Data security and correlated methods
The data security device addresses the security risks of Cloud storage by encrypting and splitting data into multiple particles stored or routed across different entities, ensuring the data remains secure even if one entity is compromised.
Patent Information
- Application Number
- PCT/EP2024/080822
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-03
- Filing Date
- 2024-10-31
- Publication Date
- 2025-05-08
AI Technical Summary
Storing data in the Cloud poses security risks due to untrusted administrators, potential security issues, data misuse for AI services, risk of blacklisting, and access by hosting countries or agencies for espionage.
A data security device that encrypts data, splits it into multiple particles, and stores these particles in different memory entities or routes them through different paths, ensuring that no single entity can access the complete secret, even if one memory entity is compromised.
This approach provides a high level of security by ensuring that even if one particle is compromised, the complete secret remains unreadable, thereby mitigating the risks associated with Cloud storage.
Smart Images

Figure EP2024080822_08052025_PF_FP_ABST
Abstract
Description
Data Security and Correlated MethodsDescriptionThe present invention relates to data security, amongst others, how to securely store data, and to a device for securely retrieving such data as well as to correlated methods. The present invention in particular relates to a safe storage of data, for example, but not necessarily in the Cloud and makes reference to a concept introduced as Particular Cloud Security, PCS.BackgroundStoring data in the Cloud is most convenient for companies of different scales as well as for individuals: There is no need for hardware investments, no need for maintenance, no hassle with security updates. But storing data in the Cloud automatically leads to a scenario where another company has full permanent access to this data, and even to data thought to be deleted a long time ago which is known as the effect that “the internet does not forget”.There are five major threats when storing data with Cloud storage providers: a) One of the numerous administrators who have access to the data by virtue of their function is not fully trustworthy. b) The data confidentiality is compromised, if the Cloud storage provider has an undiscovered security issue like third party access to keys and master keys. c) Algorithms process the data in order to extract the data owners Intellectual property (IP) to build or update artificial intelligence (Al) services which provide high value for the Cloud storage providers and their investors. d) Al blacklists the data owner after content scanning with dangerous consequences like loss of access to the data, loss of certifications, impact on credit scores or suddenly bad reputation - with difficult or even increasingly no transparency on the reasons or the process of decision making, e.g., due to increasingly complex neural network-based algorithms and myriads of data sources. e) Hosting countries, agencies or organizations gain access and use the data for industrial espionage or other means.There is, thus, a need for securely storing and / or retrieving data.An object of the present invention is to provide for a data security device for securely storing data and for a data decryption device for securely retrieving data as well as for corresponding methods that allow for securely storing data to memories such as a Cloud memory and / or for securely transporting data.This object is achieved by the subject matter as defined in the independent claims.A finding of the present invention is that by not only storing encrypted data and a key in different devices but to further split the information to be stored into different parts or particles a high level of security may be achieved when storing those particles in different memory entities and / or by routing the memory data to be stored along different routes, e.g., through the internet. Such a concept allows that one of the particles does not lead to the overall secret, even if breaking the key itself as this would result in an incomplete and unreadable secret such that one of the above identified issues at one Cloud storage provider do not render the remotely stored secret accessible for others. Further, even when securely storing data another threat is a so-called Deep Packet Inspection that might lead in data, e.g., encrypted cypher and a key being transmitted separate from one another but over a same infrastructure such as a network operated by a same operator, to be accessible for such an operator.According to an embodiment, a data security device comprises an Encrypter for encrypting a bit sequence using an encryption bit sequence to obtain an encrypted bit sequence. The data security device comprises a data Splitter for splitting the encrypted bit sequence into at least a first encrypted bit sub-sequence as a first particle and a second encrypted bit subsequence as a second particle. A key Splitter of the data security device is configured for splitting the encryption bit sequence into at least a first encryption sub-key as a third particle and a second encryption sub-key as a fourth particle. An interface of the data security device is configured for storing first memory data being the first particle or a derivative thereof, and second memory data being the second particle or a derivative thereof in different memory entities. Further, third memory data being the third particle or a derivative thereof and fourth memory data being the fourth particle or a derivative thereof is stored in different memory entities. Alternatively or in addition, the first memory data and second memory data are routed along different routes for data storage and the third memory data and the fourth memory data are routed on different routes for data storage. Whilst storing the first andsecond memory data, the third and fourth memory data respectively mainly addresses the issue related to data storage, routing the memory data along different routes addresses the issue of a man-in-the-middle-attack eavesdropping communication. The embodiment allows to store both the encrypted and the key used for encoding in memory devices such as remote memory devices and, in particular, Cloud storages whilst preventing an attack on the communication route, an attack on one of the memory entities respectively, to allow for preventing the secret from being lost.According to an embodiment, a data decryption device comprises an input interface for receiving, from different memory entities, first memory data and second memory data associated with an encrypted sequence and for receiving, from different memory devices or entities, third memory data and fourth memory data associated with an encryption bit sequence. The data decryption device comprises a combiner or Inverse Splitter, i.e., a device for inverting the encoder-side splitting, for generating the encrypted bit sequence based on combining the first and second memory data, and for generating the encryption bit sequence based on the third and fourth bit sequence. The data decryption device comprises a Decrypter configured for decrypting the encrypted bit sequence using the encryption bit sequence to obtain a decrypted bit sequence. The device comprises an output for providing the decrypted bit sequence.Further embodiments relate to a method for securing data and a method for decoding data as well as to a computer readable storage medium having stored thereof a computer program having a program code for performing such a method and / or to machine code that encodes the described methods.Further embodiments are defined in the dependent claims.Preferred embodiments of the present invention are described hereinafter making reference to the accompanying drawings in which:Fig. 1 shows a schematic block diagram of a data security device according to an embodiment;Fig. 2 shows a schematic block diagram of an Encrypter according to an embodiment;Fig. 3a shows a schematic block diagram of at least part of a data security device according to an embodiment, comprising the Encrypter of Fig. 2;Fig. 3b shows a schematic block diagram of a data security device illustrating a possible concept of generating encrypted bit sequence according to an embodiment;Fig. 3c shows a basis for generating redundancy information according to an embodiment;Fig. 4 shows a schematic block diagram of a concept of storing first to sixth memory data using three memory entities that are location and / or arranged in different control domains and / or jurisdictions according to an embodiment;Fig. 5 shows a schematic block diagram for illustrating operation of a Splitter according to an embodiment ;Fig. 6 shows a schematic block diagram of a data decryption device according to an embodiment;Fig. 7 shows a schematic block diagram of a data decryption device according to an embodiment that is adapted to combine also redundancy information;Fig. 8 shows a schematic block diagram of an inverse splitter or combiner according to an embodiment;Fig. 9 shows a schematic block diagram of Decrypter according to an embodiment;Fig. 10 shows a particle according to an embodiment;Fig. 11 shows a schematic flow chart of a method according to an embodiment described herein that may be used for encrypting or storing data; andFig. 12 shows a schematic flowchart of a method according to an embodiment that may be used for decrypting data.Equal or equivalent elements or elements with equal or equivalent functionality are denoted in the following description by equal or equivalent reference numerals even if occurring in different figures.In the following description, a plurality of details is set forth to provide a more thorough explanation of embodiments of the present invention. However, it will be apparent to those skilled in the art that embodiments of the present invention may be practiced without these specific details. In other instances, well known structures and devices are shown in block diagram form rather than in detail in order to avoid obscuring embodiments of the present invention. In addition, features of the different embodiments described hereinafter may be combined with each other, unless specifically noted otherwise.Embodiments of the present invention relate to encrypting a bit sequence and to decrypt data retrieved from memory devices. A bit sequence to be encrypted may sometimes be referred to as a secret in connection with the embodiments. From encoding a secret using an encryption bit sequence, e.g., a key, an encrypted bit sequence, that may sometimes also be referred to as cypher, may be obtained.Some of the embodiments described herein may be described with regard to encoding a specific amount of data or a predefined amount of data such as a number of bits and / or bites. Such a scenario may relate, for example, to encode or transport files or containers of data that may be identified to have a beginning or start and an end. However, embodiments of the present invention are not limited to such a static structure of data and may also be used, without any limitation, for encoding and / or transporting a bit stream. That is, a bit sequence described herein may be a stream of bits or a number of at least one file. Accordingly, an encryption bit sequence may be considered as a stream of bits or may comprise a structure or amount / number of bits according to the at least one file. In preferred embodiments, the encryption bit sequence, the key, has a length or number of bits / bites, being at least a length of the bit sequence, the secret.Embodiments described herein relate to particles of data, wherein based on the above, a particle is not necessarily to be considered as comprising a predefined or pre-set number of bits. As a particle, in connection with the embodiments described herein, one may understand a fraction, a part or a subset of bits derived from data. For example, an encrypted bit sequence, the cypher, is split up into at least a first and a second particle, wherein the group of particles obtained may fully represent the source or particles, e.g., thecypher. That is, when combining the particles derived from the cypher, the cypher may be restored. Accordingly, other data such as the encryption key, referred to as the encryption bit sequence, may be split up into at least two particles that, when combined again, restore or represent the encryption bit sequence. It is noted that it might be preferred to split up the cypher into a corresponding number of particles when compared to the particles derived from the encryption key. However, this is not a necessary implementation and the number of particles derived from the encrypted bit sequence and the number of particles derived from the encryption bit sequence may differ from each other whilst both of them are at least two.Embodiments referring to a particle, thus, relate to a sub-sequence of bits being a part of the respective overall sequence, e.g., the encrypted bit sequence or the encryption bit sequence. Such particles may be a subset of bits of the overall sequence being extracted or copied to obtain the particle, e.g., by using the odd-numbered bits 1 , 3, 5, 7, ... of the overall sequence for a first particle and the even-numbered bits 0, 2, 4, 6, 8, ... for another particle not excluding other rules of generating a particle.Embodiments described herein relate to storing different memory data being obtained from different particles of a same source such as the encoded or encrypted bit sequence or the key bit sequence in different memory entities. As a memory entity, memory devices or groups of devices may be understood that allow for storing data, e.g., remotely or via accessing a local or remote network, e.g., using public infrastructure. A non-limiting example of such a configuration is a Cloud storage entity that comprises hardware storage at one or multiple locations accessed and / or interconnected by public network such as the internet. It is possible to address those devices individually, e.g., by selecting different Cloud storage providers, by configuring IP addresses and the like that allow to have different memory devices being located in different control domains such as companies or jurisdictions. For example, with regard to companies, if an employee of one company accesses the Cloud storage of the company, a memory device of a different company is unaffected by this threat. Further, if in one jurisdiction a threat arises for data security, e.g., by means of the government or a change of laws, this threat does not necessarily affect memory devices located in other jurisdictions.Referring now to Fig. 1 there is shown a schematic block diagram of a data security device 10 according to an embodiment. Data security device 10 is configured for encrypting a bit sequence 12, i.e. , a secret, being, for example, a block of bits / bites or a stream of bits. Thebit sequence 12 may be obtained, e.g., calculated or retrieved, internally of data security device 10 or may be received from another device, e.g., using a wired or wireless data interface.Data security device 10 comprises an Encrypter 14, e.g., an apparatus or a processing unit, for encrypting the bit sequence 12 using an encryption bit sequence 16. The encryption bit sequence may be referred to as a key or encryption key. A result of the Encrypter 14 provided and obtained from the bit sequence 12 and the encryption bit sequence 16 is an encrypted bit sequence 18. The encrypted bit sequence 18 may be referred to as a cypher.Data security device 10 further comprises a data Splitter 22, e.g., an apparatus or a processing unit, configured for splitting the encrypted bit sequence 18 into at least a first encrypted bit sub-sequence 18A and a second encrypted bit sub-sequence 18B. Data Splitter 22 may be configured for splitting the encrypted bit sequence 18 into more than two encrypted bit sub-sequences. The encrypted bit sub-sequences 18A and 18B may be referred to as first particle, second particle, respectively.The data Splitter 22 may be configured for implementing a static or variable rule for splitting the data, e.g., by implementing an algorithm. Such an algorithm may be software implemented or hardware implemented. By way of example, and for achieving a high level of security, the data Splitter 22 may be configured for assigning a first predefined bit of the encrypted bit sequence 18 to the first encrypted bit sub-sequence 18A based on a position of the bit in the encrypted bit sequence 18. A second predefined bit of the encrypted bit sequence may be assigned to the second encrypted bit sub-sequence 18B based on a different position of the bit in the encrypted bit sequence 18. For example, and to achieve a simple but nevertheless secure implementation, the data Splitter may be configured for assigning bits of the encrypted bit sequence 18 having an odd bit number to either the first encrypted bit sub-sequence 18A or the second encrypted bit sub-sequence 18B. The remaining bits, i.e., bits of the encrypted bit sequence having an even bit number, are assigned to the other encrypted bit sub-sequence 18B, 18A, respectively. For example, odd numbers may be assigned to or may form the first particle and even bits may form the second particle or vice versa.The concept described does not exclude having other rules of assigning bits to the respective encrypted bit sub-sequence, e.g., forming groups of bits that are assigned to one of the sub-sequences 18A, 18B, respectively. Alternatively or in addition, a varying distancebetween two adjacent bits may be implemented, e.g., having the first bit, the third bit, the sixth bit, the ninth bit or the like assigned to the encrypted bit sub-sequence 18A and the remaining bits to the other encrypted bit sub-sequence 18B. Such a varying distance between bits may be of particular advantage when generating at least a third particle from the encrypted bit sequence. According to an embodiment, to obtain a higher number of particles and / or memory data, a data security device may be configured for hierarchically splitting a stream or a particle, e.g., splitting a result of splitting to obtain two (or more) splitted parts thereof, such as by splitting the encryption key sub-sequence 16A, the encryption sub-sequence 16B, the first encrypted bit sub-sequence 18A and / or the second encrypted bit sub-sequence 18B.According to an embodiment, the key Splitter 24 is configured for generating the third particle 16A for decryption of the first particle 18A and for generating the fourth particle 16B for decryption of the second particle 18B. This works in an advantageous manner when using the XOR-operation for encryption / decryption. The data security device may be adapted for encryption and for decryption, e.g., by retrieving the stored memory data. The data security device 10 may be configured for storing memory data 16A’ and 18A’ in different memory entities and / or to route the first memory data 18A’ and the third memory data 16A’ differently. Further, the data security device may be adapted for storing the second memory data 18B’ and the fourth memory data 16B’ in different memory entities or to route the second memory data 18B’ and the fourth memory data 16B’ along different routes. In a preferred embodiment, the data security device is configured for storing first memory data 18A’ and fourth memory data 16B’ in a same memory entity and / or for storing the second memory data 18B’ and the third memory data 16A’ in a same memory entity.The data security device 10 comprises a key Splitter 24, e.g., an apparatus or a processing unit, configured for splitting the encryption bit sequence according to a splitting rule and into at least a first encryption sub-key 16A and a second encryption sub-key 16B. The splitting rule may be same or different when compared to the splitting rule implemented by data Splitter 22 wherein the number of encryption sub-keys obtained with key Splitter 24 may be same or different when compared to the number of encrypted bit sub-sequences obtained by data Splitter 22. According to a preferred embodiment the key Splitter 24 is configured for splitting the encryption bit sequence 16 according to a splitting rule implemented by the data Splitter 22 for splitting the encrypted bit sequence 18. According to this embodiment, the encryption sub-key 16A comprises bits of the encryption bit sequence 16 that correspond to bits of the encrypted bit sub-sequence 18A. Further, according to thatembodiment, the encryption sub-key 16B comprises bits of the encryption bit sequence 16 corresponding to the bits of the encrypted bit sub-sequence 18B. For example, when having the encrypted bit sequence 18 and the encryption bit sequence 16 of a same length and when splitting according to a same rule, e.g., according to an odd / even-separation, the even-bit comprising sub-sequences, e.g., 16A and / or 18A may comprise bits corresponding to one another, e.g., the respective first, third, fifth, seventh, ... bits. Furthermore, bits of the respective second sub-sequences 16B and 18B may correspond to one another. This is of particular advantage when implementing the Encrypter 14 to encrypt the bit sequence 12 by use of an XOR operation.The encryption key sub-sequences 16A and 16B may be referred to as a third particle, fourth particle, respectively.The data security device 10 further comprises an interface for storing first memory data 18A’, second memory data 18B’, third memory data 16A’ and fourth memory data 16B’. When compared to the first to fourth particles, memory data 18A’ may be the encrypted bit sub-sequence 18A or a derivative of it, second memory data 18B’ may be the encrypted bit sub-sequence 18B or a derivative of it, third memory data 16A’ may be the first encryption key sub-sequence 16A or a derivative of it and fourth memory data 16B’ may be the second encryption key sub-sequence 16B or a derivative thereof. Different memory data belonging to or originating from the same data such as first and second memory data on the one hand and third and fourth memory data on the other hand are stored in different memory entities such that first memory data 18A’ and second memory data 18B’ are stored in different memory entities and third memory data 16A’ and forth memory data 16B’ are stored in different memory entities. As an alternative or in addition, the first memory data 18A’ and second memory data 18B’ are routed on different routes for data storage and third memory data 16A’ and fourth memory data 16B’ are routed on different routes for data storage.Preferably, memory data 18A’ and the second memory data 18B’ are stored in memory entities being arranged or located in different control domains and / or jurisdictions. The third memory data 16A’ and the fourth memory data 16B’ are also stored in different control domains and / or jurisdictions. This does not prevent to have a cross-wise commonly used storage for memory data originating from different data streams, e.g., to store the first memory data 18A’ along with the fourth memory data 16B’ and / or storing the second memory data 18B’ along with the third memory data 16A’.For example, when bits of the different memory data correspond to one another based on bits of the particles corresponding to one another, such mixed pairs of memory data are, when being hacked or accessed in an unauthorized way , not related or associated with one another such that the part of the key being obtained may not be used to decode the part of the secret.A correlation or association between a respective memory data and the source thereof is a possibility provided by embodiments described herein, e.g., when further processing one or more of the particles, i.e., encrypted bit sub-sequences 18A, 18B and / or encryption key sub-sequences 16A and 16B.For example, embodiments provide for one or more advantageous modifications that may allow, implemented alone or in combination of at least two, further improvements in security, the improvements relating to determining authentication information, reordering or restructuring the particles and removing at least one fragment from a particle.Fig. 2 shows a schematic block diagram of an Encrypter 20, e.g., an apparatus or a processing unit, that may be used as Encrypter 14 of data security device 10.The Encrypter 20 may be configured for receiving the bit sequence 12 and for generating the encryption bit sequence 16, e.g., by using a source of randoms, e.g., a random noise generator 28 to determine a random-based encryption bit sequence that may optionally be stored in a cache or other type of local memory 32 which allows a use of the encryption bit sequence 16 in a later instance of time or to collect random values. As an alternative, the encryption bit sequence may be received from an external source, e.g., a source of advanced entropy. An encryption module 34 may be configured for encoding the bit sequence 12 using the encryption bit sequence 16, e.g., based on a bit-wise XOR operation to obtain the encrypted bit sequence 18. Those bit sequences 16 and 18 may provide for a basis for obtaining the memory data to be stored in different memory entities 34A and 34B, e.g., located in different control domains and / or jurisdictions.In other words, embodiments relate to a stream of data, which is called a “stream of secrets”. The stream of secrets could be data of any type. Embodiments are agnostic to the specific structure of the processed data. The stream of secrets may be short and distinct in case of messages, data objects or regularly sized files. But the system may also be applied to a continuous stream of secrets.Embodiments relate to a system for encryption and disassembly of a stream of secrets into multiple streams of(a) random noise-encrypted secrets,(b) random noise data,(c) redundancy information such as parity bits, which each shall be called a “particle stream” in the following.In other words, Fig. 2 shows a schematic diagram of an apparatus referred to as “Encrypter” that is in accordance with embodiments of the present invention. The module “Encrypter” receives a secret, e.g., a stream or block of data and uses random noise (random data) for encrypting the secret using the logical operation “exclusive or” (“XOR”). The random noise on the one hand and the encrypted secret, the “cypher”, on the other hand - at least in view of matching bits of memory data - are stored in different storages, e.g., operated by different providers, located in different jurisdictions. It is of no or at most neglectable impact for data security when storing non-matching information together in one memory entity such as memory data containing the even bits of the encrypted bit sequence and the odd bits of the encryption bit sequence or vice versa. According to embodiments, the encoded secret is distributedly stored at more than a single place and the used key is distributedly stored at more than a single place.It is to be noted that the embodied apparatus may be a remote device with regard to a source of the secret, e.g., a device operated by a service provider. Alternatively, or in addition, the device may be operated at least in parts at the source of secrets or directly or safely connected hereto to avoid transmission of the secret, e.g., using an internet connection.Fig. 3a shows a schematic block diagram of at least part of a data security device 30 according to an embodiment. Data device 30 may comprise the Encrypter 20.First memory data 36A comprising, e.g., the even bits of the encrypted bit sequence 18 and second memory data 36B comprising or being based on the odd bits of the encrypted bit sequence 18 as well as third memory data 38A and fourth memory data 38B that may comprise or be based on the even bits of the encryption bit sequence 16, the and odd bits respectively may be provided by a Splitter 42, e.g., an apparatus or a processing unit, that may implement functionality of data Splitter 22 and key Splitter 24 of data security device10. An even value is understood to have a value being 2n, wherein an odd value corresponds to 2n-1 with n e Z with n >=0. Further, to separate the data on a per bit basis is one of several embodiments. According to other embodiments, the splitting may relate to any other size of unit, e.g., 2 bits, 3 bits or any other number of bits or a number of bytes, e.g., 1 byte, 2 bytes or the like. The separation may be constant for the data to be split but may also vary, e.g. based on a position in the respective stream.In addition, the data security device 30 may comprise a data processor, possibly forming a part of Encrypter 20, Splitter 42 or a different section or unit of data security device 30 configured for generating first and second redundancy information 44A, 44B, respectively, forming a fifth particle, a sixth particle, respectively.For example, first redundancy information 44A may relate to a parity of cypher, i.e., redundancy information determined from the encoded bit sequence. Such redundancy information may be stored such that in a case where one of the first and second particles is lost, missing information may be reconstructed. Accordingly, by generating a second redundancy information 44B from the encryption bit sequence, a missing third or fourth particle may be reconstructed. It is noted that determining such redundancy information is optional and that both redundancy information 44A and 44B may be determined independently from one another, i.e., one of both might be generated whilst the other is not whilst not excluding other embodiments that generate both redundancy information 44A and 44B.In other words, Fig. 3a shows a block diagram of a system for encryption and disassembly with m=1 , m relating here to a rank of disassembly, the value of 1 indicating one step of separation. A higher value of m may indicate a hierarchical or iterative disassembly, e.g., splitting a splitted bit sequence at least one additional time.In particular, Fig. 3a shows a schematic block diagram of a device according to an embodiment further comprising a data disassembly module referred to as “Splitter” configured for splitting the encoded secret, i.e., the cypher and / or the random noise, preferably but not necessarily both.Details about generating the splitted stream of cyphers and / or the splitted stream of randoms are presented in Fig. 3b and Fig. 3c. For illustration purposes, a secret stream of 4 data values is given: x[0], x[1], x[2], x[3]. For each data value the Encrypter generates arandom noise value r[n] . Data values and random noise values are then combined with the XOR function, resulting in a stream of cyphers c[n].The subsequent Splitter splits the stream of cyphers into multiple streams, similarly the streams of randoms. While doing so, streams of parity for the cypher and random noise are calculated.Fig. 3b shows a schematic block diagram of data security device 30 illustrating a possible concept of generating encrypted bit sequence 18. The bit sequence 12 may be obtained so as to comprise a bit value x[n] where n is an index counting bits. Similarly, encryption bit sequence 16 may be provided with a corresponding number of bits r[n]. In Fig. 3b there is shown a conjunction of bit x[0] with r[0] by using an XOR operation. That is, the corresponding bits r[i] and x[i] are XORed, whilst “i” represents an index of the n-bits. In a preferred embodiment, data files and / or data streams to be encrypted may be split into parts or blocks of a specific size such as a size of a data buffer, a part thereof or a different size.In other words, Fig. 3b: shows a system for encryption and disassembly with m=1 , showing a first data value to be processed. Fig. 3b further shows the system after processing a first data value x[0], leading to (a) a first cypher value c[0] in the stream of even cyphers and (b) a first random noise value r[0] in the stream of even random noise.In Fig. 3c the next bits r[1] and x[1] are XORed for the encrypted bit sequence 18 represented by “c” as cypher whilst, by way of example, the first particle 36A may comprise the first bit c[0] whilst the subsequent odd bit c[1] may be part or basis for the second particle 36B. Similarly, r[0] and r
[0001] may be part or basis of encryption bit sequence 16 and, thus, of third and fourth particles 38A, 38B.Additionally, Fig. 3c shows a basis for generating redundancy information 44A and 44B. For example, redundancy information 44A may be obtained by XORing to obtain parity of a cypher “pc” where, e.g., a first bit pc[0] may be obtained by XORing first and second bits c[0] and c
[0001] both forming the respective first bit of particle 36A and 36B. Alternatively or in addition, redundancy information related to sequence r, pr, may be obtained by XORing subsequent bits of the encryption bit sequence 16, e.g., r[0] and r[1]. In a next step processing x[2] further parity information may be generated by using bits of i=2 and i=3.In other words, Fig. 3c: shows a system for encryption and disassembly with m=1 , showing a first and second data value to be processed. Further, Fig. 3c shows the system after processing the second data value x[1], leading to (a) a first cypher value in the stream of odd cyphers c
[0001] , (b) a first random noise value r
[0001] in the stream of odd random noise, (c) a first parity value pc[0] for the stream of cyphers and (d) a first parity value pr[O] for the stream of randoms.The encrypted and split / disassembled stream can be securely processed and / or stored by Cloud processing and / or storage providers without the need of trusting them (Fig. 4). There is no need of storing the original secrets or copies of the original secrets in an own IT- infrastructure or at Cloud storage providers claiming to be extra secure.Alternatively, or in addition to storing said information on different memory devices, embodiments may also relate to transmitting the different particles via different routes to a dedicated recipient, e.g., a receiving device such as via different routes through the internet optionally using different protocols and / or other network connections.Fig. 4 shows a schematic block diagram of a concept of storing first to sixth memory data 36A’, 36B’, 38A’, 38B’, 44A’ and 44B’ using, for example, three memory entities 34A, 34B and 34C that are located and / or arranged in different control domains and / or jurisdictions. For example, first memory data 36A’ being derived from the encrypted bit subsequence 36A may be stored together with fourth memory data 38B’ being derived from the fourth particle, i.e., the second encryption key sub-sequence 38B. Accordingly, memory data 36B’ and memory 38A’ may be stored together whilst avoiding that, by accessing or stealing data from one of the memory entities the complete secret may be obtained. Fig. 4 shows an improvement where the respective memory data 44A’ being derived from the first parity information (parity of a cypher) 44A and memory data 44B’ being derived from redundancy information 44B (parity of random noise) are stored in a memory entity being separate from memory entities 34A and 34B to avoid storage of parity information together or in the same memory entity when compared to the secret related or key related memory data. It is possible but not necessary to store both memory data 44A’ and 44B’ in a same memory entity.One or more of the first to sixth memory data is advantageously stored in a Cloud storage.In other words, Fig. 4: illustrates a concept of a distributed storage of particle streams. As may be seen from Fig. 4, an apparatus according to an embodiment of the present invention may be configured for storing non-matching particles in a same data storage, e.g. the particle stream of even cyphers and the particle stream of odd randoms are stored in a first physical memory device, e.g. in Europe; and wherein the particle stream of odd cyphers and the particle stream of even randoms are stored in a second physical memory device, e.g. in North America.In a third physical memory device, e.g. in Asia, one or more, e.g., two parity bit sequences are stored to grant redundancy as described herein.The particle streams may be trustworthy stored in a distributed manner and the original stream of secrets can be restored at any time exclusively by the creator of the stream of secrets which holds the specific access credentials for the Cloud storages. Storing a given stream of secrets as particle streams in a distributed manner needs to satisfy the following requirements in order to be truly safe:The particle streams are preferably stored in independent data storage entities or in different control domains, that include but are not limited to at least one of:(a) different particle streams are advantageously stored by different Cloud storage providers;(b) different particle streams are advantageously stored in different countries / jurisdictions .If at least requirement (a) or requirement (b) is met, the cryptographic principle of secret sharing is satisfied. In the context of this invention the group of entities among which an encrypted secret is distributed are preferably Cloud storage services offered by competing companies in different jurisdictions.If agencies of the hosting country demand or force access to the stored data, the single particles, as they are split and / or encrypted, do not reveal information. If there is a security issue with the hosting company and attackers have access to the particles, they also cannot extract confidential information.If a Cloud storage provider is offline (e.g., IPs blocked by a country, cyber-attack, etc.) some particles aren't available and cannot be used to reconstruct the original stream of secrets by the owner. In this case the algorithm uses the invention’s fault tolerance system - streams of parity bits which are stored by other Cloud storage providers, preferably again in a different country. This provision not only adds fail-safety in cases of technical malfunction but also makes Cloud storage robust against extortion, let it be malware attacks or governmental influence.In addition to encryption and disassembly, the invention has a system for reassembling and decrypting the particle streams into the original stream of secrets.The overall system may be referred to as “Particle Cloud Security Gateway”, “PCS Gateway”.Fig. 5 shows a schematic block diagram for illustrating operation of Splitter 42. Splitter 42 may be configured for operating on both, the encrypted bit sequence 18 and the encryption key sequence 16. However, data Splitter 22 may be configured similarly as may be key Splitter 24. Upon receiving, e.g., the encrypted bit sequence 18, a demultiplexer (DEMUX) 46 may be configured for assigning the respective bit to either the first encrypted bit subsequence 36A or the second encrypted bit subsequence 36B based on a decision being made in a selector 48. Together, the demultiplexer 46 and the selector 48 may implement a respective splitting rule.By using a combiner 52, e.g., XORing two subsequent bits of the encrypted bit sequence and, thus, combining information from both particles 36A and 36B redundancy information 44A may be determined.In other words, embodiments relate to a method and a system for disassembly. The system for disassembly comprises two modules which subsequently process the data streams.The first module is an encryption module (“Encrypter”) which provides or produces random noise data and applies the logical operation “exclusive or” (XOR) to the secrets (see Fig. 2 and Fig. 5). XOR is applied bit-by-bit. The mathematical symbol ® shall be used to denote XOR in the following.XORing secrets with random noise is a technique used in the field of cryptography by the well-known one-time pad (OTP) encryption scheme. OTP encryption is in information theory known to be a mathematically secure cryptosystem which is also known to remain secure in the context of upcoming quantum computer computational power: even infinite computational power cannot decrypt OTP encryption.For computational efficiency, the Encrypter has a cache of random noise in order to output random noise as fast as the stream of secrets delivers data. Because randomness is crucial for the algorithm, the module meets these requirements by using a cryptographically secure pseudorandom number generator (CSPRNG) to fill the cache of randoms. The module furthermore allows to attach a hardware random number generator (HRNG) or other sources of high entropy, to ensure high quality randomness for the encryption with a stream of random noise.The Encrypter outputs two streams, the stream of encrypted secrets called stream of cyphers. And the stream of random noise sourced from the modules random noise cache.These two streams are inputs to the succeeding module called “Splitter” 42. It applies a 1-to-n demultiplexer (DEMUX), with n=2 in the further elaborations, resulting in two particle cypher streams (Fig. 5.). The Splitter 42 demultiplexes also the random noise stream. The demultiplexer splits the cypher stream into at least 2 streams. By implementing such a blind rule for splitting stream of cyphers, i.e., to assign data elements into a first or second (or third, ...) stream, advantageously there is obtained a loss of all personal information which allows such secrets to be stored in accordance with privacy protecting laws even without further processing, i.e., the parts do not reveal such information as indicated above.Because of this blind rule for processing streams of secrets the invention does not need to know the size of the stream of secrets in advance which is most advantageous when dealing with streams.Fig. 5 also shows details of the module for disassembly (only showing processing of cypher, with random noise being handled equally).According to embodiments, to add fault tolerance, a separate module (named “PCS Parity”) of the system may calculate and add redundancy information by means of a stream of parity bits. This technique only needs half the size of the cypher and random noise streams asthe amount of parity bits is essentially at most half of the original amount / number of bits, see for example, Fig. 3c. For example, an even length of the cypher may lead to same or equal lengths of the encrypted bit sub-sequences 36A and 36B, e.g., when assuming an even / odd separation. For example, a length of even cypher, e.g., encrypted bit subsequence 36A may be 10 bits and a length of odd cypher, e.g., e.g., encrypted bit subsequence 36B may be 10 bits, both together resulting in a length of parity information 44 as being 10 bits. However, according to the same embodiment, an uneven length of the cypher, e.g., 19 bits may lead to different lengths of the encrypted bit sub-sequences 36A and 36B, e.g., one having 10 bits and the other 9, which may also result in 10 bits of parity, thereby exceeding half of the length of 19 bits. However, as the lengths of secrets and cyphers may be significantly more than 10 bits, e.g., several 100 bits or more, this effect of exceeding half the length may be neglected. For fault tolerance one stream of parity bits for the stream of cyphers and one for the stream of randoms is required.If one of two cypher particle streams vanishes, the stream of parity bits could be used to reconstruct it, with least computational effort in terms of speed and memory footprint. Reconstruction can be calculated on the fly, in a streaming way of calculation. Given a single value from the even stream of cyphers and given the corresponding value of the stream of parity, the corresponding value of the odd stream of cyphers can be reconstructed as follows: odd[n] = even[n] ® parity[n]If the single value from the even stream of cyphers is not available but the odd one is, reconstructing works equivalently: even[n] = odd[n] ® parity[n]The same principle holds true for the random noise particle streams.The Splitter can be applied to the streams iteratively or recursively. Without recursion the module may create 6 particle streams, two of them being disassembled streams of cyphers, one being a stream of parity bits for the cypher, two more being disassembled streams of random noise and one stream of parity bits for the random noise. When applying the Splitter recursively with the depth of m and m>0, the Splitter may output 3*2mstreams of particles.In pseudo code the recursive splitting looks like this (not showing the stream of parity data for brevity): i=0 split(stream, i)[even, odd] = divide(stream) if i<m i++ split(even, i) split(odd, i) wherein m relates to the rank of disassembly. Such iterative or hierarchic disassembly of streams in at least 2 sub-streams may be implemented independently for the encrypted secret and for the key sequence, i.e. the hierarchy may be implemented in only one of both or in both, it may comprise a same number of iterative or hierarchical steps or a different number and it may disassemble the particles into a same or different number of subparticles in different hierarchical steps.Fig. 6 shows a schematic block diagram of a data decryption device 60 according to an embodiment. Data decryption device 60 comprises an input interface 54 configured for receiving, from different memory entities, memory data 16A’ and 16B’ and for receiving, also from different memory devices as described herein, memory data 18A’ and 18B’. A combiner 56, e.g., an apparatus or a processing unit, is configured for generating the encrypted bit sequence 18 based on memory data 18A’ and 18B’. Further, the combiner 56 is configured for generating the encryption bit sequence 16 based on the memory data 16A’ and 16B’. Such combination may invert the operation of data Splitter 22 and / or 24, Splitter 42 respectively e.g., when obtaining the particles based on distinguishing between even and odd bits, said even and odd bits may be joined again.A Decrypter 58, e.g., an apparatus or a processing unit, may decrypt the encrypted bit sequence 18 using the encryption bit sequence 16 to obtain a decrypted bit sequence 12’ that is, in an error-free case, identical with the original bit sequence 12. Possible bit errors might be corrected, e.g., using an error correction code or the like. An output interface 62 may provide the decrypted bit sequence 12’.In case the data security device providing the memory data 16A’ 16B’ 18A’ and 18B’ is adapted to perform additional security mechanisms, those security mechanisms may be considered and inverted at data decryption device 60.Fig. 7 shows a schematic block diagram of a data decryption device 70 according to an embodiment that is optionally adapted to use redundancy information 44A’ and / or 44B’ to restore, e.g., when using redundancy information 44A’, one of memory data 36A’ and 36B’, to restore, e.g., when using redundancy information 44B’, one of memory data 38A’ and 38B, respectively. Although Fig. 7 relates to an embodiment where both redundancy information 44A’ and 44B’ may be used, according to other embodiments, only one of both redundancy information 44A’ and 44B’ may be provided to the data decryption device 70. With reference to Fig. 3C and Fig. 5, a lost particle may be restored by the use of the redundancy information. Preferably, when using redundancy information, both redundance information 44A’ and 44B’ is determined and properly storedFig. 8 shows a schematic block diagram of the inverse Splitter or combiner 62 configured for combining encrypted bit sub-sequences 36A’ and 36B’, e.g., using a multiplexer 64 controlled by a selector 66 to obtain a restored cypher being, e.g., in an error-free case, cypher 18.Fig. 9 shows a schematic block diagram of Decrypter 58 according to an embodiment that is configured for XORing the encryption bit sequence 16 and the encrypted bit sequence 18 to obtain the decrypted sequence 12’.In other words, embodiments also relate to a method and a system for reconstruction.For inverting encryption and disassembly, embodiments provide a system which reassembles and decrypts the particle streams into the original stream of secrets (see Fig. 7). This system also comprises two modules, which subsequently process the streams:The first module (Fig. 8) is the inverse of the Splitter (“Inverse Splitter”) 62, it joins two particle streams to one using a n-to-1 multiplexer (MUX) 64, with n=2 in these elaborations.This also could be processed iteratively or recursively, resulting in the stream of cyphers and the stream of randoms. In case of a missing or corrupted particle stream the corresponding stream of parity bits is used to recover the missing or corrupted stream. Forexample, from the two cypher streams a combined cypher stream is reassembled and from the two random noise streams a combined random noise stream is reassembled, each based on knowledge of the mechanism used for generating the streams, e.g., which is even and which is odd.The second module (Fig. 9) is a decryption module (“Decrypter”) 58, which XORs the combined stream of cypher and the combined stream of randoms. This module outputs the reconstructed stream of secrets.In the following, several advantageous modifications are described that may be implemented at a data security device described herein. An inverse mechanism may be used at a data security device according to an embodiment.According to an embodiment, a data security device may comprise a data processor configured for determining, for at least one, two, three or more, or all of the first to fourth particles, e.g., also for the fifth and sixth particle, and on the basis of the same particle or on the basis of the corresponding memory data, a particle authentication information that is associated with the memory data obtained from the particle. That is, for one or more of the particles, there may be determined a particle authentication information. An example for such a particular authentication information is a message authentication code (MAC) wherein this is a non-limiting example only. Examples of a MAC are CMAC, HMAC. An example for such a message authentication code is a Hash-value that may be used to determine, after reassembly of the particle at the data decryption device, whether the particle was manipulated or corrupted or not. The data security device may be adapted for storing the particle authentication information in a different memory entity as the associated memory data.Such authentication information is determined, according to an embodiment, in addition or as an alternative to the optional particle authentication information with regard to the secret, i.e. , the bit sequence 12. According to such an embodiment, a data processor of the data security device is configured for determining a secret-related authentication information from the bit sequence. The data security device may store the secret-related authentication information locally or in a different memory entity as the associated memory data, i.e., memory data 18A’ and 18B’ for a verification of a reassembled and decrypted bit sequence 12’. That is, after decrypting the secret it may be verified by use of the secret-related authentication information, whether the process of encrypting, splitting then inverse splittingand decrypting was executed correctly. Using particle authentication information may be used to determine whether the secret, the encrypted secret respectively was manipulated or not. Such secret-related authentication information may be determined based on the same algorithms or methods as used for the particle authentication information, e.g., using a message authentication code or a hash value.By using such a concept, a data decryption device described herein may retrieve at least one of the particle authentication information, e.g., from a data memory different from the corresponding memory data and for verifying data integrity of at least one of the first encrypted bit sub-sequence generated from the first memory data using a first particle authentication information; a second encrypted bit sub-sequence generated from the second memory data using a second particle authentication information; a first encryption key sub-sequence generated from the third memory data using a third particle authentication information and a second encryption key sub-sequence generated from the fourth memory data using a fourth particle authentication information.According to a further advantageous modification that may be implemented in addition or as an alternative to other modifications described herein whilst remaining nevertheless an optional implementation is a concept that is referred to as combinatorial explosion.With reference to Fig. 10 there is shown a particle 65 which may be any of the particles 16A, 16B, 18A, 18B, 44A or 44B described herein. Such a particle 65 may comprise several data blocks 661, ... , 66nwith n being any number larger than 1 so that the illustrated example three blocks shall not limit the embodiments described herein. For example, a size of blocks 66j may be determined by a memory such as a buffer or any other selector value. According to an embodiment, a data processor of the data security device implementing this concept may determine a plurality of sections within each of the blocks, wherein the number of sections may be same or different when comparing different blocks 66j. By way of example, a number of four sections 68i,j with i representing the block number and j representing an index within the block is shown. It is noted that advantageously, a significant number greater than four is used for the number of sections, e.g., 6, 8, 12, 16, or even larger. The data security device may change a sequence or order of sections 68 within a block and preferably avoids a change of sequences between blocks. That is, according to an optional embodiment, the data processor is adapted for rearranging the sections within blocks of the respective particle or a derivative thereof to implement an intra-block rearrangement whilst avoiding an inter-block rearrangement.Rearranging the sections 68 within blocks 66 may be implemented according to a rearrangement rule. The data security device may be configured for locally storing information identifying the rearrangement rule for a later reconstruction of the first order shown for particle 65 when retrieving the memory data.As shown in Fig. 10, a modified particle 65’ may comprise the sections in a changed order whilst possibly but not necessarily maintaining an order of the blocks. By use of this embodiment, the information being stored in the memory entities is further made useless for an attacker as even if becoming aware of the data, it is unknown how the bits are ordered.According to an advantageous modification, the data processor may be adapted for applying a different rearrangement rule for at least two, for more than two, even for all of the particles, especially for the first to fourth particle. A respective information may be stored locally at the device allowing for a reconstruction. In an advantageous modification of the embodiment described, the rearrangement rule is a random based rule making it even harder to attack the particles.According to a further modification that may be implemented in addition or as an alternative whilst nevertheless remaining an optional modification, a data processor of a data security device described herein may be configured for removing at least one fragment from at least one of the particles or a derivative thereof to obtain a fragmented particle. The memory data described herein may be generated based on the fragmented particle and information identifying their removed part may be stored, advantageously locally, for a later reconstruction.A fragment may be a continuous or distributed subset of bits of the particle. A portion removed as the fragment may be selected according to different criteria, e.g., a data memory at the device storing the fragments, a consumption of computational power and the like. For example, a share or portion of the fragment with respect to the fragmented data may be within an interval of at least 0.1 % and at most 15 %, of at least 0.5 % and at most 12 % or at least 1 % and at most 10 % such as 128 bits out of 4096 bits which is a nonlimiting example only for the amount of extracted data and the size of a data block that may be used.In a data decryption device, the at least one fragment, i.e., the removed part may be retrieved for reconstruction and may be inserted into the fragmented data to obtain a defragmented data or particle. The fragmented data may be obtained, e.g., by the respective combiner combining or inverse splitting the received memory data or derivatives.None, one or a subset or even all of the modifications described herein may be implemented at a data security device according to an embodiment. Thus, the modifications, especially the rearrangement of sections and removing at least one fragment of a particle may change the content of particles or a part thereof. This may cause another modification not to operate on the particle itself but on a derivative thereof, e.g., reordering sections of a fragmented particle or vice versa. The memory data derived from the particle may, thus, be the particle or be subject of one or more of the modifications described herein.Whilst having described devices 10 and 60 as separate devices, according to an embodiment, a data security device described herein may be adapted in accordance with the data decryption device described herein. Thus, a data security device may comprise an input interface for receiving, from the different memory entities, the first through fourth memory data. The data security device may comprise a combiner for generating the encrypted bit sequence based on combining the first and second memory data and for generating the encryption bit sequence based on the third and fourth memory data. A Decrypter of the data security device may be configured for decrypting the encrypted bit sequence using the encryption bit sequence to obtain the bit sequence, a decrypted bit sequence respectively.Accordingly, a data decryption device described herein such as data decryption device 60 may comprise an Encrypter, a data Splitter and a key Splitter as well as the interface 26 described in connection with Fig. 1.Alternatively or in addition, the data decryption device 60 may be configured for receiving the first to fourth memory data being generated from a data security device described herein.Alternatively or in addition, when using the secret-related authentication information, a data decryption device may be configured for retrieving such secret-related authentication information from a local memory or from a different memory entity that stores at least a partof the encrypted secret. The data decryption device may be configured for verifying a data integrity of the decrypted bit sequence using the secret-related authentication information.With reference to the combinatorial explosion, a data processor of a data decryption device may retrieve the information identifying the rearrangement rule. The data decryption device may restore the original order by rearranging sections determined from at least one of the first to fourth memory data according to the rearrangement rule to obtain a respective rearranged order of sections. The data decryption device may be configured for obtaining the encrypted bit sequence and / or the encryption bit sequence based on the rearranged order of sections. That is, the rearrangement rule may be stored at the decrypting device. According to an advantageous embodiment the encrypting device stores such information locally for a later decoding at the same device. In case of transmission of the information identifying the rearrangement rule it is of advantage to ensure that this information is routed differently when compared to the memory data.With regard to the use of parity, the data decryption device may, e.g., in case of a data failure or transmission failure, use the redundancy information for restoring a sub-sequence of the encrypted bit sequence associated with the first or second memory data and / or for restoring a sub-sequence of the encryption bit sequence associated with the third or fourth memory data. The redundancy information may be received with the input or stored locally. As the redundancy information itself does not reveal the secret, it is possible to store the information at a different, possibly cost effective Cloud provider.In other words, embodiments relate to a method and a system for data integrity control.The PCS Gateway software also comprises a module for a continuous application of data integrity controls (“PCS Integrity”). The controls are two-fold:First the data integrity of the particles received back from the Cloud storage providers is controlled to ensure that there has been no data manipulation during storage and / or transport.Subsequently, the data integrity of the original secret is controlled before and after processing by the PCS gateway software to ensure that the reassembled data fully matches the original secret.For integrity control of the particles before and after data transport and storage:The cryptographic method / system of calculating a message authentication code (MAC) is applied in one of its commonly used forms like CMAC, HMAC or others. The MAC values are calculated from a digest of each particle along with one or more private keys, which are stored in a locally used key-store and which are used for all particles of a given secret. The MAC values of the particles are stored cross-Cloud: a particle's MAC is not stored along with the particle at the particle's Cloud location but with another particle in another Cloud.For integrity control of the particles, when reassembling the particles: (a) the new MAC of each particle is calculated based on the particles digest and the private key(s), (b) the old MAC values, which have been calculated when uploading the particles and which have been stored cross-Cloud are downloaded, (c) the MAC values are compared: if the newly and the previously calculated MACs are identical it is proven that the respective particle has not been modified while being stored or transferred and its integrity is therefore granted. This proof needs to be met for all particles of a given secret. It assures that all the data has not been modified while being stored or transmitted.For integrity control of the original secret before and after PCS Gateway processing:A similar approach is used to prove the correctness of the PCS algorithm itself. While disassembling a secret the MAC of the secret itself is calculated, also based on a secret’s digest and one or more private keys.This MAC value may then be encrypted with random-noise using the Encrypter module. Then, the cypher of the MAC is stored with particles in one Cloud storage while the random noise used for encrypting the MAC is stored with other particles in another Cloud storage used for a given secret.When combining solutions described above, one may arrive at a number of memory data exceeding the number of 4, e.g., at least 5, at least 6, at least 7 or more such as 8 or more. According to an embodiment, at least two portions of memory data derived from the secret, at least two from the encryption bit sequence, a parity information derived from the encrypted bit sequence or from other data and a parity information derived from the encryption bit sequence may be obtained such as derived from and, in addition memory data derived from the particle authentication information may be obtained and the encrypted MAC.For integrity control of the original secret (a) the new MAC of the secret is calculated after reassembling the particles based on the secret's digest and the private key(s), (b) the old MAC value of the secret, which has been calculated before uploading the particles and which has been stored as developed above, is downloaded and reassembled and (c) the MAC values are compared: if the newly calculated MAC of the secret and the previously calculated and stored MAC are identical, it is proven that the PCS algorithm worked properly and reconstructed the original secret perfectly identically.In case of application of the PCS Stealth module as described for a method and system for data confidentiality during transport to storage, the integrity control of the original secret before and after PCS Gateway processing differs as follows:The MAC value of the secret is stored directly on-premise in the PCS Gateway without the need of being encrypted and splitted, respectively being decrypted and reassembled.The old and the new MAC can be compared directly.According to an embodiment, a method / system for data confidentiality during transport to storage is provided.When secrets are stored, the probability of being hacked is higher by magnitude in contrast to secrets that are transferred. While secrets are often stored for years, they are typically transferred only in a fraction of a second. And while many entities have the possibility to attack stored secrets, only few large scale entities like carriers, network infrastructure providers or state agencies do have the chance to get their hands on the rushing data.When secrets are stored, they are safe by design with PCS, due to the encryption with random noise data, the splitting of data and the fact that each storage provider has access only to a subset of the data.When secrets are transferred, all particles of the secrets typically pass the same network infrastructure. Operators of this infrastructure may circumvent current methods of security for data transfer and gain access to the secrets, e.g. using advanced Deep Packet Inspection (DPI). Against this threat PCS already achieves a higher level of security due to encryption and splitting of information into multiple particles which would have to be identified and reassembled first.But even full security by design can be achieved also for the transport of secrets:The two principles of secret sharing and encryption with random noise used by PCS for storing particles can also be implemented to render secret confidentiality breaches during transport practically impossible by adding another principle, the mathematics of combinatorial explosion resulting from permutation of objects.This technique for secure secret transfer is called “PCS Stealth”.With PCS Stealth small fractions of the particles are punched out, removed from the particle streams, leaving incomplete particles. Punched-out fractions are chosen e.g., randomly and are stored on-premise in the PCS Gateway, together with the location of where exactly the fractions have been removed from the stream of data. Punching out fractions of the secrets and the random noise and storing them on-premise is the secret-sharing part of the invention’s secret data transport feature.In data processing incomplete data may generally be completed by guessing algorithms using methods of interpolation of surrounding data values. With PCS this is practically impossible because (a) particles bear no structure and look like random noise and b) it is not known where exactly data is missing with the particles not revealing any criteria on how to find it out.Algorithms may try to reassemble the particles and test the result for the probability of whether the original secret or parts of it are contained. To prevent this, PCS utilizes another mathematical principle, the principle of combinatorial explosion due to permutation of objects.With Stealth, PCS processes data in small blocks. Each block is organized in adjacent sections. When flushing a block to the Cloud storages, PCS Stealth automatically rearranges the sequence of sections. The information on how sections are rearranged is stored on-premise in the PCS Gateway. This permutation P of sections is computationally extremely lightweight but leads to a combinatorial explosion when attackers want to crack the right order of the sections:P(n) = nl, n e Z with n > 1If, by providing a non-limiting example, a block of 4096 bytes is organized in n = 16 sections, with a length of 128 bytes each, there are 16! (16 factorial) possible arrangements of these sections. Because random noise particles and cypher particles both undergo permutationof data sections the total combinatorial explosion leads to 16! * 16! = 4,37763136697395e26 permutations in the given example, for just one single block.Punching out fragments before section permutation scatters the missing fractions over the data stream. Without knowledge where and how much data is missing in unstructured binary objects, attempts of data interpolation are impossible. Consequently, PCS Stealth also renders data transport safe by design.PCS Stealth imposes some preconditions which need to be met: meta-data, describing further aspects of an object, are often stored along with the object when using Cloud storage. Meta-data may be for example the name of an object, type of the object, a unique handle to the object, digests, creator of the object and so forth. As such meta-data may significantly reduce the combinatorial complexity, meta-data needs to be stored on-premise in the PCS Gateway and not with the particles in the Clouds.Furthermore, particles are identified by random IDs, different for each particle belonging to an object. These IDs are also stored on-premise in the PCS Gateway.Finally, to assure enough permutational complexity for small objects, particles may be padded with random data, differently for each particle. Information about padding also needs to be stored on-premise in the PCS Gateway.Embodiments relate to a method and system for a PCS with massive parallel computation using dedicated hardware solutionsPCS may be designed for massive data throughput and even for massive parallel computation:- PCS works with data streams: as soon as the first data arrives PCS starts computations and does not need to wait until the complete data has arrived to start working.- While processing current data, prior processed data is sent out to the data storages in parallel.- Additionally, data streams can be split into small data sequences. Several small data sequences can be processed in parallel, which makes PCS even faster.The processing itself is very fast because of the XOR methodology.Parallelisation of calculations also applies to MAC as well as the generation of noise.PCS in its core may use XOR for (a) encrypting a secret with random noise and (b) to calculate parity bits used for fault tolerance. Secrets and random noise can be provided as vectors of data and can be rapidly computed on massive parallel computational units like Graphics Processing Units (GPU).PCS processes streams of data. It does not need to know the length of the streams prior to processing, nor any other further information besides of where to stream the particles to. Furthermore, it only requires minimal working memory.Albeit embodiments relate to processing a high amount of data such as several KB, several MB or even GB or more, the invention may be used with any data size, grouped to blocks or not, as it only needs at least two data values, an even-indexed value with its follow-up odd-indexed value of the stream of secrets to process a single output value for each particle stream. This value, e.g., as one of several values, can immediately be committed in parallel to (a) the calculation of the Message Authentication Code and (b) to the network infrastructure for sending the data to the Cloud storages.MACs are designed to work with streams of data, also allowing for online computation as data arrives, rather than requiring the entire data to be available at once. The MAC values are immediately available when processing of the stream of data is done. It preferably is processed in parallel to data transmission to speed up overall computation time.Fig. 11 shows a schematic flow chart of a method 1100 according to an embodiment described herein that may be used for encrypting and / or storing data. A step 1110 comprises encrypting a bit sequence using an encryption bit sequence to obtain an encrypted bit sequence. A step 1120 comprises splitting the encrypted bit sequence into at least a first encrypted bit sub-sequence as a first particle and a second encrypted bit subsequence as a second particle. A step 1130 comprises splitting the encryption bit sequence into at least a first encryption sub-key as a third particle and a second encryption sub-key as a fourth particle.Method 1100 comprises at least step 1140a and for further increased security also step 1140b. Step 1140a comprises storing first memory data being the first particle ora derivative thereof and second memory data being the second particle or a derivative thereof in different memory entities and storing third memory data being the third particle or a derivative thereof and fourth memory data being the fourth particle or a derivative thereof in different memory entities. Step 1140b comprises routing the first memory and second memory data on different routes for data storage and routing the third memory data and fourth memory data on different routes for data storage.Fig. 12 shows a schematic flowchart of a method 1200 according to an embodiment that may be used for decrypting data. A step 1210 comprising obtaining, from different memory entities, first memory data and second memory data associated with an encrypted sequence. Step 1120 comprises obtaining, from different memory devices third memory data and fourth memory data associated with an encryption bit sequence.A step 1230 comprises generating the encrypted bit sequence based on the first and second memory data; and generating the encryption bit sequence based on the third and fourth bit sequence. Step 1240 comprises decrypting the encrypted bit sequence using the encryption bit sequence to obtain a decrypted bit sequence. Step 1250 comprises providing the decoded bit sequence.Embodiments provide for methods and systems that differ from plain OTP encryption which also uses logical operation XOR:OTP can be used to encrypt a secret of a sender in order to transfer the secret to a receiver in an insecure environment where attempts to reveal the secret may occur.OTP encryption makes sure that only the intended receiver could reconstruct the secret. To be able to do so the receiver needs both at the same time, the cypher and a one-by-one copy of the OTP.Therefore, the OTP key is required to be shared prior to sending the encrypted secret. And it needs to be shared in a fully secure way opening similar threats as for the protected secret.The invention similarly uses XOR of secrets and random noise. But the goal is the opposite: the receiver shall not be able to reconstruct the secret by any means. According to an aspect of the invention, the receiver may only apply some operations on the data like storing the data.In classical OTP encryption the sender and the receiver both have - after pre-sharing the OTP, encryption, transfer of the cypher and decryption - the same secret, transferred through a potentially insecure channel. In the context of this invention the sender does not need to have the secret any more. But the sender is able to reconstruct the secret any time. The secret is securely saved as cypher and OTP in the Cloud. Cypher and OTP are stored by different and competing Cloud storage providers which preferably operate under different jurisdictions and potentially use different technology. T o make this even more robust, cypher and OTP are split in parts (particles) and distributed on various Cloud storage providers.The OTP key has (due to the encryption method) to comprise at least the same number of information units such as characters, bits or bytes as the secret and will therefore reach the same data volume. In classical OTP encryption this makes safe pre-sharing the key through an extra channel even more challenging.Furthermore, OTP was invented to encrypt and decrypt data of fixed size, while the innovation uses the concept on potentially infinite streams of data. This may be obtained by operating a source of randomness and for continuously collecting random information until a data stream has ended. As the random noise is transferred as streams of data to various Cloud storage providers and the encrypted secret is transferred also as streams of data, the data volume no longer poses a problem.Why demultiplexer and the multiplexer preferably use a chunk size of 1 Byte:Each data element of the stream of data - as well as each element of the streams of cyphers and randoms, due to the nature of the algorithm - has the length of x bits. At least some embodiments may preferably use a length of x=8 bits which is a built-in size of bits in computer systems and programming languages used to build computer software. The length of the stream of secrets is therefore typically a whole-number multiple of 8 bits, thus bytes.More general, the length of the stream of secrets may also be a whole-number multiple of m*8 bits, thus m*bytes, where m is an integer >0. In computer science it is not uncommon to use m = 2n, where n is an integer >0 (resulting in values like this: 2, 4, 8, 16, 32, ...).In different applications and use cases embodiments may operate with differently sized data elements. As the used logical function XOR operates on the single bits of the data elements independently, the description of the embodiments holds true for all possible sizes for the data elements as long as during decryption corresponding pairs of bits are available.Demultiplexing and therefore also multiplexing, may use blocks of sequencing data elements. According to embodiments, for splitting the key sequence and the encoded bit sequence a same splitting rule is applied so that when combining or demultiplexing the data again, corresponding data elements are available. The first block is forwarded to the even stream of cyphers, the following block subsequently to the odd stream of cyphers. Also, the length of the blocks may be different, i.e., blocks of the even stream and blocks of the odd stream of cyphers may comprise a different length. As described, the sizes of the blocks may vary based on the length of the stream of data or other criteria. But handling streams of data as a stream of bytes and using a block size of 1 (single Byte) is most efficient, because: a) no counter is needed to check if the current block is filled or not and no extra information has to be processed and to be stored to find out how long the current block should be. The only requirement is whether the most recently processed byte has been an even or odd byte in the data stream; b) It is the natural data format of computer hard- and software.However, it is advantageous to have blocks of the same size for a respective DEMUX operation to combine particles received from different memory entities and related to same data. That is, blocks of different sizes are possible within a stream and it is preferred or even necessary to have blocks of corresponding sizes in different streams.Some advantageous modifications may result in boundary conditions for other modifications. For example, when using the redundancy information as described, it is of advantage to use blocks of a same length of blocks for a specific stream, whereas the sizes may vary for different streams. When not implementing the use of parities, the size of the blocks may also vary within a stream.Embodiments can process data flows / streams as well as data containers or blocks.Multiplexer, Demultiplexer:In electrical engineering, the sharing of electronic signals would be done with a demultiplexer. Such a concept is transferred to the present embodiment, whereby multiplexers and demultiplexers are also referred to for the formal description of the process.Different embodiments of the inventionEmbodiments of the invention can not only be used for storage. In principle, one could use it to build a virtual private network (VPN) without an actual VPN, e.g., as some countries have banned VPNs. Embodiments may ensure that the particles come from the transmitter to the receiver via different routes (i.e. computers, networks, etc.) to still provide for safety. That is, the different parts of information may be routed differently from a source device, e.g. comprising the Encrypter and / or sending the particles to a sink device that decodes information. This may also be implemented by using different data transfer protocols.Embodiments may be used as an add-on for known data systems and / or may be implemented as stand-alone solutions.Further embodiments using state of the art computation and cryptographic facilities may be added, based on further requirements and given restrictions.Although some aspects have been described in the context of an apparatus, it is clear that these aspects also represent a description of the corresponding method, where a block or device corresponds to a method step or a feature of a method step. Analogously, aspects described in the context of a method step also represent a description of a corresponding block or item or feature of a corresponding apparatus.Depending on certain implementation requirements, embodiments of the invention can be implemented in hardware or in software. The implementation can be performed using a digital storage medium, for example a floppy disk, a DVD, a CD, a ROM, a PROM, an EPROM, an EEPROM or a FLASH memory, having electronically readable control signals stored thereon, which cooperate (or are capable of cooperating) with a programmable computer system such that the respective method is performed.Some embodiments according to the invention comprise a data carrier having electronically readable control signals, which are capable of cooperating with a programmable computer system, such that one of the methods described herein is performed.Generally, embodiments of the present invention can be implemented as a computer program product with a program code, the program code being operative for performing one of the methods when the computer program product runs on a computer. The program code may for example be stored on a machine readable carrier.Other embodiments comprise the computer program for performing one of the methods described herein, stored on a machine readable carrier.In other words, an embodiment of the inventive method is, therefore, a computer program having a program code for performing one of the methods described herein, when the computer program runs on a computer.A further embodiment of the inventive methods is, therefore, a data carrier (or a digital storage medium, or a computer-readable medium) comprising, recorded thereon, the computer program for performing one of the methods described herein.A further embodiment of the inventive method is, therefore, a data stream or a sequence of signals representing the computer program for performing one of the methods described herein. The data stream or the sequence of signals may for example be configured to be transferred via a data communication connection, for example via the Internet.A further embodiment comprises a processing means, for example a computer, or a programmable logic device, configured to or adapted to perform one of the methods described herein.A further embodiment comprises a computer having installed thereon the computer program for performing one of the methods described herein.In some embodiments, a programmable logic device (for example a field programmable gate array) may be used to perform some or all of the functionalities of the methods described herein. In some embodiments, a field programmable gate array may cooperatewith a microprocessor in order to perform one of the methods described herein. Generally, the methods are preferably performed by any hardware apparatus.The above described embodiments are merely illustrative for the principles of the present invention. It is understood that modifications and variations of the arrangements and the details described herein will be apparent to others skilled in the art. It is the intent, therefore, to be limited only by the scope of the impending patent claims and not by the specific details presented by way of description and explanation of the embodiments herein.
Claims
Claims1 . A data security device comprising: an Encrypter (14; 20) for encrypting a bit sequence (12) using an encryption bit sequence (16) to obtain an encrypted bit sequence (18); a data splitter (22; 42) for splitting the encrypted bit sequence (18) into at least a first encrypted bit sub-sequence (18A) as a first particle and a second encrypted bit subsequence (18B) as a second particle; a key splitter (24; 42) for splitting the encryption bit sequence (16) into at least a first encryption sub-key (16A) as a third particle and a second encryption sub-key (16B) as a fourth particle, an interface (26) for a) storing first memory data (18A’) being the first particle or a derivative thereof and second memory data (18B’) being the second particle or a derivative thereof in different memory entities; and for storing third memory data (16A’) being the third particle or a derivative thereof and fourth memory data (16B’) being the fourth particle or a derivative thereof in different memory entities; and / or b) routing the first memory data (18A’) and second memory data (18B’) on different routes for data storage and routing the third memory data (16A’) and fourth memory data (16B’) on different routes for data storage.
2. The data security device according to claim 1 , configured for storing the first memory data (18A’) and the second memory data (18B’) in memory entities being arranged in different control domains and / or jurisdictions; and configured for storing the third memory data (16A’) and the fourth memory data (16B’) in memory entities being arranged in different control domains and / or jurisdictions.
3. The data security device according to claim 1 or 2, wherein the key splitter (24; 42) is configured for generating the third particle for decryption of the first particle and for generating the fourth particle for decryption of the second particle; wherein the data security device is adapted for storing the first memory data (18A’)and the third memory data (16A’) in different memory entities; or to route the first memory data (18A’) differently from the third memory data (16A’); and wherein the data security device is adapted for storing the second memory data (18B’) and the fourth memory data (16B’) in different memory entities; or to route the first memory data (18A’) separated from the third memory data (16A’).
4. The data security device of claim 3, configured for storing the first memory data (18A’) and the fourth memory data (16B’) in a same memory entity (34A); and / or for storing the second memory data (18B’) and the third memory data (16A’) in a same memory entity (34B).
5. The data security device of one of the previous claims, comprising a data processor configured for determining, for at least one or all of the first to fourth particles, and from one of the first to fourth memory data a particle authentication information that is associated with the memory data obtained from the particle; wherein the data security device is adapted for storing the particle authentication information in a different memory entity as the associated memory data.
6. The data security device of one of the previous claims, comprising a data processor configured for determining a secret-related authentication information from the bit sequence (12); wherein the data security device is adapted for storing the secret-related authentication information locally or in a different memory entity as the associated memory data for a verification of a decrypted bit sequence (12’).
7. The data security device of one of the previous claims, comprising a data processor configured for: determining sections (68) within at least one of the first to fourth particle or a derivative thereof and for rearranging the sections (68) from a first order to a modified order based on a rearrangement rule; and generating the memory data based on the modified order; andlocally storing information identifying the rearrangement rule for a later reconstruction of the first order when retrieving the memory data.
8. The data security device of claim 7, wherein the data processor is adapted for applying a different rearrangement rule for at least two or for each of the first to fourth particle.
9. The data security device of claim 7 or 8, wherein the rearrangement rule is a random based rule.
10. The data security device of one of claims 7 to 9, wherein the data processor is adapted for rearranging the sections (68) within blocks (66) of the respective particle (65) or the derivative to implement an intra-block rearrangement whilst avoiding an interblock rearrangement.11 . The data security device of one of the previous claims, comprising a data processor configured for: removing at least one fragment as a portion of data from at least one of the first to fourth of particle or a derivative thereof to obtain a fragmented particle; generating the memory data based on the fragmented particle; and storing information identifying the removed part for a later reconstruction.
12. The data security device of one of the previous claims, comprising a data processor configured for generating a first redundancy information from the encrypted bit sequence (18) and for providing the first redundancy information as a fifth particle (44A) for a later decoding of the encrypted bit sequence (18), e.g., to a memory entity; and / or for generating a second redundancy information from the encryption bit sequence (16) and for providing the second redundancy information as a sixth particle (44B) for a later decoding of the encryption key sequence, e.g., to a memory entity.
13. The data security device of one of the previous claims, configured for at least one of the first memory data (18A’), the second memory data (18B’), the third memory data (16A’) and the fourth memory data (16B’) to be stored in a Cloud storage as the memory entity.
14. The data security device of one of previous claims, wherein the data splitter (22; 42) is configured for assigning a first predefined bit of the encrypted bit sequence (18) to the first encrypted bit sub-sequence (18A) based on a position of the bit in the encrypted bit sequence (18); and for assigning a second predefined bit of the encrypted bit sequence (18) to the second encrypted bit sub-sequence (18B) based on a different position of the bit in the encrypted bit sequence (18).
15. The data security device of claim 14, wherein the data splitter (22; 42) is configured for assigning bits of the encrypted bit sequence (18) having an eveneven bit number to either the first encrypted bit sub-sequence (18A) or the second encrypted bit subsequence (18B); and for assigning bits of the encrypted bit sequence (18) having an odd bit number to the other encrypted bit sub-sequence.
16. The data security device of one of the previous claims, wherein the key splitter (24; 42) is configured for splitting the encryption bit sequence (16) according to a splitting rule implemented by the data splitter (22; 42) for splitting the encrypted bit sequence (18); wherein the first encryption sub-key comprises bits of the encryption bit sequence (16) corresponding to bits of the first encrypted bit sub-sequence (18A); and wherein the second encryption sub-key (16B) comprises bits of the encryption bit sequence (16) corresponding to the bits of the second encrypted bit sub-sequence (18B).
17. The data security device of one of the previous claims, wherein the data splitter (22; 42) is configured for hierarchically or iteratively splitting the first and / or second encrypted bit sub-sequence (18B) into at least two encrypted bit sub-sequences in at least one iteration; and / or wherein the key splitter (24; 42) is configured for hierarchically or iteratively splitting the first and / or second key sequence into at least two key sub-sequences in at least one iteration.
18. The data security device of one of the previous claims, configured for generating a random-based noise sequence as the encryption bit sequence (16).
19. The data security device of claim 18, configured for generating the random-based noise sequence having a length being at least a length of the bit sequence (12).
20. The data security device of one of the previous claims, wherein the bit sequence (12) is a stream of bits and / or wherein the encryption bit sequence (16) is a stream of bits.
21. The data security device of one of the previous claims, an input interface (54) for receiving, from the different memory entities, the first memory data (18A’) and the second memory data (18B’); and for receiving, from the different memory devices third memory data (16A’) and fourth memory data (16B’); the data security device comprising a combiner for generating the encrypted bit sequence (18) based on combining the first and second memory data (18A’ and 18B’); and for generating the encryption bit sequence (16) based on the third and fourth memory data (16A’ and 16B’); the data security device comprising a Decrypter configured for decrypting the encrypted bit sequence (18) using the encryption bit sequence (16) to obtain the bit sequence.
22. A data decryption device comprising: an input interface (54) for receiving, from different memory entities, first memory data (18A’) and second memory data (18B’) associated with an encrypted sequence; and for receiving, from different memory devices third memory data (16A’) and fourth memory data (16B’) associated with an encryption bit sequence (16); a combiner (56) for generating the encrypted bit sequence (18) based on the first and second memory data (18A’ and 18B’); and for generating the encryption bit sequence (16) based on the third and fourth memory data (16A’ and 16B’); a Decrypter (58) configured for decrypting the encrypted bit sequence (18) using the encryption bit sequence (16) to obtain a decrypted bit sequence (12’);an output (62) for providing the decrypted bit sequence (12’).
23. The data decryption device of claim 22, configured for retrieving at least one of a first to fourth particle authentication information from a data memory different from the data memory storing the corresponding memory data and for verifying data integrity of at least one of: a first encrypted bit sub-sequence (18A) generated from the first memory data (18A’) using a first particle authentication information; a second encrypted bit sub-sequence (18B) generated from the second memory data (18B’) using a second particle authentication information; a first encryption key sub-sequence generated from the third memory data (16A’) using a third particle authentication information; and a second encryption key sub-sequence generated from the fourth memory data (16B’) using a fourth particle authentication information.
24. The data decryption device of claim 22 or 23, configured for retrieving a secret-related authentication information from a local memory or from a different memory entity and for verifying data integrity of the decrypted bit sequence using the secret-related authentication information.
25. The data decryption device of one of claims 22 to 24, comprising a data processor configured for: retrieving information identifying a rearrangement rule; and for rearranging sections determined from at least one of the first to fourth memory data (18A’, 18B’, 16A’, 16B’) according to the rearrangement rule to obtain a respective rearranged order of sections; wherein the data decryption device is configured for obtaining the encrypted bit sequence (18) and / or the encryption bitsequence (16) based on the rearranged order of sections.
26. The data decryption device of one of claims 22 to 25, wherein in case of a data failure or transmission failure, the data decryption device is configured for using redundancy information for restoring a sub-sequence of the encrypted bit sequence (18) associated with the first or second memory data (18A’ or 18B’); and / or for restoring a sub-sequence of the encryption bit sequence (16) associated with the third or fourth memory data (16A’ or 16B’); wherein the redundancy information is received with the input.
27. The data decryption device of one of claims 22 to 26, comprising a data processor configured for: retrieving information identifying a removed part of a fragmented data for a reconstruction; and inserting, into the fragmented data obtained by the combiner, the removed part to obtain a defragmented particle.
28. The data decryption device of one of claims 22 to 27, further comprising an Encrypter (14; 20) for encrypting a bit sequence (12) using an encryption bit sequence (16) to obtain the encrypted bit sequence (18); a data splitter (22; 42) for splitting the encrypted bit sequence (18) into at least a first encrypted bit sub-sequence (18A) as a first particle and a second encrypted bit subsequence (18B) as a second particle; a key splitter (24; 42) for splitting the encryption bit sequence (16) into at least first encryption sub-key (16A) as a third particle and a second encryption sub-key (16B) as a fourth particle, an interface (26) for a) storing the first memory data (18A’) being the first particle or a derivative thereof and the second memory data (18B’) being the second particle or a derivative thereof in different memory entities; and for storing the third memory data (16A’) being the third particle or a derivative thereof and thefourth memory data (16B’) being the fourth particle or a derivative thereof in different memory entities; and / or b) routing the first memory data (18A’) and second memory data (18B’) on different routes for data storage and routing the third memory data (16A’) and fourth memory data (16B’) on different routes for data storage.
29. The data decryption device of one of claims 22 to 28, configured for receiving the first to fourth memory data (16B’) being generated from a device according to one of claims 1 to 21.
30. A method (1100) for securing data, the method comprising: encrypting (1110) a bit sequence using an encryption bit sequence to obtain an encrypted bit sequence; splitting (1120) the encrypted bit sequence into at least a first encrypted bit subsequence as a first particle and a second encrypted bit sub-sequence as a second particle; splitting (1130) the encryption bit sequence into at least a first encryption sub-key as a third particle and a second encryption sub-key as a fourth particle, storing (1140a) first memory data being the first particle or a derivative thereof and second memory data being the second particle or a derivative thereof in different memory entities; and storing third memory data being the third particle or a derivative thereof and fourth memory data being the fourth particle or a derivative thereof in different memory entities; and / or routing (1140b) the first memory data and second memory data on different routes for data storage and routing the third memory data and fourth memory data on different routes for data storage.31 . A method (1200) for decoding data, the method comprising: obtaining (1210), from different memory entities, first memory data and second memory data associated with an encrypted sequence; andobtaining (1220), from different memory devices, third memory data and fourth memory data associated with an encryption bit sequence; generating (1230) the encrypted bit sequence based on the first and second memory data; and generating the encryption bit sequence based on the third and fourth memory data; decrypting (1240) the encrypted bit sequence using the encryption bit sequence to obtain a decrypted bit sequence; and providing (1250) the decoded bit sequence.
32. A computer readable digital storage medium having stored thereon a computer program having a program code for performing, when running on a computer, a method according to claim 30 or 31.
Citation Information
Patent Citations
Method and apparatus for realizing information sharing in blockchain
CN108768633A
Non-autonomous dynamical orbit cryptography
US20040228480A1
Securing a data segment for storage
US20120311346A1
Cyphertext management method, cyphertext management apparatus, and program
US20190027067A1
Systems and methods of using cryptographic primitives for error location, correction, and device recovery
US20190229925A1