Data Segmentation and Random Distribution for Ransomware Resilience

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security techniques, such as encryption and error correction codes, are inadequate in preventing data corruption attacks like ransomware and do not ensure data confidentiality, as they restrict data utilization and cannot cope with attacks that compromise server authority.

Innovation Solution

A method and apparatus that divide original data into multiple partial data pieces, randomly distribute them across multiple servers, and apply error correction codes with noise insertion to ensure data resilience and confidentiality, allowing only authorized restoration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data encryption technology is applied to secure data stored in the server, then data confidentiality is improved, but data utilization deteriorates and the system cannot cope with data corruption attacks such as ransomware

Engineering Contradiction:
Improvedata confidentialityVSAvoiddata utilization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The original data is divided into multiple partial data pieces and distributed across multiple servers. This segmentation ensures that even if one server is compromised, the attacker cannot retrieve complete data. The patent applies this by partitioning data into several segments and storing them separately, thus resolving the contradiction between security and usability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines error correction codes with data segmentation to create a composite security mechanism. The error correction capability is integrated with the segmented data structure, providing both confidentiality and resilience against corruption attacks. This composite approach allows data to be secured while maintaining usability through error correction and authorized restoration.

Inventive Principle:
Principle #40Composite materials

2Reliability

If general error correction code is applied to protect data, then data restoration function is provided for transmission errors, but the system cannot cope with attacks that damage all stored data such as ransomware

Engineering Contradiction:
Improvedata restoration functionVSAvoiddata corruption attack resistance
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

By dividing data into multiple segments stored on different servers, the patent ensures that error correction codes only need to handle partial data loss rather than complete data corruption. This segmentation makes the system resilient to ransomware attacks that would otherwise overwhelm traditional error correction mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies error correction codes in advance to the segmented data before storage, creating a preliminary protective layer. This pre-applied error correction capability enables automatic restoration of corrupted segments without requiring full data access, thus preventing ransomware from successfully encrypting and destroying the complete dataset.

Inventive Principle:
Principle #9Preliminary anti-action

3Ease of operation

If data is stored centrally on a single server for easy access, then data usability is improved, but the system becomes vulnerable to attacks that compromise server authority

Engineering Contradiction:
Improvedata access efficiencyVSAvoidsecurity against authority compromise
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments data and distributes it across multiple servers, eliminating the single point of failure inherent in centralized storage. Each server holds only a portion of the data, so compromising one server does not give attackers authority over the complete dataset. This distributed architecture maintains security while enabling efficient access through coordinated retrieval.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10902144B2Method and apparatus for securing data
Publication Date: 2021.01.26 ELECTRONICS & TELECOMM RES INST
  • US10902144B2 patent drawing
  • US10902144B2 patent drawing
  • US10902144B2 patent drawing

AI summary

In the present invention, by providing an apparatus for securing data comprising a memory for storing information for data processing, a processor configured to partition original data into a plurality of partial data and generate a plurality of divided data by randomly determining positions of each of the plurality of partial data within the original data, and a communication interface configured to transmit each of the plurality of divided data to each of a plurality of servers, respectively, if an attacker obtains a portion of the divided data, it prevents the entire original data from being restored, and the legitimate user can restore the original data accurately even if some divided data is corrupted, and provides an efficient data polymorphic dividing technique that can minimize the amount of calculation required to secure data.