Affine Mapping Secure Cloud Outsourcing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing for computational outsourcing is hindered by security concerns, as cloud servers may expose sensitive user data and provide invalid or incomplete results due to lack of trustworthiness and resource optimization by administrators.
Innovation Solution
The implementation of an affine mapping-based secure outsourcing scheme that transforms computational problems into secure forms for cloud processing, ensuring the cloud cannot infer original inputs or outputs, and allows users to verify results through inverse transformations, while balancing computational complexity and security demands.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Power
If cloud servers are used for computational outsourcing, then computational power and storage resources are improved, but security and privacy of user data deteriorate
Solution Approach 1:
The system performs preliminary actions by transforming the original computational problem into a secure form before outsourcing to the cloud. The client applies secret keys and transformation algorithms to encode the input data and problem structure, ensuring that sensitive information is protected before being sent to untrusted cloud servers. This preliminary security preparation allows safe outsourcing while maintaining data confidentiality.
Solution Approach 2:
The patent introduces cryptographic intermediaries including secret keys, transformation algorithms, and verification mechanisms that mediate between the user and cloud servers. These intermediaries enable secure communication and computation by encoding data in ways that preserve confidentiality while allowing the cloud to perform legitimate computational tasks on the encoded information.
2Productivity
If cloud servers process outsourced tasks, then productivity is improved, but trustworthiness and result validity deteriorate
Solution Approach 1:
The system implements feedback mechanisms where the client can verify the correctness of cloud-computed results. Transformation algorithms are designed to allow verification of whether the cloud server performed the computation correctly on the encoded input, providing feedback that ensures result validity without requiring trust in the cloud provider. This enables productivity gains while maintaining accountability.
Solution Approach 2:
The client performs preliminary setup of verification mechanisms and encoded problem structures that enable later validation of cloud results. By preparing verification data and transformation rules before outsourcing, the system ensures that result validity can be checked afterward, addressing trustworthiness concerns while maintaining high productivity through cloud processing.
3Reliability
If affine mapping transformation is applied to protect privacy, then security is improved, but computational complexity increases
Solution Approach 1:
The patent applies parameter changes by using affine mapping transformations that modify the representation of computational problems while preserving their essential structure. The transformation changes parameters such as coordinate systems and data encoding formats in ways that protect privacy but are designed to maintain computational efficiency. The affine properties ensure that transformations can be applied and reversed with reasonable computational overhead.
4Loss of information
If secure transformation schemes are implemented, then information leakage is prevented, but communication overhead increases
Solution Approach 1:
The affine mapping transformation changes the parameters of data representation to achieve security goals while controlling communication overhead. By using efficient linear algebraic transformations, the system protects information from leakage during outsourcing while minimizing the additional communication required to transmit transformed data and verification information between client and cloud servers.
Data Source
AI summary
Systems and methods of the present invention provide for one or more server computers communicatively coupled to a network and configured to: receive a request to execute a computational task, including a transformed input used to execute a computational task. A client computer transforms the original input into the transformed input, using an affine mapping where the transformed input is a one-to-one equivalent to the original input (but which can't be inferred by the server computer), and according to a user selection limiting the computational complexity of the mapping according to resource constraints on the client. The server may then execute the computational task and transmit a result to the client to apply an inverse affine mapping, and receive a response which verifies that the computational task result is complete and valid.


