Encrypted Zone Isolation for Data Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual private networks (VPNs) are vulnerable to data privacy breaches, as unauthorized applications can access sensitive information, and current solutions require significant user expertise and complexity, failing to fully prevent the flow of undesired data.

Innovation Solution

A system and method for establishing user-controlled zones of restricted data interaction, using encrypted communications through a public network, where each zone isolates data interactions, preventing unauthorized access and allowing customized control over data sharing based on geographic, domain, or application-specific criteria.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a virtual private network is used to extend private network through public network, then network communication capability is improved, but data privacy security deteriorates due to unauthorized access

Engineering Contradiction:
Improvenetwork communication capabilityVSAvoiddata privacy security
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network communication into multiple isolated zones (encrypted zone and unencrypted zone) within the device. Each zone handles specific types of traffic with appropriate security measures, preventing unauthorized applications from accessing sensitive encrypted communications while maintaining overall network connectivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different parts of the system: the encrypted zone uses strong encryption and access controls for sensitive communications, while the unencrypted zone handles non-sensitive traffic. This local differentiation of security properties protects privacy-critical data without compromising overall system functionality.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If current privacy protection solutions are implemented to prevent unauthorized data access, then data security is improved, but user experience complexity and operational difficulty increase

Engineering Contradiction:
Improvedata securityVSAvoiduser experience complexity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements automatic zone assignment and encryption management without requiring user intervention. The system automatically determines which communications should be encrypted and routes them to the encrypted zone, eliminating the need for users to manually configure security settings or understand complex privacy protection mechanisms.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary encryption layer managed by the operating system that sits between applications and the network. This intermediary automatically handles encryption and decryption operations, shielding users from complex cryptographic operations while maintaining strong security protections.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If traditional VPN solutions are used to encrypt all communications, then data privacy is improved, but system resource consumption and processing overhead increase

Engineering Contradiction:
Improvedata privacyVSAvoidsystem resource consumption
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The patent segments communications into encrypted and unencrypted portions based on sensitivity and context. Only communications requiring privacy protection are routed through the encrypted zone, reducing the overall volume of encrypted traffic and associated computational overhead compared to encrypting all communications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies encryption selectively rather than universally - encrypting only the portion of communications that require privacy protection while leaving non-sensitive communications in the unencrypted zone. This partial application of encryption reduces resource consumption while maintaining adequate security for sensitive data.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11122013B2System and method for encrypting data interactions delineated by zones
Publication Date: 2021.09.14 GEN DIGITAL INC
  • US11122013B2 patent drawing
  • US11122013B2 patent drawing
  • US11122013B2 patent drawing

AI summary

A system and method for establishing zones of control for communications among computing devices. Zones of control refer to the concept of unique user-controlled silos separating the interactions between computer devices over the network. When the user of a device connects to a networked computing environment of any kind, at least some data may be sent from the user's device onto the network, as well as downloaded to the user's device. These “data interactions” are usually frequent and numerous. With a private encrypted browsing session established, communications within an established zone of control may be isolated from all other communications and vice versa.