Storage System Encryption Anomaly Detection via Entropy Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current storage systems lack an effective mechanism for timely detection of data corruption, which can lead to data loss if corruption remains undetected for an extended period and an uncorrupted version of the data no longer exists.

Innovation Solution

The system detects data corruption by examining encryption anomalies based on entropy and digital signatures, suspending data accesses when anomalies are detected, and using machine learning to set predetermined thresholds for anomaly detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data corruption detection mechanisms are added to the storage system, then data integrity is improved, but device complexity increases

Engineering Contradiction:
Improvedata integrityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The storage system performs self-diagnosis by automatically examining its own data for encryption anomalies using entropy analysis and digital signature verification. The system monitors its own data integrity without requiring external detection mechanisms, thereby improving reliability while minimizing additional system complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces traditional mechanical or manual data corruption detection methods with information-theoretic entropy analysis and cryptographic digital signature verification. This substitution enables automated, efficient detection of encryption anomalies without requiring complex physical inspection mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Speed

If encryption anomaly detection is performed continuously during data accesses, then detection speed is improved, but use of energy increases

Engineering Contradiction:
Improvedetection speedVSAvoidenergy consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The entropy analysis and digital signature verification are performed continuously during normal data access operations rather than as separate batch processes. By integrating the detection functionality into the existing data access pathways, the system achieves timely corruption detection without requiring additional processing cycles or excessive energy consumption.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If data accesses are suspended upon detecting an encryption anomaly, then reliability is improved, but loss of time occurs

Engineering Contradiction:
Improvedata integrityVSAvoidaccess time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system suspends data accesses proactively upon detecting an encryption anomaly to prevent potential data corruption from spreading. By taking preventive action at the moment of anomaly detection, the system protects data integrity while minimizing the time window for potential damage, thereby reducing overall time loss compared to allowing corruption to propagate.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11379289B2Encryption detection
Publication Date: 2022.07.05 EMC IP HLDG CO LLC
  • US11379289B2 patent drawing
  • US11379289B2 patent drawing
  • US11379289B2 patent drawing

AI summary

Detecting data corruption in a storage system includes examining portions of the data for encryption anomalies and providing an indication in response to detecting an encryption anomaly. The encryption anomalies may be based on entropy of the data. The entropy of the data may vary based on an inherent nature of the data. One of the portions of data may be deemed to be encrypted in response to an entropy value exceeding a predetermined threshold. The predetermined threshold may be based on prior data accesses. The predetermined threshold may be determined using machine learning. Portions of the data may be examined for encryption anomalies during data accesses. Data accesses may be suspended in response to detecting an encryption anomaly. Encryption anomalies may include data that is flagged to be encrypted not being detected as being encrypted and/or data that is flagged to not be encrypted being detected as being encrypted.