Quantum-Safe Data Sharding via Overlay Network Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing encryption methods are vulnerable to quantum computing attacks, and conventional networking systems lack effective methods to secure data in-motion against such threats.

Innovation Solution

The implementation of a set of methods and architecture that utilize information theoretical security to segment data into shards, transport it across application layer content routers, and provide Zero Trust Data transfer, ensuring end-to-end security and safety guarantees against quantum computing attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional encryption methods are used to secure data in-motion, then data security is provided under current computational capabilities, but security is compromised against quantum computing attacks

Engineering Contradiction:
Improvedata securityVSAvoidresistance to quantum computing attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments data into multiple shards using information theoretic security methods. Each shard contains only a portion of the original data, and a threshold number of shards are required to reconstruct the complete data. This segmentation approach ensures that even if quantum computers break traditional encryption, they cannot access the complete data without collecting sufficient shards from multiple distributed locations.

Inventive Principle:
Principle #1Segmentation

2Productivity

If data is transmitted across conventional networks, then data transfer efficiency is maintained, but data is vulnerable to wiretapping and interception

Engineering Contradiction:
Improvedata transfer efficiencyVSAvoidwiretapping and interception
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces overlay network content routers as intermediaries that forward data shards without having the capability to reconstruct or access the original data. These routers act as mediators that route segments through multiple paths while maintaining information theoretic security, preventing wiretapping attacks even though data traverses conventional network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If traditional security architectures are used, then existing security infrastructure is leveraged, but Zero Trust security model cannot be implemented

Engineering Contradiction:
Improvesecurity infrastructureVSAvoidZero Trust security guarantee
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements Zero Trust security by segmenting data into shards that are distributed across multiple locations and forwarded through multiple routers. No single router or node has access to the complete data, and each segment is protected by information theoretic security. This architectural segmentation enables Zero Trust principles where no intermediary is trusted with the complete data set.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12206686B2AIOps guided, quantum-safe zero trust data transfer methods in-motion with segmented, data transfer across an overlay network
Publication Date: 2025.01.21 CHACKO PETER
  • US12206686B2 patent drawing
  • US12206686B2 patent drawing
  • US12206686B2 patent drawing

AI summary

The present disclosure relates to Overlay Content Forwarding (OCF) Methods to transfer data across a wide area network without introducing a single point of data breach or wire-tapping on a Zero Trust Data transfer paradigm. Methods are applied on a system built upon Data Transport Controllers (DTC) and USC with AIOps capabilities. System modules are deployed across various geo locations in a Wide Area Network, operating at the control of Universal Security Controller (USC). USC extracts system, security and storage activity telemetry data from DTC controllers, update Routes through XML updates and Routing update exchanges, to orchestrate Autonomous, de-duplicated, segmented data forwarding across exclusive path overlay network guided by AIOps mechanisms. Data is segmented in unintelligible manner based on information theory and sent across different, exclusive path across DTC nodes in an overlay network in different application sessions and reassembled at destination DTC node to recover the original content. Segment transfer across overlay support de-duplication in-transit as an overlay based storage reduction service.