Selective Data Encryption for NAS-to-Cloud Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data encryption methods are inefficient and costly due to the need to encrypt entire datasets, despite varying levels of confidentiality within the data, and are vulnerable to modern computing power and quantum computing threats.

Innovation Solution

A method to identify and group data items based on confidentiality levels, applying appropriate encryption methods to each subset, and decrypting upon arrival at the destination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If entire datasets are encrypted using traditional methods, then data confidentiality is maintained, but encryption efficiency and cost are reduced

Engineering Contradiction:
Improvedata confidentialityVSAvoidencryption efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments datasets into individual data items or smaller groups based on confidentiality levels. Each segment is then encrypted independently using appropriate encryption methods, rather than encrypting the entire dataset as a single unit. This segmentation approach maintains data confidentiality for each item while significantly improving encryption efficiency and reducing computational costs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different encryption methods and key lengths to different data items based on their specific confidentiality requirements. High-sensitivity data receives stronger encryption (e.g., 256-bit keys), while less sensitive data uses lighter encryption methods. This local quality approach ensures adequate protection for each data item without uniformly over-encrypting all data, thereby improving overall encryption efficiency.

Inventive Principle:
Principle #3Local quality

2Reliability

If strong encryption methods with larger key sizes are used, then data security is improved, but computational cost and processing time increase

Engineering Contradiction:
Improvedata securityVSAvoidcomputational cost
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The patent determines the appropriate encryption strength for each data item based on its confidentiality level. Critical data items receive strong encryption with larger key sizes (e.g., 256-bit), while less critical items use weaker encryption methods. This local quality approach ensures high security for sensitive data while reducing computational cost and energy consumption for less sensitive data.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent dynamically adjusts encryption parameters such as key length and algorithm selection based on the confidentiality classification of each data item. By changing these parameters according to data sensitivity rather than using fixed strong encryption for all data, the system achieves appropriate security levels while optimizing computational resource usage and reducing processing time.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If selective encryption is implemented based on data sensitivity, then encryption efficiency improves, but system complexity increases

Engineering Contradiction:
Improveencryption efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments data into confidentiality-based groups and applies encryption selectively to each segment. This segmentation simplifies the overall encryption process by breaking it into manageable parts with different encryption requirements, making the system more efficient while keeping the complexity of each individual encryption operation relatively simple and standardized.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12450364B2Selective encryption while loading from network attached storage system
Publication Date: 2025.10.21 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12450364B2 patent drawing
  • US12450364B2 patent drawing
  • US12450364B2 patent drawing

AI summary

According to one embodiment, a method, computer system, and computer program product for selective dataset encryption is provided. The embodiment may include identifying one or more data items within one or more datasets to be moved from network attached storage to cloud-based storage. The embodiment may also include determining an encryption method to be performed on each data item based on a level of confidentiality or sensitivity of each data item. The embodiment may further include sorting each data item into one or more groups based on the determined encryption method. The embodiment may also include performing each determined encryption method to the corresponding group.