ART-CRYPTO Hardware Encryption for Brute Force Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital data security systems in cyberspace rely heavily on software-oriented tools, which are vulnerable to hacking, consume significant CPU resources, and lack effective key management, making them susceptible to brute force attacks and difficult to manage, especially in scenarios involving system administrators and ex-employees.
Innovation Solution
The ART-CRYPTO secure architectural system employs a hardware-based approach with a Fast Key-Changing Apparatus for AES cipher engine, using pseudo-random number generators and isolated random access memory to ensure that digital files are always encrypted, except during processing, with dynamic key management and user authentication through identity and authorization management, preventing unauthorized access and brute force decryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If software-oriented encryption tools are used, then ease of operation is improved, but security reliability deteriorates due to vulnerability to hacking and brute force attacks
Solution Approach 1:
The patent replaces software-oriented encryption tools with a hardware-based encryption apparatus. The encryption function is implemented in dedicated hardware circuitry rather than software, making it resistant to software-based hacking and brute force attacks while maintaining ease of operation through automated hardware enforcement of security policies.
Solution Approach 2:
The patent introduces an intermediary hardware layer between the data storage and processing components. This hardware encryption apparatus acts as a mediator that enforces encryption/decryption operations and access control policies, preventing direct software access to encrypted data and thereby improving security reliability.
2Device complexity
If a single encryption key is used for the whole system, then device complexity is reduced, but security reliability deteriorates due to vulnerability to key compromise
Solution Approach 1:
The patent segments the single system-wide encryption key into multiple individual file encryption keys, each stored in separate encrypted data files. This segmentation ensures that compromise of one key does not affect the security of other files, thereby improving security reliability while the hardware apparatus manages the complexity of key distribution automatically.
Solution Approach 2:
The patent applies different encryption keys to different data files, creating local quality variation in the encryption scheme. Each file has its own encryption characteristics and key, allowing selective access and preventing total system compromise if one key is breached, thus improving security reliability.
3Ease of operation
If software cryptography processes are used, then ease of operation is improved, but productivity deteriorates due to high CPU consumption
Solution Approach 1:
The patent replaces software cryptography processes that consume CPU resources with dedicated hardware encryption circuitry. The encryption and decryption operations are performed by specialized hardware components rather than general-purpose CPU instructions, significantly improving processing productivity while maintaining ease of operation through automated hardware enforcement.
Data Source
AI summary
The ART-CRYPTO secure architectural system, designed for cyber security is always to keep the digital file/data encrypted, except for the processing period. The system's crypto engine is composed of fast key-changing apparatus (FKCA) array, which is an AES (Advanced Encryption Standard) cipher, which uses a key stream to achieve a file encryption/decryption, wherein the key stream prevents side channel attack and there is no key management. The system's identification and authorization management (IAM) distributed sub-system prevents ID fraud, malware, ransomware, spammer, and DDoS attacks. A data base (DB) with a special file structure (SFS) authorizes that a user accessing encrypted files according to user file attributes and its identification verification, prevents lowing the system's Cryptography level or having a back door design, which increases the possibility of breaching. The secure architectural system also solves the dilemma of privacy and security.


