Format-Preserving Encryption for Valid Checksum Data Strings
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional encryption techniques alter the format of data items, making it difficult to selectively access or process sensitive information, and existing format-preserving encryption algorithms may not maintain valid checksums or relationships between characters, leading to compatibility issues with software applications.
Innovation Solution
Format-preserving encryption and decryption algorithms that maintain the original format of data strings, such as credit card numbers, by using a block cipher-based approach and index mappings, ensuring that the checksum remains valid and allowing for selective encryption and decryption without altering the string format.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional encryption algorithms (AES, DES) are used to encrypt sensitive data, then data security is improved, but the format of the encrypted data is altered making it incompatible with legacy systems and difficult to selectively access
Solution Approach 1:
The patent applies parameter changes by modifying the encryption algorithm's output parameters to match the input format. The FPE algorithm transforms the ciphertext format parameters (length, character set, structure) to be identical to the plaintext format, allowing encrypted data to remain compatible with legacy systems while maintaining security.
Solution Approach 2:
The patent segments the encryption process into format-preserving transformation steps. The block cipher is applied in a controlled manner with index mappings that ensure each character position in the ciphertext corresponds to the same position in the plaintext, maintaining format integrity while providing selective encryption capability.
2Adaptability or versatility
If format-preserving encryption is used to maintain data format, then compatibility with legacy systems is improved, but checksum validity and character relationships may be lost
Solution Approach 1:
The patent applies preliminary action by computing and storing the checksum of the plaintext before encryption. This pre-computed checksum is then used to verify or regenerate the checksum for encrypted data, ensuring that checksum validity is maintained throughout the encryption process without compromising format preservation.
Solution Approach 2:
The patent implements feedback mechanisms where the encryption process monitors and adjusts character transformations to maintain checksum validity. The system continuously checks whether the encrypted output satisfies checksum constraints and applies corrective transformations if needed, ensuring both format preservation and checksum integrity.
3Productivity
If selective encryption of individual data items is implemented, then data access efficiency is improved, but system complexity increases
Solution Approach 1:
The patent extracts the encryption capability to the application level rather than requiring system-wide encryption infrastructure. Individual data items can be encrypted on-demand using the FPE algorithm without affecting other parts of the system, reducing overall system complexity while enabling selective encryption where it is actually needed.
Data Source
AI summary
Format preserving encryption (FPE) cryptographic engines are provided for performing encryption and decryption on strings. A plaintext string may be converted to ciphertext by repeated application of a format preserving encryption cryptographic algorithm. Following each application of the format preserving cryptographic algorithm, the resulting version of the string may be analyzed to determine whether desired string constraints have been satisfied. If the string constraints have not been satisfied, further applications of the format preserving cryptographic algorithm may be performed. If the string constraints have been satisfied, the current version of the string may be used as an output for the cryptographic engine.


