Format-Preserving Encryption for Valid Checksum Data Strings

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional encryption techniques alter the format of data items, making it difficult to selectively access or process sensitive information, and existing format-preserving encryption algorithms may not maintain valid checksums or relationships between characters, leading to compatibility issues with software applications.

Innovation Solution

Format-preserving encryption and decryption algorithms that maintain the original format of data strings, such as credit card numbers, by using a block cipher-based approach and index mappings, ensuring that the checksum remains valid and allowing for selective encryption and decryption without altering the string format.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional encryption algorithms (AES, DES) are used to encrypt sensitive data, then data security is improved, but the format of the encrypted data is altered making it incompatible with legacy systems and difficult to selectively access

Engineering Contradiction:
Improvedata securityVSAvoidformat compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies parameter changes by modifying the encryption algorithm's output parameters to match the input format. The FPE algorithm transforms the ciphertext format parameters (length, character set, structure) to be identical to the plaintext format, allowing encrypted data to remain compatible with legacy systems while maintaining security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments the encryption process into format-preserving transformation steps. The block cipher is applied in a controlled manner with index mappings that ensure each character position in the ciphertext corresponds to the same position in the plaintext, maintaining format integrity while providing selective encryption capability.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If format-preserving encryption is used to maintain data format, then compatibility with legacy systems is improved, but checksum validity and character relationships may be lost

Engineering Contradiction:
Improveformat compatibilityVSAvoidchecksum validity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by computing and storing the checksum of the plaintext before encryption. This pre-computed checksum is then used to verify or regenerate the checksum for encrypted data, ensuring that checksum validity is maintained throughout the encryption process without compromising format preservation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the encryption process monitors and adjusts character transformations to maintain checksum validity. The system continuously checks whether the encrypted output satisfies checksum constraints and applies corrective transformations if needed, ensuring both format preservation and checksum integrity.

Inventive Principle:
Principle #23Feedback

3Productivity

If selective encryption of individual data items is implemented, then data access efficiency is improved, but system complexity increases

Engineering Contradiction:
Improvedata access efficiencyVSAvoidencryption system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts the encryption capability to the application level rather than requiring system-wide encryption infrastructure. Individual data items can be encrypted on-demand using the FPE algorithm without affecting other parts of the system, reducing overall system complexity while enabling selective encryption where it is actually needed.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9489521B2Format preserving encryption methods for data strings with constraints
Publication Date: 2016.11.08 MICRO FOCUS LLC
  • US9489521B2 patent drawing
  • US9489521B2 patent drawing
  • US9489521B2 patent drawing

AI summary

Format preserving encryption (FPE) cryptographic engines are provided for performing encryption and decryption on strings. A plaintext string may be converted to ciphertext by repeated application of a format preserving encryption cryptographic algorithm. Following each application of the format preserving cryptographic algorithm, the resulting version of the string may be analyzed to determine whether desired string constraints have been satisfied. If the string constraints have not been satisfied, further applications of the format preserving cryptographic algorithm may be performed. If the string constraints have been satisfied, the current version of the string may be used as an output for the cryptographic engine.