Secure Data Exchange via Dual-Gate Encryption and Virtual File Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud-based data handling systems inadequately protect sensitive data from unauthorized access, relying solely on user authentication methods which are not highly efficient.

Innovation Solution

A system and method utilizing two data gates for encrypting and decrypting data with authentication-based keys, generating virtual files with metadata, and storing encrypted data across multiple public data storages in restricted regions to enhance security and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is stored in cloud-based public data storages, then data accessibility and processing efficiency are improved, but data security and protection from unauthorized access deteriorate

Engineering Contradiction:
Improvedata processing efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides encrypted data into multiple separate data packets and distributes them across different public data storages. Each packet alone is insufficient to reconstruct the original data, providing security while maintaining accessibility. This segmentation approach allows efficient cloud-based processing without compromising security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary decryption key that acts as a mediator between the encrypted data packets stored in public cloud and the authorized user. The key is required to assemble and decrypt the data, providing a security layer that doesn't prevent access but controls who can actually use the data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional authentication methods (usernames and passwords) are used, then ease of operation is improved, but security effectiveness deteriorates

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary encryption of data before storing it in the cloud, using authentication data as the encryption key. This preliminary security measure ensures that even if the cloud storage is compromised, the data remains protected without requiring complex authentication changes for users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transforms the authentication approach by changing the parameter from simple username-password verification to using authentication data as an encryption key. This parameter change maintains user-friendly authentication while significantly enhancing security effectiveness through cryptographic protection.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If data is encrypted and distributed across multiple storages, then security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements data gates that perform multiple functions: encryption, packetization, distribution across storages, and decryption/assembly. This multi-functional approach consolidates complex security operations into standardized components, managing system complexity while maintaining high security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system employs automated data gates that independently handle encryption, packet creation, distribution, and decryption processes without requiring manual intervention. This self-service automation manages the inherent complexity of distributed encryption systems through programmatic operations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3557469B1System, method and computer program for secure data exchange
Publication Date: 2022.06.22 ROHDE & SCHWARZ GMBH & CO KG
  • EP3557469B1 patent drawingFigure 1
  • EP3557469B1 patent drawingFigure 2
  • EP3557469B1 patent drawingFigure 3

AI summary

A system (10) for secure data exchange is provided. The system (10) comprises at least two data gates (11a, 11b). In this context, a first data gate (11a) of the at least two data gates (11a, 11b) is configured to encrypt original data (12) with a key based on authentication data (15) and to generate at least one virtual file (13) comprising meta data of the original data (12), whereas a second data gate (11b) of the at least two data gates (11a, 11b) is configured to assemble and/or decrypt the encrypted original data (14) with the key. In addition to this, the assembly and/or decryption of the encrypted original data (14) is initiated by at least one user input (16) with respect to the at least one virtual file (13).