Virtual Storage Encryption via Pre-Upload Data Stream Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtual storage systems lack security, as they do not encrypt files, are easily accessible with single-factor authentication, and are not PCI Compliant, leading to concerns about data privacy and ownership.
Innovation Solution
A virtual storage system that encrypts electronic documents using multi-factor authentication and is PCI Compliant, ensuring secure storage and ownership retention with users holding the encryption keys, implemented through a specifically-designed API and redundant physical storage devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If files are stored in a typical virtual storage system without encryption, then storage accessibility and ease of operation are improved, but security and data protection deteriorate
Solution Approach 1:
The system performs preliminary encryption of files before they are stored in the virtual storage system. The encryption process is initiated during the upload phase, and the encrypted version is what gets stored. This preliminary action ensures that security is built-in from the start rather than added later, resolving the contradiction by maintaining both accessibility (through proper authentication) and security (through pre-encryption).
Solution Approach 2:
The patent introduces an intermediary encryption layer between the user and the stored files. This intermediary process transforms readable files into encrypted formats that require authentication to access. The intermediary mechanism allows the system to maintain ease of operation for authorized users while providing strong security against unauthorized access, thus resolving the contradiction between accessibility and security.
2Ease of operation
If single-factor authentication is used for accessing virtual storage systems, then ease of operation is improved, but security and protection against unauthorized access deteriorate
Solution Approach 1:
The authentication process is segmented into multiple independent factors that must all be satisfied for successful access. Rather than relying on a single authentication method, the system divides security into separate layers (such as knowledge-based, possession-based, and biometric factors), allowing each factor to remain relatively simple while collectively providing strong security. This segmentation resolves the contradiction by maintaining operational ease at each step while achieving high overall security.
Solution Approach 2:
The authentication mechanism uses a composite approach, combining multiple authentication factors into a unified access control system. Just as composite materials combine different substances to achieve properties that individual materials cannot provide alone, the composite authentication system combines multiple factors to achieve security levels that single-factor authentication cannot provide, while maintaining reasonable ease of operation through modular implementation.
3Ease of manufacture
If files are stored on third-party servers without encryption, then storage cost and ease of operation are improved, but data ownership control and security deteriorate
Solution Approach 1:
The patent extracts the encryption function from the third-party storage infrastructure and implements it on the user's side or through a trusted intermediary. By taking out the encryption process from the untrusted storage environment, users maintain control over their data's security state even when stored on third-party servers. This extraction allows cost-effective use of third-party storage while preserving data ownership and security control.
Solution Approach 2:
The system applies preliminary anti-action by pre-encrypting files before they are handed over to third-party storage providers. This preliminary protective measure ensures that even if the third party gains unauthorized access, the data remains protected. The preliminary anti-action resolves the contradiction by enabling cost-effective third-party storage while maintaining strong data ownership control through advance encryption.
Data Source
AI summary
A virtual storage system in data communication with a user computing device via a communication network and file encryption methods for encrypting electronic documents to be uploaded into a virtual storage system where the virtual storage system includes at least one processor which captures a data stream corresponding to an electronic document retrieved from an external system, to be uploaded to the virtual storage system, and creates at least one encryption parameter and encrypts the data stream captured using the at least one encryption parameter created. The virtual storage system further includes a plurality of redundant physical storage devices in data communication with the at least one processor and each configured to store the encrypted data stream corresponding to the electronic document.


