Shared Security Appliance for Distributed Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure computing systems face challenges in providing comprehensive and adaptable physical and logical security for data processing, particularly in distributed networks, where data is vulnerable to unauthorized access and modification, and industry-specific security requirements often necessitate updates in security measures.

Innovation Solution

A secure computing device is encapsulated within a physical enclosure with a security manager, cryptographic engine, and FPGAs, providing hardware-based security algorithms, secure boot services, and erasing data upon tampering detection, while also offering modular security services and industry-specific best practices through a cloud computing infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security measures are programmed into applications independently, then each application can meet its specific security requirements, but programmers are hindered from developing and using a collective set of best practices

Engineering Contradiction:
Improvesecurity requirements complianceVSAvoidcollective best practices adoption
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a shared security utility appliance that provides universal security services to multiple applications. The appliance contains a security manager that can be configured with industry-specific security requirements and best practices, making them available to all connected applications. This allows applications to benefit from collective security expertise while maintaining their individual security compliance, resolving the contradiction between customized security requirements and collective best practices adoption.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If security requirements are updated over time, then security measures can adapt to new threats, but applications must be reprogrammed to comply with updated requirements

Engineering Contradiction:
Improvesecurity requirements updatesVSAvoidapplication reprogramming
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a shared security utility appliance as an intermediary between security requirements and applications. The appliance's security manager maintains a repository of security requirements and best practices that can be updated independently. When requirements change, the security manager automatically updates its configuration and communicates changes to connected applications through standardized interfaces, eliminating the need to reprogram applications and reducing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If data is stored in distributed networks, then data accessibility is improved, but data becomes vulnerable to unauthorized access and modification

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized access and modification
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent combines security functions into a centralized shared utility appliance that serves multiple applications in the distributed network. The appliance implements unified security policies, authentication mechanisms, and data protection measures that apply across the entire network. This merging approach maintains data accessibility throughout the distributed network while providing consistent security protection against unauthorized access and modification at the network level.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9537898B2Shared security utility appliance for secure application and data processing
Publication Date: 2017.01.03 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9537898B2 patent drawing
  • US9537898B2 patent drawing
  • US9537898B2 patent drawing

AI summary

A method is disclosed that includes registering an application with a security information technology element (ITE), where the security ITE includes a secure computing device located within a protection envelope and configured to provide security services for one or more applications. The security ITE also provides a secure processing environment for hosting applications, and includes cryptographic services and hardware acceleration. A security manager within the security ITE is configured to erase data within the protection envelope upon detecting physical tampering.