Multi-Cloud Data Fragmentation for Jurisdiction-Independent Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Companies face challenges in storing data in cloud environments due to jurisdictional conflicts, data security breaches, and the risk of data loss when using single cloud service providers, especially for sensitive information like PII, which can lead to mandatory disclosures and access issues.
Innovation Solution
A system that segments and encrypts data files across multiple cloud service providers in different jurisdictions, ensuring no single provider has access to the complete file, using a lookup table and encryption key for reassembly, thus making the data jurisdiction-independent and secure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored in a single cloud service provider, then data access and management is simplified, but data security and jurisdictional compliance are compromised
Solution Approach 1:
The patent divides data files into multiple segments and distributes them across different cloud service providers in different jurisdictions. Each segment alone is insufficient to reconstruct the original data, providing security while maintaining accessibility through coordinated retrieval from multiple providers.
Solution Approach 2:
The patent introduces an intermediary system that manages the segmentation, encryption, and reassembly of data across multiple cloud providers. This intermediary coordinates data retrieval and reassembly, maintaining ease of operation while distributing data security responsibilities across multiple jurisdictions.
2Reliability
If data is segmented and distributed across multiple cloud service providers, then data security and jurisdictional independence are improved, but system complexity increases
Solution Approach 1:
The patent employs an intermediary management system that abstracts the complexity of multi-provider data segmentation and reassembly. This intermediary handles the coordination, encryption key management, and data reconstruction processes, shielding users from the underlying system complexity while maintaining security and jurisdictional independence.
Solution Approach 2:
The patent creates a universal data management system that can operate across multiple cloud service providers and jurisdictions through standardized protocols. This multi-functional system handles segmentation, encryption, distribution, and reassembly uniformly, reducing complexity by providing a single interface for diverse operations.
3Speed
If complete data files are stored at cloud service providers, then data retrieval is faster, but data becomes subject to jurisdictional laws and security breaches
Solution Approach 1:
The patent segments data files into multiple parts distributed across different cloud providers in different jurisdictions. This segmentation prevents any single jurisdiction from governing the complete data and reduces security breach impact, while retrieval speed is maintained through parallel fetching of segments from multiple providers.
Solution Approach 2:
The patent distributes data segments across the dimensional space of multiple cloud service providers and jurisdictions rather than concentrating them in a single location. This spatial distribution across dimensions enables faster retrieval through parallel access while reducing exposure to any single jurisdiction's laws or security vulnerabilities.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A cloud based system for providing data security, the system having a processor which creates a source data file; wherein the source data file is split into at least one fragments; an encryption key associated with the at least one fragments; and wherein the at least one fragments is encrypted by the encryption key; a plurality of cloud storage providers; wherein the at least one fragments is distributed among the plurality of cloud storage providers whereby no single cloud storage provider possesses all of the at least one fragments; a pointer file which is created on a local computer; wherein the pointer file stores the location of the at least one fragments; and wherein the pointer file is accessed; the encryption key authenticates the plurality of cloud storage providers; the at least one fragments are transferred from the plurality of cloud storage providers to the local computer; and wherein the at least one fragments are reassembled; and the source data file is deleted.