Transformation Knowledge Key for Cloud Data Shielding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IT solutions face challenges in securely deploying data in untrusted environments, particularly in cloud computing, where encryption keys become insecure and costly due to large overhead, and there is a need for scalable and cost-effective data protection methods.

Innovation Solution

The use of a transformation knowledge key, generated using shielding algorithms, to transform data into shielded form, allowing it to be stored in untrusted environments while maintaining security and scalability, with the key dynamically changing and being unique for each instance of storage, thereby limiting data loss to a single record.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional encryption methods are used in cloud environments, then data security is maintained, but key management overhead and costs increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidkey management overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the encryption key management functionality from the cloud environment and places it in a trusted computing module (TCM) or secure enclave that resides on the client device. This separation removes the burden of key management from the cloud provider while maintaining strong encryption, directly addressing the contradiction between security and management overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a trusted computing module as an intermediary between the cloud storage system and the encryption/decryption operations. This TCM acts as a secure mediator that holds and manages encryption keys locally, eliminating the need for cloud-based key management while ensuring data security throughout the upload, storage, and retrieval processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If data is stored in untrusted cloud environments, then cost-effectiveness and scalability improve, but security risks increase

Engineering Contradiction:
ImprovescalabilityVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the data protection functionality into two parts: data encryption/decryption operations that can be performed anywhere, and key management that is isolated in a trusted computing module. This segmentation allows data to be stored in untrusted cloud environments with full scalability while the segmented key management remains secure in the client's TCM.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary encryption of data before uploading to cloud storage, with the encryption keys generated and stored in the trusted computing module in advance. This preliminary security action ensures that data is protected from the moment of creation, allowing safe storage in untrusted environments while maintaining security controls.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9209971B2Method and system for shielding data in untrusted environments
Publication Date: 2015.12.08 COFACTOR COMPUTING LLC
  • US9209971B2 patent drawing
  • US9209971B2 patent drawing
  • US9209971B2 patent drawing

AI summary

Described herein are techniques related to shielding data. A method and system for generating a transformation knowledge key (TKK) may include a TKK generator operable to generate a TKK used to shield the data. The TKK is configured to include at least two components. A library of shielding algorithms is configured to include at least two types of shielding algorithms. The TKK generator is configured to select the at least two types of shielding algorithms to generate the at least two components. The TKK generator is operable to concatenate the at least two components in a configurable order to generate the TKK.