Client-Side Encryption for Secure Remote Data Backup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data backup and archiving solutions for small businesses and individuals are inefficient and insecure, as they often lack the technical expertise and resources to manage reliable, geographically remote, and cost-effective data storage, making them vulnerable to data loss and unauthorized access.

Innovation Solution

A Web-Services-based data backup and archiving system that allows users to securely store data in remote facilities using client-side encryption, with the encryption key stored doubly encrypted to prevent access by service providers or storage facilities, enabling secure, reliable, and cost-effective data backup and archiving.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data is stored in mass-storage devices accessible by networked computer systems, then data backup and archiving capacity is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvedata backup and archiving capacityVSAvoidsecurity against unauthorized access
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the encryption function from the storage system and places it on the client side. Each client generates and stores its own encryption key locally, and data is encrypted before being transmitted to the remote storage facility. This extraction ensures that even though data is stored remotely in large capacity facilities, only the client with the correct key can access it, thereby maintaining security while improving backup capacity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces encryption as an intermediary mechanism between the client and the remote storage facility. The encryption key acts as a mediator that controls access to the data. The remote storage facility stores only encrypted data and cannot access the plaintext without the key, thus enabling secure remote storage with large capacity while preventing unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is stored in geographically remote locations, then reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata reliabilityVSAvoidease of data management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by having the client computer perform encryption of data before transmission to the remote facility. The client also manages its own encryption keys locally. This self-service approach ensures data is encrypted at the source without requiring complex configuration or management at the remote facility, thereby maintaining ease of operation while achieving reliable geographically distributed storage.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent segments the backup system into independent client-side encryption modules and a remote storage facility that only handles encrypted data. Each client operates independently with its own encryption key, allowing for easy operation at the client level while achieving reliability through geographic distribution. The segmentation isolates the complexity of encryption from the storage facility operations.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If client-side encryption is used, then security is improved, but device complexity deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent uses disposable encryption keys that are generated and stored locally on each client computer. These keys are simple cryptographic elements that provide strong security without requiring complex key management systems. The keys are stored in secure locations on the client and used to encrypt data before transmission, providing security while keeping the complexity manageable through the use of standard cryptographic primitives rather than complex key infrastructure.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS8041677B2Method and system for data backup
Publication Date: 2011.10.18 OPEN TEXT CORPORATION
  • US8041677B2 patent drawing
  • US8041677B2 patent drawing
  • US8041677B2 patent drawing

AI summary

Embodiments of the present invention are directed to Web-Services-based data backup and data-archiving applications that provide remote data backup and data archiving to private individuals, small businesses, and other organizations that need reliable, secure, geographically remote, and cost-effective data backup, data archiving, and backed-up and archived-data retrieval. In one embodiment of the present invention, a private or small-business client contracts with a service provider for data-backup and data-archiving services. The service provider, in turn, contracts with a remote data-storage facility to provide secure, reliable data backup and data archiving to the personal or small-business client. A client-side application is downloaded to the client computer and configured to allow the client to store locally encrypted data at the remote, data-storage facilities. Neither the service provider nor the data-storage facility can decrypt or otherwise access the information stored by the client.