Format-Preserving Encryption Coupling for Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for protecting sensitive data within a domain, such as encryption, often fail to preserve the format and syntax of the data, leading to compatibility issues with existing processes and systems, and are not effectively implemented across multiple locations, resulting in unauthorized access and data loss.
Innovation Solution
The implementation of a consistent format-preserving encryption (C-FPE) system that uses transparent couplings, such as proxy services and shim APIs, to translate sensitive data elements into protected forms while maintaining their syntax and internal semantics, ensuring consistent encryption across the domain and reversing it for external interactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional encryption is used to protect sensitive data, then data security is improved, but data format and syntax are lost making existing processes incompatible
Solution Approach 1:
The patent applies parameter changes by transforming the encryption approach to preserve data format parameters. Format-Preserving Encryption (FPE) changes the encryption parameters to ensure that encrypted output maintains the same format, length, and syntax characteristics as the original plaintext, allowing existing processes to continue functioning without modification while maintaining security.
Solution Approach 2:
The patent introduces transparent couplings as intermediary components that mediate between existing processes and encrypted data. These couplings act as mediators that automatically perform format-preserving encryption/decryption operations, allowing processes to interact with encrypted data as if it were plaintext while maintaining security through the intermediary layer.
2Reliability
If data is encrypted to prevent unauthorized access, then security is improved, but data must be consistently encrypted across multiple locations which increases system complexity
Solution Approach 1:
The patent applies universality by creating a standardized format-preserving encryption system that can be consistently applied across multiple locations and data types. The same FPE algorithm and transparent coupling architecture can be universally deployed throughout the distributed system, ensuring consistent encryption behavior without requiring location-specific customizations, thereby reducing overall system complexity.
Solution Approach 2:
The patent applies preliminary action by pre-configuring transparent couplings at data entry points and establishing consistent encryption rules before data flows through the system. This preliminary setup ensures that all sensitive data is automatically and consistently encrypted across multiple locations without requiring complex real-time coordination or manual intervention during data processing.
3Adaptability or versatility
If transparent couplings are inserted to preserve data format, then process compatibility is improved, but data flow paths become more complex
Solution Approach 1:
The patent applies the taking out principle by extracting the encryption/decryption logic from the main data processing flow and encapsulating it within transparent couplings. This extraction allows the core business processes to remain simple and unchanged while the encryption functionality is isolated in separate, manageable coupling components that automatically handle format preservation without interfering with the primary data flow.
Data Source
AI summary
A method and system for consistent format preserving encryption (C-FPE) are provided to protect data while the data is in a domain while allowing encrypted data to be treated inside the domain as if it were the unencrypted data. The method includes inserting a coupling into a data flow at a perimeter of the domain, and translating a data element from an unprotected data element to a protected data element using the coupling such that the data element is a protected data element within the domain.


