Wavefront Pre-Transform Circuit for Secure Remote Data Wiping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage technologies, such as RAID, lack sufficient privacy and reliability in remote wiping operations, especially when dealing with data stored across multiple disk drives or in cloud storage sites.
Innovation Solution
The implementation of wavefront pre-processing and post-processing transforms for remote wiping, utilizing a wavefront pre-transform circuit and post-transform circuit with switching circuits and a controller to dynamically manage input and output streams, ensuring secure and reliable data transport and retrieval by converting data into unique linear combinations for storage and retrieval.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If RAID techniques are used for data storage, then data redundancy is provided, but privacy and reliability in remote wiping operations are insufficient
Solution Approach 1:
The patent segments data into multiple independent stripes that are distributed across different storage sites. Each stripe is encrypted independently, allowing selective wiping of individual stripes without affecting others. This segmentation enables reliable remote wiping by isolating data components while maintaining system manageability.
Solution Approach 2:
The patent introduces an intermediary encryption layer that sits between the storage system and data access points. This encryption intermediary transforms data into an unreadable format during transmission and storage, providing privacy protection without requiring changes to the underlying storage architecture, thus avoiding increased system complexity.
2Quantity of substance
If data is distributed across multiple disk drives or cloud storage sites, then storage capacity and redundancy are increased, but remote wiping operations become complicated
Solution Approach 1:
The patent implements dynamic encryption keys that can be independently controlled for different data stripes and storage sites. This dynamic key management allows the system to adaptively wipe specific portions of distributed data by simply changing cryptographic keys, making remote wiping operations simple despite data being scattered across multiple locations.
Solution Approach 2:
The patent performs preliminary encryption and segmentation of data before distribution to multiple storage sites. This pre-processing organizes data into manageable, independently controllable units with unique encryption identifiers, enabling straightforward remote wiping operations later by targeting specific encrypted units without complex coordination across storage sites.
3Reliability
If existing storage technologies are used, then data can be stored and retrieved, but privacy protection during data transport and storage is insufficient
Solution Approach 1:
The patent replaces physical security mechanisms with cryptographic substitution. Instead of relying on physical access controls or secure hardware transport, the system uses mathematical encryption to protect data during transport and storage. This substitution provides strong privacy protection without requiring complex physical security infrastructure.
Solution Approach 2:
The patent changes the state of data from plaintext to encrypted form through parameter transformation. By applying cryptographic transformations to data parameters during transport and storage, the system achieves privacy protection while maintaining data usability upon retrieval, avoiding the need for complex secure transport mechanisms.
Data Source
AI summary
An input switching circuit dynamically connects, based on an input mapping table, input streams to inputs of a wavefront pre-transform circuit. An output switching circuit dynamically connects, based on an output mapping table, output data at outputs of the wavefront pre-transform circuit to transport streams. A controller controls, based on a wiping command, at least one of the input and output switching circuits to alter at least one of the input and output mapping tables such that the at least one of the input and output switching circuits is disabled for connection. A first subset of the transport streams operates in a foreground mode available to a user and is transported for storage in remote storage sites at a network and a second subset of the transport streams operates in a background mode available to an administrator and is not transported for storage in the remote storage sites.


