Cloud Storage Protocol Rotation for Credential Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud storage systems face security risks due to compromised communications protocols, which can lead to data theft and unauthorized access, especially when data is stored in a single location without adequate redundancy and protocol diversification.

Innovation Solution

A method and system that transmit data to multiple cloud storages using different communications protocols, allowing protocol changes over time or in response to security breaches, with data divided across geographically separated vendors to enhance security and redundancy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is stored in a single cloud storage using a single communications protocol, then device complexity is reduced, but security is compromised when the protocol is breached

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments data into multiple parts and stores them in different cloud storages using different communications protocols. This segmentation ensures that if one protocol is compromised, only a portion of the data is at risk, while the complete data remains secure in other cloud storages using different protocols.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of communications protocols by using multiple different protocols (e.g., HTTPS, FTP, SFTP) across different cloud storages. This parameter diversification prevents a single protocol vulnerability from compromising the entire data set, as each cloud storage uses a different protocol with its own security characteristics.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If data is distributed across multiple cloud storages using different protocols, then security is enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The storage controller is designed with multi-functionality to handle multiple communications protocols and interact with multiple cloud storages. This universal capability allows the system to distribute data across different protocols and cloud providers while maintaining a single point of control, thereby managing complexity centrally rather than分散ly.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The storage controller acts as an intermediary between the host system and multiple cloud storages. It abstracts the complexity of managing multiple protocols and cloud providers, presenting a unified interface to the host while handling protocol-specific operations internally. This mediator role simplifies the overall system architecture despite the underlying complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If a communications protocol is compromised, then data security is breached, but protocol diversity limits the scope of compromise

Engineering Contradiction:
Improvedata theft riskVSAvoidprotocol management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

By segmenting data and storing portions in different cloud storages using different protocols, the patent limits the harmful impact of a protocol compromise. When one protocol is breached, only the data portion stored via that protocol is exposed, while other data segments remain protected by different protocols, thereby containing the scope of the security breach.

Inventive Principle:
Principle #1Segmentation

4Reliability

If data is stored in geographically separated cloud storages, then redundancy and security are improved, but loss of time for data retrieval increases

Engineering Contradiction:
ImproveredundancyVSAvoiddata retrieval time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-distributing data segments to multiple geographically separated cloud storages before any security incident or data retrieval need. This advance distribution ensures that data is already in multiple locations with redundancy established, so when retrieval is needed, the system can immediately access the nearest or most available copy without delay.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10122832B2Communications of usernames and passwords to a plurality of cloud storages via a plurality of communications protocols that change over time
Publication Date: 2018.11.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10122832B2 patent drawing
  • US10122832B2 patent drawing
  • US10122832B2 patent drawing

AI summary

A computational device has an interface to access a heterogeneous cloud storage comprised of a first cloud storage maintained by a first entity and a second cloud storage maintained by a second entity. The computational device transmits, via a first communications protocol over the interface, a first set of data comprising usernames to a first cloud storage maintained by a first entity. The computational device transmits, via a second communications protocol, a second set of data comprising passwords corresponding to the usernames to a second cloud storage maintained by a second entity. On elapse of a first predetermined amount of time or the first communications protocol being compromised, the first communications protocol is changed to a third communications protocol. On elapse of a second predetermined amount of time or the second communications protocol being compromised, the second communications protocol is changed to a fourth communications protocol.