Data Storage Encryption with Compression and Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing frequency and sophistication of unauthorized data access attacks highlight the need for robust at-rest data encryption solutions that provide full cryptographic integrity and cannot be undetectably bypassed.

Innovation Solution

A system and method that integrate a compression engine and an encryption engine within a data storage device to generate compressed and encrypted data packets, respectively, with meta data indicating characteristics, using algorithms like Lempel-Ziv for compression and AES-256 for encryption, ensuring secure data storage and retrieval.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data encryption is implemented in the storage system architecture, then data security and cryptographic integrity are improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the compression engine and encryption engine into a single storage system architecture where data is compressed and encrypted in sequence through integrated processing stages. The compression engine generates compressed data packets with metadata, which are then processed by the encryption engine to produce encrypted data packets, creating a unified security solution that manages complexity through functional integration.

Inventive Principle:
Principle #5Merging (Combining)

2Manufacturing precision

If compression is applied to data before encryption, then data integrity and storage efficiency are improved, but processing time increases

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent applies compression as a preliminary action before encryption, where the compression engine first processes the host data stream packet to generate a compressed data packet. This preliminary compression step reduces the data size and improves integrity before the subsequent encryption operation, optimizing the overall processing workflow by performing data preparation in advance.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If metadata is included with encrypted data packets, then data management and verification capabilities are improved, but data storage requirements increase

Engineering Contradiction:
Improvedata management capabilityVSAvoiddata storage requirements
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by including metadata only where necessary for data management and verification. The compressed data packet includes a first set of metadata indicative of characteristics of the compressed data, and the encrypted data packet includes a second set of metadata indicative of characteristics of the encrypted data. This targeted metadata inclusion provides necessary management capabilities while minimizing unnecessary data storage requirements.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7706538B1System, method and data storage device for encrypting data
Publication Date: 2010.04.27 ORACLE AMERICAN INC
  • US7706538B1 patent drawing
  • US7706538B1 patent drawing
  • US7706538B1 patent drawing

AI summary

A system, method and data storage device for encrypting data to provide at-rest data encryption of data in the data storage device. The system includes a compression engine for receiving a host data stream packet and selectively generating a compressed data packet, and an encryption engine in electronic communication with the compression engine for receiving an unencrypted data packet from the compression engine. The unencrypted data packet comprises the compressed data packet when the compression engine generates the compressed data packet. The unencrypted data packet comprises the host data packet when the compression engine does not generate the compressed data packet. The encryption engine generates an encrypted data packet having an encrypted component corresponding to the unencrypted data packet and a set of meta data indicative of one or more characteristic of the encrypted data packet.