Cloud Data Repository Encryption and Partitioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computing paradigms face challenges in maintaining security and efficiently indexing data on client devices as network connectivity improves, leading to increased costs and security concerns in cloud-based data storage systems.

Innovation Solution

A cloud-based data repository system utilizing symmetric and/or asymmetric cryptographic keying technology to encrypt data with user-specific private keys, allowing secure storage and decryption only by authorized users, along with AI and MLR for probabilistic analysis to determine storage locations and key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is stored locally on client devices, then security is manageable and data access is direct, but computing costs increase and scalability is limited

Engineering Contradiction:
ImprovesecurityVSAvoidcomputing cost efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments data storage by creating user-specific partitions within the cloud repository. Each user has their own partition that is encrypted with their public key, allowing secure separation of data while maintaining cloud-based scalability. This resolves the contradiction by enabling secure storage without requiring expensive local infrastructure on each client device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cloud-based repository as an intermediary between client devices and data storage. Instead of direct local storage, data is transmitted to the cloud where it is encrypted and stored in user-specific partitions. This intermediary enables secure, scalable storage while reducing the computational burden on individual client devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If symmetric cryptography is used for data encryption, then encryption speed is fast, but key transmission becomes vulnerable and complex

Engineering Contradiction:
Improveencryption speedVSAvoidkey transmission security risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent employs asymmetric cryptography (public-key encryption) for data storage in the cloud. Each user has a public key for encryption and a private key for decryption. This asymmetric approach eliminates the need for secure key transmission between parties, as the public key can be freely distributed while the private key remains secure with the user. This resolves the contradiction by maintaining encryption speed while eliminating key transmission vulnerabilities.

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The system enables users to independently manage their own encryption keys for their data partitions. Users can generate, store, and control their private keys without requiring server intervention or transmission. This self-service approach to key management eliminates transmission security risks while maintaining efficient encryption operations.

Inventive Principle:
Principle #25Self-service

3Productivity

If cloud-based storage is implemented, then computing costs are reduced and scalability improves, but data security becomes more challenging

Engineering Contradiction:
Improvecomputing cost efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The cloud repository is segmented into user-specific partitions, each encrypted with the user's public key. This segmentation ensures that even though data is stored centrally in the cloud, each user's data is isolated and encrypted, maintaining security while enabling cost-effective scalable storage. The partitioning mechanism allows secure multi-tenant cloud storage without compromising data protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses encryption as an intermediary layer between the cloud storage infrastructure and user data. The cloud repository stores encrypted data, and the encryption mechanism acts as a mediator that protects data integrity and confidentiality. This approach enables secure cloud storage while maintaining the cost and scalability benefits of centralized storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If AI and MLR are used for data analysis and indexing, then data management efficiency improves, but system complexity increases

Engineering Contradiction:
Improvedata management efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system employs AI and machine learning algorithms that automatically analyze data characteristics, determine appropriate partitions, and manage indexing without requiring manual intervention. The system self-services data organization by using algorithms to infer data properties and automatically route data to appropriate locations. This automation improves efficiency while the complexity is abstracted away from the user interface.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses AI/MLR to dynamically determine indexing parameters and storage location based on data characteristics. The system changes organizational parameters automatically based on analyzed data properties, such as determining partition locations based on inferred data types, users, or contexts. This dynamic parameter adjustment improves management efficiency while keeping the complexity contained within automated algorithms rather than manual configuration.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8601598B2Off-premise encryption of data storage
Publication Date: 2013.12.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8601598B2 patent drawing
  • US8601598B2 patent drawing
  • US8601598B2 patent drawing

AI summary

A system that enables a cloud-based data repository to function as a secure ‘drop-box’ for data that corresponds to a user is provided. The ‘drop box’ can be facilitated through the use of cryptographic keying technologies. For instance, data that is ‘dropped’ by or on behalf of a particular user can be encrypted using a public key that corresponds to a user-specific private key. Thus, although the data resides within the large pool of ‘cloud-based’ data, it is protected since it can only be decrypted by using the private key, which is kept secret. The innovation can further facilitate user-centric secure storage by partitioning the cloud-based repository into multiple partitions, each of which corresponds to specific indexing criteria.