Encryption Management via Look-Up Tables and Remote Re-encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing encryption management systems face challenges in efficiently identifying and securing data protected by at-risk encryption algorithms, leading to potential data interception and unauthorized access.

Innovation Solution

A method and system that utilize look-up tables to map time periods or data locations to encryption algorithms, allowing for efficient identification and execution of security actions, such as decrypting and re-encrypting data with a stronger algorithm, using remote resources to maintain data security without disrupting customer workloads.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is identified by checking each piece of data to verify the encryption algorithm used, then data security is ensured, but system efficiency decreases and computing resources are wasted

Engineering Contradiction:
Improvedata securityVSAvoidsystem efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-creating look-up tables that map time periods and encryption algorithms to data locations before security actions are needed. When an encryption algorithm is identified as at-risk, the system can immediately query the pre-built look-up table to identify affected data, eliminating the need to check each data piece individually during security incidents.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces look-up tables as an intermediary data structure between the encryption management system and the actual data storage. These tables store pre-computed mappings between encryption algorithms, time periods, and data locations, serving as a mediator that enables efficient identification of affected data without direct inspection of each data element.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is decrypted and re-encrypted using local resources, then data security is enhanced, but customer workloads are disrupted

Engineering Contradiction:
Improvedata securityVSAvoidworkload continuity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the decryption and re-encryption operations from the customer's local environment and relocates them to a remote encryption management system. By taking out these security-critical operations from the customer premises, the system can perform them during off-peak times or using dedicated security resources without impacting customer business operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a remote encryption management system as an intermediary between the customer's data and the re-encryption process. This intermediary handles all decryption and re-encryption operations externally, allowing customers to continue their workloads uninterrupted while their data is being secured through algorithm updates.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11641349B2Encryption management
Publication Date: 2023.05.02 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11641349B2 patent drawing
  • US11641349B2 patent drawing
  • US11641349B2 patent drawing

AI summary

Aspects of the present disclosure relate to encryption management. A determination can be made whether an encryption algorithm is at-risk. In response to determining that the encryption algorithm is at-risk, data protected by the encryption algorithm can be identified. A security action can then be executed on the data protected by the encryption algorithm.