Trustworthy XML Envelopes for Cloud Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud and network storage services lack effective solutions for ensuring the security, privacy, and integrity of data, leading to user concerns about data exposure and interference when data is stored or processed remotely.

Innovation Solution

A trustworthy platform is established using mathematical transformation techniques, such as searchable encryption, to decouple data protection from storage containers, allowing data to act as its own custodian through cryptographic key management, ensuring containerless data security and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is stored in cloud services or network storage, then data accessibility and storage capacity are improved, but data security and privacy are compromised due to third-party access risks

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments data into multiple fragmented portions and stores them across different locations. No single entity can reconstruct the complete data without all fragments, thereby maintaining security while enabling cloud storage accessibility. This directly resolves the contradiction by allowing data to be stored remotely (improving accessibility) while preventing any single third party from accessing the complete data (maintaining security).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic intermediaries including homomorphic encryption schemes and secret sharing mechanisms that act as mediators between the data owner and cloud storage providers. These intermediaries enable secure computation and data retrieval without exposing the actual data to the cloud provider, thus maintaining security while enabling cloud-based data access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is encrypted using traditional methods, then data confidentiality is improved, but data processing and search capabilities are lost

Engineering Contradiction:
Improvedata confidentialityVSAvoiddata processing capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the cryptographic parameters by employing homomorphic encryption schemes that allow mathematical operations to be performed on encrypted data. This enables data processing and search operations to be conducted on encrypted data without decryption, thus maintaining confidentiality while restoring processing capabilities that were previously lost with traditional encryption methods.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the traditional mechanical decryption-encryption process with homomorphic cryptographic operations that allow computation directly on ciphertext. This substitution eliminates the need to decrypt data for processing, thereby maintaining confidentiality while enabling data processing capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Volume of stationary object

If cloud storage services are used, then storage capacity and device independence are improved, but trust and control over data are reduced due to physical separation from storage

Engineering Contradiction:
Improvestorage capacityVSAvoidtrust and control
Core Design Contradiction:
Volume of stationary objectVSReliability

Solution Approach 1:

The patent applies preliminary cryptographic transformations including encryption and fragmentation before data is uploaded to cloud storage. These preliminary actions ensure that data is protected before leaving the user's control, maintaining trust and control even though physical storage occurs remotely in the cloud with large capacity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service cryptographic mechanisms where the data owner maintains control over encryption keys and can independently manage data access and retrieval. This self-service approach to key management enables users to maintain trust and control over their data while utilizing cloud storage capacity, as they can independently grant or revoke access without relying on the cloud provider's security measures.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2513804B1Trustworthy extensible markup language for trustworthy computing and data services
Publication Date: 2020.10.28 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2513804B1 patent drawingFigure 1
  • EP2513804B1 patent drawingFigure 2
  • EP2513804B1 patent drawingFigure 3

AI summary

A digital escrow pattern for data services can include selective access for obscured data at a remote site or in a cloud service, distributing trust across multiple entities to avoid a single point of data compromise. Based on the pattern, a "trustworthy envelope" for any kind of payload enables curtained access through a variety of decorations or seals placed on the envelope that allow for a gamut of trust ranging with guarantees such as, but not limited to, confidentiality, privacy, anonymity, tamper detection, integrity, etc. For instance, XML tags can be applied or augmented to create trust envelopes for structured XML data. Some examples of mathematical transformations or 'decorations' that can be applied to the XML data include, but are not limited to, size-preserving encryption, searchable-encryption, or Proof(s) of Application, blind fingerprints, Proof(s) of Retrievability, etc.