Standalone Storage Device with Multi-Layer Biometric Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage systems are vulnerable to unauthorized access due to reliance on communication channels like Wi-Fi and Bluetooth, and they lack effective methods to secure data based on its complexity and importance, compromising confidentiality, integrity, and accessibility.

Innovation Solution

A stand-alone portable storage device that operates independently, using a touchscreen keypad for manual data entry, storing data locally without communication, and employing a multi-layered fingerprint access system with primary and recovery access options to ensure only the owner can access the data, with features like low battery alerts and reminder settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If communication channels like Wi-Fi and Bluetooth are used for data storage and access, then accessibility and convenience are improved, but security and confidentiality are worsened due to vulnerability to unauthorized access

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent removes communication modules (Wi-Fi, Bluetooth) from the data storage device, extracting the vulnerable communication functionality while retaining the core storage function. This creates a physically isolated storage device that cannot be accessed remotely, eliminating the security risks associated with network communication while preserving local data accessibility.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a multi-layer authentication system as an intermediary between the user and stored data. This includes biometric authentication (fingerprint, iris, face recognition), PIN codes, and encryption keys that mediate access requests, ensuring that only authorized users can access data even though the device itself is highly accessible.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a single password authentication method is used for all data, then ease of operation is improved, but security is worsened because all data becomes equally vulnerable

Engineering Contradiction:
Improveauthentication simplicityVSAvoiddata protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication system into multiple independent layers: biometric authentication layer, PIN code layer, encryption key layer, and data-specific access codes. Each layer provides a different level of security for different types of data, allowing users to apply stronger authentication to more sensitive data while maintaining ease of access for less sensitive information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different authentication methods and security levels to different data items based on their sensitivity and importance. Critical data requires multiple authentication factors and complex access codes, while less sensitive data can be accessed with simpler methods. This creates locally optimized security for each data element rather than a uniform approach.

Inventive Principle:
Principle #3Local quality

3Reliability

If multiple security control options are implemented, then data protection is improved, but device complexity and ease of operation are worsened

Engineering Contradiction:
Improvedata confidentialityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a dynamic authentication system that adapts the required security level based on the data being accessed, user credentials, and security policies. The system automatically adjusts the authentication challenge complexity, requiring more factors for sensitive operations and fewer for routine access, thereby managing complexity dynamically rather than statically.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables users to self-configure their own authentication methods and security preferences through an intuitive interface. Users can register multiple biometric identifiers, set preferred authentication methods for different data types, and manage their own access codes, reducing the burden on the system to manage complex authentication for all users uniformly.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If data is stored in connected systems, then accessibility is improved, but integrity and confidentiality are worsened due to potential breaches in the network

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the data storage function from networked systems and implements it in a standalone device with no network communication capabilities. This physical isolation ensures data integrity by eliminating network-based attack vectors while maintaining accessibility through local device access and secure data retrieval protocols.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11341268B2System and method for storing digital data with enhanced privacy
Publication Date: 2022.05.24 RAJESH TERGAON MUNAVALLI DEMANNA
  • US11341268B2 patent drawing
  • US11341268B2 patent drawing
  • US11341268B2 patent drawing

AI summary

The present invention provides a storage device (100) which consists of multiple access levels to access data or information depending on its importance, usefulness, severity, criticality and vulnerability. Further, the storage device (100) ensures data protection through confidentiality, integrity and accessibility for information security by disabling any connection with external communication channels such as Wi-Fi, Bluetooth and so on. Further, the storage device (100) is designed to erasing all the credentials data after 5 unsuccessful attempts ensuring security of the data or information. Authenticated data or information stored on the device can only be accessed by the owner of the device thereby preserving the integrity of the stored data. Reminders may be set for authentication related data which helps change the authentication credentials in time.