Encryption Scheme Recommendation System for Data Storage Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data owners face challenges in ensuring data security when outsourcing storage to third-party providers, as they lose control over their data and must manually determine appropriate encryption schemes, which is time-consuming and costly, especially considering varying sensitivity levels and computational resources.

Innovation Solution

A system and method that recommend encryption schemes for datasets based on attributes and dependencies, providing tailored recommendations for each portion of the data, including key labels and reasons, to optimize security and efficiency without requiring manual expert analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data owners manually determine appropriate encryption schemes for outsourced data, then data security can be ensured, but the process becomes time-consuming and costly

Engineering Contradiction:
Improvedata securityVSAvoidtime to determine encryption scheme
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated self-service by having the encryption scheme recommendation system automatically analyze dataset attributes and dependencies, then generate encryption scheme recommendations without requiring manual expert analysis. The system parses the dataset, identifies sensitive portions, determines dependencies, and produces tailored encryption recommendations autonomously.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

An intermediary recommendation system is introduced between the data owner and the encryption process. This system acts as a mediator that automatically analyzes data characteristics and recommends appropriate encryption schemes, eliminating the need for data owners to manually determine encryption parameters while ensuring security requirements are met.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data owners manually determine appropriate encryption schemes for outsourced data, then data security can be ensured, but the cost increases significantly

Engineering Contradiction:
Improvedata securityVSAvoidcost to determine encryption scheme
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The automated recommendation system performs self-service by automatically analyzing dataset attributes and dependencies to generate encryption scheme recommendations. This eliminates the need to hire security experts or spend extensive manual time on encryption scheme selection, significantly reducing costs while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses automated algorithms and computational resources (relatively cheap and readily available) instead of expensive human expert time. The recommendation engine processes data characteristics and generates encryption recommendations through computational means rather than manual analysis, reducing the cost burden on data owners.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Ease of manufacture

If encryption schemes are applied uniformly to entire datasets, then implementation is simple, but it fails to account for varying sensitivity levels of different data portions

Engineering Contradiction:
Improveease of encryption implementationVSAvoidadaptability to data sensitivity variations
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system segments the dataset into multiple portions based on sensitivity levels and dependencies. It parses the dataset to identify different data portions, determines their sensitivity characteristics, and recommends encryption schemes tailored to each segment. This allows differential encryption where different portions receive appropriate encryption levels based on their specific requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The recommendation system applies local quality by tailoring encryption schemes to specific portions of the dataset based on their local characteristics. Each data portion receives encryption recommendations suited to its sensitivity level and dependency relationships, rather than applying a uniform encryption approach to the entire dataset. This optimizes both security and efficiency for each local region of the data.

Inventive Principle:
Principle #3Local quality

4Productivity

If automated encryption recommendations are generated for each data portion, then security and efficiency are optimized, but system complexity increases

Engineering Contradiction:
Improveefficiency of encryption processVSAvoidcomplexity of encryption recommendation system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system replaces manual mechanical analysis with automated computational processes. Instead of human experts manually analyzing data characteristics and recommending encryption schemes, the system uses automated parsing, attribute identification, and dependency analysis algorithms to generate recommendations efficiently. This substitution of mechanical human analysis with computational automation improves productivity despite increased system complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11475020B2Encryption scheme recommendation
Publication Date: 2022.10.18 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11475020B2 patent drawing
  • US11475020B2 patent drawing
  • US11475020B2 patent drawing

AI summary

One embodiment provides a method, including: receiving, from a user, a dataset for encryption before its storage at a data storage location, wherein the dataset comprises a plurality of portions; identifying (i) attributes of the dataset and (ii) dataset dependencies; generating a recommendation for an encryption scheme to be used for the dataset, wherein the generating comprises (i) generating, based upon the attributes and the dataset dependencies, a recommendation of an encryption scheme for each portion of the dataset and (ii) identifying, based upon the dataset dependencies, a key label for each portion of the dataset, wherein the key label identified for a portion of the dataset that is dependent on another portion of the dataset is the same as the key label identified for said another portion of the dataset; and providing, to the user, (i) the generated recommendation and (ii) a description identifying reasons for the generated recommendation.