Cryptographic Data Splitting for Secure Storage Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage systems face vulnerabilities in data access and security, particularly in centralized networks, where unauthorized users can steal physical disks or exploit network vulnerabilities, leading to data loss and corruption risks.
Innovation Solution
A secure data storage system that employs a secure storage appliance to cryptographically split and distribute data across multiple physical storage devices, ensuring that no single disk can be used to access the data without multiple corresponding encryption keys, and implements a hierarchical access control system to manage administrative roles and encryption keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If data is stored in a centralized data storage system, then data access speed and retrieval efficiency are improved, but data security and vulnerability to unauthorized access deteriorate
Solution Approach 1:
The patent divides data into multiple fragments and distributes them across multiple storage devices. Each fragment alone is insufficient to reconstruct the original data, providing security while maintaining access efficiency through parallel retrieval of multiple fragments.
Solution Approach 2:
The patent introduces cryptographic keys as intermediaries between the stored data fragments and the reconstruction process. These keys act as mediators that control access to the data, allowing secure centralized storage while preventing unauthorized access even if physical disks are stolen.
2Reliability
If data is encrypted and distributed across multiple storage devices, then data security is improved, but system complexity and access management difficulty worsen
Solution Approach 1:
The patent creates a universal key management system that handles multiple cryptographic keys through a single interface. The key management server provides multi-functional capabilities including key generation, distribution, rotation, and revocation, simplifying access management despite the distributed encrypted storage architecture.
Solution Approach 2:
The patent combines multiple cryptographic keys into a unified key management structure where all keys are managed through a single server. This merging approach consolidates the complexity of managing multiple encrypted data fragments into a centralized key management system, reducing overall system complexity.
3Reliability
If administrative access control is implemented, then data protection against unauthorized modification is improved, but ease of operation and administrative management deteriorate
Solution Approach 1:
The patent implements dynamic administrative access control where user permissions can be flexibly adjusted through the key management system. Administrators can dynamically grant or revoke access rights to specific data fragments or entire volumes without restructuring the storage system, maintaining strong protection while improving ease of operation.
Solution Approach 2:
The patent incorporates feedback mechanisms in the key management system that track and log all access requests and administrative actions. This feedback provides audit trails and real-time monitoring, enabling administrators to manage access rights efficiently while maintaining robust data protection through automated security policies.
Data Source
AI summary
Methods and systems for administrative management of a secure data storage network are disclosed. One system includes a secure storage appliance configured to host a plurality of volumes, each volume associated with a plurality of shares stored on a corresponding plurality of physical storage devices and having a plurality of volume management settings, wherein each volume is accessible by a group of one or more users, each user assigned an administrative access level, the volume management settings are editable by a first user from the group of one or more users associated with the volume and assigned an administrative access level sufficient to edit the volume management settings, and the volume management settings are inaccessible by a second user from outside the group of one or more users associated with the volume and assigned an administrative access level at least equal to that of the first user.


