Verifiable Trust via Composite Wrapper Composition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud and network storage services lack effective solutions for ensuring the security, privacy, and integrity of data, leading to user concerns about data exposure and tampering when data is stored or processed remotely.

Innovation Solution

A trustworthy platform is implemented using composite mathematical transformations to protect data and metadata with separate entities for key generation, cryptographic technology, and cloud services, enabling secure, containerless data storage and access through searchable encryption and access control mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is stored in cloud services with third-party providers, then storage capacity and accessibility are improved, but data security and privacy are compromised due to lack of physical control

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments data into multiple fragments and distributes them across different storage locations. No single fragment contains the complete data, so even if one storage location is compromised, the full data cannot be reconstructed without additional fragments from other locations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic wrappers as an intermediary layer between the data and the cloud storage service. These wrappers encrypt the data fragments and control access to them, allowing the service provider to store and manage the data without being able to access its contents.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic encryption is applied to data before cloud storage, then data privacy is improved, but data integrity verification and accessibility are worsened

Engineering Contradiction:
Improvedata privacyVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies cryptographic wrappers to data fragments before storing them in the cloud. This preliminary encryption action ensures that even if data is accessed without authorization, it remains protected. The wrappers are designed to be removed or decrypted only by authorized parties with proper credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements verification mechanisms that provide feedback on data integrity. Hash values and metadata are stored alongside the encrypted fragments, allowing the system to verify that data has not been tampered with during storage or transmission without requiring decryption.

Inventive Principle:
Principle #23Feedback

3Reliability

If composite wrappers with multiple transformations are applied to data, then data protection is improved, but system complexity and processing overhead are worsened

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the complex protection mechanism into separate, manageable components: fragmentation of data, independent cryptographic wrapping of each fragment, and separate verification processes. This segmentation allows each component to be optimized and managed independently, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent designs the cryptographic wrapper system to perform multiple functions simultaneously: encryption for confidentiality, integrity verification through embedded hashes, and access control through metadata. This multi-functionality reduces the need for separate systems for each protection aspect.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2513833B1Verifiable trust for data through wrapper composition
Publication Date: 2019.08.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2513833B1 patent drawingFigure 1
  • EP2513833B1 patent drawingFigure 2
  • EP2513833B1 patent drawingFigure 3

AI summary

A digital escrow pattern for data services can include selective access for obscured data at a remote site or in a cloud service, distributing trust across multiple entities to avoid a single point of data compromise. Based on the pattern, a "trustworthy envelope" for any kind of payload enables curtained access through a variety of decorations or seals placed on the envelope that allow for a gamut of trust ranging with guarantees such as, but not limited to, confidentiality, privacy, anonymity, tamper detection, integrity, etc. Verifiable trust is provided through families of techniques that are referred to as wrapper composition. Multiple concentric and/or lateral transform wrappers or layers can wholly or partially transform data, metadata or both to mathematical transform (e.g., encrypt, distribute across storage, obscure) or otherwise introduce lack of visibility to some or all of the data, metadata or both.