Multi-Cloud Data Fragmentation for Ransomware-Resilient Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies face challenges in managing and securing data in cloud environments due to jurisdictional complexities, data breaches, and ransomware attacks, with existing systems lacking resilience and compliance with multiple legal requirements.

Innovation Solution

A cloud-based system that segments and encrypts data files across multiple cloud service providers, creating jurisdiction-independent storage and enabling automatic self-healing from ransomware attacks by distributing encrypted fragments and using a pointer file for reassembly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is stored in a single cloud vendor's infrastructure, then data access and management is simplified, but data security and compliance with multiple jurisdictional laws are compromised

Engineering Contradiction:
Improvedata access and managementVSAvoiddata security and compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides data into multiple segments or fragments and distributes them across different cloud service providers located in various jurisdictions. Each segment alone is insufficient to reconstruct the complete data, ensuring that no single provider has access to the full dataset. This segmentation approach maintains security and compliance while enabling data access through coordinated retrieval from multiple providers.

Inventive Principle:
Principle #1Segmentation

2Reliability

If data is encrypted and segmented across multiple cloud providers, then data security and jurisdictional compliance are improved, but system complexity and data retrieval overhead increase

Engineering Contradiction:
Improvedata security and complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a coordinator system that acts as an intermediary between users and the distributed cloud providers. This coordinator manages the segmentation, encryption, and retrieval processes, handling the complexity of coordinating multiple providers while presenting a simplified interface to users. The coordinator tracks data segments across providers and orchestrates their assembly when data access is requested.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If all data segments are stored in one location, then data retrieval is fast and simple, but the system becomes vulnerable to ransomware attacks and single points of failure

Engineering Contradiction:
Improvedata retrieval speedVSAvoidresilience to attacks and failures
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments data into multiple parts and distributes them across different cloud service providers in different locations. This geographic and organizational distribution eliminates single points of failure, as ransomware or failures at one provider cannot affect all data segments. The system retrieves segments from multiple providers and reassembles them, maintaining both security and operational continuity.

Inventive Principle:
Principle #1Segmentation

4Reliability

If data is distributed across multiple jurisdictions, then compliance with local data laws is improved, but determining applicable jurisdiction and managing legal requirements becomes complex

Engineering Contradiction:
Improvecompliance with data privacy lawsVSAvoidjurisdictional management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies different data segments to different jurisdictions based on specific compliance requirements. Each cloud provider operates within its local jurisdiction, storing segments that comply with local laws. The system configures which segments are placed in which jurisdictions based on the data's sensitivity, access requirements, and applicable legal frameworks, enabling targeted compliance management.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12499248B2Systems and methods for breach-proof, resilient, compliant data in a multi-vendor cloud environment and automatically self heals in the event of a ransomware attack
Publication Date: 2025.12.16 CALAMU TECHNOLOGIES CORP
  • US12499248B2 patent drawing
  • US12499248B2 patent drawing
  • US12499248B2 patent drawing

AI summary

A cloud-based system and method for securely storing data formed into cloud technology-specific data objects (hereinafter, “buckets”) by an S3 gateway, comprising obtaining a source data bucket from the S3 gateway; splitting the data bucket into at least three fragments; encrypting the fragments using an encryption key associated with the fragments and distributing the encrypted fragments among at least three cloud storage providers, and creating a pointer file containing information for retrieving the encrypted fragments. When a system user requests access to the data, the system ensures the request is legitimate, then uses the information stored in the pointer file to retrieve the stored encrypted bucket fragments from the plurality of clouds, decrypts the fragments and reconstructs the data buckets, and provides data access to the S3 gateway.