In-Computer Offline Storage for Zero Vulnerability Computing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy cybersecurity systems are unable to completely secure personally identifiable information (PII) from online risks, as data stored in networked devices remains vulnerable to attacks, and existing solutions only reduce the attack surface or encrypt data, but do not eliminate vulnerabilities.
Innovation Solution
A hardware architecture implementing In-Computer Offline Storage (ICOS) using non-volatile memory (NVM) integrated into network-connected devices, allowing users to toggle data online or offline, combined with homomorphic encryption for enhanced security, creating a zero-vulnerability computing (ZVC) paradigm.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If PII is stored in online devices for accessibility, then data availability is improved, but vulnerability to cyber attacks increases
Solution Approach 1:
The patent divides the storage system into two separate segments: an online storage component for accessibility and an offline storage component for security. The offline storage device is physically disconnected from the network, creating a secure enclave that eliminates network-based attack vectors while maintaining data accessibility through controlled online/offline switching.
Solution Approach 2:
The patent introduces an intermediary offline storage device that acts as a mediator between the online computer system and secure data storage. This intermediary device with hardware switch controls data exposure to the network, allowing selective connection that protects PII from online threats while enabling authorized access when needed.
2Object-affected harmful factors
If data is kept offline for security, then vulnerability to attacks is reduced, but data accessibility deteriorates
Solution Approach 1:
The patent implements a dynamic storage system where the offline storage device can be switched between offline and online states via a hardware switch. This dynamic capability allows the system to adapt between maximum security (offline) and maximum accessibility (online) based on user needs, rather than being fixed in one state.
Solution Approach 2:
The patent changes the connectivity parameter of the storage device from a fixed state to a variable state. By introducing a hardware switch that can toggle the device between connected and disconnected states, the system allows users to dynamically adjust the accessibility parameter according to security requirements.
3Object-affected harmful factors
If encryption is applied to protect data, then security is improved, but processing speed deteriorates
Solution Approach 1:
The patent extracts the encryption/decryption process from the online computing environment and moves it to the offline storage device. By performing cryptographic operations locally on the offline device rather than transmitting encrypted data to online systems for processing, the patent maintains security while enabling faster local access to decrypted data when the device is online.
Data Source
AI summary
A Zero Vulnerability computing (ZVC) device by providing offline data storage of Personally Identifiable Info (PII) within a networked computer without compromising any functionalities of the host computing device. A hardware switch or alternatively a software switch or a combination is proposed to provide the control of such in-computer cold storage of data to the user to instantly access offline cold data whenever required. To further secure the data using homomorphic encryption. The above objectives are achieved by: a) Non-volatile memory of NAND or NOR type made accessible to the user via available USB or SD card ports on the host device; b) a toggle switch to control the offline/online status of the stored data; c) further boosting the security of stored data by deploying fully homomorphic encryption for cold storage and creating a buffer (warm storage) between cold and hot storage using partially homomorphic encryption.


