Data Vaporizer Fragmentation for Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based storage solutions face skepticism due to security, integrity, and confidentiality concerns, with existing proprietary solutions being inflexible and vulnerable to local failures and hacking attacks, limiting data migration to the cloud.
Innovation Solution
The Data Vaporizer system anonymizes, encrypts, and fragments data, distributing it across multiple cloud storage providers to ensure fault tolerance, security, and compliance, using erasure coding and secret sharing to prevent data breaches and ensure data availability even in the event of provider failures or collusion.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is stored in cloud-based storage solutions, then storage capacity and accessibility are improved, but security, integrity, and confidentiality are compromised
Solution Approach 1:
The patent segments data into multiple fragments using erasure coding and distributes these fragments across multiple cloud storage providers. No single provider holds the complete data, making it impossible for them to access or compromise the entire dataset. This segmentation approach allows cloud storage accessibility while preventing security breaches through fragmentation and distributed storage.
Solution Approach 2:
The patent introduces an intermediary layer between the user and cloud storage providers that handles encryption, fragment generation, and key management. This intermediary system ensures that even if cloud providers have access to stored fragments, they cannot reconstruct or access the original data without the decryption keys, which are managed separately. This mediator layer resolves the contradiction by enabling cloud storage while maintaining security through cryptographic protection.
2Reliability
If proprietary encryption and access control mechanisms are used by cloud storage providers, then data protection is improved, but adaptability to client needs deteriorates
Solution Approach 1:
The patent implements dynamic and configurable security parameters that can be adjusted according to client needs. Users can specify different encryption algorithms, key lengths, erasure coding schemes, and distribution strategies based on their specific requirements. This dynamic configuration capability allows the system to adapt to varying client needs while maintaining strong data protection through customizable security measures.
Solution Approach 2:
The patent allows clients to change security parameters such as encryption strength, fragment distribution ratios, and storage provider selection based on their evolving needs. The system supports parameter adjustments without requiring proprietary lock-in, enabling clients to optimize security and performance characteristics according to their specific use cases while maintaining robust data protection through configurable cryptographic and coding parameters.
3Reliability
If data is encrypted and fragmented across multiple storage providers, then security and fault tolerance are improved, but system complexity increases
Solution Approach 1:
The patent employs universal erasure coding algorithms and standardized cryptographic protocols that can be implemented across multiple storage providers and systems. These multi-functional approaches allow the same technical mechanisms to provide both security and fault tolerance simultaneously, reducing the need for separate specialized systems and thereby managing complexity while achieving multiple reliability goals through unified cryptographic and coding frameworks.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The data vaporizer provides secure online distributed data storage services that securely store and retrieve data in a public distributed storage substrate such as public cloud. The data vaporizer vaporizes (e.g., fragmented into tiny chunks of configurable sizes) data and distributes the fragments to multiple storage nodes so that the data is not vulnerable to local disk failures, secures data so that even if some of the storage nodes are compromised, the data is undecipherable to the attacker, stores data across multiple cloud storage providers and/or parties using keys (e.g., tokens) provided by multiple parties (including the owners of the data) and maintains data confidentiality and integrity even where one or more data storage provider is compromised. The data vaporizer is configurable for different domain requirements including data privacy and anonymization requirements, encryption mechanisms, regulatory compliance of storage locations, and backup and recovery constraints.