Granular Textual String Encryption for Untrusted Storage Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption methods for digital data transmitted over communication networks lack sufficient granularity, failing to simultaneously meet the security requirements of multiple hosted applications, particularly in scenarios where user data is stored on remote servers beyond the user's control, leading to privacy and integrity risks.

Innovation Solution

A system and method that employs highly granular cryptographic techniques to encrypt discrete textual character strings at the client terminal before transmission to a network node, allowing the network node to store and process the data without decryption, while enabling authorized clients to decrypt the data for use, thereby maintaining user privacy and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is stored on remote servers for hosted applications, then service accessibility and functionality are improved, but user privacy and data integrity are compromised due to lack of control

Engineering Contradiction:
Improveservice accessibilityVSAvoiddata integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments data into encrypted portions that can be selectively stored and processed. The encryption is applied at a granular level allowing specific data fields to be encrypted while others remain accessible, enabling the system to maintain both security and functionality simultaneously

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an encryption layer as an intermediary between the user and the remote server. This intermediary protects data integrity while allowing the server to still process and store the encrypted data, thus resolving the contradiction between accessibility and integrity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is applied to all data transmitted over networks, then data security is improved, but application functionality and ease of use are reduced

Engineering Contradiction:
Improvedata securityVSAvoidapplication functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by encrypting only specific portions of data that require security protection, while leaving other portions unencrypted and fully accessible to applications. This selective encryption approach maintains application functionality while providing security where needed

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial encryption rather than full encryption of all data. This partial action allows the system to achieve sufficient security for sensitive data while avoiding the excessive action of encrypting everything, thereby maintaining ease of operation and application functionality

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If granular encryption of discrete textual strings is implemented, then data privacy and security are improved, but system complexity and processing overhead are increased

Engineering Contradiction:
Improvedata privacyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the encryption process into discrete operations on individual textual strings rather than requiring encryption of entire data structures. This segmentation reduces the complexity of implementation while maintaining strong privacy protection for each discrete data element

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses cryptographic copying mechanisms where encrypted data can be transmitted and stored without decryption, allowing the system to maintain security while reducing processing complexity. The encrypted copies can be processed by the server without requiring complex decryption operations

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10025940B2Method and system for secure use of services by untrusted storage providers
Publication Date: 2018.07.17 CYBER ARK SOFTWARE LTD
  • US10025940B2 patent drawing
  • US10025940B2 patent drawing
  • US10025940B2 patent drawing

AI summary

A method for encrypting data. The method comprises receiving, from a user, via a client terminal, digital content including at least one textual string for filling in at least one field in a document managed by a network node via a computer network, encrypting the at least one textual string, and sending the at least one encrypted textual string to the network node via the computer network so as to allow filling in the at least one field with the at least one encrypted textual string. The network node is configured for storing and retrieving the at least one textual encrypted string without decrypting.