Secure Data Exchange via Dual-Gate Encryption and Virtual File Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud-based data handling systems inadequately protect sensitive data from unauthorized access, relying solely on user authentication methods which are not highly efficient.
Innovation Solution
A system and method utilizing two data gates for encrypting and decrypting data with authentication-based keys, generating virtual files with metadata, and storing encrypted data across multiple public data storages in restricted regions to enhance security and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is stored in cloud-based public data storages, then data accessibility and processing efficiency are improved, but data security and protection from unauthorized access deteriorate
Solution Approach 1:
The patent divides encrypted data into multiple separate data packets and distributes them across different public data storages. Each packet alone is insufficient to reconstruct the original data, providing security while maintaining accessibility. This segmentation approach allows efficient cloud-based processing without compromising security.
Solution Approach 2:
The patent introduces an intermediary decryption key that acts as a mediator between the encrypted data packets stored in public cloud and the authorized user. The key is required to assemble and decrypt the data, providing a security layer that doesn't prevent access but controls who can actually use the data.
2Ease of operation
If traditional authentication methods (usernames and passwords) are used, then ease of operation is improved, but security effectiveness deteriorates
Solution Approach 1:
The patent performs preliminary encryption of data before storing it in the cloud, using authentication data as the encryption key. This preliminary security measure ensures that even if the cloud storage is compromised, the data remains protected without requiring complex authentication changes for users.
Solution Approach 2:
The patent transforms the authentication approach by changing the parameter from simple username-password verification to using authentication data as an encryption key. This parameter change maintains user-friendly authentication while significantly enhancing security effectiveness through cryptographic protection.
3Reliability
If data is encrypted and distributed across multiple storages, then security is improved, but system complexity increases
Solution Approach 1:
The patent implements data gates that perform multiple functions: encryption, packetization, distribution across storages, and decryption/assembly. This multi-functional approach consolidates complex security operations into standardized components, managing system complexity while maintaining high security.
Solution Approach 2:
The system employs automated data gates that independently handle encryption, packet creation, distribution, and decryption processes without requiring manual intervention. This self-service automation manages the inherent complexity of distributed encryption systems through programmatic operations.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system (10) for secure data exchange is provided. The system (10) comprises at least two data gates (11a, 11b). In this context, a first data gate (11a) of the at least two data gates (11a, 11b) is configured to encrypt original data (12) with a key based on authentication data (15) and to generate at least one virtual file (13) comprising meta data of the original data (12), whereas a second data gate (11b) of the at least two data gates (11a, 11b) is configured to assemble and/or decrypt the encrypted original data (14) with the key. In addition to this, the assembly and/or decryption of the encrypted original data (14) is initiated by at least one user input (16) with respect to the at least one virtual file (13).