Jurisdiction Independent Cloud Data Storage Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Companies face challenges in ensuring data security and compliance with jurisdictional data privacy laws when storing data in cloud environments, as cloud vendors may be subject to different legal requirements and can compromise data security, leading to potential data breaches and legal obligations for mandatory disclosures.
Innovation Solution
A cloud-based system that segments and encrypts data files, distributing encrypted segments across multiple cloud service providers in different jurisdictions, ensuring that no single provider has complete data and allowing reassembly only when authorized, thus maintaining jurisdictional independence and compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored in a single cloud vendor's infrastructure, then data access and management is simplified, but data security and jurisdictional compliance are compromised
Solution Approach 1:
The patent divides data files into multiple segments and distributes them across different cloud vendors in different jurisdictions. Each vendor only holds a portion of the data, making it impossible for any single vendor to access complete data files. This segmentation resolves the contradiction by maintaining security through distribution while enabling access through coordinated retrieval.
Solution Approach 2:
The patent introduces a data loss prevention (DLP) system as an intermediary layer between users and cloud vendors. The DLP system manages data segmentation, encryption, distribution, and reassembly, simplifying user interaction while ensuring security compliance. This intermediary resolves the contradiction by handling the complexity of multi-vendor coordination transparently.
2Reliability
If data is distributed across multiple cloud service providers in different jurisdictions, then data security and jurisdictional independence are improved, but system complexity increases
Solution Approach 1:
The DLP system acts as a centralized intermediary that manages all complexities of multi-jurisdictional data distribution. It handles segmentation, encryption key management, vendor coordination, and data reassembly, shielding users from system complexity while maintaining security benefits.
Solution Approach 2:
The patent creates encrypted copies of data segments and distributes them across multiple vendors. Each vendor receives identical encryption standards and data format specifications, simplifying management through standardization while maintaining security through distribution.
3Speed
If complete data files are stored at cloud vendors, then data retrieval is faster, but unauthorized access and data breaches become more likely
Solution Approach 1:
By segmenting data files and distributing segments across multiple vendors, the patent ensures that no single vendor possesses complete data files. This prevents unauthorized access at the vendor level while enabling fast retrieval through parallel processing of segments from multiple sources.
Solution Approach 2:
The patent performs preliminary encryption and segmentation of data before distribution. Encryption keys are securely managed and prepared in advance, allowing rapid decryption and reassembly of data segments during retrieval without compromising security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention relates to a cloud based system for providing data security. The system comprises a processor which receives a data file from a user. The data file is directed to a first file location and encrypted and segmented into a plurality of data blocks. The plurality of data blocks is then assigned with a unique identifier and redirected to a plurality of cloud based storage providers. The plurality of cloud based storage providers are located in a plurality of jurisdictions. Each of the plurality of data blocks is then assigned a second file location. The unique identifier and the file locations of each of the plurality of data blocks is updated in the system.