Trusted Platform Module Authentication Codes for Data Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data integrity is compromised during transit to storage due to malicious activities, errors, or other factors, leading to potential loss of access to data.

Innovation Solution

Incorporating integrity verification data, such as message authentication codes, into the data payload before storage, and using a trusted platform module to generate and verify these codes, ensuring data integrity throughout the storage pipeline.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is stored in distributed environments without integrity verification, then storage capacity and accessibility are improved, but data integrity and reliability deteriorate due to potential modifications during transit

Engineering Contradiction:
Improvedata integrityVSAvoidstorage pipeline complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by generating integrity verification data (authentication codes) before data enters the storage pipeline. The application generates authentication codes using a trusted platform module and secret key before data transit, allowing verification to be performed later without adding complexity to the storage infrastructure itself. This resolves the contradiction by preparing verification mechanisms in advance rather than requiring complex real-time verification in the storage pipeline.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing authentication codes as a mediating element between the application and storage pipeline. These codes serve as verification tokens that travel with the data through the distributed storage system, enabling integrity verification without requiring the storage components themselves to perform complex verification operations. This maintains storage simplicity while ensuring data integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If integrity verification data is added to data payload, then data reliability is improved, but data transmission and storage efficiency deteriorate

Engineering Contradiction:
Improvedata integrityVSAvoiddata transmission efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by adding only essential integrity verification elements (authentication codes) to the data payload rather than implementing comprehensive verification mechanisms throughout the entire data structure. The authentication code is a compact cryptographic representation that provides integrity verification with minimal overhead, preserving data transmission efficiency while ensuring reliability.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If data traverses multiple intermediary entities in storage pipeline, then storage flexibility and accessibility are improved, but susceptibility to malicious modifications increases

Engineering Contradiction:
Improvestorage pipeline flexibilityVSAvoiddata modification risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback by including authentication codes that enable verification of data integrity at any point in the storage pipeline. When data is retrieved or inspected at any intermediary entity, the authentication code provides immediate feedback on whether the data has been modified during transit. This allows the system to maintain flexible multi-entity storage architecture while detecting and preventing malicious modifications through cryptographic verification.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250036813A1Managing threats to data storage in distributed environments
Publication Date: 2025.01.30 DELL PROD LP
  • US20250036813A1 patent drawing
  • US20250036813A1 patent drawing
  • US20250036813A1 patent drawing

AI summary

Methods and systems for managing data storage are disclosed. The storage of data may be managed by implementing a framework for checking whether payloads requested for storage have been modified prior to storage. The checks may be performed using integrity verification data that is based on corresponding payloads and keys. The payloads and integrity verification data may be directed to storage along a storage pipeline. The integrity of the payloads may be verified along the storage pipeline. Once received, the storage may perform the checks using the integrity verification data as a final check before storage.