Our patented technology
Principle
Before it is stored, every file / process / execution is split into fragments and spread across several independent storage providers, with extra redundant fragments kept in reserve. No single provider ever holds a complete, readable copy of your data.
Hover over a provider card to see which fragments belong to it, or click Simulate outage to see what happens when two providers go down at once, and how the extra fragments seamlessly take over until they come back online.
Security against algorithm theft and/or reverse engineering
Astran’s AONT construction follows Kerckhoffs's principle (i.e. it should not be a problem if attackers come in possession of the algorithm).
Case in point, Astran uses a slightly customized version of the construction presented in Resch11 to resist the attack presented in Chen17 and update its primitives to more current ones.
Our construction has been proven by an external auditor and the resulting document can be made available to prospective customers.
Confidentiality of the data
Astran’s AONT is chunked into blocks and stored on competing hosts. The confidentiality is guaranteed since:
- each cloud storage provider only possesses a fragment of the AONT-masked data that does not give significant information on the secret
- the fragments do not collectively give significant information on the secret up to a given threshold k
Our construction has been proven by an external auditor and the resulting document can be made available to prospective customers.
Post-quantum attackers
Astran instantiates the production AONT with primitives that aren’t subject to exponential quantum speedup attacks; our primitives are chosen to remain secure after the advent of the quantum threat.
Astran's AONT-RS algorithm construction exclusively depends on symmetric ciphers and hash functions which are not vulnerable to Shor’s algorithm, which we predict will break classical asymmetric schemes (e.g. RSA, Elliptic Curves, ElGamal).