Virtual Storage Encryption via Pre-Upload Data Stream Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual storage systems lack security, as they do not encrypt files, are easily accessible with single-factor authentication, and are not PCI Compliant, leading to concerns about data privacy and ownership.

Innovation Solution

A virtual storage system that encrypts electronic documents using multi-factor authentication and is PCI Compliant, ensuring secure storage and ownership retention with users holding the encryption keys, implemented through a specifically-designed API and redundant physical storage devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If files are stored in a typical virtual storage system without encryption, then storage accessibility and ease of operation are improved, but security and data protection deteriorate

Engineering Contradiction:
Improvefile accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary encryption of files before they are stored in the virtual storage system. The encryption process is initiated during the upload phase, and the encrypted version is what gets stored. This preliminary action ensures that security is built-in from the start rather than added later, resolving the contradiction by maintaining both accessibility (through proper authentication) and security (through pre-encryption).

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary encryption layer between the user and the stored files. This intermediary process transforms readable files into encrypted formats that require authentication to access. The intermediary mechanism allows the system to maintain ease of operation for authorized users while providing strong security against unauthorized access, thus resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If single-factor authentication is used for accessing virtual storage systems, then ease of operation is improved, but security and protection against unauthorized access deteriorate

Engineering Contradiction:
Improveauthentication simplicityVSAvoidaccess security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into multiple independent factors that must all be satisfied for successful access. Rather than relying on a single authentication method, the system divides security into separate layers (such as knowledge-based, possession-based, and biometric factors), allowing each factor to remain relatively simple while collectively providing strong security. This segmentation resolves the contradiction by maintaining operational ease at each step while achieving high overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication mechanism uses a composite approach, combining multiple authentication factors into a unified access control system. Just as composite materials combine different substances to achieve properties that individual materials cannot provide alone, the composite authentication system combines multiple factors to achieve security levels that single-factor authentication cannot provide, while maintaining reasonable ease of operation through modular implementation.

Inventive Principle:
Principle #40Composite materials

3Ease of manufacture

If files are stored on third-party servers without encryption, then storage cost and ease of operation are improved, but data ownership control and security deteriorate

Engineering Contradiction:
Improvestorage costVSAvoiddata ownership control
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent extracts the encryption function from the third-party storage infrastructure and implements it on the user's side or through a trusted intermediary. By taking out the encryption process from the untrusted storage environment, users maintain control over their data's security state even when stored on third-party servers. This extraction allows cost-effective use of third-party storage while preserving data ownership and security control.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies preliminary anti-action by pre-encrypting files before they are handed over to third-party storage providers. This preliminary protective measure ensures that even if the third party gains unauthorized access, the data remains protected. The preliminary anti-action resolves the contradiction by enabling cost-effective third-party storage while maintaining strong data ownership control through advance encryption.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS9003183B2Virtual storage system and file encryption methods
Publication Date: 2015.04.07 VIRTUAL STRONGBOX INC
  • US9003183B2 patent drawing
  • US9003183B2 patent drawing
  • US9003183B2 patent drawing

AI summary

A virtual storage system in data communication with a user computing device via a communication network and file encryption methods for encrypting electronic documents to be uploaded into a virtual storage system where the virtual storage system includes at least one processor which captures a data stream corresponding to an electronic document retrieved from an external system, to be uploaded to the virtual storage system, and creates at least one encryption parameter and encrypts the data stream captured using the at least one encryption parameter created. The virtual storage system further includes a plurality of redundant physical storage devices in data communication with the at least one processor and each configured to store the encrypted data stream corresponding to the electronic document.