Cloud Storage Protocol Rotation for Credential Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud storage systems face security risks due to compromised communications protocols, which can lead to data theft and unauthorized access, especially when data is stored in a single location without adequate redundancy and protocol diversification.
Innovation Solution
A method and system that transmit data to multiple cloud storages using different communications protocols, allowing protocol changes over time or in response to security breaches, with data divided across geographically separated vendors to enhance security and redundancy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is stored in a single cloud storage using a single communications protocol, then device complexity is reduced, but security is compromised when the protocol is breached
Solution Approach 1:
The patent segments data into multiple parts and stores them in different cloud storages using different communications protocols. This segmentation ensures that if one protocol is compromised, only a portion of the data is at risk, while the complete data remains secure in other cloud storages using different protocols.
Solution Approach 2:
The patent changes the parameter of communications protocols by using multiple different protocols (e.g., HTTPS, FTP, SFTP) across different cloud storages. This parameter diversification prevents a single protocol vulnerability from compromising the entire data set, as each cloud storage uses a different protocol with its own security characteristics.
2Reliability
If data is distributed across multiple cloud storages using different protocols, then security is enhanced, but device complexity increases
Solution Approach 1:
The storage controller is designed with multi-functionality to handle multiple communications protocols and interact with multiple cloud storages. This universal capability allows the system to distribute data across different protocols and cloud providers while maintaining a single point of control, thereby managing complexity centrally rather than分散ly.
Solution Approach 2:
The storage controller acts as an intermediary between the host system and multiple cloud storages. It abstracts the complexity of managing multiple protocols and cloud providers, presenting a unified interface to the host while handling protocol-specific operations internally. This mediator role simplifies the overall system architecture despite the underlying complexity.
3Object-affected harmful factors
If a communications protocol is compromised, then data security is breached, but protocol diversity limits the scope of compromise
Solution Approach 1:
By segmenting data and storing portions in different cloud storages using different protocols, the patent limits the harmful impact of a protocol compromise. When one protocol is breached, only the data portion stored via that protocol is exposed, while other data segments remain protected by different protocols, thereby containing the scope of the security breach.
4Reliability
If data is stored in geographically separated cloud storages, then redundancy and security are improved, but loss of time for data retrieval increases
Solution Approach 1:
The system performs preliminary actions by pre-distributing data segments to multiple geographically separated cloud storages before any security incident or data retrieval need. This advance distribution ensures that data is already in multiple locations with redundancy established, so when retrieval is needed, the system can immediately access the nearest or most available copy without delay.
Data Source
AI summary
A computational device has an interface to access a heterogeneous cloud storage comprised of a first cloud storage maintained by a first entity and a second cloud storage maintained by a second entity. The computational device transmits, via a first communications protocol over the interface, a first set of data comprising usernames to a first cloud storage maintained by a first entity. The computational device transmits, via a second communications protocol, a second set of data comprising passwords corresponding to the usernames to a second cloud storage maintained by a second entity. On elapse of a first predetermined amount of time or the first communications protocol being compromised, the first communications protocol is changed to a third communications protocol. On elapse of a second predetermined amount of time or the second communications protocol being compromised, the second communications protocol is changed to a fourth communications protocol.


