Virtual Execution Framework for Secure External Data Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Financial institutions face challenges in securely aggregating and externally storing data due to risks of information leakage, especially when sharing proprietary information, and existing solutions either rely on costly centralized mechanisms or lack control over data processing and communication.

Innovation Solution

A virtual execution framework based on virtual machines (VMs) is used to control data processing and communication, allowing financial institutions to apply encryption and decryption independently, thereby minimizing information leakage risks and enabling secure external storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If data is aggregated and stored externally to save costs, then storage costs are reduced, but information leakage risk increases

Engineering Contradiction:
Improvestorage costVSAvoidinformation leakage risk
Core Design Contradiction:
Loss of energyVSObject-affected harmful factors

Solution Approach 1:

The patent divides data into multiple fragments and distributes them across different storage locations. No single location contains the complete original data, which prevents information leakage even if one storage point is compromised. This segmentation allows external storage while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism that controls access to distributed data fragments. This intermediary layer manages the reconstruction and access of original data, ensuring that only authorized entities can retrieve complete information, thus reducing information leakage risk during external storage operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a centralized trusted institution is used for data aggregation, then security is improved, but operational costs increase

Engineering Contradiction:
Improvedata securityVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

Instead of relying on a single centralized trusted institution, the patent segments data across multiple storage locations. This distributed approach eliminates the need for expensive centralized infrastructure while maintaining security through the principle that no single point holds complete sensitive information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables participating institutions to independently manage and control their own data fragments with autonomous encryption and access control. This self-service capability removes dependence on expensive centralized trusted institutions while maintaining security through distributed control mechanisms.

Inventive Principle:
Principle #25Self-service

3Reliability

If original data is kept confidential through centralized control, then information leakage is prevented, but data processing flexibility is reduced

Engineering Contradiction:
ImproveconfidentialityVSAvoiddata processing freedom
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments data while maintaining processing flexibility through distributed computation. Each fragment can be processed independently at different locations, and results are aggregated to produce final outcomes. This enables adaptable data processing without compromising confidentiality, as no single entity accesses complete original data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent moves data processing from a centralized vertical model to a distributed horizontal model. Multiple processing entities operate in parallel on different data fragments, increasing processing freedom and adaptability while maintaining confidentiality through the distributed architecture.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9043933B2Method of processing data to enable external storage thereof with minimized risk of information leakage
Publication Date: 2015.05.26 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9043933B2 patent drawing
  • US9043933B2 patent drawing
  • US9043933B2 patent drawing

AI summary

A method is provided to process data so that the data can be externally stored with minimized risk of information leakage. A framework (virtual execution framework) based on virtual machines (VMs) is utilized as a substitute for a trusted institution. Encryption of consolidated data can reduce risk of information leakage and enhance security. Since the virtual execution framework can control connection and direction of communication, financial institutions are allowed to apply encryption to data on their own, which makes the data further appropriate for external storage. By allowing financial institutions to apply their own decryption, it is possible to prevent one of two financial institutions from retrieving externally stored data into the external execution framework without intervention of the other. Additionally, associated acting subjects can be provided with freedom depending on the degree of information leakage risk.