Dynamic Data File Signatures for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need to secure user data stored in public cloud computing environments from unauthorized access, as users cannot control the security of cloud systems or communication networks, making existing mechanisms inadequate for preventing data exposure and hacking.

Innovation Solution

A processor-implemented system generates and manages dynamic data file signatures for media files, requiring these signatures for access, which change upon access or expiration, ensuring only authorized users can access the data, even if the cloud system or network is compromised.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If user data is stored in a public cloud computing environment, then data accessibility and storage capacity are improved, but security control and protection from unauthorized access deteriorate

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the authentication process by separating the static cloud storage system from dynamic per-file signatures. Each data file receives a unique, time-limited signature that is independently validated, allowing public accessibility while maintaining granular security control at the file level rather than requiring centralized authentication for the entire cloud system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces data file signatures as an intermediary authentication mechanism between the cloud storage system and accessing devices. These signatures act as mediators that verify authorization without requiring direct control or trust in the cloud system's security infrastructure, enabling secure access in public environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data file signatures are continuously regenerated upon each access, then security against unauthorized access is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsignature management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic signatures that automatically regenerate upon each data file access or after a predetermined time period. This dynamic approach maintains high security by ensuring signatures are time-limited and file-specific, while the automated regeneration process manages complexity through systematic rather than manual operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the temporal parameter of authentication by implementing time-limited signatures that automatically expire after a predetermined period. This parameter change enhances security by limiting the window for unauthorized access, while the systematic time-based management reduces operational complexity compared to perpetual authentication mechanisms.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If dynamic signatures are implemented for each data file, then protection against network compromises and cloud hacking is improved, but authentication time and access processing increase

Engineering Contradiction:
Improveprotection from cloud hackingVSAvoidauthentication time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-generating and storing data file signatures alongside their corresponding data files in the cloud storage system. This preliminary preparation eliminates the need for real-time signature generation during authentication, reducing access time while maintaining the security benefits of file-specific, time-limited signatures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates and stores copies of authentication credentials (signatures) within the cloud storage system itself, rather than requiring external verification. This copying approach allows rapid local validation of signatures during access requests, minimizing authentication time while maintaining strong security through distributed verification.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11138344B2Securing access to user data stored in a cloud computing environment
Publication Date: 2021.10.05 OOMA INC
  • US11138344B2 patent drawing
  • US11138344B2 patent drawing
  • US11138344B2 patent drawing

AI summary

Systems and methods for securing access to user data stored in a networked location are described herein. A first user device may generate data that a user may desire to keep private. The generated data may be transmitted to, and stored at, a networked location, which then makes it vulnerable to malicious attack or exposure to unintended recipients. To protect the user data stored at the networked location, a recursive data file signature is generated for each stored data file. In order to access the stored data file, the user needs to provide the data file signature. In addition, every time the user data is accessed by the user, the data file signature is changed. In this way, the exposed data file signature will no longer be valid if an unauthorized entity tries to access the user data.