Data Encryption Apparatus for Multi-Environment Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data security systems face challenges in providing a single, cost-effective, and performance-efficient solution for securely protecting data across multiple system operating environments, including cloud and on-premise environments.
Innovation Solution
A data encryption/decryption apparatus and method that considers the environment and application for data distribution, using a receptor to receive data, an encryptor to superencipher the data using environment-specific keys and access information, and a transmitter to send the encrypted data to the target environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single security system is implemented across multiple system operating environments (cloud and on-premise), then data protection consistency is improved, but system complexity and implementation cost increase
Solution Approach 1:
The security system is segmented into environment-specific key management components. Each operating environment (cloud, on-premise) has its own key management system that generates and manages cryptographic keys locally. The encryption apparatus is also segmented to perform different encryption operations based on the target environment, with separate handling for distributor environments and cloud environments.
Solution Approach 2:
The system implements local quality by allowing different encryption methods and key management approaches for different environments. Cloud environments use one set of cryptographic operations while on-premise environments use another, optimizing security for each specific context rather than forcing a uniform approach across all platforms.
2Adaptability or versatility
If cryptographic keys are directly registered in a cloud environment key management system, then data encryption capability is improved, but security control and performance efficiency deteriorate
Solution Approach 1:
An encryption apparatus acts as an intermediary between the key management system and the cloud environment. This intermediary generates cryptographic keys locally, performs encryption operations on data before it leaves the distributor environment, and transmits only encrypted data to the cloud. This prevents direct exposure of plaintext keys and data to the cloud environment while maintaining encryption capability.
Solution Approach 2:
The encryption apparatus performs preliminary encryption actions on data before transmission to the cloud environment. By encrypting data in advance within the distributor environment using locally-generated keys, the system ensures that sensitive information never暴露在 the cloud environment, maintaining security control while enabling cloud-based data storage and processing.
3Adaptability or versatility
If network expansion is performed to provide a single security system, then system coverage is improved, but cost and performance efficiency worsen
Solution Approach 1:
The encryption functionality is extracted from the cloud environment and placed back into the distributor environment through the encryption apparatus. This extraction eliminates the need for costly network expansion and centralized key management infrastructure, as each environment independently manages its own cryptographic operations locally, reducing both infrastructure costs and network dependency.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An apparatus and method for data encryption. The data encryption apparatus includes a receptor to receive distribution target data including one or more distribution target cryptographic keys and a distribution target application from a distributor environment, an encryptor to superencipher the distribution target data using a distribution target environment cryptographic key acquired from a distribution target environment and access information on the distribution target data, and a transmitter to transmit the superenciphered distribution target data and the distribution target application to the distribution target environment.