Archived Data Versioning and Retention Locks Against Ransomware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data archiving systems are vulnerable to ransomware attacks, especially in cloud storage, as they lack effective protection mechanisms without relying on separate backups, which are often unavailable or compromised.

Innovation Solution

Implementing an anti-attack archive store with versioning and retention locks in cloud storage systems to create a new version of data upon attempted changes and apply locks to the original, coupled with notification to IT operations systems for remedial actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data is stored in cloud storage without separate backups, then storage efficiency is improved, but vulnerability to ransomware attacks increases

Engineering Contradiction:
Improvestorage efficiencyVSAvoidprotection against ransomware
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system segments data into multiple versions stored in the cloud storage hierarchy. When ransomware attempts to encrypt data, the system creates a new version segment that remains protected while the encrypted version becomes isolated. This segmentation allows the system to maintain storage efficiency while providing protection through version isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by automatically creating versions of data before ransomware can encrypt it. The versioning mechanism is pre-configured in the cloud storage system, so when encryption is detected, a protected version already exists and can be restored to, eliminating the need for separate backup infrastructure.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional backup systems are used, then protection against ransomware is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improveprotection against ransomwareVSAvoidbackup infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges the backup function with the primary cloud storage system by utilizing the cloud provider's native versioning capabilities. Instead of maintaining separate backup infrastructure, the protection mechanism is integrated into the storage system itself, reducing device complexity while maintaining ransomware protection through automatic version creation and retention policies.

Inventive Principle:
Principle #5Merging (Combining)

3Quantity of substance

If data is archived in cloud storage, then storage cost is reduced, but security against cyberattacks deteriorates

Engineering Contradiction:
Improvestorage costVSAvoidsecurity against cyberattacks
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The cloud storage versioning system acts as an intermediary between the archived data and potential ransomware attacks. When encryption is detected, the versioning mechanism creates an intermediate protected copy that prevents the ransomware from affecting the original archived data, thereby maintaining security while using cost-effective cloud storage for archiving.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250272388A1Ransomware protection for archived data
Publication Date: 2025.08.28 OPEN TEXT SA ULC
  • US20250272388A1 patent drawing
  • US20250272388A1 patent drawing
  • US20250272388A1 patent drawing

AI summary

A computer-implemented method for protection of archival data is provided. The computer-implement method can comprise creating a first version of an object in an anti-attack store and storing an archival file in the object in the anti-attack store. The anti-attack store has associated anti-attack functionality triggerable based on detecting an attempted change to the object in the anti-attack store. The associated anti-attack functionality comprises automatically creating a new version of the object and automatically applying a retention lock to the first version of the object without applying the attempted change to the first version of the object, the retention lock specifying a retention period for the first version of the object.