Multi-Cloud Block Storage Data Fragmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cloud storage solutions lack adequate data security and availability, as they cannot effectively prevent unauthorized access and are vulnerable to data loss due to single-point outages, with encryption being insufficient against rogue employees and limited by dependency between disks.

Innovation Solution

A distributed block storage arrangement across multiple separate clouds, where data is encoded into multiple pieces stored across different clouds, requiring at least two pieces and the key to reconstruct the original data, ensuring security and availability even if one cloud becomes unavailable or compromised.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data is stored in conventional cloud storage solutions, then storage capacity and scalability are improved, but data security and protection against unauthorized access deteriorate

Engineering Contradiction:
Improvestorage capacityVSAvoiddata security
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent divides data into multiple fragments and distributes them across separate cloud storage services. Each fragment alone is insufficient to reconstruct the original data, providing security while maintaining storage capacity. This directly addresses the contradiction by segmenting data so that unauthorized access to individual clouds does not compromise overall data security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary encoding mechanism that transforms data into encoded fragments before storage. This intermediary layer ensures that even if cloud storage is compromised, the original data cannot be recovered without the proper decoding key, thus improving data security while preserving storage functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is applied to cloud stored data, then protection against unauthorized access is improved, but access control and prevention of rogue employee access deteriorate

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoidaccess control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments both the data and the decryption key into multiple parts, distributing them across different cloud services. This ensures that even a rogue employee with access to one cloud cannot access the complete data or key, maintaining security while allowing controlled access through proper authentication of multiple fragments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a dimensional layer to access control by requiring authentication across multiple dimensions (multiple cloud services) rather than a single point of access. This multi-dimensional approach prevents rogue employees from accessing data through a single compromised account while maintaining ease of operation for authorized users.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If data is mirrored locally for availability, then data availability and recovery speed are improved, but infrastructure complexity and cost deteriorate

Engineering Contradiction:
Improvedata availabilityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments data storage across multiple external cloud services rather than requiring local mirroring infrastructure. This eliminates the need for complex local redundant storage systems while maintaining data availability through distributed cloud-based fragments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent leverages the self-service capabilities of cloud providers to handle data replication and availability, eliminating the need for enterprise infrastructure to independently manage mirroring. The cloud services themselves provide the redundancy and availability mechanisms.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If all data is stored in a single cloud service, then storage management simplicity is improved, but vulnerability to single-point outages and data loss deteriorates

Engineering Contradiction:
Improvestorage management simplicityVSAvoidvulnerability to outages
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments data across multiple cloud services, eliminating single-point failure risks while maintaining operational simplicity through automated encoding and distribution. The system automatically manages the complexity of multi-cloud storage, presenting a unified interface to users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of storage distribution from centralized to distributed across multiple clouds. This parameter change fundamentally reduces vulnerability to outages while the automated encoding process maintains management simplicity by handling the distribution transparently.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11385958B2Multi cloud transactional storage for availability and security
Publication Date: 2022.07.12 EMC IP HLDG CO LLC
  • US11385958B2 patent drawing
  • US11385958B2 patent drawing
  • US11385958B2 patent drawing

AI summary

One example method includes exposing a block storage which is distributed across a group of multiple sites, receiving a primary write request that identifies data to be stored, separating data identified in the primary write request into multiple data pieces, encoding the data pieces by creating multiple new blocks of data based on the multiple data pieces, where the data pieces are encoded in such a way that when a sufficient number, but fewer than all, of the multiple new blocks of data are retrieved, the data identified in the write request is recoverable by decoding, and writing the new blocks of data to different respective sites of the group, where writing of the new blocks of data is performed in conjunction with a plurality of secondary write requests, each of which corresponds to one of the new blocks of data.