Self-Shredding RAID Data Distribution for Drive Theft Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data storage systems, such as RAID, do not adequately address data privacy and security, particularly when some drives are compromised or stolen, as they lack effective mechanisms to prevent unauthorized access and data disclosure.

Innovation Solution

A self-shredding RAID mode that generates randomization values and transforms sensitive data, distributing transformed segments across multiple storage devices in a way that renders compromised devices useless for data reconstruction, ensuring that even with unlimited computational resources, an attacker cannot retrieve data from stolen disks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If RAID stores data across multiple drives for fault tolerance and speed, then data retrieval speed and reliability improve, but data privacy and security deteriorate when drives are stolen or compromised

Engineering Contradiction:
Improvedata retrieval speedVSAvoiddata exposure to unauthorized access
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments sensitive data into multiple separate portions and distributes them across multiple storage devices. Each portion alone is insufficient to reconstruct the original data, providing security against drive theft while maintaining RAID's speed benefits through parallel access to multiple drives.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces randomization values as an intermediary element that transforms the sensitive data before storage. These randomization values act as a mediator that obscures the actual data content on each drive, requiring combination with other drives to reveal the original information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If RAID mirrors data on multiple drives for redundancy, then data reliability improves, but data privacy deteriorates because compromised drives still contain reconstructable data

Engineering Contradiction:
Improvedata recovery capabilityVSAvoiddata security
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies local quality by making each storage device have a different functional property - each drive stores a unique portion of transformed data that is locally useless without the other drives. This ensures that compromise of individual drives does not expose the original data while maintaining overall system reliability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent converts the harmful aspect of data redundancy (which normally creates security vulnerabilities) into a benefit by using the same multi-drive distribution mechanism to simultaneously provide both fault tolerance and enhanced security. The fragmentation itself becomes the security feature rather than a vulnerability.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Quantity of substance

If traditional RAID stores data portions on separate drives, then storage capacity and speed improve, but security against drive theft deteriorates as stolen drives contain usable data fragments

Engineering Contradiction:
Improvestorage capacityVSAvoidunauthorized data access
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary transformation of the sensitive data using randomization values before distributing it across storage devices. This preliminary action ensures that the data stored on each drive is already obscured and unusable without the other drives, preventing unauthorized access while maintaining full storage capacity utilization.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8806227B2Data shredding RAID mode
Publication Date: 2014.08.12 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US8806227B2 patent drawing
  • US8806227B2 patent drawing
  • US8806227B2 patent drawing

AI summary

A method of storing sensitive data by generating randomization values, transforming the sensitive data and the randomization values into a result, and storing separate portions of the result on at least two storage devices, such that the sensitive data cannot be disclosed if any one of the storage devices is compromised.