Retention Lock Certification Tokens for Tamper-Proof Backup Audits

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing backup systems face challenges in securely maintaining and auditing the retention lock status of files, particularly in deduplication systems, as backup application catalogs are vulnerable to malicious corruption and tampering.

Innovation Solution

Implement cryptographic methods to certify retention lock status by encrypting lock status information using a storage target's private key, generating a lock status token, and storing it in the backup application catalog, ensuring the integrity of the lock status can be independently audited.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If backup application catalogs store retention lock status information, then auditing capability is improved, but vulnerability to malicious corruption and tampering increases

Engineering Contradiction:
Improveauditing capabilityVSAvoidcatalog integrity
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent introduces a cryptographic intermediary mechanism where the storage target signs retention lock status information using its private key. This cryptographic intermediary (the signed status) bridges the gap between the catalog storage and auditing needs, allowing verification of integrity without directly trusting the catalog storage. The intermediary transforms the vulnerable catalog entry into a verifiable cryptographic proof.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/trust-based catalog storage system with a cryptographic verification system. Instead of relying on the physical security or trustworthiness of the catalog storage, the system uses cryptographic signatures and verification algorithms to ensure integrity. This substitution transforms the reliability mechanism from physical/security-based to mathematical/cryptographic-based.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If cryptographic certification methods are implemented, then tamper-proof status is improved, but system complexity increases

Engineering Contradiction:
Improvetamper-proof statusVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic verification logic from the overall backup system and implements it as a separate, dedicated function in the auditor. The storage target's signing operation remains simple, while the complex verification algorithms are isolated in the auditing component. This extraction allows the core backup functionality to remain simple while adding tamper-proof capabilities only where needed.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses cryptographic copying where the retention lock status is transformed into a signed cryptographic copy that can be verified independently. The original status information and the cryptographic signature work together to create a verifiable record without requiring complex changes to the original storage mechanism. The signature acts as a cryptographic copy that proves authenticity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12598082B2Cryptographic method to certify retention lock status for opaque data in a backup system
Publication Date: 2026.04.07 DELL PROD LP
  • US12598082B2 patent drawing
  • US12598082B2 patent drawing
  • US12598082B2 patent drawing

AI summary

The retention lock (RL) status for a backup file stored in a storage target is certified by obtaining the RL status and encrypting it using an encryption key process to create a certified RL status. This signs the RL status by the entity storing the backup file, rather than an application setting the retention lock. The certified RL status is provided as a token to backup software of a deduplication backup system, wherein it can be made available for inspection and audit. The data may include opaque data that is data not interpreted by the filesystem. The request for RL status includes the opaque data, which is returned as part of the response, and which can be returned in part as cleartext.