Cryptographic Data Splitting for Secure Storage Availability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage systems face vulnerabilities such as unauthorized access and data loss due to centralized storage, where physical disks can be stolen or compromised, and backup systems are prone to failure or theft, lacking robust security measures for data availability and recovery.
Innovation Solution
A block-level data storage security system that splits and encrypts data across multiple physical storage devices, presenting it as a virtual disk, allowing only authorized access and ensuring data security by requiring multiple disks and encryption keys for reconstitution, with failover mechanisms to maintain data availability in case of appliance failure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored in a centralized data storage system, then data access is simplified and management is easier, but the system becomes vulnerable to unauthorized access, physical theft, and catastrophic failure
Solution Approach 1:
The patent divides data into multiple fragments and stores them across separate storage devices in a distributed network. Each fragment alone is insufficient to reconstruct the original data, requiring a threshold number of fragments. This segmentation prevents unauthorized access while maintaining data availability through distributed redundancy.
Solution Approach 2:
The patent introduces cryptographic keys as intermediaries between the stored data fragments and the original data. These keys are distributed separately from the data fragments and are required to reconstruct the original data. This intermediary layer adds security without complicating data management operations.
2Reliability
If data is encrypted and split across multiple storage devices, then security is improved and unauthorized access is prevented, but system complexity increases
Solution Approach 1:
The patent implements automatic key management and data reconstruction mechanisms that operate without manual intervention. The system self-manages the cryptographic operations, fragment assembly, and security protocols, reducing the perceived complexity for users while maintaining high security standards.
Solution Approach 2:
The patent creates a multi-functional storage system that simultaneously provides security, redundancy, and distributed storage capabilities through a unified architecture. The same infrastructure handles data fragmentation, encryption, key management, and reconstruction, reducing overall system complexity compared to separate systems for each function.
3Reliability
If backup systems are implemented to prevent data loss, then data recovery capability is improved, but the backup systems themselves become vulnerable to failure, theft, or corruption
Solution Approach 1:
The patent segments data into multiple fragments distributed across different storage devices in a network, eliminating the need for traditional centralized backup systems. Each fragment is stored separately, and the system can recover data from any sufficient subset of fragments, making the system resilient to individual device failures, theft, or corruption.
Solution Approach 2:
The patent implements redundant data fragments and distributed storage as a preventive measure against data loss. By storing multiple copies of data fragments across the network before any failure occurs, the system cushions against potential failures, theft, or corruption of individual storage devices without requiring separate backup systems.
Data Source
AI summary
Methods and systems for maintaining data connectivity in a secure data storage network are disclosed. In one aspect, a method includes assigning a volume to a primary secure storage appliance located in a secure data storage network the primary secure storage appliance selected from among a plurality of secure storage appliances located in the secure data storage network, the volume presented as a virtual disk to a client device and mapped to physical storage at each of a plurality of storage systems. The method further includes detecting at one of the plurality of secure storage appliances a failure of the primary secure storage appliance. The method also includes, upon detecting the failure of the primary secure storage appliance, reassigning the volume to a second secure storage appliance from among the plurality of secure storage appliances, thereby rendering the second secure storage appliance a new primary secure storage appliance.


