Secure Data Storage via Segmented Encryption and Dynamic Relocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication protocols for secure data storage are vulnerable to unauthorized access due to the risk of compromised passwords and the impracticality of widespread deployment of one-time password systems that require users to carry tokens or cards.

Innovation Solution

A method that combines user-authentication procedures with data segmentation, distributing sensitive information across a network and using intelligent agents to securely move and reassemble encrypted portions of data only after authenticating the user, thereby enhancing security by making it impossible for unauthorized users to locate and assemble the data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is stored in a single location for prolonged periods, then storage efficiency is improved, but security is worsened due to vulnerability to unauthorized access

Engineering Contradiction:
Improvestorage efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides sensitive data into multiple separate portions and distributes them across different network locations. Each portion alone is insufficient to reconstruct the original data, providing security while maintaining storage efficiency. This directly resolves the contradiction by eliminating the need to choose between single-location storage and distributed storage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic relocation of data portions across the network using intelligent agents. Data portions are continuously moved between different network locations based on security policies and access requests, making it difficult for unauthorized users to locate and assemble complete data sets while maintaining efficient distributed storage.

Inventive Principle:
Principle #15Dynamics

2Reliability

If one-time password systems with tokens or cards are deployed, then authentication security is improved, but ease of operation is worsened due to requirement for users to carry physical devices

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces physical token or card-based authentication systems with software-based intelligent agents that can securely traverse the network. These agents perform authentication functions without requiring users to carry physical devices, thereby maintaining high authentication security while significantly improving user convenience and enabling widespread deployment.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If data portions are constantly moved across the network, then security is improved by making location determination impossible, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces intelligent agents as intermediary components that manage the complex task of data portion relocation. These agents handle the complexity of tracking, moving, and securing data portions across the network, allowing the overall system to achieve high security without directly exposing the complexity of data management to users or other system components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8694801B2Method and computer program for securely storing data
Publication Date: 2014.04.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8694801B2 patent drawing
  • US8694801B2 patent drawing
  • US8694801B2 patent drawing

AI summary

A method of securely storing data comprising the steps of: dividing the data into a plurality of secure components; encrypting the secure components; moving each secure component to a different location which is substantially inaccessible to an unauthorized request; storing the secure components at the different locations for a period of time; repeating the moving and storing steps; moving all of the secure components to a single location in response to an authorized request; decrypting each of the secure components; and assembling the plurality of secure components to reconstruct the original data.