Cryptographic File Layer Using Secret Sharing for Secure Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data security solutions rely on perimeter hardware and software technologies, which can compromise data integrity and accessibility, and lack the ability to securely share data among multiple communities of interest without compromising security.
Innovation Solution
A cryptographic file system layer intercepts and modifies data at the bit level, using multi-factor secret sharing and encryption to secure data in designated directories, ensuring provable security and accessibility, and allowing secure data sharing across multiple communities of interest.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If perimeter hardware and software technologies are used for data security, then data protection is provided, but data integrity and accessibility are compromised
Solution Approach 1:
The patent extracts the security function from traditional perimeter-based hardware and software solutions and embeds it directly into the file system layer. This allows security to operate transparently at the file level without requiring separate perimeter defense mechanisms, thereby maintaining data protection while improving accessibility through integrated operation.
Solution Approach 2:
The patent introduces a cryptographic file system layer as an intermediary between the application layer and the underlying file system. This layer intercepts file operations, applies cryptographic protections selectively to designated directories, and restores data when retrieved, enabling secure and accessible data operations without modifying existing applications or hardware.
2Reliability
If multiple perimeter technologies are deployed for security, then data security is enhanced, but system complexity increases
Solution Approach 1:
The patent merges multiple security functions (encryption, authentication, integrity checking) into a single cryptographic file system layer. This consolidation eliminates the need for multiple separate perimeter technologies while maintaining comprehensive security, thereby reducing system complexity through functional integration.
Solution Approach 2:
The cryptographic file system layer provides universal security services across multiple directories and file types through a single integrated solution. It can selectively apply security policies to different designated directories, supporting multiple communities of interest with a unified system rather than requiring separate security infrastructures.
3Reliability
If data is secured using traditional encryption methods, then confidentiality is maintained, but data sharing among multiple communities of interest is compromised
Solution Approach 1:
The patent applies different security policies and cryptographic parameters to different designated directories based on local requirements. Each directory can have its own access control list and encryption settings, allowing data to be securely shared among different communities of interest with appropriate access levels while maintaining confidentiality through targeted cryptographic protection.
Data Source
AI summary
The systems and methods disclosed herein transparently provide data security using a cryptographic file system layer that selectively intercepts and modifies (e.g., by encrypting) data to be stored in a designated directory. The cryptographic file system layer can be used in combination with one or more cryptographic approaches to provide a server-based secure data solution that makes data more secure and accessible, while eliminating the need for multiple perimeter hardware and software technologies.


