Probability based synchronized state machine encryption, decryption, and entanglement

EP4634807A2Pending Publication Date: 2025-10-22SONKSURU INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2023904390
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-12-14
Filing Date
2023-12-11
Publication Date
2025-10-22

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

Methods, apparatus, devices, systems, and software for probability based synchronized state machine encryption and decryption.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] PROBABILITY BASED SYNCHRONIZED STATE MACHINE ENCRYPTION, DECRYPTION, AND ENTANGLEMENT

[0002] CROSS-REFERENCE TO RELATED APPLICATIONS

[0003] This application claims priority to and benefit of U.S. Provisional Patent Application Serial No. 63 / 432,574 filed December 14, 2022, which is fully incorporated by reference and made a part hereof.

[0004] COPYRIGHT AND TRADEMARKS

[0005] A portion of the disclosure of this patent document may contain material that is subject to copyright or trademark protection by the inventor. The inventor has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent files or records, but otherwise reserves all copyright rights whatsoever. Trademarks such as product or brand names so registered at the Trademark Office or otherwise protected by law and owned by another are used herein only as helpful illustrations and are not indicative of any endorsement or claim of utility by the inventor or said third party mark holders.

[0006] FIELD OF THE INVENTION

[0007] The present invention relates to data security of in-flight or static data at rest.

[0008] BACKGROUND

[0009] With quantum computers on the horizon, current methods of data encryption are at risk of their keys being exposed. The risk of exposure is due to quantum computer algorithms reducing the complexity of many computationally hard encryption methods. This warrants a new method of data encryption that can survive both current quantum computer and future computers.

[0010] Ideally, only the sender and receiver should know the encrypted message. Much like Quantum Entanglement Communication, which has two endpoints synchronized together with its fidelity limitation, a similar version can be formed in the digital world but maintain 100% digital fidelity. This structure of protecting endpoints can be used in any trusted point-point communication ranging from a text message to a top-secret video conference call. This technology can also be applied to stationary data.

[0011] Therefore, systems, methods, devices and computer program products are desired that overcome challenges in the art, some of which are described above.

[0012] SUMMARY

[0013] Safe time of encrypted data is dependent upon the difficulty to solve the hard encryption math puzzle or by brute force search of the problem space. No keys are used in the disclosed encrypting or decrypting process meaning there is no hard math puzzle to be solved, defeating quantum computer algorithms from attacking and exposing the encrypted data. What is left is a brute force attack to simulate the exact operations performed by the encryption algorithm and then rolling that process backwards to recover original data white-text.

[0014] The disclosed systems, methods and computer program products are based upon the digital analog of quantum entangled particles. The use of a highly complex and configurable state machines makes up the end-points. The complexity of the state machines can be scaled based upon the available computing power in the application and the associated threat due to loss of the privacy of the data. The state machine is deployed at both the encryption and decryption sites, which in some instances could be the same location. Additionally, the ability to pass metadata in-band with the encrypted data stream is disclosed.

[0015] The state machines accept a data input stream to encrypt. It breaks the input into subdivisions of data that can be either fixed length or variable length. Invertible operations as well as random noise generators configured with a statistical probability are performed upon that data. Each part of the data stream is encrypted independently of earlier data in the stream. The data is then passed as output. For decryption, the operations are reversed.

[0016] For real-time connections such as TCP / IP, a mechanism changes the state machines encryption at all endpoints for each subsequent connection. This avoids any type of interruption of the connection to force retransmission and inadvertently disclosing some information that may be used to decrypt some basic levels of security of the state machine. Also, random data can be streamed from the state machine while there is no live data to process. By providing dummy data on the output terminal this requires any observer to capture all data in the hopes of decrypting at some future point but there is no hint as to the start / end of a valid data segment. This further contributes to the problem space of a third party eavesdropper of the state machines.

[0017] The need for a pseudorandom number generator (PRNG) or secret sequence of data is needed to keep the endpoint state machines in sync. There are several options that can be used as the PRNG. Therefore, disclosed and described herein is an approach that optimizes the performance of the encryption / decryption processes.

[0018] Other systems, methods, features and / or advantages will be or may become apparent to one with skill in the art upon examination of the following drawings and detailed description. It is intended that all such additional systems, methods, features and / or advantages be included within this description and be protected by the accompanying claims. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The components in the drawings are not necessarily to scale relative to each other. Like reference numerals designate corresponding parts throughout the several views.

[0020] FIG. 1 illustrates and example of a communication channel with an eavesdropper in the design;

[0021] FIG. 2 illustrates a flowchart for an exemplary method of data encryption;

[0022] FIG. 3 illustrates a flowchart for an exemplary method of data decryption;

[0023] FIG. 4 illustrates exemplary block operations according to embodiments disclosed herein;

[0024] FIG. 5 illustrates exemplary object level operations according to embodiments disclosed herein; and

[0025] FIG. 6 shows an example computing environment in which example embodiments and aspects may be implemented.

[0026] DETAILED DESCRIPTION

[0027] Before the present methods and systems are disclosed and described, it is to be understood that the methods and systems are not limited to specific synthetic methods, specific components, or to particular compositions. It is also to be understood that the terminology used in this entire application is for the purpose of describing particular embodiments only and is not intended to be limiting.

[0028] As used in the specification and the appended claims, the singular forms “a,” “an” and “the” include plural referents unless the context clearly dictates otherwise. Ranges may be expressed herein as from “about” one particular value, to “about” another particular value, or from “about” one value to “about” another value. When such a range is expressed, another embodiment includes from the one particular value, to the other particular value, or from the one particular value to the other particular value. Similarly, when values are expressed as approximations, by use of the antecedent “about,” it will be understood that the particular value forms another embodiment. It will be further understood that the endpoints of each of the ranges are significant both in relation to the other endpoint, and independently of the other endpoint.

[0029] “Optional” or “optionally” means that the subsequently described event or circumstance may or may not occur, and that the description includes instances where said event or circumstance occurs and instances where it does not.

[0030] Throughout the description and claims of this specification, the word “comprise” and variations of the word, such as “comprising” and “comprises,” means “including but not limited to,” and is not intended to exclude, for example, other additives, components, integers or steps. “Exemplary” means “an example of’ and is not intended to convey an indication of a preferred or ideal embodiment. “Such as” is not used in a restrictive sense, but for explanatory purposes.

[0031] Disclosed are components that can be used to perform the disclosed methods and systems. These and other components are disclosed herein, and it is understood that when combinations, subsets, interactions, groups, etc. of these components are disclosed that while specific reference of each various individual and collective combinations and permutation of these may not be explicitly disclosed, each is specifically contemplated and described herein, for all methods and systems. This applies to all aspects of this application including, but not limited to, steps in disclosed methods. Thus, if there are a variety of additional steps that can be performed it is understood that each of these additional steps can be performed with any specific embodiment or combination of embodiments of the disclosed methods.

[0032] As will be appreciated by one skilled in the art, the methods and systems may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the methods and systems may take the form of a computer program product on a computer-readable storage medium having computer-readable program instructions (e.g., computer software) embodied in the storage medium. More particularly, the present methods and systems may take the form of web-implemented computer software. Any suitable computer-readable storage medium may be utilized including hard disks, CD-ROMs, DVD- ROMs, optical storage devices, or magnetic storage devices.

[0033] Embodiments of the methods and systems are described below with reference to block diagrams and flowchart illustrations of methods, systems, apparatuses and computer program products. It will be understood that each block of the block diagrams and flowchart illustrations, and combinations of blocks in the block diagrams and flowchart illustrations, respectively, can be implemented by computer program instructions. These computer program instructions may be loaded onto a general-purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions which execute on the computer or other programmable data processing apparatus create a means for implementing the functions specified in the flowchart block or blocks.

[0034] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including computer-readable instructions for implementing the function specified in the flowchart block or blocks. The computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions that execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks.

[0035] Accordingly, blocks of the block diagrams and flowchart illustrations support combinations of means for performing the specified functions, combinations of steps for performing the specified functions and program instruction means for performing the specified functions. It will also be understood that each block of the block diagrams and flowchart illustrations, and combinations of blocks in the block diagrams and flowchart illustrations, can be implemented by special purpose hardware-based computer systems that perform the specified functions or steps, or combinations of special purpose hardware and computer instructions.

[0036] The present methods and systems may be understood more readily by reference to the following detailed description of preferred embodiments and the Examples included therein and to the Figures and their previous and following description.

[0037] Systems, devices, methods and computer program products are described herein for probability based synchronized state machine encryption. As shown in FIG. 1, a probability based synchronized state machine simulates quantum entanglement communication through its design with the ability to encrypt each byte / unit of a message independently of the others. In order to communicate, you need to be able to send data. Quantum entanglement occurs when two particles are inextricably linked together no matter their separation from one another whereas if a third party tries to monitor this entanglement, it is detectable as the entanglement collapses. Quantum entanglement communication (QEC) is a technology that uses the properties of entangled particles to privately transmit binary data. Having the state machine FIG. 1 (the encryptor 100 in FIG.l) sync with the decryptor 200 leaves an eavesdropper 300 or observer with no a priori knowledge about the message content. This can be considered a data diode between the encryptor 100 and decryptor 200, for bidirectional communication to flow, and additional set of encryptor and decryptor would be required in the opposite direction. To the eavesdropper 300, the data appears to be random noise of some length to decrypt with a problem space of 256AL where L is the length of the observed message assuming an 8-bit byte unit size. With an encrypted message “HELLO” with length of L=5, there are approximately 1.1 trillion solutions in the problem space. The probability of finding this exact solution would be ~ 1 in 1.1 trillion, again with no a priori knowledge of the message context as it could be any binary combination of the five values. This state machine can exist within any software or hardware device which requires or needs to leverage an encryption / decryption mechanism. Examples might include software applications such as Video-On-Demand streaming applications as the client or decryptor and an associated streaming server acting as the encryptor. The disclosed embodiments can be used with any device that utilizes and for of digital communication within the device or between physical devices. Most notably would be personal computers to routing equipment or company routers between locations across public communication networks.

[0038] The problem is worse, as there is no indication that “HELLO” is the correct decryption. Again, the observer has no a priori knowledge, so “HeLlO”, “hellO”, “Hola!”, “AWARD”, “BEACH”, 0x0102030405, etc. are all valid solutions to the observer. There is no reference to solve the problem with any level of certainty. All solutions are just as probable as any other, so the returned solution would be the 1.1 trillion solutions with the same probability.

[0039] If the observer has some a priori knowledge or context about the secure data, the problem starts to get easier. If the observer knows it is an English word, the Free Dictionary lists more than 158,000 words with a 5-character length. This is a much simpler set to provide, but again, the “actual” solution to the problem is still a guess at 1 in 158,000. With more context and a priori knowledge such as knowing the data is in the Scrabble™ Dictionary, this limits the combinations to about 9,000. Much more manageable in terms of a solution set for decryption, but again, which one of the 9,000 words as they all still have equal probability.

[0040] The five-character length message should have better protection than a 1 in 9,000 probability for safety. Although this is still not good odds to guess the original word, the application such as the Scrabble™ board may provide additional constraints on the problem space such as fixed location of letters. The security of this very short simple message can be increased by injecting noise into the output data. The state machine encryptor 100 can statistically determine where and the amount of noise to inject into the data output so it can be removed during decryption by the decryptor 200, but the eavesdropper 300 will now have the added task of finding the noise and removing it from the data.

[0041] The addition of noise increases the problem space based upon any a priori knowledge. Returning back to the 8-bit byte message format again, each noise particle increases the complexity by a minimum factor of 256, but there is now also the need to determine where the noise was injected so in the case of five bytes with one noise byte or six byte length, then the 1 in 6 chance of knowing the location of that noise to remove it must be considered. Without the knowledge of knowing the data is five characters long, you need to consider removing additional noise as well as part of the solution until you have a single byte output as it can be a single character message with five bytes of noise.

[0042] The number of encryptors, decryptors, and eavesdroppers is application dependent. Though FIG. 1 shows a single unit of each, there can be any number of each of these roles in a final application. Further, the state machines within the encryptor 100 and decryptor 200 of FIG. 1 uses a PRNG as part of its state machine. The state may include a deterministic seed to the PRNG so the values can be synchronized between all configured decryptors 200. The seed should be made up of a private secret, optionally it can contain a public portion as well. Since the private seed selects from a near infinite number of potential encryption algorithms, including a public section to this seed add an near infinite number of possibilities on top of the privately selected encryption algorithm. This allows public exchange of pail of the seed, but doesn’t disclose the base secret. This is a public index into the private encryption space. Depending upon the application and encryption needs, the public portion would not be reused to further obfuscate the base encryption algorithm blocking crafted data samples to help discover patterns or mask noise from truth data. Additional means can be employed to automatically change the public or semi-public, an obfuscated public index addition, such as using the preamble data to shift this encryption index. An exemplary embodiment of a PRNG system for the state machines would be based upon a seed made of private, public, and semi-public sections. The order of these values can be changed based upon decreasing the variation in the seed near the start of the seed value. This seed can be a series of bytes with an index value added at the end. The seed can be used with a SHA256 / SHA512 function to create a hash value. This hash value can be decomposed into individual objects or bytes and delivered when the PRNG requires data for probability and / or invertible function parameters. The objects are consumed from one series of hash bytes and once exhausted, the index can be updated and a new hash generated. This process repeats as long as the state machine requires PRNG data. This hash process can be optimized by recording the SHA256 / SHA512 internal algorithm state prior to processing the index value at the end, or where the seed value may change the most if earlier byte might frequently change. This prevents the re-computation of that portion of the hash significantly reducing the CPU load for subsequent data by only requiring the inclusion of the newly updated portion of the seed value to complete the hash updates.

[0043] To clarify the purpose and novelty of the synchronized state machines (entanglement), this allows for the transmission and storage of encrypted message / data without the need to store the mask / pad. For example, the approach described in this specification in one embodiment for One Time Pad (OTP) encryption, among other more complex algorithms, to be utilized with no transmission of the mask to decrypt the message. Current OTP technology requires the transmission of not only the encrypted message but also some secret way of transmitting the mask data to the decryptor to restore the original message. This has many drawbacks including twice the bandwidth requirement, public exposure of the mask, which is a security risk, as well as limited manipulation that can be done to the original message / data to ensure security. Furthermore, this entanglement method allows for any level of complex operations to be performed at a first location and have the reverse preformed at the same or multiple other locations without the need to retain such a mask or instructions to recover the original message / data.

[0044] An example of one system embodiment is shown in FIG. 2, which is a system encryption flowchart 400. The disclosed structure assumes the implementation will use both object and blocktype functions. Although not a required design parameter, block functions are assumed to work on a chunk of N objects from a stream and any number of functions can be chained together. On the other hand, object functions are assumed to operate on a single object such as a char, byte, short, int, long, float, double, string, etc. This is only one embodiment but the disclosed design works with one or the other if needed for the application. The features of the flow include initializing the state machine, reading in data, encrypting / processing data, and outputting the processed data.

[0045] The Init States 405 from FIG. 2 is responsible for setting up the state machine for the encryption process. This involves reading a configuration file, determining the mode of encryption / decryption, configuring the PRNG, and determining the block & object functions configure with their probabilities. It is also responsible for determining if an initial handshaking process need to take place to obtain more information for the PRNG.

[0046] Once the initial state is set, Read Some Data 410 starts to process data. This can be a single object, a fixed block size, or a variable block size based upon the configuration. This process step also determines if metadata is being passed at this point in the stream. Metadata might include; description / file name of the stream, changes to public / private components of the PRNG, indirect references to PRNG resources, signaling to end-point, flagging noise, etc. If required, this data is sent along the “Meta Inject” path to Output Data 425. Once the data for processing has been determined, it is passed into Process Block 500. After all block operations have been performed, the data is passed to Process Objects 600. Once processed, Write Some Data 420 will pass the proper data to Output Data 425 for inclusion in the data stream. At 430, More Data?, if an End Of File or End of Stream hasn’t been detected, the process continues back to 410 to start the next section of data for processing. If there is no more data, the process goes to End 440.

[0047] FIG. 3 illustrates a system decryption flowchart 450, which shows the reverse process of that shown in FIG. 2. Most of this process is identical to the encryption process shown in FIG. 2 with a few differences. First, the Init States 405 sets the mode for decryption, which causes the inverse functions to be used within the block / objects Operations. It also reverses the order of these functions so in Process Objects 600 and Process Block 500, the exact inverse of the encryption processes (FIG. 2) is maintained.

[0048] Another difference is within the step, Read Some Data 410. Metadata is decoded here and removed from the stream; it doesn’t need to be sent to the output but acted upon. This step 410 in decrypt mode now determines the size of the proper input block for the Process Objects 600 block, which is now done prior to the Process Block 500. This reason for this is again to reverse the operations performed during encryption. Since Process Objects 600 was processed last during encryption, it now needs to be done first. The Write Some Data 420 will send the decrypted data to Output Data 425 which is the original Input 415 processed in FIG. 2.

[0049] FIG. 4 Block Operation 500 shows more of the detail of handling a block function. START 502 begins the process passing the block data to Apply Function 504. A probability is pulled from the PRNG and compared to that of the functions configured. If the probability of the current block function is greater than or equal to the PRNG value, that operation is performed upon the block data, otherwise More Functions? 510 checks if all configured block functions have been evaluated. If not, control returns to the start, otherwise the data is passed out through the END 512.

[0050] Rendering percentages forms the basis of the described probability tests. The purpose of rendering percentages is to test the probability of an event occurring within the state machine. The PRNG is the main source of random data when there is a need to keep the state synchronized. For added obfuscation at low computational cost, sampled white text / unencrypted data or metadata can be used as random data in some operations. For computational efficiency, configured probabilities are converted to the domain of the random data source. In the case of the embodiment above, SHA512 bytes are used for rendering percentages. Here, 100% probability would be converted to a maximum value for a byte, OxFF, where a 50% probability would be converted to a value halfway through the domain sequence or 0x80. A PRNG byte will be obtained to test the probability, if it is less than or equal to, the probability is considered true otherwise false. This same operation can be reversed, converting the PRNG byte back to a percentage and testing for true / false. There are any number of ways of rendering percentages for a probability test. Another example would be to test above the probability value, so 75% would be considered true if it is above the 25% threshold, same goes for the byte calculations. It should be noted, 100% and 0% are edge cases, since these are affectively true and false by definition, it is computationally more efficient to not test these values and take them at face value. An embodiment of rendering percentages could test these values if so desired as it isn’t required either way. There is no restriction on the means of rendering percentages, any valid repeatable method will keep the state machines synchronized.

[0051] A note on obtaining a probability from the PRNG, it is also possible to use all or partial results of the actual data stream. For example, if y is the result of the PRNG or y = PRNG for short, a number of additional independent features can be applied to this function. For example, y = PRNGAx(t-l), here the result of the PRNG will be XORed with the previous value of x which represents the truth input data being encrypted. It is possible to use any previous input value, PRNG, or even any previous value of the encrypted data. It is even possible to weight values based upon the output of value in a form of recursion. That is, y = yl*PRNG + y2*x(t-l), or the returned probability is some weight of PRNG based upon a different y 1 = F(PRNG) value plus the previous input data point in time weighted by y2 = F(PRNG). It is further possible to exclude the use of PRNG and simply base y upon some other source, even an external data source known by both state machines, either a priori or passed by metadata within the encryption system.

[0052] If the function is to be applied based upon 504, there is a determination if the system is configured for Encryption through Encrypt? 504. If so, Apply Function 508 is applied to the data stream. If not, Apply Inverse Function 506 is applied to reverse the process to decode the data. The processed data is then again passed through to 510 to see if the block operations have been completed.

[0053] The detail of the Object Operation 600 is shown in FIG. 5. The difference between steps 500 and 600 includes that all objects are processed separately rather than as a block of objects. So, the START 602 queues data for Get Object 604, this Object goes through a similar set of steps as a block does, only at the object level. Apply Function? 606 pulls a probability from the PRNG check to see if it selects the current Object function. Although not required, this block only uses a single function per object unlike the block operations which can be chained together. A different implementation handling objects like blocks would allow multiple operations upon a single object. This is an application specific choice.

[0054] For one exemplary implementation, a frequency number is assigned to each different object function during configuration. That is functions A, B, C may be assigned a frequency of 2, 1, 1. Frequency of the functions are summed together, and then a probability is applied based upon each individual frequency value. So, A, B, C would be assigned 50%, 25%, 25% probability. These are converted to cover a 100% range, so A would be selected for probabilities up to 50%, B for 50+% to 75%, and C the remaining 75+% to 100%. Now, each probability value pulled will match one of those pre-configured functions probability range. The proper function, once the range is reached, is then applied through the similar block flow given testing at 608 for encryption, using either steps 612 or 610, as appropriate. Step 614 checks if there are more functions and passes control back to 606 if true. If there are more Objects, 616 will queue the object operation result and send the control back to process the next object. Once the queued objects have been exhausted, the queued results will be passed to the END 620.

[0055] The concept of frequency or probability of a certain action / feature can be accomplished in a number of ways. For example, a PRN sample can be converted into a probability and compared, or the probability of interest can be converted to match the sample and compared. There are no restrictions on how probability is determined and how to test that against the probability / frequency for a desired action.

[0056] Any number of invertible functions can be configured as a block or object operations. Also, the number and sequence of the Block Operation 500 and Object Operation 600 can be changed. The only requirement is to assure that for decryption, the exact reverse of the inverse functions is used to match the encryption process. The example implementations shown in FIG. 2 and FIG. 3 was chosen to illustrate this reversal of operations between encryption / decryption. Any combination of other sequences, number of blocks, or types of data binning can be used. Dedicated encryption / decryption can be configured for specific applications, such as only encrypting / decrypting the data within a video frame for instance. So, the underlying structure of the input is maintained and only variable data portions of the stream are encrypted / decrypted.

[0057] An Invertible function is any F(x)=y where there exists a similar F(y)=x in the range of the type of object represented by x. That is, if x is a byte, then the forward function of values in the valid domain of a byte 0x00->0xFF applied as x returns a value y within the same or different domain such as a short (0x0000->0xFFFF). Any other output domain can be used which can be locally specific to the individual functions including but not limited to; int, float, double, complex, bit, nibble, list, vector, and string. This flexibility allows for very complex object and block functions such as Deep Learning functions such as Convolutional Network, Deep Networks, Natural Language Processing, Detection networks, anomaly detection, compression networks, etc. Then, when that returned y value is fed into the inverse function, the original x value is returned. Some applications may tolerate or desire a lossy version of x is return in an acceptable range which would make it an acceptable inversion of the initial function. The discussion here applies more to getting back the exact encrypted input during the decryption cycle, but specialized systems for lossy functions also apply.

[0058] Some examples of Object based invertible functions might include XOR, subtraction, addition, bit roll left / right, expanding the byte into several sub-bytes, y = x, y = 3*x +5 etc. These functions take a single object during the forward function, resulting in either a similar object or different object type once encrypted. The inverse would then take that encrypted object type and return it back to the original object. Objects can also have influence from previous values in the data stream such as y(t) = 3*x(t) + x(t-l) + y(t-l). The value x(t) is the current object being processed and y(t) is the encrypted value at time t. Since the stream is processed in sequence, at time t, x(t-l) & y(t-l) have been established. Both of these values will be valid during the decryption process as well. There are certain features / functions that can be implemented at the object / block level which would exclude these encryption features so they need to be compatible with the rest of the system configuration.

[0059] The injection of noise or random data can also be accomplished at the object level. That is, when F(x) is requested, (y, nl, n2, n3) vector may be returned. This would be accomplished by requesting a NOISE type of function and in this example, four values would be returned, one being an operation on x, and 3 random noise values. The state machine would then invert this by taking the inverse operation of y, and deleting nl, n2, & n3 from the data stream.

[0060] Block based invertible functions can include the object based invertible function but might operate on more than one object at a time. Some examples of block functions might include a shift to the right of all data in the block, rolling the data in a circular buffer. Other block related examples might include Discrete / Fast Fourier Transforms (DFT / FFT), insert random data blocks, expand data block to larger size, implement data compression algorithm, and implement self-correcting messages. Self-correcting messages can be formed by way of techniques such as Hamming Codes, Reed- Solomon, Turbo Codes, etc. Given there is no expected loss in the digital data transmission / storage, the encryption algorithm can leverage self-correcting messages to improve obfuscation of the original or truth data. The state machine would consider a block, the desired amount of deleted / corrupted data, corrupt or delete such data from the output stream, and properly form the output with the required recovery data. The data would be transmitted with the known errors and the decryption state machine would reverse the process, recovering the corrupted / lost data and removing the recovery data from the data stream enhancing the file / stream data security. Also note that the state machine can be configured for constant block sizes or variable sizes depending on the desired complexity and level of data obfuscation desired.

[0061] All invertible functions, both object and block based can access the PRNG for more details of internal operation of the function input parameters. For example, the XOR function will need a value from the PRNG to XOR against the passed object x. As stated above, the returned value from the PRNG can be weighted and dependent upon prior truth data or encrypted output data. So, the XOR function, due to instructions within the state machine, might implement x(t) XOR x(t-b), x(t) XOR y(t-b), or x(t) XOR PRNG where x(t) is the current value being encrypted, and x(t-b) / y(t-b) are the truth data or encrypted data computed b objects ago. Block functions such as SHIFT BYTES might request the number of bytes or percent of bytes to shift left / right. Here a PRNG value is obtained (like all PRNG values as described above), converted to a percent of the block size to establish how big a shift and direction to perform the shift. Self-correcting blocks might have a range of values to select from to omit from the data stream and the state machine PRND will be queried to determine the value for the current block. The block function will then use that value to form the encrypted block or decrypt the block. Types of metadata passed can be encryption type and application specific. The detection of metadata can easily be flagged at the start of a block / object segment. A number of methods have been contemplated to also obfuscate both its presence in the stream and its value. A preferred method might reserve the first byte / object of each block such that if it matches the associated PRNG value, metadata is present and it needs to be recovered during decryption. Metadata present in-band with the encrypted data will act as supplementary random noise further obfuscating the truth data in the stream. It can also be encrypted based upon either the same rules or different rules pre-configured into the state machine. Depending on the encryption / secrecy requirements, this data could be left in white text if desired. Doing so clearly flags sections of the file as not including the encrypted data. This might be acceptable if the only goal is to reduce processing time but pass the metadata to the end application, such as a video streaming client.

[0062] For the encryption process, the associate PRNG value object value would be injected into the stream to flag the included metadata with the metadata value. Rules such as offsets from the associate PRNG may flag specific metadata types such as data stream length (original digital document size) or size of postamble buffering. If there is no metadata, the first object of the block is ignored and processing continues. If metadata is present, the size of the metadata can be passed, sized by PRNG, or computed in-line. The metadata itself can be considered a block in addition to the original truth data. Metadata can include any data of interest to the encryption system or an end application.

[0063] Some encryption system metadata examples might include transmitting IP address (for connection validation), data stream name (digital asset name), data stream length (digital asset length), postamble size, new state machine setting, not transmitting signal, external URL / source for state machine update, time stamp, etc. Some application specific metadata might include Data File Name / Size, Owner, Copyright, subscriber ID, Description, Movie Closed Caption Data, Song / Movie Title / Author / Artist, Song / Movie Rating, List of actors & roles, Movie description, calling ID, Destination phone number, Vehicle Identification Number (VIN) for firmware updates, software CRC, application instruction code (UPDATE FIRMWARE / FIRMWARE UPDATE PASSCODE), REST interface assignment, new IP address, etc. Including state machine updates such as public or secret sections can change the behavior of the synchronized state machines while transmitting.

[0064] In addition to injecting noise to obfuscate the actual size of the truth data, a preamble and / or postamble can be added to obfuscate the start / end of the truth data. The state machine can be configured to add a certain size range of random data to both the start and end of the encrypted data stream. For ease of implementation of the postamble, the data stream length could be passed to truncate the data at the receiving state machine, discarding the postamble random data. This additional frustrates the efforts of the FIG. 1, eavesdropper 300 in that the file will have random data padded at the start and end of the file. The stall and end can no longer be assumed to be at the beginning and end of the transmitted data stream.

[0065] In the case of a high security edge devices were encryptor 100 and decryptor 200 wish a highly secure real-time communication channel or tunnel, a specific configuration of the system can be implemented which will drive up the costs of observing for the eavesdropper 300 of FIG. 1. Configuring the Encryptor & Decryptor for a continuous data stream will force the eavesdropper 300 to capture and store all data seen across the communication channel / tunnel. When no truth data is available to transmit across the channel, encryptor 100 will send metadata stating to ignore the sent data and then push along some number of random data bytes. The decryptor 200 will then receive that data, detect metadata is being sent, decode it and determine the data is to be ignored and then discard that data. Meanwhile, eavesdropper 300 sees a continuous stream of data, so there is no apparent beginning or end of a transmission. For any hope to decode this data in the future, the continuous stream of data will need to be captured and stored for future processing. Depending upon the channel between encryptor 100 and decryptor 200, the system can be optimized to maximize the available bandwidth of that channel, even injecting ignore metadata when input truth data has been exhausted to maintain the maximum output data rate. So, if the channel between the two endpoints is a saturated lOGBs connection, store requirements for the eavesdropper 300 would approach 4.5 TB / hour or 108TB / day. The costs here can become immense depending upon the eavesdropper 300 listening time.

[0066] With this continuous data stream, using additional metadata such as the ability to change the internal state of the state machine will change the encryption method in real-time with no apparent breaks in the communication channel. These changes can be forced a fixed or random times with minimum values. The changes can be forced in the middle of transmitting a valid data stream, making its encryption a combination of a number of different encryption schemes. Also, with any break in the data stream accidental or from external factor like Denial of Service (DOS) attacks, streams can reestablish a connection with a guaranteed different encryption method.

[0067] One means of changing the encryption method would be to alter a public portion of the state machine settings. This could be derived from the preamble during a reconnection or even for a static file. That is, using the preamble calculate a public value used to alter the PRNG output. Optionally, a random public value can be generated by the encryptor 100 FIG. 1. Using the Unix time stamp of the same system and a known portion of the current PRNG secret portion, this public value can be encrypted along with a sync secret known by the decryptor 200 FIG. 1. This sync type of package is transmitted to the decryptor 200. The decryptor 200 will recall its Unix time stamp and the same known secret portion of the PRNG and decrypt the sent message looking to see if it can match the sync secret value. If not, it assumes the Unix time stamps are not a match and makes incremental changes back and forward in time until the sync secret value is matched. Optionally, a random offset can be used to adjust the Unix time stamp to force a search by the Decryptor and further obfuscate the actual value used. At this point, the encrypted public value as well as the matching Unix time stamps can be used on both the encryptor 100 and decryptor 200 as part of the state machine settings and the communication channel can be re-established. The search range of the decryptor’s 100 Unix time stamp can be limited in the configuration based upon expected values. Also, an offset might be added in the state machine configurations so that this offset value also needs to be obtained by the eavesdropper 300 for decryption of the data stream.

[0068] A weakness of using the PRNG for noise in repeating or encryption systems, ones that use the same configuration, given enough samples and test data a mask can be formed to eliminate injected noise. Although this simplifies the problem of hacking the encryption, the problem decreases from a problem on the order of 257A(L+N) to that of 256AL. So, it renders the addition of noise in these applications ineffective and a waste of computer resources. Since the state machine knows where the noise exists in the encrypted output and it is simply deleted from that stream, a true machine base or pure random number generator can be used for all noise injections. Using this true random number generator for the preamble with the generation of a semi-public seed adjustment creates a powerful static digital asset encryption. Each asset with a new random preamble will then use a completely different encryption scheme making the decryption of any two digital assets different and independent. Following this thought, that means if an Eavesdropper manages to crack asset A, this decryption technique will not work for asset B. In real-time encryption applications, this request to a different random number generator is not required and may add more delay to the streamed content. In these cases, using the PRNG is advisable as the state machine doesn’t reset.

[0069] The other distention here is the use of both private / secret content and public / semi-public information to initialize the state machine and PRNG. This allows for public disclosure of additionally agreed upon seed information which selects a new encryption method which is only known to the encryptor 100 and decryptor 200. Eavesdropper 300 sees this public information or can obtain it. Given the state machine is initialed and / or updated with the new public information, the Eavesdropper 300 doesn’t have the private / secret or the probabilities and functions implemented within the state machines. This makes this public information to Eavesdropper 300 less useful and merely a flag to indicate that the communication channel encryption could change and to start decrypting the file again with new rules which it has to learn. This public disclosure assures the ability to rapidly change encryption even during a real-time stream without disrupting the streamed content. It is even possible to use the metadata to instruct both configured state machines to obtain new secret data via a 3rdparty disclosed within the metadata. This new secret would be acquired by yet another set of paired state machines like FIG. 1 , this might include 2 sets for each operation for bidirectional communication with the 3rdparty system or a simple one-way listing channel to obtains the secret. This requirement would be application and need determined.

[0070] Special consideration can be given to edge devices such as routers connected to public networks. State machine configuration can be internally set based upon the destination IP address. This can be used as part of the public data of the PRNG internal to the state machines. Any traffic routed to known and configured IP address will form a software defined network with a private encrypted link.

[0071] Above, entanglement was specified using encryption and decryption as a primary example of the technology. Other application of this technology have been contemplated as well as created but are not limited to the following. As described earlier, metadata can be merged within the encrypted data stream and extracted during decryption. The generic form of what is described is a Multiplexer and Demultiplexer. The advantage of the entangled solution allows for one or more data streams; metadata, computational data, video data, audio data, sensor data, control data / commands. A practical example of this would be to multiplex a data stream and control stream over a single satellite uplink connection. The frequency of the control data can be non-symmetrical to the data and upon demand by injecting a metadata packet into the stream. The same way, two or more generic data / control channels can be formed for any other application; PTZ camera & video data, steering / power / break / lights / camera channels for a drone / RC car, position & communication channels for a wilderness walkie-talkie, video / audio / video control channels for a video conference equipment, etc. The same concept can be used to multiplex across a single channel to connect to more than one piece of equipment. So, a serial connection into a control room can control two or more pieces of equipment.

[0072] Computing Environment

[0073] FIG. 6 shows an example computing environment in which example embodiments and aspects may be implemented. The computing device environment is only one example of a suitable computing environment and is not intended to suggest any limitation as to the scope of use or functionality. The computing environment of FIG. 6 may be a computing device 700 used by a encryptor 100, decryptor 200, among other aspects of the disclosure. For example, computing device 700 may be a component of or comprise a cloud computing and storage system. Computing device 700 may comprise all or a portion of a server. State machines, as described herein, may be implemented on one or more computing devices 700. Each computing device may have one or more processors. In various implementations, computing devices 700 used by the various parties may be interconnected with one another through various connections, including networks. Such networks may be wired (including fiber optic), wireless, or combinations thereof including parallel, RS-232 (all serial communication from point to point), Visual (Infra-Red), audible (modem for example). Other connections / communication standards can also be improved such as USB, PCI Express, Firewire, Fiber Channel, HDMI, I2C, SPI, etc. Some of these are important for applications such as wireless barcode readers, Credit Card Terminals, walkie-talkies, radios, video conferencing, etc..

[0074] Numerous other general purpose or special purpose computing devices environments or configurations may be used. Examples of well-known computing devices, environments, and / or configurations that may be suitable for use include, but arc not limited to, personal computers, server computers, handheld or laptop devices, multiprocessor systems, cloud-based systems, microprocessorbased systems, network personal computers (PCs), minicomputers, mainframe computers, embedded systems, Internet of Things devices, network switches, network routers, network edge devices, Modulator-demodulators (modems), industrial control equipment, including distributed computing environments that include any of the above systems or devices, and the like. The computing environment may include a cloud-based computing environment.

[0075] Computer-executable instructions, such as program modules, being executed by a computer may be used. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform particular tasks or implement particular abstract data types. Distributed computing environments may be used where tasks are performed by remote processing devices that are linked through a communications network or other data transmission medium. In a distributed computing environment, program modules and other data may be located in both local and remote computer storage media including memory storage devices.

[0076] With reference to FIG. 6, an example system for implementing aspects described herein includes a computing device, such as computing device 700. In its most basic configuration, computing device 700 typically includes one or more processing units 702 and one or more memory 704. Depending on the exact configuration and type of computing device, memory 704 may be volatile (such as random-access memory (RAM)), non-volatile (such as read-only memory (ROM), flash memory, etc.), or some combination of the two. This most basic configuration is illustrated in FIG. 6 by dashed line 706.

[0077] Computing device 700 may have additional features / functionality. For example, computing device 700 may include additional storage (removable and / or non-removable) including, but not limited to, magnetic or optical disks or tape. Such additional storage is illustrated in FIG. 6 by removable storage 708 and non-removable storage 710. Computing device 700 typically includes a variety of computer readable media. Computer readable media can be any available media that can be accessed by the device 700 and includes both volatile and non-volatile media, removable and non-removable media.

[0078] Computer storage media include volatile and non-volatile, and removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Memory 704, removable storage 708, and non-removable storage 710 are all examples of computer storage media. Computer storage media include, but are not limited to, RAM, ROM, electrically erasable program read-only memory (EEPROM), flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium which can be used to store the desired information, and which can be accessed by computing device 700. Any such computer storage media may be part of computing device 700.

[0079] Computing device 700 may contain communication connection(s) 712 that allow the device to communicate with other devices over networks. Such networks may be public or private, combinations thereof, and may include the internet. Computing device 700 may also have input device(s) 714 such as a keyboard, mouse, pen, voice input device, touch input device, etc. Output device(s) 716 such as a display, speakers, printer, etc. may also be included.

[0080] It should be understood that the various techniques described herein may be implemented in connection with hardware components or software components or, where appropriate, with a combination of both. Illustrative types of hardware components that can be used include Field- programmable Gate Arrays (FPGAs), Application-specific Integrated Circuits (ASICs), Applicationspecific Standard Products (ASSPs), System-on-a-chip systems (SOCs), Complex Programmable Logic Devices (CPLDs), etc. The methods and apparatus of the presently disclosed subject matter, or certain aspects or portions thereof, may take the form of program code (i.e., instructions) embodied in tangible media, such as floppy diskettes, CD-ROMs, hard drives, or any other machine-readable storage medium where, when the program code is loaded into and executed by a machine, such as a computer, the machine becomes an apparatus for practicing the presently disclosed subject matter. Although exemplary implementations may refer to utilizing aspects of the presently disclosed subject matter in the context of one or more stand-alone computer systems, the subject matter is not so limited, but rather may be implemented in connection with any computing environment, such as a network or distributed computing environment. Still further, aspects of the presently disclosed subject matter may be implemented in or across a plurality of processing chips or devices, and storage may similarly be effected across a plurality of devices. Such devices might include personal computers, network servers, and handheld devices, for example.

[0081] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

Claims

CLAIMSWhat is claimed is: A method of encrypting data comprising the steps of: a. initializing a system state; b. processing unencrypted data to produce encrypted data from at least a portion of the unencrypted data, wherein said encrypted data is produced based upon a probabilistic state machine probabilities found through deterministic random data, where said processing comprises: i. rendering percentages from deterministic random data, ii. testing for one or more configured operations probability to be applied, iii. acquiring a configured block size of unencrypted data to ingest, iv. acquiring additional parameter data needed for operations, v. applying the configured operations to ingested data, vi. updating the system state; and c. outputting the encrypted data. The method of claim 1, further comprising repeating steps a.-c. until the unencrypted data is exhausted. The method of claim 1, wherein said unencrypted data to ingest is from a random data, deterministic random data, time stamp, IP address, computer internal state, probabilistic state machine internal state, external data acquisition, data file, memory, or a network port. The method of claim 1, wherein said configured block size is dynamically determined. The method of claim 1, wherein said one or more configured operations are an invertible function. The method of claim 1, wherein said one or more configured operations are an injection of configured meta-data.

7. The method of claim 1, wherein said one or more configured operations are updates to the system state and / or operations on the ingested data.

8. The method of claim 1, wherein said one or more configured operations are external locations of updates to the system state.

9. The method of claim 8, wherein the external locations include another IP address, a website, or a remote or local device.

10. The method of claim 1 , wherein said one or more configured operations are an injection of random data.

11. The method of claim 1, wherein said one or more configured operations are operations changing the system state.

12. The method of claim 2, wherein outputting the encrypted data comprises outputting a stream of encrypted data after exhaustion of the unencrypted data, wherein random data is injected into the stream of encrypted data to increase obfuscation of valid data.

13. The method of claim 1, wherein said unencrypted data is a binary object of any length equal to or smaller than the configured block size.

14. The method of claim 1, wherein said one or more configured operations are system state, bit, binary object, or block based.

15. The method of claim 2, wherein the unencrypted data is exhausted when no additional output is required.

16. The method of claim 1, wherein said system state includes preconfigured metadata.

17. The method of claim 1, wherein said system state includes preconfigured function probabilities.

18. The method of claim 1, wherein said system state includes preconfigured constant data.

19. The method of claim 1, wherein said system state includes preconfigured access to external metadata, and accesses a remote location to find such metadata.

20. The method of claim 1, wherein said system state includes preconfigured access to external constant data, and accesses a remote location to find such constant data.

21. The method of any one of claims 1-20, wherein the method is used to encrypt an output of an existing data encryption, transformative , or protective algorithm.

22. The method of any one of claims 1-21, wherein a decryption mask or pad information is not required and is not transmitted with the encrypted data.

23. The method of claim 22, wherein the decryption mask or pad information is not stored.

24. A method of decrypting encrypted data comprising the steps of: a. initializing a system state, wherein the initialized system state matches a system state of an encrypting method used to encrypt the data; b. processing the encrypted data to produce decrypted data from at least a portion of the encrypted data based upon a probabilistic state machine probabilities found through one or more deterministic random data generator, where said processing comprising: i. rendering percentages from deterministic random data, ii. testing for one or more configured operations probability to be applied, iii. mimicking the encrypting method to calculate data length and parameters needed, iv. acquire any required encrypted data to ingest, v. acquire additional parameter data needed for operations, vi. apply inverse operations to ingested encrypted data, vii. update system state; and c. output prepared decrypted data.

25. The method of claim 24, further comprising repeating steps a.-c. until the encrypted data is exhausted.

26. The method of claim 24, wherein said encrypted data to ingest is from a random data, deterministic random data, time stamp, IP address, computer internal state, probabilistic state machine internal state, external data acquisition, data file, memory, or a network port.

27. The method of claim 24, wherein said one or more configured operations are an invertible function.

28. The method of claim 24, wherein said one or more configured operations are an injection of configured meta-data.

29. The method of claim 24, wherein said one or more configured operations arc updates to the system state.

30. The method of claim 24, wherein said one or more configured operations are external locations of updates to the system state.31 . The method of claim 30, wherein the external locations include another TP address, a website, or a remote or local device.

32. The method of claim 24, wherein said one or more configured operations arc an injection of random data.

33. The method of claim 24, wherein said one or more configured operations are operations changing the system state.

34. The method of claim 25, wherein outputting the decrypted data comprises outputting a stream of decrypted data after the exhaustion of the encrypted data, wherein random data is rejected from the stream of decrypted data.

35. The method of claim 24, wherein said one or more configured operations are internal state, bit, binary object, or block based.

36. The method of claim 25, wherein the encrypted data is exhausted when no additional output is required.

37. The method of claim 24, wherein said system state includes preconfigured metadata.

38. The method of claim 24, wherein said system state includes preconfigured function probabilities.

39. The method of claim 24, wherein said system state includes preconfigured constant data.

40. The method of claim 24, wherein said system state includes preconfigured access to external metadata, and accesses a remote location to find such metadata.

41. The method of claim 24, wherein said system state includes preconfigured access to external constant data, and accesses a remote location to find such constant data.

42. The method of any one of claims 24-41, wherein the decrypted data is processed by an existing data decryption, transformative , or protective algorithm.

43. The method of any one of claims 23-41, wherein a decry ption mask or pad information is not required.

44. The method of claim 43, wherein the decryption mask or pad information has not been stored.

45. A method of entangling two or more computational devices, said method comprising: a. initializing a system state matching across all the two or more computational devices; b. determine a scheme of application synchronization; c. initialize one or more pseudo-random number generators; d. draw samples pseudo-random numbers from the one or more pseudo-random number generators; e. convert the drawn pseudo-random numbers samples to probabilities; f. test a frequency of action occurring against converted samples g. take action if the tested frequency of action is within a specified frequency; and h. perform steps d. through g. for all desired entangled events.

46. The method of claim 45, further comprising repeating steps a.-h. until a purpose of entanglement is exhausted.

47. The method of claim 45, wherein said system state includes preconfigured metadata.

48. The method of claim 45, wherein said system state includes preconfigured function probabilities.

49. The method of claim 45, wherein said system state includes preconfigured constant data.

50. The method of claim 45, wherein said system state includes preconfigured access to external metadata, and accesses a remote location to find such metadata.

51. The method of claim 45, wherein said system state includes preconfigured access to external constant data, and accesses a remote location to find such constant data.The method of any one of claims 43-49, wherein the method of entangling two or more computational devices is used to merge two or more data or metadata streams into a single stream. The method of claim 50 wherein a first of the two or more data or metadata streams comprises a data stream and a second of the two or more data or metadata streams comprises a control stream and the data stream and the control stream are merged into the single stream. The method of any one of claims 45-53, wherein a decryption mask or pad information is not required. A system for encrypting data, said system comprising: one or more processors; and a memory, wherein the memory is in communication with the one or more processors, said memory storing computer-readable instructions, said computer-readable instructions cause the one or more processors to: a. initialize a system state; b. process unencrypted data to produce encrypted data from at least a portion of the unencrypted data, wherein said encrypted data is produced based upon probabilistic state machine probabilities found through deterministic random data, where said processing comprises: i. rendering percentages from deterministic random data, ii. testing for one or more configured operations probability to be applied, iii. acquiring a configured block size of unencrypted data to ingest, iv. acquiring additional parameter data needed for operations, v. applying the operations to ingested data, vi. updating the system state; and c. outputting the encrypted data. The system of claim 55, further comprising repeating steps a.-c. until the unencrypted data is exhausted.

57. The system of claim 55, wherein said unencrypted data to ingest is from a random data, deterministic random data, time stamp, IP address, computer internal state, probabilistic state machine internal state, external data acquisition, data file, memory, or a network port.

58. The system of claim 55, wherein said configured block size is dynamically determined.

59. The system of claim 55, wherein said one or more configured operations are an invertible function.

60. The system of claim 55, wherein said one or more configured operations are an injection of configured meta-data.

61. The system of claim 55, wherein said one or more configured operations are updates to the system state.

62. The system of claim 55, wherein said one or more configured operations are external locations of updates to the system state.

63. The system of claim 62, wherein the external locations include another IP address, a website, or a remote or local device.

64. The system of claim 55, wherein said one or more configured operations are an injection of random data.

65. The system of claim 55, wherein said one or more configured operations are operations changing the system state.

66. The system of claim 56, wherein outputting the encrypted data comprises outputting a stream of encrypted data after exhaustion of the unencrypted data, wherein random data is injected into the stream of encrypted data to increase obfuscation of valid data.

67. The system of claim 55, wherein said unencrypted data is a binary object of any length equal to or smaller than the configured block size.

68. The system of claim 55, wherein said one or more configured operations are system state, bit, binary object, or block based.

69. The system of claim 53, wherein the unencrypted data is exhausted when no additional output is required.

70. The system of claim 55, wherein said system state includes preconfigured metadata.

71. The system of claim 55, wherein said system state includes preconfigured function probabilities.

72. The system of claim 55, wherein said system state includes preconfigured constant data.

73. The system of claim 55, wherein said system state includes preconfigured access to external metadata, and accesses a remote location to find such metadata.

74. The system of claim 55, wherein said system state includes preconfigured access to external constant data, and accesses a remote location to find such constant data.

75. The system of any one of claims 55-74, wherein the method is used to encrypt an output of an existing data encryption, transformative , or protective algorithm.

76. The system of any one of claims 55-75, wherein a decryption mask or pad information is not required and is not transmitted with the encrypted data.

77. The system of claim 76, wherein the decryption mask or pad information is not stored.

78. A system for decrypting encrypted data, said system comprising: one or more processors; and a memory, wherein the memory is in communication with the one or more processors, said memory storing computer-readable instructions, said computer-readable instructions cause the one or more processors to: a. initialize a system state, wherein the initialized system state matches a system state of an encrypting method used to encrypt the data; b. process the encrypted data to produce decrypted data from at least a portion of the encrypted data based upon a probabilistic state machine probabilities found through one or more deterministic random data generator, where said processing comprising: i. rendering percentages from deterministic random data, ii. testing for one or more configured operations probability to be applied, iii. mimicking the encrypting method to calculate data length and parameters needed,iv. acquire any required encrypted data to ingest, v. acquire additional parameter data needed for operations, vi. apply inverse operations to ingested encrypted data, vii. update system state; and c. output prepared decrypted data.

79. The system of claim 78, further comprising repeating steps a.-c. until the encrypted data is exhausted.

80. The system of claim 78, wherein said encrypted data to ingest is from a random data, deterministic random data, time stamp, IP address, computer internal state, probabilistic state machine internal state, external data acquisition, data file, memory, or a network port.

81. The system of claim 78, wherein said one or more configured operations are an invertible function.

82. The system of claim 78, wherein said one or more configured operations are an injection of configured meta-data.

83. The system of claim 78, wherein said one or more configured operations are updates to the system state.

84. The system of claim 78, wherein said one or more configured operations are external locations of updates to the system state.

85. The system of claim 84, wherein the external locations include another IP address, a website, or a remote or local device.

86. The system of claim 78, wherein said one or more configured operations are an injection of random data.

87. The system of claim 78, wherein said one or more configured operations are operations changing system state.

88. The system of claim 78, wherein outputting the decrypted data comprises outputting a stream of decrypted data after exhaustion of the encrypted data, wherein random data is rejected from the stream of decrypted data.

89. The system of claim 78, wherein said one or more configured operations are system state, bit, binary object, or block based.

90. The system of claim 89, wherein the encrypted data is exhausted when no additional output is required.

91. The system of claim 78, wherein said system state includes preconfigured metadata.

92. The system of claim 78, wherein said system state includes preconfigured function probabilities.

93. The system of claim 78, wherein said system state includes preconfigured constant data.

94. The system of claim 78, wherein said system state includes preconfigured access to external metadata, and accesses a remote location to find such metadata.

95. The system of claim 78, wherein said system state includes preconfigured access to external constant data, and accesses a remote location to find such constant data.

96. The system of any one of claims 78-96, wherein the decrypted data is processed by an existing data decryption, transformative , or protective algorithm.

97. The system of any one of claims 78-96, wherein a decryption mask or pad information is not required.

98. The method of claim 97, wherein the decryption mask or pad information has not been stored.

99. A system for entangling at least two computational devices, said system comprising: a first computational device, said first computational device comprising at least a first one or more processors and a first memory in communication with said first one or more processors, said first memory having computer-readable instructions stored thereon that are executable by the first one or more processors; and a second computational device, said second computational device comprising at least a second one or more processors and a second memory in communication with said second one or more processors, said second memory having computer-readable instructions stored thereon that are executable by the second one or more processors,wherein the first computational device and the second computational device are connected via a connection, and wherein the first one or more processors and / or the second one or more processors execute the computer-readable instructions stored on the first memory and / or the second memory, causing the first one or more processors and / or the second one or more processors to: a. initialize a system state matching across all ate least two computational devices; b. determine a scheme of application synchronization; c. initialize one or more pseudo-random number generators; d. draw samples pseudo-random numbers from the one or more pseudo-random number generators; e. convert the drawn pseudo-random numbers samples to probabilities; f. test a frequency of action occurring against converted samples g. take action if the tested frequency of action is within a specified frequency; and h. perform steps d. through g. for all desired entangled events.

100. The system of claim 99, further comprising repeating steps a.-h. until a purpose of entanglement is exhausted.

101. The system of claim 99, wherein said system state includes preconfigured metadata.

102. The system of claim 99, wherein said system state includes preconfigured function probabilities.

103. The system of claim 99, wherein said system state includes preconfigured constant data.

104. The system of claim 99, wherein said system state includes preconfigured access to external metadata, and accesses a remote location to find such metadata.

105. The system of claim 99, wherein said system state includes preconfigured access to external constant data, and accesses a remote location to find such constant data.. The system of any one of claims 99-105, wherein the method of entangling two or more computational devices is used to merge two or more data or metadata streams into a single stream. . The system of claim 106 wherein a first of the two or more data or metadata streams comprises a data stream and a second of the two or more data or metadata streams comprises a control stream and the data stream and the control stream are merged into the single stream.. The system of any one of claims 99-107, wherein the connection comprises one of more of serial, parallel, USB, wireless, point-point, file system, data file, database, cloud, VPN, SDN, fiber, and the like, connections between the first computational device and the second computational device. . The system of any one of claims 99-108, wherein a decryption mask or pad information is not required. . A non-transitory computer-readable medium have computer-executable instructions stored thereon, said computer-executable instructions causing one or more processors to execute a method of encrypting data comprising the steps of: a. initializing a system state; b. processing unencrypted data to produce encrypted data from at least a portion of the unencrypted data, wherein said encrypted data is produced based upon a probabilistic state machine probabilities found through deterministic random data, where said processing comprises: i. rendering percentages from deterministic random data, ii. testing for one or more configured operations probability to be applied, iii. acquiring a configured block size of unencrypted data to ingest, iv. acquiring additional parameter data needed for operations, v. applying the operations to ingested data, vi. updating the system state; and c. outputting the encrypted data.

111. The computer-readable medium of claim 110, wherein the method further comprises repeating steps a.-c. until the unencrypted data is exhausted.

112. The computer-readable medium of claim 110, wherein said unencrypted data to ingest is from a random data, deterministic random data, time stamp, IP address, computer internal state, probabilistic state machine internal state, external data acquisition, data file, memory, or a network port.

113. The computer-readable medium of claim 110, wherein said configured block size is dynamically determined.

114. The computer-readable medium of claim 110, wherein said one or more configured operations are an invertible function.

115. The computer-readable medium of claim 110, wherein said one or more configured operations are an injection of configured meta-data.

116. The computer-readable medium of claim 110, wherein said one or more configured operations are updates to the system state.

117. The computer-readable medium of claim 110, wherein said one or more configured operations are external locations of updates to the system state.

118. The computer-readable medium of claim 117, wherein the external locations include another IP address, a website, or a remote or local device.

119. The computer-readable medium of claim 110, wherein said one or more configured operations are an injection of random data.

120. The computer-readable medium of claim 110, wherein said one or more configured operations are operations changing the system state.

121. The computer-readable medium of claim 111, wherein outputting the encrypted data comprises outputting a stream of encrypted data after exhaustion of the unencrypted data, wherein random data is injected into the stream of encrypted data to increase obfuscation of valid data.

122. The computer-readable medium of claim 110, wherein said unencrypted data is a binary object of any length equal to or smaller than the configured block size.

123. The computer-readable medium of claim 110, wherein said one or more configured operations are system state, bit, binary object, or block based.

124. The computer-readable medium of claim 111, wherein the unencrypted data is exhausted when no additional output is required.

125. The computer-readable medium of claim 110, wherein said system state includes preconfigured metadata.

126. The computer-readable medium of claim 110, wherein said system state includes preconfigured function probabilities.

127. The computer-readable medium of claim 110, wherein said system state includes preconfigured constant data.

128. The computer-readable medium of claim 110, wherein said system state includes preconfigured access to external metadata, and accesses a remote location to find such metadata.

129. The computer-readable medium of claim 110, wherein said system state includes preconfigured access to external constant data, and accesses a remote location to find such constant data.

130. The computer-readable medium of any one of claims 110-129, wherein the method is used to encrypt an output of an existing data encryption, transformative , or protective algorithm.

131. The computer-readable medium of any one of claims 110-130, wherein a decryption mask or pad information is not required.

132. The computer-readable medium of claim 131 , wherein the decryption mask or pad information has not been stored.

133. A non-transitory computer-readable medium have computer-executable instructions stored thereon, said computer-executable instructions causing one or more processors to execute a method of decrypting encrypted data comprising the steps of: d. initializing a system state, wherein the initialized system state matches a system state of an encrypting method used to encrypt the data;e. processing the encrypted data to produce decrypted data from at least a portion of the encrypted data based upon a probabilistic state machine probabilities found through one or more deterministic random data generator, where said processing comprising: i. rendering percentages from deterministic random data, ii. testing for one or more configured operations probability to be applied, iii. mimicking the encrypting method to calculate data length and parameters needed, iv. acquire any required encrypted data to ingest, v. acquire additional parameter data needed for operations, vi. apply inverse operations to ingested encrypted data, vii. update system state; and f. output prepared decrypted data.

134. The computer-readable medium of claim 133, wherein the method further comprises repeating steps a.-c. until the encrypted data is exhausted.

135. The computer-readable medium of claim 133, wherein said encrypted data to ingest is from a random data, deterministic random data, time stamp, IP address, computer internal state, probabilistic state machine internal state, external data acquisition, data file, memory, or a network port.

136. The computer-readable medium of claim 133, wherein said one or more configured operations are an invertible function.

137. The computer-readable medium of claim 133, wherein said one or more configured operations are an injection of configured meta-data.

138. The computer-readable medium of claim 133, wherein said one or more configured operations are updates to the system state.

139. The computer-readable medium of claim 133, wherein said one or more configured operations are external locations of updates to the system state.

140. The computer-readable medium of claim 139, wherein the external locations include another IP address, a website, or a remote or local device.

141. The computer-readable medium of claim 133, wherein said one or more configured operations are an injection of random data.

142. The computer-readable medium of claim 133, wherein said one or more configured operations are operations changing the system state.

143. The computer-readable medium of claim 134, wherein outputting the decrypted data comprises outputting a stream of decrypted data after exhaustion of the encrypted data, wherein random data is removed from the stream of decrypted data.

144. The computer-readable medium of claim 133, wherein said one or more configured operations arc internal state, bit, binary object, or block based.

145. The computer-readable medium of claim 133, wherein the encrypted data is exhausted when no additional output is required.

146. The computer-readable medium of claim 133, wherein said system state includes preconfigured metadata.

147. The computer-readable medium of claim 133, wherein said system state includes preconfigured function probabilities.

148. The computer-readable medium of claim 133, wherein said system state includes preconfigured constant data.

149. The computer-readable medium of claim 133, wherein said system state includes preconfigured access to external metadata, and accesses a remote location to find such metadata.

150. The computer-readable medium of claim 133, wherein said system state includes preconfigured access to external constant data, and accesses a remote location to find such constant data.

151. The computer-readable medium of any one of claims 133-150, wherein the decrypted data is processed by an existing data decryption, transformative, or protective algorithm.

152. The computer-readable medium of any one of claims 133-150, wherein a decryption mask or pad information is not required.

153. The computer-readable medium of claim 152, wherein the decryption mask or pad information has not been stored.

154. A non-transitory computer-readable medium have computer-executable instructions stored thereon, said computer-executable instructions causing one or more processors to execute a method of entangling two or more computational devices, said method comprising: a. initializing a system state matching across all the two or more computational devices; b. determine a scheme of application synchronization; c. initialize one or more pseudo-random number generators; d. draw samples pseudo-random numbers from the one or more pseudo-random number generators; e. convert the drawn pseudo-random numbers samples to probabilities; f. test a frequency of action occurring against converted samples g. take action if the tested frequency of action is within a specified frequency; and h. perform steps d. through g. for all desired entangled events.

155. The computer-readable medium of claim 154, wherein the method further comprises repeating steps a.-h. until a purpose of entanglement is exhausted.

156. The computer-readable medium of claim 154, wherein said system state includes preconfigured metadata.

157. The computer-readable medium of claim 154, wherein said system state includes preconfigured function probabilities.

158. The computer-readable medium of claim 154, wherein said system state includes preconfigured constant data.

159. The computer-readable medium of claim 154, wherein said system state includes preconfigured access to external metadata, and accesses a remote location to find such metadata.. The computer-readable medium of claim 154, wherein said system state includes preconfigured access to external constant data, and accesses a remote location to find such constant data. . The computer-readable medium of any one of claims 154-160, wherein the method of entangling two or more computational devices is used to merge two or more data or metadata streams into a single stream. . The computer-readable medium of claim 161, wherein a first of the two or more data or metadata streams comprises a data stream and a second of the two or more data or metadata streams comprises a control stream and the data stream and the control stream are merged into the single stream. . The computer-readable medium of any one of claims 154-162, wherein a decryption mask or pad information is not required.