Distributed Backup Sharding for Cyberattack-Resilient Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection systems face vulnerabilities due to the consolidation of critical data in a single location, making them susceptible to cyber-attacks and physical threats, as they share common security flaws.

Innovation Solution

A distributed data protection system that disperses critical data across hundreds or thousands of devices, minimizing the risk of simultaneous compromise by leveraging diverse technologies with unique vulnerabilities, using heartbeat and canary signals for attack detection, and implementing a lockdown mode to secure data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is consolidated in a single location for easier management and access, then operational efficiency is improved, but security against cyber-attacks deteriorates

Engineering Contradiction:
Improvedata access efficiencyVSAvoidcyber-attack vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments critical data into multiple shards and distributes them across hundreds or thousands of devices in a distributed network. This segmentation eliminates the single point of failure while maintaining data accessibility through coordinated retrieval from distributed nodes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nested encryption where data is encrypted multiple times with different keys at different levels. The encryption keys themselves are distributed and stored separately from the encrypted data, creating a nested security structure that must be systematically unpacked to access the information.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If data is distributed across multiple devices to improve security, then resilience against attacks is improved, but system complexity increases

Engineering Contradiction:
Improvedata protection resilienceVSAvoiddistributed system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements heartbeat signals that continuously monitor the health and availability of distributed data nodes. When an attack or failure is detected, the system receives feedback and automatically triggers a lockdown mode, suspending operations to prevent further compromise while maintaining data integrity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent implements canary signals as early warning indicators deployed within the distributed system. These canary signals detect attacks before they spread to critical data nodes, allowing the system to take preliminary protective actions and activate lockdown mode before full compromise occurs.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If common storage and software are used in production/backup networks for ease of operation, then operational simplicity is improved, but exposure to security flaws increases

Engineering Contradiction:
Improvesystem operation simplicityVSAvoidsecurity flaw exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts critical data from the production and backup networks, removing it from environments that use common storage and software with known security vulnerabilities. The extracted data is then stored in a separate distributed network using specialized secure storage mechanisms, isolating it from common attack vectors.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary layer of encrypted data shards and distributed storage nodes that mediate between the production network and the backup network. This intermediary structure prevents direct access to critical data while maintaining the operational simplicity of the original systems through automated data management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250377985A1Distributed data protection for physical security
Publication Date: 2025.12.11 DELL PROD LP
  • US20250377985A1 patent drawing
  • US20250377985A1 patent drawing
  • US20250377985A1 patent drawing

AI summary

Providing data protection by distributing backup data among a large plurality of distributed devices. A number of networked devices are deployed to protect data of a target device in the network. Each device of contains memory sufficient to store at least a portion of backed up data from the target device. Index information for backup data of the target device stored in each device. A cyber-attack condition is detected by a heartbeat or canary signal. Upon detection of an attack the devices enter a lockdown mode. The index information is used to reconstruct the backed up data from the portion of backed up data stored on each respective device.