Data Fragment Shuffling for Storage Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data protection techniques in storage systems are inadequate for securing cryptographic keys and hash values, as they can be vulnerable to attacks that infer physical storage locations through access pattern analysis and eavesdropping.
Innovation Solution
The method involves obtaining data items, dividing them into portions, swapping their positions, slicing them into fragments, and shuffling these fragments across multiple storage nodes, using a mix and slice encryption technique combined with a shuffle index to obfuscate physical storage locations, making it difficult to decrypt without all fragments and resistant to collusion.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is stored using traditional encryption and access control functions, then data protection is provided, but the storage locations of cryptographic keys and hash values remain vulnerable to access pattern analysis and eavesdropping attacks
Solution Approach 1:
The patent divides cryptographic keys and hash values into multiple data portions and further slices them into multiple data fragments. Each fragment is stored on a different storage node, so that no single node contains the complete data. This segmentation prevents attackers from reconstructing the original data by monitoring or compromising a single storage location, thereby resolving the vulnerability to access pattern analysis and eavesdropping while maintaining data protection.
Solution Approach 2:
The patent introduces a new dimension of security by distributing data fragments across multiple storage nodes rather than relying solely on traditional encryption at a single location. This spatial distribution across multiple nodes adds a dimensional layer of protection, making it significantly more difficult for attackers to infer storage locations or intercept complete data through conventional eavesdropping methods.
2Reliability
If data is divided into portions and sliced into fragments across multiple storage nodes, then security and resistance to attacks are enhanced, but system complexity increases
Solution Approach 1:
While segmentation into multiple data portions and fragments does increase system complexity, the patent manages this complexity through systematic processes for dividing, swapping, slicing, and shuffling data. The complexity is distributed across multiple storage nodes rather than concentrated in a single system, making the overall system more resilient and secure despite the increased structural complexity.
Solution Approach 2:
The patent implements dynamic shuffling of data fragments across storage nodes, where the physical storage locations are not fixed but can be reassigned. This dynamic approach enhances security by preventing attackers from establishing stable access patterns, while the systematic nature of the shuffling process manages the complexity through predictable, rule-based operations rather than arbitrary complexity.
Data Source
AI summary
Techniques are provided for securing data storage by slicing swapped data portions into data fragments and shuffling a physical storage location of the data fragments. One method comprises obtaining at least one data item; dividing the at least one data item into a plurality of data portions; swapping respective positions of at least two of the data portions of the at least one data item; slicing the plurality of data portions, following the swapping, into a plurality of data fragments; and shuffling a distribution of the data fragments across a plurality of storage nodes in a storage system by moving at least one data fragment from a current physical storage location on a current storage node to a different physical storage location on a different storage node. A predefined number of the plurality of data fragments may be needed to reconstruct the data item.


