Dynamic Key Rotation for Secure Data Fragmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data security solutions are static and vulnerable to unauthorized access, especially at client endpoints, where data is generated and accessed, and they struggle with seamlessly integrating multiple security mechanisms without introducing additional security risks.
Innovation Solution
The system fragments data into multiple encrypted fragments, which are then securely stored and transmitted using unique keys, allowing for dynamic key regeneration and management, enabling secure storage and transmission while minimizing the need for secure communication channels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional static data security mechanisms are deployed at a data storage location, then data security is provided, but the system remains vulnerable to unauthorized access and cannot adapt to new security threats
Solution Approach 1:
The patent implements dynamic key rotation where encryption keys are automatically regenerated and rotated over time without requiring system reconfiguration. This allows the security mechanism to adapt to emerging threats while maintaining continuous protection, resolving the contradiction between static deployment and adaptive security needs
Solution Approach 2:
The system changes cryptographic parameters dynamically by rotating encryption keys based on time intervals or security events. This parameter change enables the same security infrastructure to provide both stable protection and adaptability to new security requirements
2Reliability
If multiple data security mechanisms are combined at a single data storage location, then data security is enhanced, but incompatibilities between solutions may introduce additional security risks
Solution Approach 1:
The patent merges multiple security mechanisms (encryption, key management, authentication) into a unified architecture where they work together seamlessly. The encryption engine integrates with the data storage system, and key rotation is automatically coordinated with access control, enhancing security while managing complexity through unified design
Solution Approach 2:
The encryption engine is designed as a universal component that can work with multiple encryption algorithms and key management strategies. This multi-functional design allows different security mechanisms to be combined without incompatibility issues, as the engine can adapt to various cryptographic approaches
3Ease of operation
If data is stored in separate storage locations with common record locators, then data organization is improved, but unauthorized access to one record exposes information to access remaining records
Solution Approach 1:
The patent segments data into separate encrypted records, each with its own unique encryption key. Even though records are organized separately with common locators for retrieval, the segmentation of encryption keys ensures that unauthorized access to one record does not compromise other records, maintaining both organization and security
4Reliability
If encryption keys are frequently rotated to enhance security, then security is improved, but the time required for encryption and transmission increases
Solution Approach 1:
The system implements periodic key rotation at predetermined intervals rather than continuously. This periodic action maintains security by regularly updating keys while minimizing the impact on encryption and transmission speed, as keys remain stable during each interval
Solution Approach 2:
Encryption keys are pre-generated and staged before rotation is needed. This preliminary action allows for smooth key transitions without interrupting ongoing encryption operations, maintaining productivity while achieving security enhancement through rotation
Data Source
AI summary
A system for authenticated communications between devices, the system comprising: a plurality of devices comprising at least a first and second device; and one or more communication pathways configured to communicatively couple the first and second devices for data streaming of a data object; and the first device comprising a memory coupled to at least one processor, the first device configured to: generate a plurality of datasets corresponding to a plurality of data fragments constituting the data object, each dataset comprising encryption keys used to encrypt the corresponding data fragments, encrypt a first dataset of the plurality of datasets using a first dataset key derived based, in part, on a first encryption algorithm, and determine a second dataset key based, in part, on at least one of the first encryption algorithm and second encryption algorithm.


