Virtual Execution Framework for Secure External Data Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Financial institutions face challenges in securely aggregating and externally storing data due to risks of information leakage, especially when sharing proprietary information, and existing solutions either rely on costly centralized mechanisms or lack control over data processing and communication.
Innovation Solution
A virtual execution framework based on virtual machines (VMs) is used to control data processing and communication, allowing financial institutions to apply encryption and decryption independently, thereby minimizing information leakage risks and enabling secure external storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If data is aggregated and stored externally to save costs, then storage costs are reduced, but information leakage risk increases
Solution Approach 1:
The patent divides data into multiple fragments and distributes them across different storage locations. No single location contains the complete original data, which prevents information leakage even if one storage point is compromised. This segmentation allows external storage while maintaining security.
Solution Approach 2:
The patent introduces an intermediary mechanism that controls access to distributed data fragments. This intermediary layer manages the reconstruction and access of original data, ensuring that only authorized entities can retrieve complete information, thus reducing information leakage risk during external storage operations.
2Reliability
If a centralized trusted institution is used for data aggregation, then security is improved, but operational costs increase
Solution Approach 1:
Instead of relying on a single centralized trusted institution, the patent segments data across multiple storage locations. This distributed approach eliminates the need for expensive centralized infrastructure while maintaining security through the principle that no single point holds complete sensitive information.
Solution Approach 2:
The patent enables participating institutions to independently manage and control their own data fragments with autonomous encryption and access control. This self-service capability removes dependence on expensive centralized trusted institutions while maintaining security through distributed control mechanisms.
3Reliability
If original data is kept confidential through centralized control, then information leakage is prevented, but data processing flexibility is reduced
Solution Approach 1:
The patent segments data while maintaining processing flexibility through distributed computation. Each fragment can be processed independently at different locations, and results are aggregated to produce final outcomes. This enables adaptable data processing without compromising confidentiality, as no single entity accesses complete original data.
Solution Approach 2:
The patent moves data processing from a centralized vertical model to a distributed horizontal model. Multiple processing entities operate in parallel on different data fragments, increasing processing freedom and adaptability while maintaining confidentiality through the distributed architecture.
Data Source
AI summary
A method is provided to process data so that the data can be externally stored with minimized risk of information leakage. A framework (virtual execution framework) based on virtual machines (VMs) is utilized as a substitute for a trusted institution. Encryption of consolidated data can reduce risk of information leakage and enhance security. Since the virtual execution framework can control connection and direction of communication, financial institutions are allowed to apply encryption to data on their own, which makes the data further appropriate for external storage. By allowing financial institutions to apply their own decryption, it is possible to prevent one of two financial institutions from retrieving externally stored data into the external execution framework without intervention of the other. Additionally, associated acting subjects can be provided with freedom depending on the degree of information leakage risk.


