Cryptographic Key Storage via Multi-Dimensional Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic systems lack secure storage and management of cryptographic keys and user authentication data, leading to potential vulnerabilities in user-independent security, portability, and availability.

Innovation Solution

A cryptographic system with a trust engine that stores cryptographic keys and user authentication data, ensuring secure storage by not releasing actual keys and using multi-dimensional data representation with encryption techniques to secure data subsets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys and user authentication data are stored in current cryptographic systems, then security functions can be performed, but the systems lack secure storage and management leading to vulnerabilities

Engineering Contradiction:
ImprovesecurityVSAvoidstorage and management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments cryptographic keys and authentication data into multiple separate data subsets stored in different locations or formats. No single subset contains the complete key material, so compromising one subset does not expose the full cryptographic secret. This segmentation resolves the contradiction by enabling secure storage through distribution while maintaining the ability to perform security functions when needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trust engine as an intermediary component that manages the segmented cryptographic data. The trust engine coordinates the reassembly and use of key subsets without exposing the actual key material, acting as a mediator between security requirements and storage constraints. This intermediary enables secure key management while maintaining system reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multi-dimensional data representation with encryption is used, then data security is improved, but processing complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies multi-dimensional encryption by encrypting data subsets along different dimensions or layers. Each encryption operation targets a specific dimension of the data structure, creating a multi-layered security approach. This resolves the contradiction by significantly enhancing data security through dimensional complexity while managing processing complexity through systematic encryption procedures.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If cryptographic keys are not released from storage, then security is maintained, but portability and availability are reduced

Engineering Contradiction:
ImprovesecurityVSAvoidportability and availability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extracts only the necessary portions of cryptographic data (individual subsets) from secure storage when needed, rather than releasing complete keys. The trust engine extracts and temporarily uses specific data subsets to perform cryptographic operations, then returns them to storage. This resolves the contradiction by maintaining security through minimal key exposure while enabling portability and availability through controlled extraction and use of cryptographic materials.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8677148B2Systems and methods for securing data
Publication Date: 2014.03.18 SECURITY FIRST INNOVATIONS LLC
  • US8677148B2 patent drawing
  • US8677148B2 patent drawing
  • US8677148B2 patent drawing

AI summary

Systems and methods are provided for securing data. A processing device receives a data set and identifies a first subset of data from a first dimension of a multi-dimensional representation of the data set. The processing device encrypts the first subset of data using a first encryption technique to yield a first encrypted subset of data and replaces the first subset of data in the multi-dimensional representation of the data set with the first subset of encrypted data. The processing device then identifies a second subset of data from a second dimension of the multi-dimensional representation of the data set, with the second subset of data including at least a portion of the first subset of encrypted data, and encrypts the second subset of data using a second encryption technique to yield a second encrypted subset of data.