Auditable Cryptographic Cloud Communication System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems fail to provide auditable, cryptographic protection for cloud computing communication systems that operate across multiple networks simultaneously, including uncontrolled networks, while allowing continuous monitoring and configuration of industrial devices without shutting them down or the enterprise server.
Innovation Solution
An auditable cryptographic protected cloud computing communication system that uses physical and virtual cryptographic modules to enable in-band and out-of-band communication, generating cryptographic keys for digital signatures and communication sessions, allowing online encryption and decryption without human intervention, and providing secure messaging across various networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic protection is implemented for cloud computing communication, then security is improved, but system complexity increases
Solution Approach 1:
The patent introduces cryptographic modules as intermediary components that handle all cryptographic operations. These modules act as mediators between the enterprise server and industrial devices, encapsulating complex cryptographic functions (key generation, encryption, decryption, authentication) within standardized interfaces. This allows the main system to benefit from cryptographic protection without directly managing the complexity of cryptographic protocols and operations.
Solution Approach 2:
The cryptographic system is segmented into distinct functional modules: key generation modules, encryption modules, decryption modules, and authentication modules. Each module performs a specific cryptographic function and can be independently configured, managed, and updated. This segmentation allows the system to implement comprehensive cryptographic protection while maintaining manageable complexity through modular architecture.
2Productivity
If continuous monitoring and configuration of industrial devices is performed, then operational availability is improved, but security risks increase
Solution Approach 1:
The patent implements cryptographic protection that operates continuously without interrupting monitoring or configuration activities. Cryptographic keys are generated and updated continuously, encryption/decryption operations occur in real-time for all communications, and authentication is performed continuously for each interaction. This ensures that security protection is always active while allowing uninterrupted industrial device operations and configuration activities.
Solution Approach 2:
Cryptographic keys and security parameters are generated and configured in advance before monitoring or configuration activities begin. Authentication credentials are pre-established between the enterprise server and industrial devices, allowing secure communications to commence immediately without compromising security. This preliminary setup enables continuous operations while maintaining robust security from the outset.
3Productivity
If cryptographic operations are performed online without human intervention, then operational efficiency is improved, but key management complexity increases
Solution Approach 1:
The cryptographic modules are designed to perform self-service operations including automatic key generation, automatic key rotation, and automatic certificate management without human intervention. The system autonomously handles the complete cryptographic lifecycle: generating keys when needed, storing them securely, using them for encryption/decryption, rotating them periodically, and revoking them when obsolete. This automation improves operational efficiency while the modular architecture keeps key management complexity contained within the cryptographic modules rather than propagating throughout the entire system.
Data Source
AI summary
An auditable cryptographic protected cloud computing communication system, wherein the system can include a plurality of industrial devices. Each industrial device can have an individualized messaging protocol enabling each industrial device to receive commands and transmit status and measurement data using the individualized messaging protocol for each industrial device.


