Secure Offline Data Streaming via Segmented Encrypted Containers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In offline environments, data sharing between devices lacks security as the safeguards present on online networks, such as firewalls and encryption, are absent, making data vulnerable to unauthorized access and copying.

Innovation Solution

A method for secure offline data sharing involves segmenting data, temporarily caching it on receiving devices in a secure, encrypted container controlled by the sending device, and authenticating receiving devices through a password exchange or secure authorization, with automatic flushing of data upon connection loss to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is shared offline between devices without network safeguards, then data accessibility and sharing capability are improved, but security and protection against unauthorized access deteriorate

Engineering Contradiction:
Improvedata sharing capabilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments data into multiple chunks or blocks before distribution. Each receiving device receives only a portion of the total data set, not the complete data. This segmentation prevents any single device from having full access to the data, thereby maintaining security while enabling offline sharing capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a coordinator device as an intermediary that manages data distribution. The coordinator orchestrates which data chunks are sent to which receiving devices, controls access permissions, and ensures that no unauthorized device can access the complete data set. This mediator maintains security protocols even in offline environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If entire shared content is stored on receiving devices, then data accessibility is improved, but security control and prevention of unauthorized copying deteriorate

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized copying
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent divides the complete data set into multiple segments that are distributed across different receiving devices. Each device stores only a fragment of the total data, making it impossible for any single device to possess or copy the entire data set. This segmentation prevents unauthorized copying while maintaining accessibility of data portions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent assigns different data segments to different receiving devices based on specific criteria. Each device has a localized portion of the data that is useful to it, but the complete data requires aggregation from multiple devices. This local quality assignment ensures accessibility while preventing any single device from having harmful copying capability.

Inventive Principle:
Principle #3Local quality

3Reliability

If data is transmitted in segmented form to multiple devices, then security control is improved, but device complexity and coordination requirements worsen

Engineering Contradiction:
Improvedata security controlVSAvoidcoordination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs a coordinator device that centralizes the complexity of data distribution management. The coordinator handles all decisions about which data segments go to which devices, manages authentication, and orchestrates the distribution process. This intermediary absorbs the coordination complexity, keeping individual receiving devices simple while maintaining security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements automated protocols where devices can independently authenticate and receive their assigned data segments without manual intervention. The system self-manages the distribution process through predefined rules and algorithms, reducing the operational complexity for users while maintaining security through automated coordination.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3899771B1Secure offline streaming of content
Publication Date: 2023.01.25 CITRIX SYSTEMS INC
  • EP3899771B1 patent drawingFigure 1
  • EP3899771B1 patent drawingFigure 2
  • EP3899771B1 patent drawingFigure 3

AI summary

Methods, systems, and computer-readable media for secure offline transmission of a plurality of data segments from a sending device to one or more receiving devices. The sending device and the one or more receiving devices may communicate via an offline local network. A secure, encrypted container may be created at the receiving device to temporarily cache the received data segments one at a time and the encrypted storage container prevents access by one or more applications of the receiving device to data stored therein based on storage instructions from the sending device. The encrypted container may be configured to store the data segments such that less than all of the data segments are stored at the receiving device at any one time.