Carrier-Grade Data Encryption Service with Distributed Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication and information exchange paradigms face significant security challenges, as evident from recent data breaches where sensitive information has been compromised, highlighting the need for robust data protection solutions.
Innovation Solution
A carrier-grade data encryption, transport, and storage service is provided, utilizing a network that includes a policy engine, encryption key management system, secure transport function, and encryption engine, allowing users to manage and control encryption keys and encrypt data using industry-standard algorithms like AES and RSA, ensuring secure data transmission and storage both in transit and at rest.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is transmitted and stored in current communication paradigms, then information exchange efficiency is improved, but data security deteriorates due to breaches and unauthorized access
Solution Approach 1:
The patent segments encryption keys into multiple parts and distributes them across different storage locations. No single location contains the complete key, so even if one storage facility is breached, the entire encryption key cannot be compromised. This allows data to be stored and accessed efficiently while maintaining security through distributed key management.
Solution Approach 2:
The patent introduces a policy engine as an intermediary component that mediates between data storage locations and access requests. The policy engine enforces security policies and coordinates key retrieval, allowing efficient information exchange while maintaining security controls. This intermediary layer prevents direct access to encrypted data, reducing vulnerability to breaches.
2Ease of operation
If encryption keys are stored in a centralized location for easy management, then key management simplicity is improved, but security deteriorates due to single point of failure and targeted attacks
Solution Approach 1:
The patent divides the encryption key into multiple segments and stores them in different locations within the network. This segmentation eliminates the single point of failure problem while maintaining manageable key control through automated policies. The system remains easy to operate because the distribution and retrieval processes are automated through the policy engine.
Solution Approach 2:
The patent implements a nested structure where encrypted data is stored in one location, key segments are stored in other locations, and the policy engine coordinates their assembly. This nested arrangement protects against targeted attacks on any single storage location while maintaining organized key management through the central policy coordination layer.
3Adaptability or versatility
If multiple storage locations are used for data redundancy and accessibility, then data availability is improved, but security control complexity increases
Solution Approach 1:
The patent makes the policy engine a universal security control that manages multiple storage locations through a single interface. This policy engine handles key segmentation, distribution, and retrieval across all locations, providing data availability through redundancy while preventing security control complexity from increasing. The same policy engine serves all storage locations uniformly.
Solution Approach 2:
The patent implements feedback mechanisms where the policy engine continuously monitors and coordinates key segment retrieval from multiple storage locations. This feedback loop ensures that data can be reconstructed from any sufficient combination of storage locations, improving availability while the automated feedback control prevents manual intervention complexity.
Data Source
AI summary
A method, a system, and a non-transitory storage medium for storing user preferences pertaining to a data encryption service that provides on-demand encryption for data in-flight and at rest; receiving data from a user device; determining whether to invoke the data encryption service based on the data and the user preferences; generating a key to encrypt the data based on determining that the data encryption service is to be invoked; generating a first message that includes the data, the key, and data indicating where encrypted data is to be stored; establishing a secure connection with a device; and transmitting the first message to the device via the secure connection.


