Cloud Data Quarantine and Recovery System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to proactively monitor and protect user data in cloud storage from permanent loss due to malicious activities like ransomware, often being reactive and limited to individual file scanning rather than comprehensive data storage area monitoring.

Innovation Solution

A system and method for proactive monitoring of user data in cloud storage, employing a telemetry and scanning module to identify anomalies, with multi-state quarantine capabilities and enhanced recovery mechanisms, allowing for data protection and recovery before permanent loss occurs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing malware scanners scan individual files on user devices, then file-level virus detection is achieved, but comprehensive data storage area monitoring is not provided

Engineering Contradiction:
Improvedata loss detection capabilityVSAvoidmonitoring scope
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent segments the monitoring function into two distinct components: (1) file-level scanning for individual file analysis, and (2) data storage area monitoring for comprehensive partition-level surveillance. This segmentation allows each component to specialize in its specific function, achieving both precise file detection and broad monitoring coverage simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from single-dimension file-level monitoring to multi-dimensional monitoring by adding the data storage area dimension. This enables simultaneous observation at both the file level and the partition level, providing comprehensive coverage that neither approach could achieve alone.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If systems react to data loss after it occurs, then response action is taken, but proactive prevention of data loss is not achieved

Engineering Contradiction:
Improvedata protection effectivenessVSAvoidtime for data recovery
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by continuously monitoring data storage areas for anomalies before they result in permanent data loss. The system detects suspicious activities, potential malware infections, and abnormal file changes in advance, allowing preventive measures to be taken before actual data loss occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes a feedback loop where the monitoring system continuously observes data storage areas, detects anomalies, triggers alerts, and enables preventive actions. This closed-loop feedback mechanism ensures that the system responds to potential threats in real-time, converting reactive response into proactive prevention.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If no quarantine mechanism is implemented, then data access is unrestricted, but data corruption spreads unchecked

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata corruption spread
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a quarantine mechanism as an intermediary between the monitoring system and data access operations. When potential threats are detected, the quarantine feature isolates affected data areas, acting as a mediator that prevents harmful factors from spreading while maintaining controlled access for analysis and recovery operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10678925B2Data quarantine and recovery
Publication Date: 2020.06.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10678925B2 patent drawing
  • US10678925B2 patent drawing
  • US10678925B2 patent drawing

AI summary

In some embodiments, disclosed subject matter involves proactive monitoring and detection of anomalies in user data hosted by a cloud storage server and user interaction with data to trigger quarantine of user data stored in the cloud storage. In at least one embodiment, data recovery from one or more quarantine states is available to a user after authentication. Quarantine levels may permit or prohibit various actions on the user data by the user who owns the data, an asynchronous process for data cleanup, and access by other authorized users, etc. In an embodiment, quarantine levels are associated with the user and affect the user data space rather than merely individual files. The proactive monitoring may include collection of telemetry based on the API calls to the cloud server, scanning of user file system and hierarchy, and other file or data space corruption. Other embodiments are described and claimed.