File-Level Encryption System for Secure Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data security solutions are either expensive and require technical expertise or are inadequate, failing to provide robust protection for data in storage and transmission, and often require complex infrastructure and skilled personnel, while also being vulnerable to human error and cyber attacks.

Innovation Solution

A computer network system with a central server and portable secure key devices that enable secure data encryption, decryption, and sharing, using two-factor authentication and symmetric key cryptography, allowing secure data operations without the need for extensive technical support or infrastructure, and providing secure file sharing across different operating systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If whole disk encryption is used to secure all data on a computing device, then data security is improved, but device complexity and cost increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments data security by implementing file-level encryption rather than whole-disk encryption. Each file is encrypted independently with its own key, allowing selective encryption of only sensitive files while leaving other data unencrypted. This reduces overall system complexity while maintaining security for critical data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security measures to different files based on their sensitivity. Sensitive files receive strong encryption with unique keys, while non-sensitive files remain unencrypted or use weaker protection. This localized approach optimizes security resources and reduces unnecessary complexity.

Inventive Principle:
Principle #3Local quality

2Reliability

If software encryption is used to secure data, then data security is improved, but ease of operation deteriorates due to password management requirements

Engineering Contradiction:
Improvedata securityVSAvoiduser operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a key management server as an intermediary between users and encrypted files. This server handles password verification, key distribution, and file access coordination automatically. Users simply need to authenticate once, and the intermediary manages the complex password and key operations behind the scenes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements automatic key management where the key management server automatically generates, stores, and distributes encryption keys without requiring user intervention. Password reset and key recovery processes are automated through the intermediary server, reducing operational burden on users.

Inventive Principle:
Principle #25Self-service

3Reliability

If a password is lost in software encryption, then data security is maintained, but loss of information occurs as files cannot be recovered

Engineering Contradiction:
Improvedata securityVSAvoidencrypted file accessibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements preliminary key backup and recovery mechanisms through the key management server. Before users lose their passwords, the system has already established backup key storage and recovery procedures. When password loss occurs, the intermediary server can retrieve backup keys or facilitate password reset without data loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The key management server provides continuous feedback about key status, storage location, and recovery options to users. The system monitors authentication attempts and maintains communication channels for password recovery, ensuring users can retrieve access information when needed while maintaining security protocols.

Inventive Principle:
Principle #23Feedback

4Productivity

If cloud services are adopted to improve functionality and accessibility, then productivity is improved, but security risks increase due to centralized data storage

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments data storage and encryption by implementing client-side encryption before data leaves the user's device. Each file is encrypted locally with unique keys, then uploaded to cloud storage. This segmentation ensures that even though data is centralized in the cloud, security is distributed and decentralized through individual file-level encryption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different security measures to different files in the cloud based on their sensitivity. Sensitive files receive strong encryption with restricted access keys, while less sensitive files may use weaker protection or broader access permissions. This localized security approach maintains high productivity while protecting critical data in the cloud environment.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8984611B2System, apparatus and method for securing electronic data independent of their location
Publication Date: 2015.03.17 I THINK SECURITY
  • US8984611B2 patent drawing
  • US8984611B2 patent drawing
  • US8984611B2 patent drawing

AI summary

The present disclosure relates to a system, apparatus and method for securing electronic files and folders independent of their location. A computer network implemented system for securing data is provided. The system includes a central server (400) that manages access to a secure data architecture that enables one or more data security operations including data encryption, data decryption and secure data sharing. A security appliance (200) is also provided that is interoperable with each of one or more computer devices (100) to integrate each computer device (100) into the secure architecture so as to enable data security operations at each computer device, by authenticating a user of each computer device (100) to the security appliance (200) and to the central server (400).