Data Encryption Apparatus for Multi-Environment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security systems face challenges in providing a single, cost-effective, and performance-efficient solution for securely protecting data across multiple system operating environments, including cloud and on-premise environments.

Innovation Solution

A data encryption/decryption apparatus and method that considers the environment and application for data distribution, using a receptor to receive data, an encryptor to superencipher the data using environment-specific keys and access information, and a transmitter to send the encrypted data to the target environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single security system is implemented across multiple system operating environments (cloud and on-premise), then data protection consistency is improved, but system complexity and implementation cost increase

Engineering Contradiction:
Improvedata protection consistencyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system is segmented into environment-specific key management components. Each operating environment (cloud, on-premise) has its own key management system that generates and manages cryptographic keys locally. The encryption apparatus is also segmented to perform different encryption operations based on the target environment, with separate handling for distributor environments and cloud environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements local quality by allowing different encryption methods and key management approaches for different environments. Cloud environments use one set of cryptographic operations while on-premise environments use another, optimizing security for each specific context rather than forcing a uniform approach across all platforms.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If cryptographic keys are directly registered in a cloud environment key management system, then data encryption capability is improved, but security control and performance efficiency deteriorate

Engineering Contradiction:
Improvedata encryption capabilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

An encryption apparatus acts as an intermediary between the key management system and the cloud environment. This intermediary generates cryptographic keys locally, performs encryption operations on data before it leaves the distributor environment, and transmits only encrypted data to the cloud. This prevents direct exposure of plaintext keys and data to the cloud environment while maintaining encryption capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The encryption apparatus performs preliminary encryption actions on data before transmission to the cloud environment. By encrypting data in advance within the distributor environment using locally-generated keys, the system ensures that sensitive information never暴露在 the cloud environment, maintaining security control while enabling cloud-based data storage and processing.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If network expansion is performed to provide a single security system, then system coverage is improved, but cost and performance efficiency worsen

Engineering Contradiction:
Improvesystem coverageVSAvoidcost and performance efficiency
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The encryption functionality is extracted from the cloud environment and placed back into the distributor environment through the encryption apparatus. This extraction eliminates the need for costly network expansion and centralized key management infrastructure, as each environment independently manages its own cryptographic operations locally, reducing both infrastructure costs and network dependency.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3817276B1Apparatus and method for data security
Publication Date: 2025.05.21 SAMSUNG SDS CO LTD
  • EP3817276B1 patent drawingFigure 1
  • EP3817276B1 patent drawingFigure 2
  • EP3817276B1 patent drawingFigure 3

AI summary

An apparatus and method for data encryption. The data encryption apparatus includes a receptor to receive distribution target data including one or more distribution target cryptographic keys and a distribution target application from a distributor environment, an encryptor to superencipher the distribution target data using a distribution target environment cryptographic key acquired from a distribution target environment and access information on the distribution target data, and a transmitter to transmit the superenciphered distribution target data and the distribution target application to the distribution target environment.