Cryptographic Data Splitting for Secure Storage Availability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage systems face vulnerabilities in data access and loss risks, with centralized storage systems being susceptible to unauthorized access and physical failures, and current duplication methods provide inadequate security and redundancy.

Innovation Solution

A block-level data storage security system that uses cryptographic splitting to distribute and encrypt data across multiple physical storage devices, ensuring that data cannot be reconstructed without appropriate access and decryption rights, and includes a secure storage appliance that manages data paths and reassesses connectivity to maintain data availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is stored in a centralized data storage system, then data access is simplified and management is easier, but the system becomes susceptible to unauthorized access and physical failures

Engineering Contradiction:
Improvedata access simplicityVSAvoiddata security and availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides data into multiple fragments or shares and distributes them across multiple storage devices. No single device contains the complete data, so compromising one device does not result in data loss or unauthorized access. The data can be reconstructed by combining a threshold number of fragments from different devices, maintaining both security and availability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secret sharing mechanism as an intermediary layer between the data and storage devices. The data is transformed into encrypted shares through mathematical functions before storage, and the original data can only be recovered by combining specific shares. This intermediary layer protects the data even if storage devices are compromised.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is duplicated across multiple storage devices for redundancy, then data availability is improved, but security is weakened because copies can be accessed independently

Engineering Contradiction:
Improvedata availabilityVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

Instead of creating complete copies of data across multiple devices, the patent segments the data into fragments and distributes these fragments across storage devices. Each fragment alone is useless without the others, preventing unauthorized access while maintaining availability through distributed storage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms the data representation from complete copies to mathematical shares with specific reconstruction thresholds. By changing the parameter of data replication from 1:1 copying to threshold-based reconstruction, the system achieves both redundancy and security.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If data is encrypted to prevent unauthorized access, then security is improved, but data recovery becomes more complex if encryption keys are lost

Engineering Contradiction:
Improveunauthorized access preventionVSAvoiddata recovery simplicity
Core Design Contradiction:
Object-affected harmful factorsVSEase of repair

Solution Approach 1:

The patent segments the encryption key into multiple key shares and distributes them separately. To decrypt data, a threshold number of key shares must be combined, providing both security (keys are protected even if some shares are compromised) and recovery capability (losing some shares doesn't prevent recovery if enough remain).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses secret sharing schemes as an intermediary between encryption and key management. This allows the system to maintain encrypted data with distributed key control, where key recovery is possible through combination of shares without requiring a single master key.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Object-affected harmful factors

If cryptographic splitting is used to distribute data across multiple devices, then security is enhanced, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidstorage system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the system automatically manages fragment distribution, tracking, and reconstruction. The complexity of cryptographic splitting is hidden from users through automated processes that handle share generation, distribution, and recombination without manual intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal storage system that can handle both secure distributed storage and traditional storage operations through a unified interface. The system provides multi-functionality by supporting data fragmentation, encryption, distributed storage, and recovery all through a single coherent architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8135980B2Storage availability using cryptographic splitting
Publication Date: 2012.03.13 UNISYS CORP
  • US8135980B2 patent drawing
  • US8135980B2 patent drawing
  • US8135980B2 patent drawing

AI summary

A secure storage appliance is disclosed, along with methods of storing and reading data in a secure storage network. In one aspect, a method includes assigning a volume to a primary secure storage appliance located in a secure data storage network, the secure data storage network including a plurality of secure data paths between the primary secure storage appliance and a client device and a plurality of secure data paths between the secure storage appliance and a plurality of storage systems, the volume corresponding to physical storage at each of the plurality of storage systems. The method also includes detecting a connectivity problem on at least one of the secure data paths. The method further includes assessing whether to reassign the volume to a different secure storage appliance based upon the connectivity problem.