Trustworthy XML Envelopes for Cloud Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud and network storage services lack effective solutions for ensuring the security, privacy, and integrity of data, leading to user concerns about data exposure and interference when data is stored or processed remotely.
Innovation Solution
A trustworthy platform is established using mathematical transformation techniques, such as searchable encryption, to decouple data protection from storage containers, allowing data to act as its own custodian through cryptographic key management, ensuring containerless data security and access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is stored in cloud services or network storage, then data accessibility and storage capacity are improved, but data security and privacy are compromised due to third-party access risks
Solution Approach 1:
The patent segments data into multiple fragmented portions and stores them across different locations. No single entity can reconstruct the complete data without all fragments, thereby maintaining security while enabling cloud storage accessibility. This directly resolves the contradiction by allowing data to be stored remotely (improving accessibility) while preventing any single third party from accessing the complete data (maintaining security).
Solution Approach 2:
The patent introduces cryptographic intermediaries including homomorphic encryption schemes and secret sharing mechanisms that act as mediators between the data owner and cloud storage providers. These intermediaries enable secure computation and data retrieval without exposing the actual data to the cloud provider, thus maintaining security while enabling cloud-based data access.
2Reliability
If data is encrypted using traditional methods, then data confidentiality is improved, but data processing and search capabilities are lost
Solution Approach 1:
The patent changes the cryptographic parameters by employing homomorphic encryption schemes that allow mathematical operations to be performed on encrypted data. This enables data processing and search operations to be conducted on encrypted data without decryption, thus maintaining confidentiality while restoring processing capabilities that were previously lost with traditional encryption methods.
Solution Approach 2:
The patent replaces the traditional mechanical decryption-encryption process with homomorphic cryptographic operations that allow computation directly on ciphertext. This substitution eliminates the need to decrypt data for processing, thereby maintaining confidentiality while enabling data processing capabilities.
3Volume of stationary object
If cloud storage services are used, then storage capacity and device independence are improved, but trust and control over data are reduced due to physical separation from storage
Solution Approach 1:
The patent applies preliminary cryptographic transformations including encryption and fragmentation before data is uploaded to cloud storage. These preliminary actions ensure that data is protected before leaving the user's control, maintaining trust and control even though physical storage occurs remotely in the cloud with large capacity.
Solution Approach 2:
The patent implements self-service cryptographic mechanisms where the data owner maintains control over encryption keys and can independently manage data access and retrieval. This self-service approach to key management enables users to maintain trust and control over their data while utilizing cloud storage capacity, as they can independently grant or revoke access without relying on the cloud provider's security measures.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A digital escrow pattern for data services can include selective access for obscured data at a remote site or in a cloud service, distributing trust across multiple entities to avoid a single point of data compromise. Based on the pattern, a "trustworthy envelope" for any kind of payload enables curtained access through a variety of decorations or seals placed on the envelope that allow for a gamut of trust ranging with guarantees such as, but not limited to, confidentiality, privacy, anonymity, tamper detection, integrity, etc. For instance, XML tags can be applied or augmented to create trust envelopes for structured XML data. Some examples of mathematical transformations or 'decorations' that can be applied to the XML data include, but are not limited to, size-preserving encryption, searchable-encryption, or Proof(s) of Application, blind fingerprints, Proof(s) of Retrievability, etc.