Trusted Gateway for Secure Cloud Storage Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud storage solutions lack vendor independence, security, and flexibility in data management, as they often require service provider-specific APIs and expose data to risks such as network attacks and vendor lock-in, while existing encryption techniques make data unsearchable and vulnerable to insider threats.

Innovation Solution

A policy-based framework that uses a trusted gateway device to manage file storage policies across multiple cloud services, enabling searchable encryption, secure data distribution, and access rights management, independent of cloud vendors, allowing for flexible data placement and retrieval.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is stored in unencrypted format in cloud storage, then user access and searchability are improved, but data security and vulnerability to network attacks deteriorate

Engineering Contradiction:
Improveuser access and searchabilityVSAvoiddata security and vulnerability to network attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by encrypting data before it is uploaded to cloud storage. The encryption process occurs in advance on the user's device, so that when data is stored in the cloud, it is already in encrypted form. This allows the data to be stored remotely without compromising security, while still enabling searchability through encrypted search mechanisms that can operate on the encrypted data without requiring decryption first.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If existing encryption techniques are used to protect cloud storage data, then data security is improved, but data searchability and user accessibility deteriorate

Engineering Contradiction:
Improvedata securityVSAvoiddata searchability and user accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent introduces an intermediary mechanism that enables search operations on encrypted data without requiring decryption. This intermediary layer allows search queries to be processed against the encrypted data structure, returning results that can then be decrypted and displayed to the user. This resolves the contradiction by maintaining encryption for security while providing a pathway for searchability through the intermediary search mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If cloud providers control encryption keys, then key management simplicity is improved, but data security and protection against insider threats deteriorate

Engineering Contradiction:
Improvekey management simplicityVSAvoiddata security and protection against insider threats
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the encryption key control from the cloud provider and places it exclusively with the user. The user's private key never leaves the user's device, and the cloud provider only handles encrypted data without access to decryption keys. This extraction of key control resolves the contradiction by eliminating the cloud provider's ability to access plaintext data, thereby protecting against insider threats while maintaining a relatively simple key management model where the user retains sole control.

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of manufacture

If vendor-specific APIs are used for cloud storage management, then integration with specific services is improved, but system flexibility and vendor independence deteriorate

Engineering Contradiction:
Improveintegration with specific servicesVSAvoidsystem flexibility and vendor independence
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal encryption standard that can be applied across multiple cloud storage vendors and platforms. By using standardized encryption algorithms and protocols that are vendor-agnostic, the system can interface with different cloud providers without requiring vendor-specific integration. This universality allows the same encryption and search mechanisms to work across multiple vendors, providing flexibility and vendor independence while still maintaining compatibility with various cloud storage services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10083309B2Secure cloud storage distribution and aggregation
Publication Date: 2018.09.25 FORTINET INC
  • US10083309B2 patent drawing
  • US10083309B2 patent drawing
  • US10083309B2 patent drawing

AI summary

Methods and systems for secure cloud storage are provided. According to one embodiment, file storage policies are maintained for users of an enterprise network by a trusted gateway device interposed between the network and multiple third-party cloud storage services. Responsive to receiving a request to store a local file from a user: (i) searchable encrypted data is created by the gateway corresponding to one or more of (a) content of the local file and (b) metadata associated with the local file and (ii) the searchable encrypted data is distributed by the gateway among the cloud storage services based on a storage diversity requirement defined by the user's file storage policy by uploading a subset of the searchable encrypted data to each of the cloud storage services.