Multi-Cloud Data Fragmentation for Ransomware-Resilient Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Companies face challenges in managing and securing data in cloud environments due to jurisdictional complexities, data breaches, and ransomware attacks, with existing systems lacking resilience and compliance with multiple legal requirements.
Innovation Solution
A cloud-based system that segments and encrypts data files across multiple cloud service providers, creating jurisdiction-independent storage and enabling automatic self-healing from ransomware attacks by distributing encrypted fragments and using a pointer file for reassembly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored in a single cloud vendor's infrastructure, then data access and management is simplified, but data security and compliance with multiple jurisdictional laws are compromised
Solution Approach 1:
The patent divides data into multiple segments or fragments and distributes them across different cloud service providers located in various jurisdictions. Each segment alone is insufficient to reconstruct the complete data, ensuring that no single provider has access to the full dataset. This segmentation approach maintains security and compliance while enabling data access through coordinated retrieval from multiple providers.
2Reliability
If data is encrypted and segmented across multiple cloud providers, then data security and jurisdictional compliance are improved, but system complexity and data retrieval overhead increase
Solution Approach 1:
The patent introduces a coordinator system that acts as an intermediary between users and the distributed cloud providers. This coordinator manages the segmentation, encryption, and retrieval processes, handling the complexity of coordinating multiple providers while presenting a simplified interface to users. The coordinator tracks data segments across providers and orchestrates their assembly when data access is requested.
3Speed
If all data segments are stored in one location, then data retrieval is fast and simple, but the system becomes vulnerable to ransomware attacks and single points of failure
Solution Approach 1:
The patent segments data into multiple parts and distributes them across different cloud service providers in different locations. This geographic and organizational distribution eliminates single points of failure, as ransomware or failures at one provider cannot affect all data segments. The system retrieves segments from multiple providers and reassembles them, maintaining both security and operational continuity.
4Reliability
If data is distributed across multiple jurisdictions, then compliance with local data laws is improved, but determining applicable jurisdiction and managing legal requirements becomes complex
Solution Approach 1:
The patent applies different data segments to different jurisdictions based on specific compliance requirements. Each cloud provider operates within its local jurisdiction, storing segments that comply with local laws. The system configures which segments are placed in which jurisdictions based on the data's sensitivity, access requirements, and applicable legal frameworks, enabling targeted compliance management.
Data Source
AI summary
A cloud-based system and method for securely storing data formed into cloud technology-specific data objects (hereinafter, “buckets”) by an S3 gateway, comprising obtaining a source data bucket from the S3 gateway; splitting the data bucket into at least three fragments; encrypting the fragments using an encryption key associated with the fragments and distributing the encrypted fragments among at least three cloud storage providers, and creating a pointer file containing information for retrieving the encrypted fragments. When a system user requests access to the data, the system ensures the request is legitimate, then uses the information stored in the pointer file to retrieve the stored encrypted bucket fragments from the plurality of clouds, decrypts the fragments and reconstructs the data buckets, and provides data access to the S3 gateway.


