Dynamic Key Rotation for Secure Data Fragmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data security solutions are static and vulnerable to unauthorized access, especially at client endpoints, where data is generated and accessed, and they struggle with seamlessly integrating multiple security mechanisms without introducing additional security risks.

Innovation Solution

The system fragments data into multiple encrypted fragments, which are then securely stored and transmitted using unique keys, allowing for dynamic key regeneration and management, enabling secure storage and transmission while minimizing the need for secure communication channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional static data security mechanisms are deployed at a data storage location, then data security is provided, but the system remains vulnerable to unauthorized access and cannot adapt to new security threats

Engineering Contradiction:
Improvedata securityVSAvoidsecurity mechanism flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic key rotation where encryption keys are automatically regenerated and rotated over time without requiring system reconfiguration. This allows the security mechanism to adapt to emerging threats while maintaining continuous protection, resolving the contradiction between static deployment and adaptive security needs

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes cryptographic parameters dynamically by rotating encryption keys based on time intervals or security events. This parameter change enables the same security infrastructure to provide both stable protection and adaptability to new security requirements

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple data security mechanisms are combined at a single data storage location, then data security is enhanced, but incompatibilities between solutions may introduce additional security risks

Engineering Contradiction:
Improvedata securityVSAvoidsecurity solution integration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security mechanisms (encryption, key management, authentication) into a unified architecture where they work together seamlessly. The encryption engine integrates with the data storage system, and key rotation is automatically coordinated with access control, enhancing security while managing complexity through unified design

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The encryption engine is designed as a universal component that can work with multiple encryption algorithms and key management strategies. This multi-functional design allows different security mechanisms to be combined without incompatibility issues, as the engine can adapt to various cryptographic approaches

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If data is stored in separate storage locations with common record locators, then data organization is improved, but unauthorized access to one record exposes information to access remaining records

Engineering Contradiction:
Improvedata organizationVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments data into separate encrypted records, each with its own unique encryption key. Even though records are organized separately with common locators for retrieval, the segmentation of encryption keys ensures that unauthorized access to one record does not compromise other records, maintaining both organization and security

Inventive Principle:
Principle #1Segmentation

4Reliability

If encryption keys are frequently rotated to enhance security, then security is improved, but the time required for encryption and transmission increases

Engineering Contradiction:
Improvedata securityVSAvoidencryption and transmission speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements periodic key rotation at predetermined intervals rather than continuously. This periodic action maintains security by regularly updating keys while minimizing the impact on encryption and transmission speed, as keys remain stable during each interval

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

Encryption keys are pre-generated and staged before rotation is needed. This preliminary action allows for smooth key transitions without interrupting ongoing encryption operations, maintaining productivity while achieving security enhancement through rotation

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11349656B2Systems and methods for secure storage and transmission of a data stream
Publication Date: 2022.05.31 UBIQ SECURITY INC
  • US11349656B2 patent drawing
  • US11349656B2 patent drawing
  • US11349656B2 patent drawing

AI summary

A system for authenticated communications between devices, the system comprising: a plurality of devices comprising at least a first and second device; and one or more communication pathways configured to communicatively couple the first and second devices for data streaming of a data object; and the first device comprising a memory coupled to at least one processor, the first device configured to: generate a plurality of datasets corresponding to a plurality of data fragments constituting the data object, each dataset comprising encryption keys used to encrypt the corresponding data fragments, encrypt a first dataset of the plurality of datasets using a first dataset key derived based, in part, on a first encryption algorithm, and determine a second dataset key based, in part, on at least one of the first encryption algorithm and second encryption algorithm.