Data Vaporizer Fragmentation for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based storage solutions face skepticism due to security, integrity, and confidentiality concerns, with existing proprietary solutions being inflexible and vulnerable to local failures and hacking attacks, limiting data migration to the cloud.

Innovation Solution

The Data Vaporizer system anonymizes, encrypts, and fragments data, distributing it across multiple cloud storage providers to ensure fault tolerance, security, and compliance, using erasure coding and secret sharing to prevent data breaches and ensure data availability even in the event of provider failures or collusion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is stored in cloud-based storage solutions, then storage capacity and accessibility are improved, but security, integrity, and confidentiality are compromised

Engineering Contradiction:
Improvestorage accessibilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments data into multiple fragments using erasure coding and distributes these fragments across multiple cloud storage providers. No single provider holds the complete data, making it impossible for them to access or compromise the entire dataset. This segmentation approach allows cloud storage accessibility while preventing security breaches through fragmentation and distributed storage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer between the user and cloud storage providers that handles encryption, fragment generation, and key management. This intermediary system ensures that even if cloud providers have access to stored fragments, they cannot reconstruct or access the original data without the decryption keys, which are managed separately. This mediator layer resolves the contradiction by enabling cloud storage while maintaining security through cryptographic protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If proprietary encryption and access control mechanisms are used by cloud storage providers, then data protection is improved, but adaptability to client needs deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoidclient needs adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic and configurable security parameters that can be adjusted according to client needs. Users can specify different encryption algorithms, key lengths, erasure coding schemes, and distribution strategies based on their specific requirements. This dynamic configuration capability allows the system to adapt to varying client needs while maintaining strong data protection through customizable security measures.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent allows clients to change security parameters such as encryption strength, fragment distribution ratios, and storage provider selection based on their evolving needs. The system supports parameter adjustments without requiring proprietary lock-in, enabling clients to optimize security and performance characteristics according to their specific use cases while maintaining robust data protection through configurable cryptographic and coding parameters.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If data is encrypted and fragmented across multiple storage providers, then security and fault tolerance are improved, but system complexity increases

Engineering Contradiction:
Improvefault toleranceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs universal erasure coding algorithms and standardized cryptographic protocols that can be implemented across multiple storage providers and systems. These multi-functional approaches allow the same technical mechanisms to provide both security and fault tolerance simultaneously, reducing the need for separate specialized systems and thereby managing complexity while achieving multiple reliability goals through unified cryptographic and coding frameworks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2755161B1Secure online distributed data storage services
Publication Date: 2018.01.10 ACCENTURE GLOBAL SERVICES LTD
  • EP2755161B1 patent drawingFigure 1
  • EP2755161B1 patent drawingFigure 2
  • EP2755161B1 patent drawingFigure 3

AI summary

The data vaporizer provides secure online distributed data storage services that securely store and retrieve data in a public distributed storage substrate such as public cloud. The data vaporizer vaporizes (e.g., fragmented into tiny chunks of configurable sizes) data and distributes the fragments to multiple storage nodes so that the data is not vulnerable to local disk failures, secures data so that even if some of the storage nodes are compromised, the data is undecipherable to the attacker, stores data across multiple cloud storage providers and/or parties using keys (e.g., tokens) provided by multiple parties (including the owners of the data) and maintains data confidentiality and integrity even where one or more data storage provider is compromised. The data vaporizer is configurable for different domain requirements including data privacy and anonymization requirements, encryption mechanisms, regulatory compliance of storage locations, and backup and recovery constraints.