Secure Folder Replication System Data Replay Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud storage systems lack effective security measures for data integrity and replay prevention, leading to risks of unauthorized access and data alteration, especially in open networks where traditional perimeter defenses are absent.

Innovation Solution

The Secure Folder Replication System (SFRS) implements a method for secure data verification and replay protection by using encryption keys and metadata management, ensuring data integrity and authenticity through a system of public and private keys, session keys, and metadata files, which are stored and synchronized across devices and cloud storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud storage systems use open networks without traditional perimeter defenses, then accessibility and convenience are improved, but security and data integrity are worsened

Engineering Contradiction:
ImproveaccessibilityVSAvoiddata integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by generating cryptographic hashes of data files and storing them in metadata files before data can be accessed or modified. This proactive approach ensures data integrity is verified beforehand, preventing unauthorized alterations while maintaining open network accessibility

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic hash functions and metadata files as intermediary elements between the data files and access requests. These intermediaries verify data integrity without requiring traditional perimeter defenses, enabling secure access over open networks

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cloud storage systems allow multiple users to share information, then collaboration and utility are improved, but security risks and unauthorized access are worsened

Engineering Contradiction:
ImprovecollaborationVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies different security measures to different data files individually. Each data file has its own cryptographic hash stored in metadata files, allowing selective verification and access control. This enables collaborative access for authorized users while maintaining individual security verification for each file

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent creates cryptographic copies (hashes) of data files and stores them separately in metadata files. These copies serve as verification references that allow multiple users to access and verify data integrity without directly copying or potentially corrupting the original data files

Inventive Principle:
Principle #26Copying

3Ease of operation

If basic authentication methods like user ID and password are used, then ease of access is improved, but protection against replay attacks and data alteration is worsened

Engineering Contradiction:
Improveease of accessVSAvoidreplay attack prevention
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces mechanical authentication systems (user IDs and passwords) with cryptographic verification mechanisms. Instead of relying on secret knowledge that can be stolen or replayed, the system uses cryptographic hashes that provide mathematical proof of data integrity and prevent replay attacks through their one-way nature

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9639711B2Systems and methods for data verification and replay prevention
Publication Date: 2017.05.02 PKWARE INC
  • US9639711B2 patent drawing
  • US9639711B2 patent drawing
  • US9639711B2 patent drawing

AI summary

A system and method are provided for the secure sharing of information stored using cloud storage services and for performing data verification and replay protection for information stored on an open network.