Smartkey Information Management for Cloud Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud storage systems provide limited protection for data confidentiality and integrity, as they rely on basic authentication methods that do not ensure data integrity or prevent unauthorized access and alteration, leading to potential misuse of shared information.
Innovation Solution
The Smartkey Information Management System employs advanced encryption key management techniques, including Smartkeys, TeamKeys, and Contingency Keys, to securely manage and share information across private and cloud storage networks, using encryption and decryption processes that ensure data integrity and access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If basic authentication methods are used in cloud storage systems, then ease of operation is improved, but data security and integrity are worsened
Solution Approach 1:
The authentication system is segmented into multiple independent factors (something you know, something you have, something you are). Each factor is verified separately through different authentication mechanisms, and all must succeed for access to be granted. This segmentation ensures that compromise of one factor does not compromise overall security while maintaining operational ease through automated multi-factor verification.
2Adaptability or versatility
If cloud storage systems allow information sharing between multiple users, then adaptability is improved, but data integrity and confidentiality are worsened
Solution Approach 1:
Access permissions and security attributes are assigned locally to each user, file, and folder rather than applying uniform rules system-wide. Each resource can have customized authentication requirements and authorization levels tailored to specific users or user groups. This allows flexible information sharing where appropriate while maintaining strict security controls where needed, enabling adaptability without compromising data integrity.
3Ease of operation
If traditional perimeter defenses are removed for open network access, then ease of operation is improved, but security protection is worsened
Solution Approach 1:
An intermediary authentication service acts as a mediator between users and cloud storage resources. This service verifies user credentials, manages session tokens, and enforces access policies without requiring traditional network perimeter infrastructure. The intermediary provides security verification directly at the application layer, enabling open network access while maintaining protection against unauthorized access and attacks.
Data Source
AI summary
A system and method are provided for the secure sharing of information across and open network and for performing management of keys used for encrypting and decrypting data.


