Cryptographic Data Splitting for Secure Storage Availability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage systems face vulnerabilities in data access and loss risks, with centralized storage systems being susceptible to unauthorized access and physical failures, and current duplication methods provide inadequate security and redundancy.
Innovation Solution
A block-level data storage security system that uses cryptographic splitting to distribute and encrypt data across multiple physical storage devices, ensuring that data cannot be reconstructed without appropriate access and decryption rights, and includes a secure storage appliance that manages data paths and reassesses connectivity to maintain data availability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored in a centralized data storage system, then data access is simplified and management is easier, but the system becomes susceptible to unauthorized access and physical failures
Solution Approach 1:
The patent divides data into multiple fragments or shares and distributes them across multiple storage devices. No single device contains the complete data, so compromising one device does not result in data loss or unauthorized access. The data can be reconstructed by combining a threshold number of fragments from different devices, maintaining both security and availability.
Solution Approach 2:
The patent introduces a secret sharing mechanism as an intermediary layer between the data and storage devices. The data is transformed into encrypted shares through mathematical functions before storage, and the original data can only be recovered by combining specific shares. This intermediary layer protects the data even if storage devices are compromised.
2Reliability
If data is duplicated across multiple storage devices for redundancy, then data availability is improved, but security is weakened because copies can be accessed independently
Solution Approach 1:
Instead of creating complete copies of data across multiple devices, the patent segments the data into fragments and distributes these fragments across storage devices. Each fragment alone is useless without the others, preventing unauthorized access while maintaining availability through distributed storage.
Solution Approach 2:
The patent transforms the data representation from complete copies to mathematical shares with specific reconstruction thresholds. By changing the parameter of data replication from 1:1 copying to threshold-based reconstruction, the system achieves both redundancy and security.
3Object-affected harmful factors
If data is encrypted to prevent unauthorized access, then security is improved, but data recovery becomes more complex if encryption keys are lost
Solution Approach 1:
The patent segments the encryption key into multiple key shares and distributes them separately. To decrypt data, a threshold number of key shares must be combined, providing both security (keys are protected even if some shares are compromised) and recovery capability (losing some shares doesn't prevent recovery if enough remain).
Solution Approach 2:
The patent uses secret sharing schemes as an intermediary between encryption and key management. This allows the system to maintain encrypted data with distributed key control, where key recovery is possible through combination of shares without requiring a single master key.
4Object-affected harmful factors
If cryptographic splitting is used to distribute data across multiple devices, then security is enhanced, but system complexity increases
Solution Approach 1:
The patent implements self-service mechanisms where the system automatically manages fragment distribution, tracking, and reconstruction. The complexity of cryptographic splitting is hidden from users through automated processes that handle share generation, distribution, and recombination without manual intervention.
Solution Approach 2:
The patent creates a universal storage system that can handle both secure distributed storage and traditional storage operations through a unified interface. The system provides multi-functionality by supporting data fragmentation, encryption, distributed storage, and recovery all through a single coherent architecture.
Data Source
AI summary
A secure storage appliance is disclosed, along with methods of storing and reading data in a secure storage network. In one aspect, a method includes assigning a volume to a primary secure storage appliance located in a secure data storage network, the secure data storage network including a plurality of secure data paths between the primary secure storage appliance and a client device and a plurality of secure data paths between the secure storage appliance and a plurality of storage systems, the volume corresponding to physical storage at each of the plurality of storage systems. The method also includes detecting a connectivity problem on at least one of the secure data paths. The method further includes assessing whether to reassign the volume to a different secure storage appliance based upon the connectivity problem.


