initial validation, and then transfers it to the cloud, thereby preserving the chain of custody while overcoming the limitations of portable devices
Solution Approach 2:
The evidence transfer process is divided into multiple stages: (1) evidence collection on portable device, (2) transfer to intermediary storage device with validation, (3) transfer from intermediary to cloud server. This segmentation allows each component to perform its function optimally while maintaining overall system reliability
2Quantity of substance
If digital evidence is transferred between devices, then storage capacity can be optimized, but the risk of data tampering or loss increases
Solution Approach 1:
The system implements continuous feedback mechanisms through cryptographic hash validation at each transfer stage. The intermediary storage device receives evidence, validates its integrity using hash codes, and only accepts evidence that passes validation. This feedback loop ensures data integrity is maintained throughout the transfer process
Solution Approach 2:
Cryptographic hash codes are generated and attached to evidence before transfer begins. These preliminary integrity checks are performed in advance at the intermediary device, preventing tampered evidence from being accepted or stored, thus proactively preventing data integrity issues
3Productivity
If portable devices are reassigned to different users, then device utilization is improved, but the chain of custody for previously captured evidence may be broken
Solution Approach 1:
Evidence is copied from the portable device to the intermediary storage device before reassignment. The original evidence remains on the portable device until successfully transferred and validated, creating a duplicate that preserves the chain of custody. The portable device can then be reassigned while the evidence copy remains secure at the intermediary device
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A process for preserving chain of custody for digital evidence captured at a portable device. The portable device transmits a request to upload the digital evidence to the cloud server via an intermediary storage device. The request includes digitally signed evidence metadata with data integrity code and authentication credentials. The portable device receives a response indicating approval to upload the digital evidence to the cloud server via the intermediary storage device. The portable device transmits the digital evidence to the intermediary storage device for uploading to the cloud server, and further transmits a request for approval to delete the digital evidence from the portable device. The portable device deletes the digital evidence only after receiving a response from the cloud server indicating an approval to delete the digital evidence from the portable device.