Secure Digital Information Storage via Distributed Key Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud-based storage solutions fail to ensure complete security of digital information as they do not prevent information leakage even if one storage provider is compromised, and rely on traditional encryption schemes requiring key management services.

Innovation Solution

The method involves encrypting digital information with multiple pseudo-random keys and transmitting the encrypted data and keys across multiple domains, ensuring that access to the information requires compromise of multiple domains, thereby increasing security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional encryption schemes are used with centralized key management, then data can be encrypted and stored, but the system requires specialized key management services and creates single points of failure

Engineering Contradiction:
Improvedata securityVSAvoidkey management service requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the encryption keys into multiple key shares and distributes them across different storage domains. Instead of centralizing key management in a single service, the system divides the key management function across multiple independent domains, eliminating the single point of failure while maintaining data security through cryptographic segmentation.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If data is stored on a single cloud provider, then storage is simple and economical, but the client surrenders control and is vulnerable to insider threats and data breaches

Engineering Contradiction:
Improvestorage simplicityVSAvoiddata control and security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies segmentation by dividing encrypted data into multiple data segments and distributing them across different cloud providers. Each provider stores only a portion of the encrypted data, making it impossible for any single provider to access the complete original information, thus maintaining client control while preserving storage simplicity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces cryptographic intermediaries (encryption keys and key shares) that mediate between the client and cloud providers. The client retains control through cryptographic mechanisms without needing to physically manage or access the distributed data segments, achieving both ease of operation and enhanced security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If data is partitioned across multiple storage providers, then resilience to single provider compromise is improved, but information leakage can still occur if one provider is compromised

Engineering Contradiction:
Improveresilience to compromiseVSAvoidinformation leakage risk
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies local quality by ensuring that each data segment stored at different locations (cloud providers) has the property of being encrypted with unique key shares. This means each location holds data with locally optimized security properties - encrypted segments that are mathematically useless without the corresponding key share, preventing information leakage even if one provider is compromised.

Inventive Principle:
Principle #3Local quality

4Ease of operation

If encryption keys are stored in centralized key management services, then key management is simplified, but the system creates vulnerability points and requires specialized third-party services

Engineering Contradiction:
Improvekey management simplicityVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the key management function from centralized services and distributes it across multiple domains. Each domain holds only a portion of the key material, and the system eliminates the need for specialized third-party key management services by implementing a distributed key architecture where key shares are managed locally at each storage domain.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system uses cryptographic intermediaries (key shares and reconstruction algorithms) to mediate key management without requiring centralized storage or specialized services. The mathematical properties of the cryptographic system enable secure key reconstruction only when sufficient key shares are combined, eliminating vulnerability points while maintaining operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10699021B2Method and a device for secure storage of at least one element of digital information, and system comprising such device
Publication Date: 2020.06.30 INESC TEC INST DE ENGENHARIA DE SISTEMAS E COMPUTADORES TECHA E CIENCIA
  • US10699021B2 patent drawing

AI summary

The present invention is enclosed in the field of digital information storage, specifically digital information storage with complies with high security and privacy requirements. It is an object of the present invention a method for secure storage of at least one element of digital information (201), comprising i) ciphering with at least one ciphering key (202) said at least one element of digital information (201) into a ciphered element of digital information (203) and ii) transmitting said ciphered element of digital information (203) and said at least one ciphering key (202) to a domain (2) (204) from a plurality of domains (2) (204) for subsequent storage, wherein said ciphered element of digital information (203) and said at least one ciphering key (202) are transmitted to different domains (2) (204). Such method may be implemented by a system comprising client devices and a front-end server.