ART-CRYPTO Hardware Encryption for Brute Force Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital data security systems in cyberspace rely heavily on software-oriented tools, which are vulnerable to hacking, consume significant CPU resources, and lack effective key management, making them susceptible to brute force attacks and difficult to manage, especially in scenarios involving system administrators and ex-employees.

Innovation Solution

The ART-CRYPTO secure architectural system employs a hardware-based approach with a Fast Key-Changing Apparatus for AES cipher engine, using pseudo-random number generators and isolated random access memory to ensure that digital files are always encrypted, except during processing, with dynamic key management and user authentication through identity and authorization management, preventing unauthorized access and brute force decryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software-oriented encryption tools are used, then ease of operation is improved, but security reliability deteriorates due to vulnerability to hacking and brute force attacks

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces software-oriented encryption tools with a hardware-based encryption apparatus. The encryption function is implemented in dedicated hardware circuitry rather than software, making it resistant to software-based hacking and brute force attacks while maintaining ease of operation through automated hardware enforcement of security policies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary hardware layer between the data storage and processing components. This hardware encryption apparatus acts as a mediator that enforces encryption/decryption operations and access control policies, preventing direct software access to encrypted data and thereby improving security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a single encryption key is used for the whole system, then device complexity is reduced, but security reliability deteriorates due to vulnerability to key compromise

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the single system-wide encryption key into multiple individual file encryption keys, each stored in separate encrypted data files. This segmentation ensures that compromise of one key does not affect the security of other files, thereby improving security reliability while the hardware apparatus manages the complexity of key distribution automatically.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different encryption keys to different data files, creating local quality variation in the encryption scheme. Each file has its own encryption characteristics and key, allowing selective access and preventing total system compromise if one key is breached, thus improving security reliability.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If software cryptography processes are used, then ease of operation is improved, but productivity deteriorates due to high CPU consumption

Engineering Contradiction:
Improveease of operationVSAvoidproductivity
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent replaces software cryptography processes that consume CPU resources with dedicated hardware encryption circuitry. The encryption and decryption operations are performed by specialized hardware components rather than general-purpose CPU instructions, significantly improving processing productivity while maintaining ease of operation through automated hardware enforcement.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10972256B2Architectural secure system for digital file in cyberspace
Publication Date: 2021.04.06 DENG ANTE
  • US10972256B2 patent drawing
  • US10972256B2 patent drawing
  • US10972256B2 patent drawing

AI summary

The ART-CRYPTO secure architectural system, designed for cyber security is always to keep the digital file/data encrypted, except for the processing period. The system's crypto engine is composed of fast key-changing apparatus (FKCA) array, which is an AES (Advanced Encryption Standard) cipher, which uses a key stream to achieve a file encryption/decryption, wherein the key stream prevents side channel attack and there is no key management. The system's identification and authorization management (IAM) distributed sub-system prevents ID fraud, malware, ransomware, spammer, and DDoS attacks. A data base (DB) with a special file structure (SFS) authorizes that a user accessing encrypted files according to user file attributes and its identification verification, prevents lowing the system's Cryptography level or having a back door design, which increases the possibility of breaching. The secure architectural system also solves the dilemma of privacy and security.