Encryption Device Data Path Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data storage systems fail to ensure secure data transmission over networks to remote cloud devices, often transmitting data unencrypted or experiencing performance degradation when encrypting data prior to transmission.

Innovation Solution

Implementing an encryption device along the data path within the primary data center to encrypt data using an encryption key corresponding to the destination device, ensuring secure transmission without the need for decryption and re-encryption at the remote storage site.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is transmitted unencrypted over the network to remote cloud devices, then transmission speed is maintained, but data security is compromised

Engineering Contradiction:
Improvedata securityVSAvoidtransmission speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The encryption device performs encryption operations in advance within the primary data center before data leaves the firewall. By pre-encrypting data at the source, the system eliminates the need for decryption and re-encryption at remote storage sites, maintaining transmission speed while ensuring data security during network transit

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An encryption device is introduced as an intermediary component within the primary data center, positioned between the data source and the network boundary. This intermediary handles encryption operations transparently, allowing data to be secured without requiring changes to remote storage systems or impacting transmission throughput

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is encrypted prior to sending over the network, then data security is improved, but performance degradation occurs

Engineering Contradiction:
Improvedata securityVSAvoiddata transfer performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Encryption is performed as a preliminary action within the primary data center infrastructure, utilizing available encryption keys and algorithms before data enters the network transmission pipeline. This approach secures data without requiring post-transmission processing at remote sites

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption device operates autonomously within the primary data center, managing its own encryption key retrieval and data processing without requiring intervention from remote storage systems. This self-contained approach eliminates redundant decryption and re-encryption operations that would degrade performance

Inventive Principle:
Principle #25Self-service

3Reliability

If data is decrypted and re-encrypted at remote storage systems, then data security is maintained, but transmission efficiency decreases

Engineering Contradiction:
Improvedata securityVSAvoidtransmission time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs the encryption action in advance at the primary data center, eliminating the need for subsequent decryption and re-encryption operations at remote storage systems. This single encryption step at the source maintains security while reducing total processing time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption function is extracted from the remote storage system and relocated to the primary data center. By removing the decryption and re-encryption requirements from remote sites, the system eliminates redundant processing steps that would increase transmission time

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10110572B2Tape drive encryption in the data path
Publication Date: 2018.10.23 ORACLE INT CORP
  • US10110572B2 patent drawing
  • US10110572B2 patent drawing
  • US10110572B2 patent drawing

AI summary

Implementations described and claimed herein provide encryption in the data path. In one implementation, login parameters from a primary data center are obtained. The login parameters include an identification of a destination device. An encryption key corresponding to the destination device is received. A write command including data for writing to the destination device is received from the primary data center. The data is encrypted inside a firewall of the primary data center using the encryption key. The encrypted data is routed over a data path to the destination device. As such, the data is secure during transmission over the network to the destination device.