Secured Container Watermarking for Data Integrity Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern enterprise systems face challenges in securing data access as employees may access business data from various locations, leading to risks of data compromise due to malicious software, such as viruses and ransomware, which can encrypt data and extort ransoms, making it difficult to detect and mitigate these threats while ensuring employee productivity.

Innovation Solution

The method involves logging and validating modifications to a secured container using digital watermarks and timestamps by trusted parties, sealing the container with specific watermarking algorithms, generating reference and updated signatures, and unsealing to validate the integrity of the container, ensuring that only authorized changes are recorded and verified.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If employees access business data from various locations using different IHSs, then employee productivity is improved, but the risk of data compromise from malicious software increases

Engineering Contradiction:
Improveemployee productivityVSAvoiddata compromise risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary integrity validation of IHS components before allowing access to business data. Watermarks are embedded in components during manufacturing, and the validation system checks these watermarks in advance to ensure component integrity, preventing compromised devices from accessing data

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An intermediary validation system is introduced between the employee's IHS and the business data. This intermediary validates the integrity of IHS components through watermark verification and component state monitoring, allowing productive remote access while filtering out compromised devices

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the integrity of components is monitored to detect compromises, then data security is improved, but the complexity of validating component modifications increases

Engineering Contradiction:
Improvedata securityVSAvoidcomponent validation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The validation system is segmented into distinct functional components: watermark embedding in manufacturing, watermark verification during access, component state monitoring, and integrity validation. Each segment handles a specific aspect of security, making the overall complex system manageable through modular organization

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Watermarks serve as copies or replicas of authentication information embedded within components. Instead of validating entire components, the system validates these embedded watermark copies, simplifying the verification process while maintaining security

Inventive Principle:
Principle #26Copying

3Reliability

If access to enterprise data is revoked when component integrity cannot be validated, then data protection is improved, but employee productivity deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoidemployee productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Instead of completely blocking access when any uncertainty exists, the system performs partial validation by checking specific watermark elements and component states. This partial action approach allows access to proceed when validation is sufficient, avoiding excessive restriction while maintaining adequate protection

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10990706B2Validation of data integrity through watermarking
Publication Date: 2021.04.27 DELL PROD LP
  • US10990706B2 patent drawing
  • US10990706B2 patent drawing
  • US10990706B2 patent drawing

AI summary

Systems and methods are provided for recording and validating modifications to a secured container. Modifications to the secured container by trusted parties are logged. The log may be maintained in a secured memory of an IHS (Information Handling System) and may be periodically validated. Each logged modification specifies a timestamp of the modification and the digital watermark assigned to the trusted party making the modification. Upon completing modifications, the secured container is sealed by imprinting the first digital watermark and the first timestamp at locations in the secured container specified by a watermarking algorithm assigned to the trusted party making the modification. Additional modifications may be serially watermarked on the secured container according the watermarking algorithm of the trusted party making each modification. The secured container is unsealed by re-applying each of the watermarking algorithms in reverse order. The integrity of the secured container, and each modification, is thus validated.