Trustworthy Computing Platform Decoupling Data From Storage Containers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud and network storage services fail to effectively address security, privacy, and integrity concerns, preventing users from adopting third-party solutions for data backup due to fears of data compromise and interference by malicious third parties.

Innovation Solution

A trustworthy platform is established using mathematical transformation techniques, such as searchable encryption, to decouple data protection from storage containers, allowing data to act as its own custodian through cryptographic key management, ensuring confidentiality, privacy, and integrity regardless of the container or hardware it is stored on.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data is stored in cloud services or network storage, then storage capacity and accessibility are improved, but security and privacy protection deteriorate due to third-party access risks

Engineering Contradiction:
Improvestorage capacityVSAvoidthird-party access risks
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent introduces cryptographic keys and mathematical transformation functions as intermediaries between the data owner and cloud storage service. The data is transformed using these intermediaries before storage, ensuring that the cloud service provider cannot access the original data without the proper keys, thus resolving the contradiction between storage accessibility and security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security control mechanism from the storage container itself and separates it into independent cryptographic key management. Instead of relying on the container's security, the system extracts security into a separate layer using mathematical transformations, allowing the data to be stored in standard cloud containers while maintaining security through the extracted cryptographic layer.

Inventive Principle:
Principle #2Taking out (Extraction)

2Object-affected harmful factors

If cryptographic key management is implemented to protect data, then security and privacy are improved, but system complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a universal cryptographic framework where a single mathematical transformation function and key management system can protect multiple data containers and types. This multi-functional approach reduces overall system complexity compared to implementing separate security mechanisms for each storage container, as the same cryptographic primitives serve multiple protection purposes across different data types and storage locations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If data is encrypted or obscured before storage, then security is improved, but data accessibility and retrieval speed deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoiddata retrieval speed
Core Design Contradiction:
Object-affected harmful factorsVSSpeed

Solution Approach 1:

The patent applies preliminary cryptographic transformation to the data before storage, creating an obscured version that maintains the data's structure and relationships. This preliminary action allows the data to be stored in an protected form while enabling efficient retrieval through the same transformation functions, avoiding the need for complete decryption during retrieval operations and thus maintaining speed while preserving security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10275603B2Containerless data for trustworthy computing and data services
Publication Date: 2019.04.30 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10275603B2 patent drawing
  • US10275603B2 patent drawing
  • US10275603B2 patent drawing

AI summary

A digital escrow pattern and trustworthy platform is provided for data services including mathematical transformation techniques, such as searchable encryption techniques, for obscuring data stored at remote site or in a cloud service, distributing trust across multiple entities to avoid a single point of data compromise. Using the techniques of a trustworthy platform, data (and associated metadata) is decoupled from the containers that hold the data (e.g., file systems, databases, etc.) enabling the data to act as its own custodian through imposition of a shroud of mathematical complexity that is pierced with presented capabilities, such as keys granted by a cryptographic key generator of a trust platform. Sharing of, or access to, the data or a subset of that data is facilitated in a manner that preserves and extends trust without the need for particular containers for enforcement.