Encryption Device Dynamic Path Switching for Secure Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems lack secure and efficient methods to switch between different communication modes, particularly in scenarios where secure communication is required, and there is a need to protect data from untrusted workstations vulnerable to attacks.

Innovation Solution

A system and method that dynamically switches communication paths based on user-selected modes, using encryption and decryption processes to ensure secure data transmission between computers, with biometric authentication and a switching system that routes encrypted data through a secure network path, preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is transmitted through an unsecured workstation, then communication efficiency is improved, but data security deteriorates

Engineering Contradiction:
Improvecommunication efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the communication path into two distinct modes: a secure path through the encryption device for sensitive applications, and a non-secure path through the workstation for general applications. This segmentation allows the system to optimize for either security or efficiency depending on the specific communication needs, resolving the contradiction by providing context-dependent routing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encryption device serves as an intermediary between the input devices and the computer system. It acts as a mediator that can either directly process secure applications or route them through the workstation, depending on the application's security requirements. This intermediary role allows the system to maintain security for sensitive applications while preserving communication efficiency for non-sensitive ones.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a secure communication path is established, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption device is designed with multi-functionality, capable of both directly processing secure applications and routing non-secure applications through the workstation. This universal design consolidates security management into a single device that can adapt its behavior based on application requirements, reducing overall system complexity compared to having separate dedicated systems for secure and non-secure communications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adjusts the communication path based on the security requirements of each application. The encryption device can switch between operating in secure mode (direct processing) and non-secure mode (workstation routing) depending on the application type. This dynamic adaptability allows the system to maintain security only where necessary, avoiding the complexity of permanently configured secure paths for all communications.

Inventive Principle:
Principle #15Dynamics

3Reliability

If encryption and decryption processes are implemented, then data security is improved, but processing time increases

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies encryption and decryption processes selectively rather than universally. Only applications that require secure communication undergo the encryption/decryption process, while non-secure applications are processed directly through the workstation without these time-consuming steps. This partial application of security measures maintains data security for sensitive applications while minimizing the time loss associated with encryption operations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP1952253B1System and method for providing secure data transmission
Publication Date: 2012.12.26 BLOOMBERG FINANCE LP
  • EP1952253B1 patent drawingFigure 1
  • EP1952253B1 patent drawingFigure 2
  • EP1952253B1 patent drawingFigure 3

AI summary

A system and method are provided, embodiments of which comprise encrypting input data based on authorization from an application program launched on a local computer device by a user. The encrypted input data that is generated by the user is sent to a network communication interface associated with the local computer device for transmission to a remote computer device. At the remote computer the received input data is decrypted, whereby based on the decrypted input data the remote computer generates encrypted response data that is associated with the decrypted first data. The encrypted response data is sent from the remote computer to the local computer, where the encrypted response data is received via the network communication interface associated with the local computer and decrypted. The local computer displays the decrypted response data on a display.