Trusted Device Data Copy for Breach Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to detect data breaches in network-connected computer systems in a timely manner, leading to periods of exposure where sensitive information is compromised without immediate identification or protective actions.
Innovation Solution
A computer-implemented method using a trusted secure computing device to generate a copy of data distributed across a network, search for sensitive information, and implement protective measures upon identification of compromised data, including discrediting authentication credentials and disconnecting from the network to prevent further exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a trusted secure computing device is used to generate a copy of distributed data and search for sensitive information, then data breach detection capability is improved, but device complexity and computational resources increase
Solution Approach 1:
The patent creates a local copy of distributed data stored across multiple network locations. This copy is then searched for sensitive information without requiring continuous network access or processing of the original distributed data, significantly reducing computational resources while maintaining detection capability. The copy approach allows offline analysis and reduces the need for complex distributed querying mechanisms.
Solution Approach 2:
The trusted secure computing device acts as an intermediary between the distributed data storage system and the detection process. It consolidates data from multiple sources into a single searchable copy, simplifying the detection architecture. This intermediary approach eliminates the need for complex distributed search coordination while maintaining security through controlled access to the consolidated copy.
2Loss of time
If sensitive information is continuously monitored in distributed data, then detection speed is improved, but data loss during exposure periods increases
Solution Approach 1:
The system performs preliminary actions by creating and maintaining a local copy of distributed data that can be searched without network connectivity. This preparation enables immediate local searching when needed, eliminating detection delays caused by network latency or unavailability. The copy is ready for instant analysis, ensuring rapid detection when sensitive information exposure is suspected.
3Reliability
If authentication credentials are revoked upon detection of compromised information, then security reliability is improved, but system operation is disrupted
Solution Approach 1:
The system implements a feedback mechanism where detection of compromised sensitive information triggers automatic revocation of authentication credentials. This closed-loop approach ensures that security breaches are responded to systematically. The feedback loop continuously monitors for compromised data and automatically initiates protective actions, balancing security requirements with operational considerations through automated decision-making.
Data Source
AI summary
A computer implemented method to detect a data breach in a network-connected computing system including generating, at a trusted secure computing device, a copy of data distributed across a network; the computing device accessing sensitive information for the network-connected computer system and searching for at least part of the sensitive information in the copy of the data; in response to an identification of sensitive information in the copy of the data identifying the sensitive information as compromised sensitive information.


