Format-Preserving Encryption Coupling for Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for protecting sensitive data within a domain, such as encryption, often fail to preserve the format and syntax of the data, leading to compatibility issues with existing processes and systems, and are not effectively implemented across multiple locations, resulting in unauthorized access and data loss.

Innovation Solution

The implementation of a consistent format-preserving encryption (C-FPE) system that uses transparent couplings, such as proxy services and shim APIs, to translate sensitive data elements into protected forms while maintaining their syntax and internal semantics, ensuring consistent encryption across the domain and reversing it for external interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional encryption is used to protect sensitive data, then data security is improved, but data format and syntax are lost making existing processes incompatible

Engineering Contradiction:
Improvedata securityVSAvoidprocess compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies parameter changes by transforming the encryption approach to preserve data format parameters. Format-Preserving Encryption (FPE) changes the encryption parameters to ensure that encrypted output maintains the same format, length, and syntax characteristics as the original plaintext, allowing existing processes to continue functioning without modification while maintaining security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces transparent couplings as intermediary components that mediate between existing processes and encrypted data. These couplings act as mediators that automatically perform format-preserving encryption/decryption operations, allowing processes to interact with encrypted data as if it were plaintext while maintaining security through the intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is encrypted to prevent unauthorized access, then security is improved, but data must be consistently encrypted across multiple locations which increases system complexity

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a standardized format-preserving encryption system that can be consistently applied across multiple locations and data types. The same FPE algorithm and transparent coupling architecture can be universally deployed throughout the distributed system, ensuring consistent encryption behavior without requiring location-specific customizations, thereby reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies preliminary action by pre-configuring transparent couplings at data entry points and establishing consistent encryption rules before data flows through the system. This preliminary setup ensures that all sensitive data is automatically and consistently encrypted across multiple locations without requiring complex real-time coordination or manual intervention during data processing.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If transparent couplings are inserted to preserve data format, then process compatibility is improved, but data flow paths become more complex

Engineering Contradiction:
Improveprocess compatibilityVSAvoiddata flow complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies the taking out principle by extracting the encryption/decryption logic from the main data processing flow and encapsulating it within transparent couplings. This extraction allows the core business processes to remain simple and unchanged while the encryption functionality is isolated in separate, manageable coupling components that automatically handle format preservation without interfering with the primary data flow.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8990553B2Perimeter encryption method and system
Publication Date: 2015.03.24 CA TECH INC
  • US8990553B2 patent drawing
  • US8990553B2 patent drawing
  • US8990553B2 patent drawing

AI summary

A method and system for consistent format preserving encryption (C-FPE) are provided to protect data while the data is in a domain while allowing encrypted data to be treated inside the domain as if it were the unencrypted data. The method includes inserting a coupling into a data flow at a perimeter of the domain, and translating a data element from an unprotected data element to a protected data element using the coupling such that the data element is a protected data element within the domain.