Breach Resistant Data Storage via Fragmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage systems are inadequate in protecting data from online breaches and unauthorized access, as data at rest encryption provides little to no protection once the system is online, and there is a need for a method that can secure data both online and offline while being cost-effective and easy to implement.
Innovation Solution
A breach resilient data storage system that encrypts and fragments data across multiple physically and logically separate storage containers, requiring data to be recombined and decrypted for access, using computationally expensive cryptographic methods and a large initial data set to prevent brute force attacks, ensuring that no single node has access to the complete data set.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data at rest encryption is used, then offline data breaches are prevented, but online data access provides no protection
Solution Approach 1:
The patent divides encrypted data into multiple fragments and distributes them across different storage containers. Each fragment alone is useless for decryption, requiring compromise of multiple storage nodes to access the complete data set. This segmentation approach extends protection from merely offline scenarios to online scenarios where multiple nodes would need to be breached simultaneously.
2Ease of operation
If data is stored in a centralized database, then data access is convenient, but the system is vulnerable to online dumping and mass querying
Solution Approach 1:
The patent fragments data into multiple pieces stored in separate containers, preventing online dumping attacks where an attacker compromises a single storage node. Even if one node is breached, only useless fragments are obtained without the complete decryption key or all fragments.
Solution Approach 2:
The patent introduces a decryption key mechanism as an intermediary layer between storage and data access. The key is required to reconstruct meaningful data from fragments, adding a security layer that prevents direct access even when storage nodes are compromised.
3Productivity
If all real storage locations are mapped in a single storage map, then data retrieval is efficient, but a compromised client can request all data in the system
Solution Approach 1:
The patent segments the storage location map into multiple distributed maps across different storage containers. Each container holds only a portion of the location information, preventing a single point of failure where all location data could be extracted. Clients must query multiple distributed maps to retrieve complete location information.
Data Source
AI summary
A breach resilient data storage system and method which encrypts, fragments, and stores data across a plurality of data stores, thereby requiring data being retrieved to be retrieved, recombined and decrypted before being accessible. The breach resilient data storage system and method includes, a plurality of storage containers, a client device from which data may be securely stored and securely stored data may be accessed, and a storage coordinator and a key keeper which track the encryption data and the placement and retrieval of fragmented data across the storage containers. Because the encrypted data is stored in fragmented bits, with none of the storage containers knowing what it is storing or having complete access to the complete set of data, a single compromised node in the system cannot be used to compromise the entire system or access any data.


