Dynamic Data Concealment via Randomized File Relocation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data security measures are inadequate in preventing unauthorized access and cryptographic attacks, as attackers can still identify and target encrypted data within secure networks, even with perimeter security in place, due to the limitations of static security techniques and the potential for insider threats.
Innovation Solution
A continuous concealment process that obfuscates and dynamically moves data across a distributed data store, creating multiple obfuscated data files that are randomly renamed and distributed across multiple computing devices, making it impractically difficult for attackers to identify and access the target data, even if they gain access to the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static security measures such as firewalls and encryption are used, then data protection is provided, but attackers can still identify and target encrypted data within the network
Solution Approach 1:
The patent implements dynamic data concealment by continuously moving encrypted data files to different locations and randomly renaming them. This transforms the static security approach into a dynamic system where data location and identity constantly change, making it extremely difficult for attackers to identify and target specific encrypted files even when they have network access
Solution Approach 2:
The system performs preliminary actions by pre-obfuscating data files with random names and continuously moving them to different locations before attackers can identify them. This proactive concealment ensures that even if attackers gain network access, the target data remains hidden and unidentifiable
2Reliability
If data is encrypted and stored in a data store, then data security is improved, but attackers can still locate and target the encrypted data files
Solution Approach 1:
The patent applies the principle of color changes by randomly renaming data files with unpredictable identifiers that change over time. This is analogous to changing the visual appearance of an object to prevent recognition. The random names act as changing identifiers that make it impossible for attackers to recognize or target specific data files based on their names or locations
3Reliability
If perimeter security is implemented, then unauthorized entry is prevented, but inside attackers with authorized access can still obtain sensitive data
Solution Approach 1:
The patent segments the data protection strategy into multiple independent layers: encryption of data content, continuous random renaming of files, and frequent relocation to different storage locations. This segmentation ensures that even if one layer (perimeter security) is compromised by insider attackers, the other layers (dynamic concealment and encryption) remain intact and continue to protect the data
Data Source
AI summary
Methods, apparatuses, and embodiments related to improving security of data that is stored and distributed over a data network. In an example, source data to be protected is partitioned into multiple files, and each file is obfuscated, such as by being encrypted, to created multiple obfuscated data files. Information as to how each obfuscated data file was obfuscated is stored in an associated trace file. The multiple obfuscated data files are moved around a data network via a data movement process that includes sending each of the multiple obfuscated data files to a different randomly selected computer, where the computer further obfuscates the obfuscated data the trace file, and sends the further obfuscated data and trace file to a next randomly selected computer. In an example, the various operations for improving security may be performed by an integrated circuit, such as a system-on-chip (SoC) or application-specific integrated circuit (ASIC).


