Self-Shredding RAID Data Distribution for Drive Theft Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data storage systems, such as RAID, do not adequately address data privacy and security, particularly when some drives are compromised or stolen, as they lack effective mechanisms to prevent unauthorized access and data disclosure.
Innovation Solution
A self-shredding RAID mode that generates randomization values and transforms sensitive data, distributing transformed segments across multiple storage devices in a way that renders compromised devices useless for data reconstruction, ensuring that even with unlimited computational resources, an attacker cannot retrieve data from stolen disks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If RAID stores data across multiple drives for fault tolerance and speed, then data retrieval speed and reliability improve, but data privacy and security deteriorate when drives are stolen or compromised
Solution Approach 1:
The patent segments sensitive data into multiple separate portions and distributes them across multiple storage devices. Each portion alone is insufficient to reconstruct the original data, providing security against drive theft while maintaining RAID's speed benefits through parallel access to multiple drives.
Solution Approach 2:
The patent introduces randomization values as an intermediary element that transforms the sensitive data before storage. These randomization values act as a mediator that obscures the actual data content on each drive, requiring combination with other drives to reveal the original information.
2Reliability
If RAID mirrors data on multiple drives for redundancy, then data reliability improves, but data privacy deteriorates because compromised drives still contain reconstructable data
Solution Approach 1:
The patent applies local quality by making each storage device have a different functional property - each drive stores a unique portion of transformed data that is locally useless without the other drives. This ensures that compromise of individual drives does not expose the original data while maintaining overall system reliability.
Solution Approach 2:
The patent converts the harmful aspect of data redundancy (which normally creates security vulnerabilities) into a benefit by using the same multi-drive distribution mechanism to simultaneously provide both fault tolerance and enhanced security. The fragmentation itself becomes the security feature rather than a vulnerability.
3Quantity of substance
If traditional RAID stores data portions on separate drives, then storage capacity and speed improve, but security against drive theft deteriorates as stolen drives contain usable data fragments
Solution Approach 1:
The patent performs preliminary transformation of the sensitive data using randomization values before distributing it across storage devices. This preliminary action ensures that the data stored on each drive is already obscured and unusable without the other drives, preventing unauthorized access while maintaining full storage capacity utilization.
Data Source
AI summary
A method of storing sensitive data by generating randomization values, transforming the sensitive data and the randomization values into a result, and storing separate portions of the result on at least two storage devices, such that the sensitive data cannot be disclosed if any one of the storage devices is compromised.


