Transformation Knowledge Key for Cloud Data Shielding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IT solutions face challenges in securely deploying data in untrusted environments, particularly in cloud computing, where encryption keys become insecure and costly due to large overhead, and there is a need for scalable and cost-effective data protection methods.
Innovation Solution
The use of a transformation knowledge key, generated using shielding algorithms, to transform data into shielded form, allowing it to be stored in untrusted environments while maintaining security and scalability, with the key dynamically changing and being unique for each instance of storage, thereby limiting data loss to a single record.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional encryption methods are used in cloud environments, then data security is maintained, but key management overhead and costs increase significantly
Solution Approach 1:
The patent extracts the encryption key management functionality from the cloud environment and places it in a trusted computing module (TCM) or secure enclave that resides on the client device. This separation removes the burden of key management from the cloud provider while maintaining strong encryption, directly addressing the contradiction between security and management overhead.
Solution Approach 2:
The patent introduces a trusted computing module as an intermediary between the cloud storage system and the encryption/decryption operations. This TCM acts as a secure mediator that holds and manages encryption keys locally, eliminating the need for cloud-based key management while ensuring data security throughout the upload, storage, and retrieval processes.
2Productivity
If data is stored in untrusted cloud environments, then cost-effectiveness and scalability improve, but security risks increase
Solution Approach 1:
The patent segments the data protection functionality into two parts: data encryption/decryption operations that can be performed anywhere, and key management that is isolated in a trusted computing module. This segmentation allows data to be stored in untrusted cloud environments with full scalability while the segmented key management remains secure in the client's TCM.
Solution Approach 2:
The patent performs preliminary encryption of data before uploading to cloud storage, with the encryption keys generated and stored in the trusted computing module in advance. This preliminary security action ensures that data is protected from the moment of creation, allowing safe storage in untrusted environments while maintaining security controls.
Data Source
AI summary
Described herein are techniques related to shielding data. A method and system for generating a transformation knowledge key (TKK) may include a TKK generator operable to generate a TKK used to shield the data. The TKK is configured to include at least two components. A library of shielding algorithms is configured to include at least two types of shielding algorithms. The TKK generator is configured to select the at least two types of shielding algorithms to generate the at least two components. The TKK generator is operable to concatenate the at least two components in a configurable order to generate the TKK.


