Isolated Encrypted Backup Storage for Compromise-Resistant Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional data backup and recovery systems leave organizations' backup data vulnerable to hacks and compromises, as malicious users can access and manipulate backup data stored on compromised systems.
Innovation Solution
A data protection service that stores backup data in an isolated, encrypted manner using a custodian key specific to the backup process, ensuring the backup data is not accessible to malicious users, and allows organizations to maintain control over cryptographic keys, even in the event of a system compromise.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If backup data is stored on the same system as production data, then data restoration is faster and easier, but the backup data becomes vulnerable to hacks and compromises
Solution Approach 1:
The patent divides the data storage architecture into separate components: production data stored in production data stores and backup data stored in isolated backup data stores. This segmentation ensures that backup data is physically separated from production systems, preventing hackers from accessing both types of data through a single compromise while maintaining independent management of each storage environment.
Solution Approach 2:
The patent introduces a data protection service as an intermediary component that manages the backup process between production systems and backup storage. This intermediary service handles data encryption, key management, and secure transfer, reducing the complexity burden on individual systems while enhancing overall security through specialized protection mechanisms.
2Reliability
If backup data is encrypted with organization-controlled keys, then data security is enhanced, but access and restoration processes become more complex
Solution Approach 1:
The patent implements preliminary encryption of backup data using organization-controlled cryptographic keys before the data is stored in backup data stores. This advance protection ensures that even if the backup storage is compromised, the data remains inaccessible without the proper keys. The encryption process is automated as part of the backup workflow, minimizing the operational burden on users.
Solution Approach 2:
The data protection service provides feedback mechanisms that track key usage, backup status, and restoration progress. This feedback system allows organizations to monitor their encrypted backup data without requiring direct access to the encryption keys, simplifying operations while maintaining security through automated status reporting and key management logging.
Data Source
AI summary
Disclosed techniques relate to security of backup data. In some embodiments, a method includes receiving, by data protection service running on a cloud computing system, a first encrypted copy of a backup of a first data store that is associated with a first account of an organization, where the first encrypted copy is encrypted using a first custodian cryptographic key that is shared between the organization and the data protection service that is different than a first production cryptographic key that is private and used by the organization to encrypt a non-backup version of the first data store. The method may include generating a second encrypted copy of the backup, including by encrypting the backup using a storage cryptographic key. The method may include storing the second encrypted copy of the backup in a second data store that is associated with the data protection service.


