Immutable Data Safe for Key Sharding and Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for managing security risks on the Worldwide Web/Public Internet are inadequate, leading to significant economic losses and breaches of private information, as evident in recent cyber-attacks on critical infrastructure and government systems.
Innovation Solution
The implementation of an immutable 'data safe' that encrypts and decrypts information using cryptographic pilot keys stored in non-volatile storage, preventing exposure and unauthorized decryption by employing secure communication protocols and hardware-based security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional encryption methods are used to protect data at rest, then data security is improved, but the computational barrier for decryption remains insufficient and keys may be exposed in case of breach
Solution Approach 1:
The patent segments the encryption key into multiple shards distributed across different storage locations. Instead of storing a single key, the system divides the key material into fragments that are stored separately, requiring aggregation of multiple shards to reconstruct the original key. This segmentation increases the computational barrier and security against breaches, as attackers would need to compromise multiple distributed storage locations rather than a single key repository.
2Ease of operation
If encryption keys are stored in accessible locations for decryption operations, then ease of operation is improved, but security is worsened due to potential key exposure
Solution Approach 1:
The patent introduces an intermediary key management system that mediates between key storage and decryption operations. Instead of directly storing and accessing encryption keys in easily accessible locations, the system uses key shards as intermediaries distributed across secure storage locations. The intermediary mechanism allows decryption operations to proceed by aggregating key shards through secure protocols, maintaining ease of operation while protecting key security through distributed storage and controlled access.
3Quantity of substance
If data is stored in external storage systems, then storage capacity is improved, but security control is worsened due to external system vulnerabilities
Solution Approach 1:
The patent extracts the key management function from external storage systems and implements it within the storage system itself through immutable data safes. By taking out the critical key management operations from potentially vulnerable external environments and embedding them directly in the storage infrastructure with immutable protection, the system maintains the storage capacity benefits of external systems while regaining security control through internal, protected key management mechanisms.
Data Source
AI summary
In one embodiment, data at rest is securely stored. A data safe performing data plane processing operations in response to requests of received read data requests, received write data requests, and received read information responses, with the data safe being immutable to processing-related modifications resulting from said performing data plane processing operations. In one embodiment, performing these data plane processing operations does not expose any pilot keys outside the data safe in clear form nor in encrypted form. The pilot keys are used to encrypt information that is subsequently stored in a storage system. One embodiment uses pilot keys to encrypt data that is subsequently stored in a storage system. One embodiment uses data cryptographic keys to encrypt data, uses the pilot keys to cryptographically-wrap (encrypt) the data cryptographic keys, and stores the cryptographically wrapped data keys and encrypted data in a storage system.


