Individual Data Unit Segmentation for Centralized Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures for centralized user data servers are inadequate against cyber-attacks, as they do not sufficiently reduce the value of the target, making it attractive for cyber-criminals to steal large volumes of sensitive data, and current distribution methods do not significantly increase security once the central server is compromised.
Innovation Solution
Implementing individual data units (IDUs) that store user data in multiple locations, each with unique logical and physical addresses, requiring multiple components to be compromised for data access, and distributing encryption/decryption keys and access codes securely across these units.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user data is stored on a central user data server, then data access and management are simplified, but the server becomes a high-value target for cyber-attacks and a single point of failure
Solution Approach 1:
The patent segments user data by storing it across multiple individual data units (IDUs) distributed across different devices and locations, rather than centralizing it on a single server. Each IDU contains encrypted portions of user data, and no single IDU holds the complete data set, thereby eliminating the central point of failure while maintaining data accessibility through distributed architecture
2Reliability
If data is encrypted and stored on the central server, then data confidentiality is improved, but the decryption keys become a critical vulnerability target
Solution Approach 1:
The patent segments decryption keys by storing different key portions in different IDUs distributed across multiple devices. Each IDU contains only a fragment of the complete decryption key, making it computationally infeasible for attackers to compromise the entire key set even if they successfully attack individual devices or IDUs
Solution Approach 2:
The patent introduces trusted intermediaries (such as trusted execution environments or secure enclaves) that facilitate decryption operations without permanently storing complete decryption keys in accessible locations. These intermediaries temporarily hold key material only when needed for authorized decryption, reducing the window of vulnerability
3Object-affected harmful factors
If data is distributed across multiple locations, then security against cyber-attacks is improved, but system complexity and data management difficulty increase
Solution Approach 1:
The patent implements universal IDUs that can function across multiple devices and platforms, providing a standardized interface for data storage and retrieval. Each IDU is designed to be platform-agnostic and can operate in various distributed environments, simplifying the management complexity by providing consistent behavior across diverse systems
Solution Approach 2:
The patent incorporates feedback mechanisms where the distributed system automatically monitors and tracks the location, status, and accessibility of data across multiple IDUs. This feedback enables automated data management operations such as replication, synchronization, and recovery, reducing the manual complexity of managing distributed data
Data Source
AI summary
An individual data unit for enhancing the security of a user data record is provided that includes a processor and a memory configured to store data. The individual data unit is associated with a network and the memory is in communication with the processor. The memory has instructions stored thereon which, when read and executed by the processor cause the individual data unit to perform basic operations only. The basic operations include communicating securely with computing devices, computer systems, and a central user data server. Moreover, the basic operations include receiving a user data record, storing the user data record, retrieving the user data record, and transmitting the user data record. The individual data unit can be located in a geographic location associated with the user which can be different than the geographic locations of the computer systems and the central user data server.


