Distributed Edge Storage Network Using Cost Function for Heterogeneous Nodes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Distributed edge storage systems face security challenges due to heterogeneous storage nodes with varying capabilities, making it difficult to implement effective security measures without compromising performance, and existing secret sharing schemes do not adequately address eavesdropping attacks where an attacker controls a group of edge devices.
Innovation Solution
A method is introduced to select storage nodes and allocate memory such that an attacker with access to a certain number of nodes (Z) cannot decode partial information of a file, using linear code keys and packetization across nodes, with the goal of minimizing costs and ensuring information theoretic secrecy, while accounting for heterogeneous storage availability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional secret sharing schemes are implemented in distributed edge storage systems, then security against eavesdropping attacks is improved, but the system fails to account for heterogeneous storage node capabilities and cannot optimize performance
Solution Approach 1:
The patent applies local quality by assigning different roles and storage capacities to different edge nodes based on their heterogeneous capabilities. Some nodes store only secret shares while others store both shares and data portions, with storage allocations tailored to individual node capacities rather than treating all nodes uniformly.
Solution Approach 2:
The system dynamically adapts to varying storage node capabilities by allowing flexible configuration of which nodes participate in storing secret shares versus data portions. The architecture enables dynamic adjustment of storage allocation based on real-time node availability and capacity, rather than requiring a static homogeneous structure.
2Reliability
If more storage nodes are added to increase security (higher Z value), then security against eavesdropping is improved, but the cost function increases due to more nodes requiring storage allocation
Solution Approach 1:
The patent implements partial action by having different nodes perform different amounts of work - some nodes only store secret shares while others store both shares and data portions. This partial differentiation reduces the overall complexity burden across the network while maintaining the required security level Z, as not every node needs to handle the full complexity of both secret and data storage.
3Ease of manufacture
If equal memory sizes are allocated to all storage nodes, then implementation simplicity is improved, but storage efficiency deteriorates due to heterogeneous node capabilities
Solution Approach 1:
The patent applies local quality by allocating storage space according to each node's actual capacity. Nodes with larger storage capabilities are assigned both secret shares and data portions, while nodes with limited capacity store only secret shares. This localized adaptation to individual node characteristics maximizes overall storage efficiency while maintaining implementation feasibility.
4Object-affected harmful factors
If an attacker controls Z storage nodes, then the attacker can access more stored information, but the system requires more nodes to maintain security, increasing overall system cost
Solution Approach 1:
The patent applies segmentation by dividing the storage system into distinct functional segments: nodes storing only secret shares and nodes storing both secret shares and data portions. This segmentation allows the system to achieve the required security level Z with a more efficient node configuration, as the segmented architecture optimizes the distribution of security-critical information across the network.
Data Source
AI summary
A set of N network-coupled edge storage nodes are selected to store a file of size |F|. The N edge storage nodes have heterogeneous storage availability and are ordered from a largest storage availability at the first edge storage node to a smallest availability at the Nth edge storage node. A value Z<N is selected, such that an attacker having access to Z edge storage nodes is unable to decode any partial information of the file. The first through Z+1th edge storage nodes are assigned a same packet size. Keys are stored in the first Z edge storage nodes and independent linear combinations of the keys combined with partitions of the file are stored in the Z+1th to the Nth edge storage nodes.


