Shared Storage Network Security via Cryptographic Hash Ledger

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing collaboration systems face limitations in providing real-time, secure, and scalable data transmission for multimedia formats, with high latency and bandwidth constraints, and lack effective security measures for sensitive information, requiring expensive dedicated networks and relying on human integrity for data protection.

Innovation Solution

A system and method for real-time, secure collaboration using a shared storage network with multi-level security and encryption, allowing authorized access, persistent data logging, and encryption key management to ensure secure and efficient data exchange, enabling real-time collaboration with reduced latency and increased bandwidth while protecting sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional data guard or security firewall is used to inspect data packets, then security protection is improved, but bandwidth is limited and latency increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidbandwidth
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the security inspection function from the data path by using cryptographic hashes instead of deep packet inspection. The guard computes hashes of data blocks and stores them in a ledger, allowing security verification without examining actual data contents, thus eliminating bandwidth limitations of traditional inspection methods

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cryptographic hashes as an intermediary between the data and security verification process. Instead of directly inspecting data packets, the system uses hash values that represent the data's integrity, enabling security checks without the bandwidth overhead of examining actual data contents

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional data guard or security firewall is used to inspect data packets, then security protection is improved, but latency increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the security verification from the data path by using pre-computed cryptographic hashes. The guard verifies data integrity by comparing hashes stored in the ledger with newly computed hashes, eliminating the time-consuming deep packet inspection process while maintaining security protection

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs security preparation in advance by computing and storing cryptographic hashes of data blocks in the ledger before actual data transmission. This preliminary hashing allows for rapid verification during data exchange without the latency of real-time deep packet inspection

Inventive Principle:
Principle #10Preliminary action

3Reliability

If dedicated networks are used for collaboration, then security is improved, but cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent makes the shared storage network multi-functional by enabling it to simultaneously provide both data storage and security verification services. The cryptographic hash ledger and access control mechanisms allow the same infrastructure to serve collaboration and security functions, eliminating the need for separate dedicated secure networks

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service security through automated cryptographic hash verification and access control. The guard automatically verifies data integrity and enforces access policies without requiring manual security management or dedicated secure infrastructure, reducing operational costs while maintaining security

Inventive Principle:
Principle #25Self-service

4Reliability

If deep packet inspection is performed to review data contents, then security protection is improved, but bandwidth consumption increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts the essential security verification function from deep packet inspection by using cryptographic hashes. Instead of examining actual data contents, the system verifies integrity through hash comparisons, dramatically reducing bandwidth consumption while maintaining security protection

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the mechanical deep packet inspection process with a cryptographic verification system. Instead of manually examining data packets, the system uses mathematical hash functions to verify data integrity, eliminating the bandwidth overhead of traditional inspection methods

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP2359592B1System and method for collaboration over shared storage
Publication Date: 2019.10.02 THE BOEING CO
  • EP2359592B1 patent drawingFigure 1
  • EP2359592B1 patent drawingFigure 2
  • EP2359592B1 patent drawingFigure 3~4

AI summary

In accordance with one or more embodiments of the present disclosure, systems and methods disclosed herein enable synergy among a group of users by providing a real-time, secure collaboration environment that allows for cooperative interaction and decision making and provide the ability for users to simultaneously view, revise, and review a document or multimedia file that resides in a shared data storage location. Real-time, low latency, rich collaboration between producers and consumers provides organization efficiency, and this collaboration provides real-time, low latency transmission of data.