Cloud Storage Virtualization for Privacy and Utilization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Businesses face challenges in utilizing unused cloud storage subscriptions due to individual end-user allocations, leading to inefficiencies and privacy concerns with existing proxy access methods.
Innovation Solution
A privacy gateway system that fragments data into encrypted chunk files, allowing secure, contiguous utilization of cloud storage by managing access and encryption, ensuring data separation and privacy through a proxy user with limited privileges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloud storage subscriptions are allocated to individual end-users, then user data privacy and access control are improved, but storage utilization efficiency deteriorates due to unused capacity remaining idle
Solution Approach 1:
The system segments storage management into two layers: individual user storage spaces remain privately controlled for data privacy, while a separate enterprise-level virtualization layer aggregates unused capacity across users. This segmentation allows simultaneous maintenance of user privacy and enterprise storage efficiency.
Solution Approach 2:
A storage virtualization intermediary layer is introduced between users and the physical storage infrastructure. This intermediary aggregates unused storage from multiple users and allocates it to enterprise needs without compromising individual user privacy or access controls.
2Adaptability or versatility
If proxy accounts are used to access entire cloud storage spaces, then storage allocation flexibility is improved, but user and content privacy security deteriorates
Solution Approach 1:
Instead of granting proxy accounts universal access to entire storage spaces, the system implements local quality control where proxies can only access specific portions of storage allocated to them. Each proxy's access is localized to particular user directories or file types, maintaining security while enabling flexibility.
Solution Approach 2:
Proxy access rights are segmented into fine-grained permissions rather than blanket access. The virtualization layer divides storage access into discrete, controllable units that proxies can access only within defined boundaries, reducing security risks while maintaining allocation flexibility.
3Reliability
If end-user storage subscriptions are tied to individual logins, then user data ownership and privacy are improved, but enterprise storage reclamation and reallocation capability deteriorates
Solution Approach 1:
The system merges individual user storage subscriptions into a unified enterprise storage pool through virtualization. While user ownership and privacy controls are maintained at the individual level, the enterprise gains the ability to reclaim and reallocate unused capacity across the organization by managing the aggregated pool.
Solution Approach 2:
The storage virtualization system provides multi-functionality: it preserves individual user ownership and privacy controls while simultaneously enabling enterprise-wide storage reclamation, allocation, and management capabilities that would be impossible with strictly individualized access.
Data Source
AI summary
The present invention discloses methods and systems for contiguous utilization of individual end-user-based cloud-storage subscriptions. Methods including the steps of: upon receiving a write request for writing a data file into at least one cloud-storage allocation unit, identifying unused available storage in the cloud-storage allocation unit; fragmenting the data file into chunk files; encrypting each chunk file; writing each chunk file to the cloud-storage allocation unit to satisfy the write request; and updating a metadatabase having metadata associated with the data file and the chunk files. Alternatively, the method further includes: upon receiving a read request for reading the data file from at least one cloud-storage allocation unit, performing lookup in the metadatabase of the metadata; reading each chunk file from the cloud-storage allocation unit; decrypting each chunk file; reassembling the chunk files into the data file using the metadata; and providing the data file to satisfy the read request.


