Secure Data Depository for Multi-Standard Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face significant administrative and financial burdens in conforming to compliance standards for data security and privacy, such as HIPAA and PCI, due to the costs associated with maintaining and accessing data in a secure manner, with no existing scheme to share these costs across multiple entities effectively.

Innovation Solution

A secure data depository assembly with multiple databases at a common location, where each database is accessible according to its associated compliance standard, using an access controller to manage access and authentication, and an auditor to maintain records, allowing shared access and reduced costs among clients.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations maintain separate secure data storage systems to comply with standards like HIPAA and PCI, then data security and compliance are ensured, but the costs of storage, maintenance, and access control become overwhelmingly burdensome for individual organizations

Engineering Contradiction:
Improvecompliance with data security standardsVSAvoidadministrative effort and costs
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple separate secure data storage systems into a single shared secure data depository where multiple organizations can store and access their sensitive data. This consolidation allows organizations to share the infrastructure costs, administrative burden, and compliance responsibilities while maintaining separate logical partitions and access controls for each organization's data.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure data depository is designed as a universal system that can serve multiple organizations and support multiple compliance standards (HIPAA, PCI, etc.) simultaneously. A single facility provides data storage, access control, security monitoring, and compliance management functions that would otherwise require separate dedicated systems for each organization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If organizations implement comprehensive access control procedures to secure sensitive data, then unauthorized access is prevented, but the administrative effort and costs to maintain proficiency with changing compliance standards increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidadministrative effort
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements automated access control mechanisms where the secure data depository itself manages authentication, authorization, and access monitoring. The system automatically enforces compliance rules and maintains security protocols without requiring continuous manual administrative intervention, reducing the time and effort needed to maintain security proficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates continuous monitoring and auditing capabilities that provide feedback on access patterns, security events, and compliance status. This automated feedback mechanism allows the system to self-adjust and maintain compliance without requiring constant manual review and updating by administrative personnel.

Inventive Principle:
Principle #23Feedback

3Productivity

If organizations store large amounts of sensitive data securely, then data availability and processing capabilities are improved, but the costs of implementing and maintaining secure storage infrastructure become prohibitively expensive

Engineering Contradiction:
Improvedata processing capabilityVSAvoidcosts
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent consolidates data storage infrastructure across multiple organizations into a shared secure data depository. This merging allows organizations to pool their resources and share the costs of maintaining secure storage infrastructure, while still providing each organization with access to large storage capacities and advanced data processing capabilities that would be prohibitively expensive individually.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7992002B2Data depository and associated methodology providing secure access pursuant to compliance standard conformity
Publication Date: 2011.08.02 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7992002B2 patent drawing
  • US7992002B2 patent drawing
  • US7992002B2 patent drawing

AI summary

A secure data depository assembly, and an associated method, provides for storage of data at a secured location forming a vault. Data associated with any of various compliance standards, such as the HIPAA (Health Insurance Portability and Accountability Act) and the PCI (Payment Card Industry) data security standard is stored at sub-vaults defined at the vault. An access controller controls access to the sub-vaults and the data stored thereat. Remote requests generated remote from the vault are routed by way of a packet data network, and, if appropriate, the access controller provides access to the vault and sub-vault contents pursuant to the request.