Encryption Engine Key Management for Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users' sensitive data is vulnerable to hacking, and existing technologies fail to adequately secure data both at rest and in transit, as well as the keys used for encryption, leading to potential misappropriation.
Innovation Solution
A system that includes a lock module to unlock an encryption engine using a master key generated from a combination of keys held by multiple key holders, allowing for decryption and re-encryption of data using different encryption keys, thereby enhancing security by continuously changing the encryption keys used for data-at-rest and in-transit.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is encrypted using a single encryption key for storage, then data security is improved, but key management becomes vulnerable to misappropriation and decryption risks
Solution Approach 1:
The patent divides the single encryption key into multiple component keys (first key, second key, third key) that are stored separately in different locations or by different key holders. Each key alone is insufficient to decrypt the encrypted data, providing segmentation-based security against key misappropriation.
Solution Approach 2:
The patent implements nested encryption where data is encrypted with one key, then the resulting ciphertext is encrypted again with another key, and so on. This creates multiple layers of encryption (Russian doll style) where each layer protects the inner layer, making key misappropriation less effective.
2Reliability
If encryption keys are stored securely to prevent misappropriation, then key security is improved, but access to encrypted data becomes more complex
Solution Approach 1:
The patent combines multiple component keys to reconstruct the full encryption capability. While keys are stored separately for security, they can be merged together when needed to decrypt data, balancing security with operational ease through controlled combination.
Solution Approach 2:
The patent introduces an intermediary decryption system or process that manages the combination of multiple keys. This intermediary handles the complexity of key management and combination, shielding users from direct complexity while maintaining secure key storage.
3Productivity
If the same encryption key is used for multiple data encryption operations, then processing efficiency is improved, but security vulnerability increases if the key is compromised
Solution Approach 1:
The patent implements dynamic key usage where different component keys are used for different encryption operations or data sets. Instead of a static single key, the system dynamically selects and combines keys based on the specific data being protected, reducing the impact of any single key compromise.
Solution Approach 2:
The patent changes the encryption parameters by using multiple different keys instead of one repeated key. Each key can have different properties or be used for different time periods, creating parameter diversity that limits the effectiveness of key compromise while maintaining processing efficiency through systematic key application.
Data Source
AI summary
Apparatuses, methods, systems, and program products are disclosed for secure data handling and storage. An apparatus includes a lock module that receives a request to decrypt encrypted data that is stored in a data repository, the encrypted data encrypted using a first encryption key, and unlocks an encryption engine in response to the request. An encryption engine may be unlocked using a master key that is generated based on combination of a plurality of keys held by a plurality of key holders. An apparatus includes a decryption module that decrypts encrypted data using an encryption engine. Encrypted data may be decrypted using a first encryption key. An apparatus includes an encryption module that re-encrypts decrypted data using an encryption engine. Decrypted data may be re-encrypted with a second encryption key that is different than a first encryption key and stored in a data repository.


