Trusted Server Compliance Operations Secure Memory Partitions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer systems face challenges in implementing trusted compliance operations within secure computing boundaries, particularly in ensuring data integrity and authenticity across various compliance regulations such as Sarbanes Oxley, Gramm Leach Bliley, and PCI DSS, which require robust security measures to protect sensitive information.

Innovation Solution

A networked computing system architecture that includes a trusted server, request handler server, client device, and smart card, utilizing secure memory partitions and cryptographic operations to establish secure communication tunnels and digital signatures for data check-in, review, approval, audit, and deletion processes, ensuring compliance with FIPS 140 and Common Criteria standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure memory partitions and cryptographic operations are implemented to ensure data integrity and authenticity, then security and compliance reliability are improved, but system complexity increases

Engineering Contradiction:
Improvecompliance reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the computing environment into isolated secure memory partitions, separating trusted compliance operations from untrusted operations. This segmentation ensures that compliance-critical functions run in protected boundaries while maintaining overall system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted server acts as an intermediary between client devices and secure memory partitions, managing cryptographic operations and compliance workflows. This intermediary handles the complexity of security operations while presenting a simplified interface to users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If digital signatures and secure communication tunnels are used to protect sensitive information, then data security is improved, but processing time increases

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Cryptographic keys and security credentials are pre-established and stored in secure memory partitions before compliance operations begin. Secure communication tunnels are pre-configured between trusted servers and client devices, eliminating the need for time-consuming security setup during actual compliance workflows.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses cryptographic hash functions to create digital fingerprints of compliance data. These hash copies serve as efficient verification mechanisms, allowing rapid validation of data integrity without requiring repeated analysis of the entire original dataset.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If multiple compliance operations (check-in, review, approval, audit, deletion) are implemented within secure boundaries, then compliance coverage is improved, but operational complexity increases

Engineering Contradiction:
Improvecompliance coverageVSAvoidoperational complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The trusted server implements a universal compliance management system that handles multiple compliance operations (check-in, review, approval, audit, deletion) through a single integrated interface. This multi-functional approach allows diverse compliance requirements to be managed through consistent processes within secure memory partitions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Compliance operations are nested within hierarchical security boundaries: client devices communicate with trusted servers, which in turn interact with secure memory partitions containing cryptographic operations. This nested structure organizes complex compliance workflows within layered security contexts.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS8826024B2Trusted compliance operations inside secure computing boundaries
Publication Date: 2014.09.02 MARQETA INC
  • US8826024B2 patent drawing
  • US8826024B2 patent drawing
  • US8826024B2 patent drawing

AI summary

In one embodiment, a method of implementing trusted compliance operations inside secure computing boundaries comprises receiving, in a secure computing environment, a data envelope from an application operating outside the secure computing environment, the data envelope comprising data and a compliance operation command, verifying, in the secure computing environment, a signature associated with the data envelope, authenticating, in the secure computing environment, the data envelope, notarizing, in the secure computing environment, the application of the command to the data in the envelope, executing the compliance operation in the secure environment; and confirming a result of the compliance operation to a client via trusted communication tunnel.