Data-Centric Storage System for Secure Long-Term Archiving
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage solutions lack robust security measures, making them vulnerable to attacks, and rely on operating systems for access, introducing additional attack vectors and compromising data integrity.
Innovation Solution
A Data-Centric Secure Data Storage System that encrypts files using on-demand generated keys, splits them into slices, and disperses them across multiple secure storage locations based on cost and accessibility metrics, ensuring data integrity and security through secure archiving and retrieval processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored using traditional network attached storage or local storage methods, then data accessibility and ease of use are improved, but data security and integrity are compromised due to reliance on operating systems and lack of encryption
Solution Approach 1:
The patent divides data into multiple slices and disperses them across different storage locations, eliminating the single point of failure in traditional storage systems. Each slice is encrypted independently, so compromising one location does not expose the entire dataset. This segmentation resolves the contradiction by maintaining accessibility through distributed storage while improving security through encryption and dispersion.
Solution Approach 2:
The patent introduces an intermediary encryption layer between the data and storage medium. Instead of storing raw data that relies on operating system security, the system encrypts data before storage and manages decryption keys separately. This intermediary layer resolves the contradiction by providing security independent of the operating system while maintaining accessibility through controlled decryption.
2Reliability
If data is encrypted and dispersed across multiple storage locations, then data security and integrity are improved, but system complexity and retrieval overhead increase
Solution Approach 1:
The patent creates a universal data storage system that handles encryption, slicing, dispersion, and retrieval through a unified architecture. The same system components manage both security functions (encryption, key management) and storage functions (slicing, dispersion, retrieval). This multi-functionality resolves the contradiction by consolidating complexity into a coordinated system rather than adding separate complex layers for security.
Solution Approach 2:
The patent performs preliminary encryption and slicing of data before storage, so that the complex security operations are completed once during ingestion rather than repeatedly during access. The system pre-processes data into encrypted slices with embedded metadata, eliminating the need for complex real-time processing during retrieval. This resolves the contradiction by moving complexity to the initialization phase while simplifying ongoing operations.
3Productivity
If traditional storage methods are used without encryption, then storage efficiency and accessibility are maintained, but data becomes vulnerable to attacks and compromise
Solution Approach 1:
The patent changes the fundamental parameter of data representation from plaintext to encrypted format. By transforming data into ciphertext before storage, the system maintains storage efficiency (encrypted data occupies similar space to plaintext) while eliminating vulnerability to attacks. The encryption parameter change resolves the contradiction by providing security without sacrificing storage efficiency.
Data Source
AI summary
Current data archiving and storage solutions seek to store data in the most accessible manner possible, often foregoing security for sake of user convenience. The technology, system, and methods proposed in this document seek to protect data in a highly resilient, secure manner, suitable for extremely long-term periods of time without loss of data integrity. The proposed solution includes methods for storing digital data, validating the integrity of the data on both sides of the transmission, encryption with keys that only the user has access to, splitting files into obfuscated slices for increased security, and determining the most effective storage location according to a novel cost metric. Data is reduced to ephemeral “ghost” files that remain faithful copies of the original data files, capable of being perceived by a user device, but never resident upon the device.


