Trusted Encrypted Data Containers for Compliant Cloud Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud storage service providers face challenges in storing encrypted data due to the unascertained nature of the data, which may violate legal regulations, leading to potential legal liabilities, and users lack assurance of data security and authenticity.

Innovation Solution

A system and method for trusted data storage on cloud servers involving a client device with a processing unit, client agent, and trusted data loading unit that encrypts data using user-determined encryption keys, generates a security data label, and uploads validated encrypted data containers to the cloud storage server, ensuring legitimacy and authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud storage service providers store encrypted data, then data privacy and security are improved, but the unascertained nature of the data may violate legal regulations and create legal liabilities

Engineering Contradiction:
Improvedata securityVSAvoidlegal liability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification and validation of encrypted data before storage. The client device verifies the encryption process and generates a security data label that authenticates the data's legitimacy and compliance with legal regulations before uploading to the cloud storage server, thereby preventing legal liabilities while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a security data label as an intermediary mechanism between the user and the cloud storage provider. This label serves as a mediator that carries verification information about the encrypted data's authenticity and compliance status, allowing the provider to store the data while having assurance of its legal standing

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cloud storage service providers use a data protection unit to assure users about data safety, then data protection is improved, but users cannot conduct a security audit or check the quality of the data protection unit

Engineering Contradiction:
Improvedata protectionVSAvoidaudit transparency
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system enables self-service verification where the client device independently performs security audits and validation of the encryption process. The user's computing device verifies the encryption keys and generates security data labels, allowing the user to audit and check the quality of data protection without requiring access to the provider's internal systems

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where the client device receives and verifies encryption keys from the user, generates security data labels with verification information, and provides feedback about the data's authenticity and protection status. This transparent feedback loop allows users to audit the protection process while maintaining secure cloud storage

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12518037B2Protected storage for decryption data
Publication Date: 2026.01.06 ACRONIS INT
  • US12518037B2 patent drawing
  • US12518037B2 patent drawing
  • US12518037B2 patent drawing

AI summary

Systems and methods for trusted storage of encrypted data onto a cloud storage server are disclosed. The system includes a client device and the cloud storage server. The client device includes a processing unit, a client agent, and a trusted data loading device. The client agent has no access to the network and is implemented within the client device. The client agent receives data and requests to upload the data from the processing unit. The client agent encrypts the data and wraps the data into an encrypted data container.