Sealed Data Processing Infrastructure for Confidentiality

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data processing systems face challenges in ensuring data confidentiality, particularly from internal threats where human factors like intentional or negligent actions by system providers and employees can lead to data misuse, as technical methods are insufficient to prevent unauthorized access and manipulation.

Innovation Solution

A data processing system is designed with a sealed infrastructure that separates network, processing, and storage areas, using internal communications networks and access control units with sensor/actor units to monitor and control access, ensuring data is encrypted outside the processing area and volatile storage is used to prevent unauthorized access, with fingerprint comparisons for component authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is stored and processed in conventional data processing systems with access control, then system availability and operational efficiency are maintained, but data confidentiality is compromised due to internal threats from providers and employees

Engineering Contradiction:
Improvedata confidentialityVSAvoidinternal threats from human factor
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system is divided into three physically separated areas: network area, processing area, and storage area. Each area has restricted access and specific functions, preventing any single point of compromise from exposing the entire system. The processing area is further isolated with its own power supply and volatile storage only.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An access control unit acts as an intermediary between the processing area and other system components. It monitors and controls all access requests, verifying authentication credentials and maintaining logs. This intermediary layer prevents direct access to sensitive areas even by authorized personnel.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control systems are implemented to prevent unauthorized access, then system security is improved, but device complexity and operational overhead increase

Engineering Contradiction:
Improvesystem securityVSAvoidaccess control infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Different security measures are applied to different areas based on their specific requirements. The processing area receives the highest level of protection with physical isolation, volatile storage, and dedicated access control. The network and storage areas have appropriate security measures but less stringent than the processing area, optimizing the balance between security and complexity.

Inventive Principle:
Principle #3Local quality

3Reliability

If data is encrypted to prevent unauthorized access, then data confidentiality is improved, but processing speed and system performance deteriorate

Engineering Contradiction:
Improvedata confidentialityVSAvoiddata processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Data is encrypted before being stored or transmitted to the network and storage areas. The processing area receives pre-encrypted data, decrypts it temporarily for processing in volatile memory, and re-encrypts it before storage or transmission. This preliminary encryption approach ensures data is protected at rest and in transit while allowing fast processing when needed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11163900B2Data processing means and method for operating the same
Publication Date: 2021.11.02 IDGARD GMBH
  • US11163900B2 patent drawing
  • US11163900B2 patent drawing
  • US11163900B2 patent drawing

AI summary

A system for reliable data processing is provided, wherein the system is implemented in a sealed infrastructure, wherein the sealed infrastructure comprises at least one processing area and a storage area, wherein the network area, the processing area, and the storage area are separated from each other physically, wherein the processing area is adapted to receive data from the storage area and/or from the network area in encrypted form, to decrypt to process the received data, and to transmit the processed data in encrypted form to the storage area and/or to the network area. Further, a method for reliable processing of data in a system according to the invention is provided.