Secure Synchronization via Isolated Storage Spaces
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies for securing intellectual property, such as remote desktop services, web-based editing tools, and digital right management, face limitations in efficiently copying and backing up electronic files while ensuring security, with issues like poor performance, high network bandwidth consumption, and user resistance to closed platforms.
Innovation Solution
A secure synchronization apparatus and method that configures an isolated space within a storage unit, accessible only via an agent program, which synchronizes objects between the isolated space and a storage server, while monitoring and preventing unauthorized input/output operations, allowing for secure intellectual property management without compromising user convenience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If remote desktop services are used to secure intellectual property, then security is improved, but network bandwidth consumption increases and performance degrades
Solution Approach 1:
The patent segments the storage system into an isolated space for sensitive intellectual property and a non-isolated space for general files. The isolated space is further divided into secure storage areas and shared storage areas, allowing selective synchronization. This segmentation enables the system to secure only the necessary intellectual property without restricting access to all files, thereby reducing unnecessary network bandwidth consumption while maintaining security for critical data.
Solution Approach 2:
The patent applies different security qualities to different regions of the storage system. The isolated space has strict access controls and encryption, while the non-isolated space has more permissive access. Within the isolated space, secure storage areas have higher security requirements than shared storage areas. This local quality differentiation allows the system to maintain high security for intellectual property while enabling convenient access and synchronization for non-sensitive files, reducing overall network bandwidth consumption.
2Reliability
If digital right management technologies are used to protect electronic objects, then security is improved, but user convenience deteriorates due to closed platform control policies
Solution Approach 1:
The patent segments the storage system into isolated and non-isolated spaces, with the isolated space further divided into secure and shared storage areas. This segmentation allows users to access and synchronize non-sensitive files in the non-isolated space without restrictions, maintaining user convenience. Meanwhile, intellectual property in the secure storage area is protected with strict access controls, achieving security without compromising overall user convenience.
Solution Approach 2:
The patent applies different access control qualities to different regions: the isolated space has strict security controls for intellectual property, while the non-isolated space has permissive access for general files. Within the isolated space, secure storage areas have higher security than shared storage areas. This local quality differentiation ensures that users experience convenience for non-sensitive operations while intellectual property remains securely protected.
3Reliability
If an isolated space is configured to secure intellectual property, then security is improved, but device complexity increases
Solution Approach 1:
The patent introduces an agent program as an intermediary between the user and the storage system. The agent program automatically manages the isolated space configuration, file classification, and synchronization processes. Users interact with the agent program through simple commands, while the agent handles the complex tasks of creating isolated spaces, classifying files, and managing synchronization. This intermediary approach maintains user-friendly operation while implementing complex security measures.
Solution Approach 2:
The agent program implements self-service functionality by automatically classifying files into isolated or non-isolated spaces based on their sensitivity, and automatically managing synchronization between devices. This automation reduces the need for users to manually configure complex security settings, thereby reducing perceived system complexity while maintaining robust security through automated isolated space management.
4Adaptability or versatility
If all files are synchronized between devices, then data accessibility is improved, but security of intellectual property deteriorates
Solution Approach 1:
The patent segments files into two categories: those in the isolated space (intellectual property) and those in the non-isolated space (general files). Only files in the non-isolated space are synchronized between devices, while files in the isolated space remain localized and protected. This segmentation enables data accessibility for non-sensitive files while maintaining security for intellectual property by preventing its synchronization to less secure environments.
Solution Approach 2:
The patent applies different synchronization qualities to different file regions. The non-isolated space allows full synchronization across devices for convenient access, while the isolated space maintains local-only storage with no synchronization. This local quality differentiation ensures that intellectual property remains secure and localized, while general files remain accessible across devices through synchronization.
Data Source
AI summary
A secure synchronization apparatus, method, and non-transitory computer readable storage medium thereof are provided. The secure synchronization apparatus of the present invention includes a storage unit, an interface, and a processing unit. The interface is electrically connected to a storage server via a network. The processing unit is electrically connected to the storage unit and the interface. The processing unit is configured to execute an operating system and execute an agent program installed on the operating system. The agent program configures an isolated space, manages an extended space within the storage unit, and synchronizes an object between the isolated space, extended space, and the storage server through the interface. The isolated space and the extended space are only recognized by the agent program installed on the operating system and the object in the two spaces is accessible only via the agent program.


