Adaptive Encryption Based on User and Data Profiling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing database security systems face inefficiencies in controlling access to files with varying security requirements, leading to resource wastage and vulnerability to unauthorized access, as they often apply generic security measures and fail to detect suspicious user behavior.
Innovation Solution
The implementation of an adaptive authorization token that stores user attributes and usage history, dynamically adjusts encryption levels based on file characteristics and user profiles, and generates self-decryption mechanisms to ensure secure and efficient access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If generic encryption is applied to all files in the data store, then security coverage is improved, but processing efficiency deteriorates due to unnecessary encryption of public information
Solution Approach 1:
The patent applies different encryption levels to different portions of data based on their sensitivity. The system identifies sensitive information (e.g., social security numbers) within files and applies strong encryption only to those specific portions, while leaving public information unencrypted or lightly encrypted. This resolves the contradiction by maintaining security coverage for sensitive data while improving processing efficiency by avoiding unnecessary encryption of public information.
2Reliability
If the same security measures are applied to all users regardless of location or trust level, then security consistency is improved, but resource efficiency deteriorates
Solution Approach 1:
The patent implements dynamic security measures that adapt based on user characteristics, location, and trust level. The system profiles users and adjusts encryption levels and security protocols accordingly - applying stricter measures to users in untrusted geographical regions or with suspicious usage patterns, while using lighter measures for trusted users on internal networks. This resolves the contradiction by maintaining security consistency through adaptive policies rather than uniform application, thereby improving resource efficiency.
3Ease of operation
If access tokens transmit credentials by default, then ease of access is improved, but security vulnerability deteriorates due to interception risk
Solution Approach 1:
The patent establishes security protocols before credential transmission occurs. The system pre-establishes secure communication channels, implements authentication mechanisms, and sets up monitoring protocols before access tokens transmit credentials. This preliminary setup ensures that when credentials are transmitted, they do so through already-secured channels with monitoring in place to detect interception attempts, thereby maintaining ease of access while reducing vulnerability.
4Reliability
If multiple data stores are used for different security requirements, then security differentiation is improved, but system complexity deteriorates
Solution Approach 1:
The patent implements a unified data store that can handle multiple security requirements through a single system. The system provides multi-functionality by incorporating dynamic encryption capabilities, user profiling mechanisms, and adaptive security protocols that can adjust to different security needs within the same data store environment. This eliminates the need for multiple separate data stores while maintaining security differentiation, thereby reducing system complexity.
Data Source
AI summary
A non-transitory computer-readable medium includes an encrypted dataset, a first access control measure, and instructions. The encrypted dataset includes a first encrypted block of data, encrypted using a first encryption algorithm, and a second encrypted block of data, encrypted using a second encryption algorithm stronger than the first. The first access control measure is associated with a first access control characteristic and is configured to selectively prevent access to the encrypted dataset. The instructions are configured, when executed by a processor of a device of a first user, to determine that a first characteristic of the first user matches the first access control characteristic. In response, the instructions are configured to decrypt the encrypted dataset to form a plain text dataset and provide the device of the first user access to the plain text dataset. Decrypting the encrypted dataset includes decrypting the first and second blocks of data.


