Split-Sensitive Data Storage for Transaction Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The secure storage of sensitive information, such as credit card numbers, is vulnerable to theft due to the risk of data breaches and unauthorized access, as organizations store complete information to facilitate convenient transactions, making it difficult to balance security and convenience.

Innovation Solution

A system divides sensitive information into two parts, storing one part on a client system and the other on a remote server, with neither system holding the complete information, and using encryption and secure hash functions to ensure that the information can only be reconstructed for transactions, then destroyed, minimizing the risk of theft.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If complete customer information is stored locally to facilitate convenient transactions, then transaction efficiency is improved, but security vulnerability increases

Engineering Contradiction:
Improvetransaction efficiencyVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the credit card number into two separate parts: the first part (e.g., first four digits) is stored on the client system, while the second part (e.g., last four digits) is stored on the remote server. This segmentation ensures that no single system holds the complete credit card number, thereby reducing security vulnerability while still enabling transactions to proceed efficiently when both parts are combined during the transaction process.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If complete credit card information is stored to avoid re-entry, then customer convenience is improved, but risk of information theft increases

Engineering Contradiction:
Improvecustomer convenienceVSAvoidrisk of information theft
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The credit card number is segmented into two portions stored at different locations. The client system stores only the first part, and the remote server stores only the second part. During transactions, both parts are temporarily combined to process the transaction, then discarded. This maintains customer convenience by avoiding re-entry while minimizing the risk of information theft since neither system holds the complete number.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the second part of the credit card number from the complete number and stores it separately on a remote server, removing it from the client system's storage. This extraction ensures that the client system never holds the complete credit card number, reducing the risk of information theft while still enabling convenient transactions through the coordinated use of both stored parts.

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If data is divided into parts and stored separately, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The credit card number is divided into two manageable parts stored at different locations. The client system stores the first part locally, while the remote server stores the second part. This segmentation provides enhanced security by ensuring that complete credit card numbers are never stored or transmitted between systems, while the complexity increase is minimized through a straightforward split-storage architecture that requires only basic coordination during transactions.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7698560B2Information storage system
Publication Date: 2010.04.13 ENDRESZ ALLAN
  • US7698560B2 patent drawing
  • US7698560B2 patent drawing
  • US7698560B2 patent drawing

AI summary

A system for storing information having a predetermined use which requires the information to be secured. The information may comprise credit card details used to complete a transaction. The system includes: (a) A client system for storing an encoded version of the information and an identifier. The encoded version is generated from first data of the information and an encoded version of the second data of the information. The information can be generated from the first data and the second data, and the predetermined use is infeasible with only one of the first data and the second data, (b) A remote server for storing the second data and an encoded identifier generated from the identifier. The client system sends at least the encoded version of the second data to the remote server. The client system or the remote server is able to generate the information from the first data and the second data. Accordingly, only part of the information to be secured is stored locally on the client system, whilst the other part is stored on the remote server, and neither the client system nor the remote server have a record of the entire information.