Secure Cloud Storage Key Custodian Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for securely storing and sharing confidential information, such as healthcare records, are inadequate as they rely solely on cryptography, which is insufficient without secure management of encryption keys, leading to unauthorized access.

Innovation Solution

A secure key-value cloud storage system using public key encryption, where a unique public/private key pair is assigned to the information owner, with the private key retained by the owner or their proxy, and stored encrypted on a cloud provider, ensuring only authorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptography is used to protect confidential information, then information security is improved, but key management complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the private key from the cloud storage system and assigns it to a key custodian entity. This separation removes the key management burden from the cloud provider, reducing their complexity while maintaining security. The cloud provider only handles encrypted data, not the keys themselves.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a key custodian as an intermediary between the information owner and the cloud storage system. This intermediary holds and manages the private keys, simplifying the overall system architecture by centralizing key management in a trusted third party rather than requiring the cloud provider to manage keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If the cloud provider stores encrypted information, then storage cost is reduced, but liability for information security increases

Engineering Contradiction:
Improvestorage costVSAvoidHIPAA liability
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the decryption capability (private key) from the cloud storage system and assigns it to a key custodian. This extraction eliminates the cloud provider's ability to access the information, thereby removing their liability for security breaches while they continue to provide storage services.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary security measures by encrypting data with public keys before storage and ensuring only authorized key custodians hold the corresponding private keys. This preliminary encryption creates a security barrier that prevents unauthorized access, including by the cloud provider themselves, thus preemptively addressing liability concerns.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If public key encryption is implemented, then access control is improved, but system complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the key custodian a universal entity that can serve multiple cloud storage providers and information owners. The key custodian manages keys across different systems and providers, reducing overall system complexity by creating a standardized key management interface rather than requiring each system to implement its own key management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9378380B1System and method for securely storing and sharing information
Publication Date: 2016.06.28 CROWDSTRIKE
  • US9378380B1 patent drawing
  • US9378380B1 patent drawing
  • US9378380B1 patent drawing

AI summary

A secure information storage system is disclosed. In an example embodiment, the secure information storage system comprises a first proxy system, a cloud storage system, an exchange registry, an access portal and a cloud-registry interface.