Verifiable Trust via Composite Wrapper Composition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud and network storage services lack effective solutions for ensuring the security, privacy, and integrity of data, leading to user concerns about data exposure and tampering when data is stored or processed remotely.
Innovation Solution
A trustworthy platform is implemented using composite mathematical transformations to protect data and metadata with separate entities for key generation, cryptographic technology, and cloud services, enabling secure, containerless data storage and access through searchable encryption and access control mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is stored in cloud services with third-party providers, then storage capacity and accessibility are improved, but data security and privacy are compromised due to lack of physical control
Solution Approach 1:
The patent segments data into multiple fragments and distributes them across different storage locations. No single fragment contains the complete data, so even if one storage location is compromised, the full data cannot be reconstructed without additional fragments from other locations.
Solution Approach 2:
The patent introduces cryptographic wrappers as an intermediary layer between the data and the cloud storage service. These wrappers encrypt the data fragments and control access to them, allowing the service provider to store and manage the data without being able to access its contents.
2Reliability
If cryptographic encryption is applied to data before cloud storage, then data privacy is improved, but data integrity verification and accessibility are worsened
Solution Approach 1:
The patent applies cryptographic wrappers to data fragments before storing them in the cloud. This preliminary encryption action ensures that even if data is accessed without authorization, it remains protected. The wrappers are designed to be removed or decrypted only by authorized parties with proper credentials.
Solution Approach 2:
The patent implements verification mechanisms that provide feedback on data integrity. Hash values and metadata are stored alongside the encrypted fragments, allowing the system to verify that data has not been tampered with during storage or transmission without requiring decryption.
3Reliability
If composite wrappers with multiple transformations are applied to data, then data protection is improved, but system complexity and processing overhead are worsened
Solution Approach 1:
The patent divides the complex protection mechanism into separate, manageable components: fragmentation of data, independent cryptographic wrapping of each fragment, and separate verification processes. This segmentation allows each component to be optimized and managed independently, reducing overall system complexity.
Solution Approach 2:
The patent designs the cryptographic wrapper system to perform multiple functions simultaneously: encryption for confidentiality, integrity verification through embedded hashes, and access control through metadata. This multi-functionality reduces the need for separate systems for each protection aspect.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A digital escrow pattern for data services can include selective access for obscured data at a remote site or in a cloud service, distributing trust across multiple entities to avoid a single point of data compromise. Based on the pattern, a "trustworthy envelope" for any kind of payload enables curtained access through a variety of decorations or seals placed on the envelope that allow for a gamut of trust ranging with guarantees such as, but not limited to, confidentiality, privacy, anonymity, tamper detection, integrity, etc. Verifiable trust is provided through families of techniques that are referred to as wrapper composition. Multiple concentric and/or lateral transform wrappers or layers can wholly or partially transform data, metadata or both to mathematical transform (e.g., encrypt, distribute across storage, obscure) or otherwise introduce lack of visibility to some or all of the data, metadata or both.