Executable Wrap Data Security via Segmented Controller

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage and delivery systems face challenges in securely managing digital rights and preventing piracy, as current digital rights management (DRM) schemes are not effective in controlling copying and piracy, and users are burdened with registering multiple devices to access legitimate content.

Innovation Solution

A system that includes a platform processor with associated memory and data storage, utilizing an executable wrap that secures data by requiring both the executable controller in data storage and its sister in memory to be accessible for the platform processor to access the data, with an executable sensor monitoring for anomalies and denying access if either component is missing or compromised, ensuring data is only accessible on a uniquely identified platform.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional DRM schemes are used to control piracy, then data security is improved, but user convenience deteriorates due to device registration requirements

Engineering Contradiction:
Improvedata securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments the controller into two separate components: an executable controller stored on the data storage device and a sister controller stored in the platform's memory. Both components are required simultaneously for data access, creating a segmented security architecture that prevents unauthorized access while maintaining user convenience across multiple devices.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If data is made accessible across multiple devices, then user convenience is improved, but piracy control deteriorates

Engineering Contradiction:
Improveuser convenienceVSAvoidpiracy control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The sister controller acts as an intermediary component that bridges the gap between multiple devices and the protected data. It is copied to the platform's memory and works in conjunction with the executable controller on the data storage device, enabling legitimate access across devices while maintaining security through the requirement of both components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If both executable controller and sister controller are required for data access, then piracy control is improved, but system complexity increases

Engineering Contradiction:
Improvepiracy controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service through automatic copying of the sister controller to the platform's memory and automatic verification of both controller components during data access. This automation reduces the perceived complexity for users while maintaining the dual-component security architecture.

Inventive Principle:
Principle #25Self-service

4Reliability

If executable sensor monitors for anomalies, then security is improved, but processing overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The executable sensor performs preliminary monitoring of the operating environment for anomalies before data access is granted. By detecting potential security threats in advance and preventing access when anomalies are detected, the system maintains high security while avoiding the need for continuous intensive processing during normal operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8448236B1System, method, and device for storing and delivering data
Publication Date: 2013.05.21 GEE KAROLYN
  • US8448236B1 patent drawing
  • US8448236B1 patent drawing
  • US8448236B1 patent drawing

AI summary

A system, method, and device optionally includes a server that is isolated from open networks which assigns secure random socket connections, e.g., communication ports that have randomly selected addresses that are hidden from accessing devices. Optionally, the secure random socket connections are dynamically assigned, i.e., the secure random socket connections are closed and opened with each command to access data secured by the server.