Trusted Gateway for Secure Cloud Storage Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud storage solutions lack vendor independence, security, and flexibility in data management, as they often require service provider-specific APIs and expose data to risks such as network attacks and vendor lock-in, while existing encryption techniques make data unsearchable and vulnerable to insider threats.
Innovation Solution
A policy-based framework that uses a trusted gateway device to manage file storage policies across multiple cloud services, enabling searchable encryption, secure data distribution, and access rights management, independent of cloud vendors, allowing for flexible data placement and retrieval.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored in unencrypted format in cloud storage, then user access and searchability are improved, but data security and vulnerability to network attacks deteriorate
Solution Approach 1:
The patent applies preliminary action by encrypting data before it is uploaded to cloud storage. The encryption process occurs in advance on the user's device, so that when data is stored in the cloud, it is already in encrypted form. This allows the data to be stored remotely without compromising security, while still enabling searchability through encrypted search mechanisms that can operate on the encrypted data without requiring decryption first.
2Object-affected harmful factors
If existing encryption techniques are used to protect cloud storage data, then data security is improved, but data searchability and user accessibility deteriorate
Solution Approach 1:
The patent introduces an intermediary mechanism that enables search operations on encrypted data without requiring decryption. This intermediary layer allows search queries to be processed against the encrypted data structure, returning results that can then be decrypted and displayed to the user. This resolves the contradiction by maintaining encryption for security while providing a pathway for searchability through the intermediary search mechanism.
3Device complexity
If cloud providers control encryption keys, then key management simplicity is improved, but data security and protection against insider threats deteriorate
Solution Approach 1:
The patent extracts the encryption key control from the cloud provider and places it exclusively with the user. The user's private key never leaves the user's device, and the cloud provider only handles encrypted data without access to decryption keys. This extraction of key control resolves the contradiction by eliminating the cloud provider's ability to access plaintext data, thereby protecting against insider threats while maintaining a relatively simple key management model where the user retains sole control.
4Ease of manufacture
If vendor-specific APIs are used for cloud storage management, then integration with specific services is improved, but system flexibility and vendor independence deteriorate
Solution Approach 1:
The patent implements a universal encryption standard that can be applied across multiple cloud storage vendors and platforms. By using standardized encryption algorithms and protocols that are vendor-agnostic, the system can interface with different cloud providers without requiring vendor-specific integration. This universality allows the same encryption and search mechanisms to work across multiple vendors, providing flexibility and vendor independence while still maintaining compatibility with various cloud storage services.
Data Source
AI summary
Methods and systems for secure cloud storage are provided. According to one embodiment, file storage policies are maintained for users of an enterprise network by a trusted gateway device interposed between the network and multiple third-party cloud storage services. Responsive to receiving a request to store a local file from a user: (i) searchable encrypted data is created by the gateway corresponding to one or more of (a) content of the local file and (b) metadata associated with the local file and (ii) the searchable encrypted data is distributed by the gateway among the cloud storage services based on a storage diversity requirement defined by the user's file storage policy by uploading a subset of the searchable encrypted data to each of the cloud storage services.


