Obfuscated Erasure Coding for Secure High-Availability Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage systems face challenges in integrating security and high availability efficiently, as off-the-shelf erasure coding methods can be reverse engineered, leading to data privacy issues and increased computational complexity, making them unsuitable for real-time data streams and archival purposes.

Innovation Solution

A storage management system that combines obfuscation operations with erasure coding using matrix operations, allowing for simultaneous transformation of data into coded fragments for redundancy and security, leveraging hardware-accelerated processing and vector instructions to enhance speed and throughput.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional obfuscation operations and erasure coding are applied separately to ensure security and high availability, then data security and reliability are improved, but computational complexity increases and processing speed decreases

Engineering Contradiction:
Improvedata security and high availabilityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines obfuscation operations and erasure coding into a single integrated process. The system applies both security obfuscation and redundancy coding simultaneously during data encoding, eliminating the need for separate processing stages. This merging reduces computational overhead while maintaining both security and high availability guarantees.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The encoding system performs multiple functions simultaneously: it provides security obfuscation, creates redundant coded fragments for high availability, and enables efficient data recovery. A single encoding operation generates coded fragments that are both secure and redundant, making the system multi-functional without requiring separate dedicated systems for each purpose.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate obfuscation and erasure coding processes are used, then security and redundancy are achieved, but processing time increases

Engineering Contradiction:
Improvesecurity and redundancyVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs obfuscation and encoding in a single preliminary action during data ingestion. By combining these operations upfront, the system avoids repeated processing during write operations and enables faster data retrieval, as the coded fragments are already both obfuscated and redundant from the initial encoding step.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The integrated encoding process maintains continuous useful action by performing obfuscation and redundancy creation in one uninterrupted operation. This eliminates the idle time and data movement between separate processing stages, keeping the data flow continuous and reducing overall processing time while maintaining security and redundancy.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If standard erasure coding is applied to data streams, then high availability is improved, but data privacy is compromised due to reverse engineering risks

Engineering Contradiction:
Improvehigh availabilityVSAvoiddata privacy risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges obfuscation and erasure coding so that coded fragments contain both security transformations and redundancy information. This integration ensures that even if the encoding structure is analyzed, the obfuscated content within the fragments protects the original data, maintaining privacy while providing high availability through the redundant fragment structure.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The coded fragments function as composite structures containing multiple layers: the outer structure provides redundancy for high availability, while the inner obfuscated content provides security. This composite approach allows the system to deliver both high availability and data privacy protection simultaneously, with each layer serving its specific protective function.

Inventive Principle:
Principle #40Composite materials

4Reliability

If multiple obfuscated copies are stored in separate physical locations for security and availability, then reliability is improved, but storage efficiency decreases

Engineering Contradiction:
Improvesecurity and availabilityVSAvoidstorage space
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system merges the functions of multiple physical copies into a single set of coded fragments. Instead of storing multiple complete obfuscated copies of data, the system stores encoded fragments that collectively represent the original data. Any sufficient subset of these fragments can reconstruct the original, reducing total storage requirements while maintaining availability and security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent changes the storage parameter from complete data copies to fragmented encoded representations. By transforming the data into coded fragments with specific redundancy properties, the system achieves the same availability guarantees with fewer storage resources, as the fragments can be combined in multiple ways to recover the original data without requiring full duplicate copies.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10656996B2Integrated security and data redundancy
Publication Date: 2020.05.19 PHAZRIO INC
  • US10656996B2 patent drawing
  • US10656996B2 patent drawing
  • US10656996B2 patent drawing

AI summary

One embodiment provides a system that facilitates integrated security and high availability. During operation, the system obtains a number of data elements from a data stream based on a number of coded fragments that a code word includes. The system determines one or more bit-level operations for the data elements in such a way that at least one of the one or more bit-level operations becomes eliminated from a process of erasure encoding. The system then obfuscates the data elements based on one or more bit-level operations. Subsequently, the system generates a code word of the erasure encoding from the obfuscated data elements based on the generator matrix. The code word comprises a plurality of coded fragments.