Partitioned Sensitive Data Assembly for Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Sensitive data installed on consumer devices or hosted remotely is vulnerable to reuse, reverse engineering, and security threats due to exposure and increased server and transmission security requirements, which compromise device functionality.

Innovation Solution

A method and system that partition sensitive data into unassembleable portions, requiring an assembly key for reassembly, with the assembled file stored only in RAM to prevent exposure and enhance security, reducing the risk of reuse and reverse engineering while improving device performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If sensitive data is installed on consumer devices, then device functionality is improved, but security vulnerability increases due to exposure to reuse and reverse engineering

Engineering Contradiction:
Improvedevice functionalityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent divides sensitive data into multiple separate portions and stores them in different locations (local device storage and remote server). These portions cannot be reassembled without an assembly key, preventing reverse engineering while maintaining device functionality through selective access to data portions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the assembly key from the main data portions and stores it separately. This key is required to reassemble the complete sensitive data, effectively removing the ability to reconstruct full data without proper authorization while allowing the device to function with partial data access.

Inventive Principle:
Principle #2Taking out (Extraction)

2Object-affected harmful factors

If sensitive data is hosted on a remote computer, then security exposure is reduced, but device functionality is compromised due to remote access time requirements

Engineering Contradiction:
Improvesecurity exposureVSAvoiddevice functionality
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent segments data into portions stored locally and remotely. Frequently accessed portions can be stored locally for quick access, while complete sensitive data remains remotely secured. This segmentation allows the device to function efficiently with local portions while maintaining security through remote storage of complete data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent allows preliminary downloading of data portions to local storage before they are needed for processing. This preliminary action reduces access time during actual use while maintaining security, as only non-sensitive portions are cached locally and the complete sensitive data remains remotely secured.

Inventive Principle:
Principle #10Preliminary action

3Speed

If complete sensitive data is stored locally, then access speed is improved, but security risk increases due to reverse engineering threats

Engineering Contradiction:
Improveaccess speedVSAvoidreverse engineering risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent divides sensitive data into multiple portions and stores them separately in local storage. Individual portions cannot be reverse engineered to reveal the complete sensitive data. The device can access these portions quickly for processing while the assembly key remains separately secured, preventing reverse engineering even if local storage is compromised.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10142106B2System and method for securing sensitive data
Publication Date: 2018.11.27 HAND HELD PRODS INC
  • US10142106B2 patent drawing
  • US10142106B2 patent drawing
  • US10142106B2 patent drawing

AI summary

An approach is provided for securing data in a technical environment. In one embodiment, a processor obtains a first file, which when executed installs a first portion of a second file and an assembly key to assemble the second file. The processor executes this first file and then obtains the second portion of the second file. The processor assembles the second file using the first portion, the second portion, and the assembly key.