Secure Synchronization via Isolated Storage Spaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies for securing intellectual property, such as remote desktop services, web-based editing tools, and digital right management, face limitations in efficiently copying and backing up electronic files while ensuring security, with issues like poor performance, high network bandwidth consumption, and user resistance to closed platforms.

Innovation Solution

A secure synchronization apparatus and method that configures an isolated space within a storage unit, accessible only via an agent program, which synchronizes objects between the isolated space and a storage server, while monitoring and preventing unauthorized input/output operations, allowing for secure intellectual property management without compromising user convenience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If remote desktop services are used to secure intellectual property, then security is improved, but network bandwidth consumption increases and performance degrades

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the storage system into an isolated space for sensitive intellectual property and a non-isolated space for general files. The isolated space is further divided into secure storage areas and shared storage areas, allowing selective synchronization. This segmentation enables the system to secure only the necessary intellectual property without restricting access to all files, thereby reducing unnecessary network bandwidth consumption while maintaining security for critical data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different regions of the storage system. The isolated space has strict access controls and encryption, while the non-isolated space has more permissive access. Within the isolated space, secure storage areas have higher security requirements than shared storage areas. This local quality differentiation allows the system to maintain high security for intellectual property while enabling convenient access and synchronization for non-sensitive files, reducing overall network bandwidth consumption.

Inventive Principle:
Principle #3Local quality

2Reliability

If digital right management technologies are used to protect electronic objects, then security is improved, but user convenience deteriorates due to closed platform control policies

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the storage system into isolated and non-isolated spaces, with the isolated space further divided into secure and shared storage areas. This segmentation allows users to access and synchronize non-sensitive files in the non-isolated space without restrictions, maintaining user convenience. Meanwhile, intellectual property in the secure storage area is protected with strict access controls, achieving security without compromising overall user convenience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different access control qualities to different regions: the isolated space has strict security controls for intellectual property, while the non-isolated space has permissive access for general files. Within the isolated space, secure storage areas have higher security than shared storage areas. This local quality differentiation ensures that users experience convenience for non-sensitive operations while intellectual property remains securely protected.

Inventive Principle:
Principle #3Local quality

3Reliability

If an isolated space is configured to secure intellectual property, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an agent program as an intermediary between the user and the storage system. The agent program automatically manages the isolated space configuration, file classification, and synchronization processes. Users interact with the agent program through simple commands, while the agent handles the complex tasks of creating isolated spaces, classifying files, and managing synchronization. This intermediary approach maintains user-friendly operation while implementing complex security measures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The agent program implements self-service functionality by automatically classifying files into isolated or non-isolated spaces based on their sensitivity, and automatically managing synchronization between devices. This automation reduces the need for users to manually configure complex security settings, thereby reducing perceived system complexity while maintaining robust security through automated isolated space management.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If all files are synchronized between devices, then data accessibility is improved, but security of intellectual property deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments files into two categories: those in the isolated space (intellectual property) and those in the non-isolated space (general files). Only files in the non-isolated space are synchronized between devices, while files in the isolated space remain localized and protected. This segmentation enables data accessibility for non-sensitive files while maintaining security for intellectual property by preventing its synchronization to less secure environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different synchronization qualities to different file regions. The non-isolated space allows full synchronization across devices for convenient access, while the isolated space maintains local-only storage with no synchronization. This local quality differentiation ensures that intellectual property remains secure and localized, while general files remain accessible across devices through synchronization.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9552365B2Secure synchronization apparatus, method, and non-transitory computer readable storage medium thereof
Publication Date: 2017.01.24 INSTITUTE FOR INFORMATION INDUSTRY
  • US9552365B2 patent drawing
  • US9552365B2 patent drawing
  • US9552365B2 patent drawing

AI summary

A secure synchronization apparatus, method, and non-transitory computer readable storage medium thereof are provided. The secure synchronization apparatus of the present invention includes a storage unit, an interface, and a processing unit. The interface is electrically connected to a storage server via a network. The processing unit is electrically connected to the storage unit and the interface. The processing unit is configured to execute an operating system and execute an agent program installed on the operating system. The agent program configures an isolated space, manages an extended space within the storage unit, and synchronizes an object between the isolated space, extended space, and the storage server through the interface. The isolated space and the extended space are only recognized by the agent program installed on the operating system and the object in the two spaces is accessible only via the agent program.