Automated Forensic Data Capture System with Selective Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in securely and reliably reviewing and auditing modifications to electronic data over time, especially for sensitive information, without hindering user access or excessively burdening bandwidth and storage resources.

Innovation Solution

An automated forensic data capture system generates and preserves records of data item modifications and access, using encryption and differentiated record types based on data sensitivity, with secure preservation and notification mechanisms to ensure integrity and compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive forensic data capture is implemented for all data items, then data integrity and audit capability are improved, but storage requirements and system resource consumption increase significantly

Engineering Contradiction:
Improvedata integrityVSAvoidstorage requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system applies different data capture strategies based on the sensitivity and criticality of individual data items. Critical and sensitive data items trigger comprehensive forensic capture with full copies and detailed metadata, while non-critical items receive minimal or no capture. This localized approach ensures high reliability for important data while significantly reducing overall storage requirements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts capture parameters based on data characteristics. By analyzing data sensitivity, criticality, and access patterns, the system modifies capture depth, retention periods, and monitoring intensity for different data types. This parameter adaptation allows comprehensive monitoring of critical data without proportionally increasing resources for all data.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If continuous monitoring and capture of data access is implemented, then audit capability and detection of improper modifications are improved, but system performance and user access speed deteriorate

Engineering Contradiction:
Improveaudit capabilityVSAvoiduser access speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system performs data capture and analysis actions in advance or asynchronously, before they impact user access performance. Forensic copies are created and metadata is captured during normal operations without blocking user requests, allowing comprehensive auditing to occur preliminarily rather than synchronously with user operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary data capture layer that operates between data storage and user access points. This intermediary component handles monitoring, copying, and analysis tasks separately from the primary data access path, enabling audit capabilities without directly interfering with user access speed through proper architectural separation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If encryption and security measures are applied to captured data records, then data security and protection against unauthorized access are improved, but computational overhead and processing time increase

Engineering Contradiction:
Improvedata securityVSAvoidcomputational overhead
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The system applies encryption and security measures selectively based on data sensitivity classification. Critical and sensitive data items receive strong encryption and enhanced security protection, while less critical data items use weaker or no encryption. This localized security approach ensures high protection for important data while minimizing computational overhead for less sensitive data.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts security parameter intensity based on data characteristics. By modifying encryption strength, key management complexity, and security monitoring intensity according to data sensitivity levels, the system achieves high security for critical data without proportionally increasing computational resources for all data.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9825763B2Systems for automated forensic data capture
Publication Date: 2017.11.21 BANK OF AMERICA CORP
  • US9825763B2 patent drawing
  • US9825763B2 patent drawing
  • US9825763B2 patent drawing

AI summary

Systems for the automated capture of forensic data information are presented. An example system may receive an access/modification request directed to a data item(s), generate an initial data capture record for the data item(s), and send the record to an isolated, secure data preservation module before granting the request. After the access/modification, the system may generate a post-access data capture record and send it to the preservation module. The system may determine the content of the generated records, based on, e.g., content of the data item(s), before generation. For example, the system may determine a first content type for records where data item(s) include critical data, and a second content type for records that do not, to, e.g., efficiently allocate system resources while minimizing any disruption to an accessing user. The system may also utilize different encryption and decryption key techniques based on, e.g., the content of the data item(s).