Pod-Based Cloud Encryption That Blocks Maintainer Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large commercial cloud computing database storage systems face security vulnerabilities due to third-party maintainers having access to user data, leading to potential data theft and breaches, especially with numerous employees handling the processing devices.
Innovation Solution
A system comprising pod computing devices, each with a central processing unit, volatile and non-volatile memory, and a communication device, securely stores user data using a private key accessible only to the user, ensuring data is encrypted and accessible only to the individual, with a central authority managing administrative functions without access to user data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If third-party maintainers are employed to operate and maintain cloud database servers, then system operational capability and maintenance efficiency are improved, but security risk increases due to maintainers having access to user data
Solution Approach 1:
The system segments the cloud infrastructure into multiple isolated pod computing devices, each handling specific user data. This segmentation allows maintainers to access and maintain the overall system while being prevented from accessing individual user data stored in encrypted form on separate pods, thus resolving the contradiction between maintenance efficiency and data security.
Solution Approach 2:
The patent introduces an intermediary encryption layer where user data is encrypted using public key cryptography before being stored on pod computing devices. The private key remains exclusively with the user, creating an intermediary security mechanism that allows maintainers to operate the system without being able to decrypt or access the actual user data, thereby maintaining both system operability and data security.
2Ease of operation
If maintainers have control over processing devices that access user data, then system maintenance and updates can be performed, but data security is compromised as maintainers become weak points in the security system
Solution Approach 1:
The system extracts the private key from the processing devices and maintains it exclusively on the user's local device. The pod computing devices contain only public keys and encrypted data, allowing maintainers to access and maintain the processing devices without having access to the private key or ability to decrypt user data, thus enabling maintenance while preserving security reliability.
Solution Approach 2:
Public key cryptography serves as an intermediary mechanism that allows maintainers to control and maintain processing devices while being mathematically prevented from accessing encrypted user data without the private key. This intermediary cryptographic layer decouples maintenance accessibility from data security, allowing both requirements to be satisfied simultaneously.
3Productivity
If multiple maintainers are employed to handle processing devices, then system operational capacity increases, but the potential for data theft increases proportionally with the number of maintainers
Solution Approach 1:
The system segments user data across multiple isolated pod computing devices, each with its own encrypted data store. This segmentation allows the system to employ multiple maintainers for operational capacity while ensuring that each maintainer, even if they access multiple pods, cannot access all user data due to the distributed encrypted storage architecture, thus scaling operational capacity without proportionally increasing data theft risk.
Solution Approach 2:
The public key cryptography system acts as an intermediary that allows multiple maintainers to operate processing devices while being uniformly prevented from accessing encrypted user data. The cryptographic intermediary ensures that regardless of how many maintainers are employed or what level of system access they have, they cannot decrypt user data without the private key, decoupling operational capacity from data theft potential.
Data Source
AI summary
A cloud data encryption and security system includes a central computing authority and a network of computing devices. At least some of the computing devices are pod computing devices physically hosted by an operator. The pod computing devices include a central processing unit and a computer readable storage media in data communication with the central processing unit. Data is encrypted in the computer readable storage media so that the owner can access the data but the operator cannot access the data.


