Shielded Data Segmentation for Untrusted Cloud Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IT solutions face challenges in securely storing data in untrusted environments, such as cloud computing, due to the increasing insecurity of encryption keys, which results in higher costs and lower performance.
Innovation Solution
The use of a transformation knowledge key, generated with multiple shielding algorithms, to transform and split data into segments, allowing secure storage in both trusted and untrusted environments, with dynamic key changes and distributed storage across multiple agents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is stored in untrusted cloud environments to reduce costs and improve scalability, then cost-effectiveness and scalability are improved, but data security deteriorates due to increasing insecurity of encryption keys
Solution Approach 1:
The patent divides data into multiple segments and stores them across different locations (trusted and untrusted environments). Each segment alone is insufficient to reconstruct the original data, providing security while enabling cloud storage. This resolves the contradiction by allowing scalability through cloud storage while maintaining security through segmentation.
Solution Approach 2:
The patent introduces transformation knowledge keys as an intermediary mechanism between the data and storage locations. These keys enable secure transformation of data before storage and facilitate retrieval without exposing the actual data in untrusted environments. This mediator approach allows cost-effective cloud storage while preserving data security.
2Reliability
If traditional encryption methods are used in untrusted environments, then data protection is attempted, but performance deteriorates and costs increase due to key management overhead
Solution Approach 1:
The patent extracts the security-critical components (transformation knowledge keys) from the untrusted environment and places them in trusted environments. The actual data can be stored in untrusted cloud environments without the keys, eliminating key management overhead in untrusted environments while maintaining protection. This resolves the contradiction by separating protection mechanisms from storage locations.
Solution Approach 2:
The patent changes the parameter of data representation by transforming data using multiple algorithms and keys before storage. The transformed data segments are stored instead of original data, providing protection without requiring traditional encryption key management in untrusted environments. This parameter change enables both protection and improved performance.
3Reliability
If data is segmented and distributed across multiple locations, then security is improved by limiting data loss to single records, but device complexity increases due to distributed storage management
Solution Approach 1:
The patent creates a universal system where the same transformation knowledge keys and segmentation approach work across both trusted and untrusted environments. This multi-functional approach simplifies management by using consistent mechanisms across different storage locations, reducing the complexity that would otherwise arise from environment-specific management. The universal system enables security through distribution while managing complexity through standardization.
Data Source
AI summary
Described herein are techniques related to shielding data, thereby enabling the shielded data to be distributively placed in untrusted computing environments for cost effective storage. A method and system may include a trusted agent operable in a trusted computing environment. The trusted agent includes a transformation knowledge key generator and a data transformer. The transformation knowledge key generator is operable to generate a transformation knowledge key, the transformation knowledge key being generated with at least two shielding algorithms to shield the data. The data transformer is operable to transform the data into N segments of shielded data using the transformation knowledge key. A communications agent securely coupled to the trusted agent is operable to securely transfer one or more of the N segments of shielded data to one or more storage devices in untrusted computing environments.


