Encryption Device Dynamic Path Switching for Secure Data Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems lack secure and efficient methods to switch between different communication modes, particularly in scenarios where secure communication is required, and there is a need to protect data from untrusted workstations vulnerable to attacks.
Innovation Solution
A system and method that dynamically switches communication paths based on user-selected modes, using encryption and decryption processes to ensure secure data transmission between computers, with biometric authentication and a switching system that routes encrypted data through a secure network path, preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is transmitted through an unsecured workstation, then communication efficiency is improved, but data security deteriorates
Solution Approach 1:
The system segments the communication path into two distinct modes: a secure path through the encryption device for sensitive applications, and a non-secure path through the workstation for general applications. This segmentation allows the system to optimize for either security or efficiency depending on the specific communication needs, resolving the contradiction by providing context-dependent routing.
Solution Approach 2:
The encryption device serves as an intermediary between the input devices and the computer system. It acts as a mediator that can either directly process secure applications or route them through the workstation, depending on the application's security requirements. This intermediary role allows the system to maintain security for sensitive applications while preserving communication efficiency for non-sensitive ones.
2Reliability
If a secure communication path is established, then data security is improved, but device complexity increases
Solution Approach 1:
The encryption device is designed with multi-functionality, capable of both directly processing secure applications and routing non-secure applications through the workstation. This universal design consolidates security management into a single device that can adapt its behavior based on application requirements, reducing overall system complexity compared to having separate dedicated systems for secure and non-secure communications.
Solution Approach 2:
The system dynamically adjusts the communication path based on the security requirements of each application. The encryption device can switch between operating in secure mode (direct processing) and non-secure mode (workstation routing) depending on the application type. This dynamic adaptability allows the system to maintain security only where necessary, avoiding the complexity of permanently configured secure paths for all communications.
3Reliability
If encryption and decryption processes are implemented, then data security is improved, but processing time increases
Solution Approach 1:
The system applies encryption and decryption processes selectively rather than universally. Only applications that require secure communication undergo the encryption/decryption process, while non-secure applications are processed directly through the workstation without these time-consuming steps. This partial application of security measures maintains data security for sensitive applications while minimizing the time loss associated with encryption operations.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system and method are provided, embodiments of which comprise encrypting input data based on authorization from an application program launched on a local computer device by a user. The encrypted input data that is generated by the user is sent to a network communication interface associated with the local computer device for transmission to a remote computer device. At the remote computer the received input data is decrypted, whereby based on the decrypted input data the remote computer generates encrypted response data that is associated with the decrypted first data. The encrypted response data is sent from the remote computer to the local computer, where the encrypted response data is received via the network communication interface associated with the local computer and decrypted. The local computer displays the decrypted response data on a display.