Trusted Encrypted Data Containers for Compliant Cloud Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud storage service providers face challenges in storing encrypted data due to the unascertained nature of the data, which may violate legal regulations, leading to potential legal liabilities, and users lack assurance of data security and authenticity.
Innovation Solution
A system and method for trusted data storage on cloud servers involving a client device with a processing unit, client agent, and trusted data loading unit that encrypts data using user-determined encryption keys, generates a security data label, and uploads validated encrypted data containers to the cloud storage server, ensuring legitimacy and authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloud storage service providers store encrypted data, then data privacy and security are improved, but the unascertained nature of the data may violate legal regulations and create legal liabilities
Solution Approach 1:
The system performs preliminary verification and validation of encrypted data before storage. The client device verifies the encryption process and generates a security data label that authenticates the data's legitimacy and compliance with legal regulations before uploading to the cloud storage server, thereby preventing legal liabilities while maintaining security
Solution Approach 2:
The patent introduces a security data label as an intermediary mechanism between the user and the cloud storage provider. This label serves as a mediator that carries verification information about the encrypted data's authenticity and compliance status, allowing the provider to store the data while having assurance of its legal standing
2Reliability
If cloud storage service providers use a data protection unit to assure users about data safety, then data protection is improved, but users cannot conduct a security audit or check the quality of the data protection unit
Solution Approach 1:
The system enables self-service verification where the client device independently performs security audits and validation of the encryption process. The user's computing device verifies the encryption keys and generates security data labels, allowing the user to audit and check the quality of data protection without requiring access to the provider's internal systems
Solution Approach 2:
The system implements feedback mechanisms where the client device receives and verifies encryption keys from the user, generates security data labels with verification information, and provides feedback about the data's authenticity and protection status. This transparent feedback loop allows users to audit the protection process while maintaining secure cloud storage
Data Source
AI summary
Systems and methods for trusted storage of encrypted data onto a cloud storage server are disclosed. The system includes a client device and the cloud storage server. The client device includes a processing unit, a client agent, and a trusted data loading device. The client agent has no access to the network and is implemented within the client device. The client agent receives data and requests to upload the data from the processing unit. The client agent encrypts the data and wraps the data into an encrypted data container.


