Secure Storage Routing Overlay Network for Quantum-Resistant Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional storage systems are inadequate in providing end-to-end data-centric security, especially against quantum computing attacks, and fail to effectively mitigate ransomware and insider threats, as they rely on computational security methods that can be broken by quantum computing resources.

Innovation Solution

The implementation of a multi-vectored, multi-layered security architecture that uses information theoretical security principles, including decentralized secure data vaulting and Exclusive-Path inter-country storage routing, to protect data at-rest and in-motion, leveraging Reed Solomon erasure coding and secure content forwarding across an overlay tunnel, thereby avoiding the need for encryption key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional encryption-based security systems are used, then data security can be maintained under current computational capabilities, but security can be broken by quantum computing resources

Engineering Contradiction:
Improvedata securityVSAvoidresistance to quantum computing attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments data into multiple partitions using Reed Solomon erasure coding, where no single partition contains the complete information. This segmentation approach provides information-theoretic security that is independent of computational capabilities, making it resistant to quantum computing attacks while maintaining data security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from computational security parameters (encryption key strength) to information-theoretic security parameters (partition distribution and reconstruction thresholds). This parameter change enables security that does not depend on computational difficulty, thereby providing resistance to quantum computing attacks.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If decentralized secure data vaulting is implemented, then resistance to ransomware and insider threats is improved, but system complexity increases

Engineering Contradiction:
Improveresistance to ransomware and insider threatsVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Data is divided into multiple partitions stored across different vaults in the decentralized network. This segmentation prevents single-point failures and protects against ransomware and insider threats, as compromising one vault does not endanger the entire dataset.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The decentralized vault network serves multiple functions simultaneously: data storage, security against ransomware, protection against insider threats, and distributed resilience. This multi-functionality justifies the increased system complexity by providing comprehensive security benefits.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If Exclusive-Path inter-country storage routing is used, then data security in-motion is improved, but network routing complexity increases

Engineering Contradiction:
Improvedata security in-motionVSAvoidnetwork routing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Data partitions are routed through exclusive paths across different countries, preventing any single network node from accessing complete data. This segmentation-based routing enhances security in-motion while the distributed path management handles the routing complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary nodes and protocols that manage the complex routing of data partitions across international boundaries. These intermediaries handle path selection and coordination, isolating the complexity from the core security functionality while maintaining secure data transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If information theoretical security is implemented instead of computational security, then resistance to quantum computing attacks is improved, but key management complexity is eliminated

Engineering Contradiction:
Improveresistance to quantum computing attacksVSAvoidencryption key management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system changes the fundamental security parameter from encryption keys (computational security) to partition distribution patterns (information-theoretic security). This eliminates key management complexity while providing quantum-resistant security, as the security relies on mathematical properties of distributed information rather than secret key management.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250097240A1System and a method to implement secure storage routing overlay network
Publication Date: 2025.03.20 CHACKO PETER
  • US20250097240A1 patent drawing
  • US20250097240A1 patent drawing
  • US20250097240A1 patent drawing

AI summary

A system to implement secure storage routing overlay network is disclosed. The system includes a plurality of content forwarding router (CFR) nodes placed at a plurality of locations spanning countries and continents and a Universal Security Controller (USC) node that receives telemetry data sent from the plurality of CFR nodes. The USC node is communicatively connected to the plurality of CFR nodes for populating and updating node state information to the plurality of CFR nodes. The USC node exchange executable instructions with the plurality of CFR nodes and further comprising the steps of creating split partition (SP) fragments at an ingress CFR node, updating each SP Fragment with an exclusive CFR List at the ingress CFR node, moving the SP fragments from the ingress CFR node to an egress CFR node across an exclusive list of CFR nodes, and terminating content transport at the egress CFR node.