Isolated Encrypted Backup Storage for Compromise-Resistant Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional data backup and recovery systems leave an organization's backup data vulnerable to hacks or compromises, as malicious users can access and manipulate backup data stored on the same systems.
Innovation Solution
A data protection service that stores backup data in an isolated, encrypted manner using a custodian key specific to the service, which is different from the organization's production key, ensuring the backup data is inaccessible to unauthorized users, even in system compromises.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If backup data is stored on the same system as production data, then data accessibility and operational efficiency are improved, but data security and vulnerability to hacks deteriorate
Solution Approach 1:
The system divides data storage into separate segments: production data remains in the original data store while backup data is stored in a different, isolated data store. This segmentation ensures that backup data is protected from hacks affecting the production system, while still maintaining efficient access when needed.
Solution Approach 2:
The patent introduces an intermediary encryption mechanism using custodian keys that bridge the production system and backup storage. The encryption layer acts as a mediator that allows secure access to backup data while preventing unauthorized access, thus maintaining both security and accessibility.
2Ease of operation
If traditional encryption methods are used with shared keys, then ease of data access is improved, but data protection and security deteriorate
Solution Approach 1:
The encryption system is segmented into multiple key types with different functions: production keys for encrypting production data, custodian keys for encrypting backup data, and recovery keys for data restoration. This segmentation allows each key to be optimized for its specific purpose, maintaining ease of operation while improving overall data protection.
Solution Approach 2:
The patent changes the cryptographic parameters by introducing custodian keys with specific properties (different from production keys) that are dedicated to backup operations. This parameter change ensures that compromise of production keys does not affect backup security, while maintaining efficient access through the specialized custodian key mechanism.
Data Source
AI summary
Disclosed techniques relate to security of backup data. In some embodiments, a method includes receiving, by data protection service running on a cloud computing system, a first encrypted copy of a backup of a first data store that is associated with a first account of an organization, where the first encrypted copy is encrypted using a first custodian cryptographic key that is shared between the organization and the data protection service that is different than a first production cryptographic key that is private and used by the organization to encrypt a non-backup version of the first data store. The method may include generating a second encrypted copy of the backup, including by encrypting the backup using a storage cryptographic key. The method may include storing the second encrypted copy of the backup in a second data store that is associated with the data protection service.


