Immutable Data Safe for Key Sharding and Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for managing security risks on the Worldwide Web/Public Internet are inadequate, leading to significant economic losses and breaches of private information, as evident in recent cyber-attacks on critical infrastructure and government systems.

Innovation Solution

The implementation of an immutable 'data safe' that encrypts and decrypts information using cryptographic pilot keys stored in non-volatile storage, preventing exposure and unauthorized decryption by employing secure communication protocols and hardware-based security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional encryption methods are used to protect data at rest, then data security is improved, but the computational barrier for decryption remains insufficient and keys may be exposed in case of breach

Engineering Contradiction:
Improvedata securityVSAvoidcomputational barrier
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the encryption key into multiple shards distributed across different storage locations. Instead of storing a single key, the system divides the key material into fragments that are stored separately, requiring aggregation of multiple shards to reconstruct the original key. This segmentation increases the computational barrier and security against breaches, as attackers would need to compromise multiple distributed storage locations rather than a single key repository.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If encryption keys are stored in accessible locations for decryption operations, then ease of operation is improved, but security is worsened due to potential key exposure

Engineering Contradiction:
Improvedecryption capabilityVSAvoidkey protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary key management system that mediates between key storage and decryption operations. Instead of directly storing and accessing encryption keys in easily accessible locations, the system uses key shards as intermediaries distributed across secure storage locations. The intermediary mechanism allows decryption operations to proceed by aggregating key shards through secure protocols, maintaining ease of operation while protecting key security through distributed storage and controlled access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Quantity of substance

If data is stored in external storage systems, then storage capacity is improved, but security control is worsened due to external system vulnerabilities

Engineering Contradiction:
Improvestorage capacityVSAvoidsecurity control
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent extracts the key management function from external storage systems and implements it within the storage system itself through immutable data safes. By taking out the critical key management operations from potentially vulnerable external environments and embedding them directly in the storage infrastructure with immutable protection, the system maintains the storage capacity benefits of external systems while regaining security control through internal, protected key management mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11861027B2Enhanced securing of data at rest
Publication Date: 2024.01.02 Q NET SECURITY INC
  • US11861027B2 patent drawing
  • US11861027B2 patent drawing
  • US11861027B2 patent drawing

AI summary

In one embodiment, data at rest is securely stored. A data safe performing data plane processing operations in response to requests of received read data requests, received write data requests, and received read information responses, with the data safe being immutable to processing-related modifications resulting from said performing data plane processing operations. In one embodiment, performing these data plane processing operations does not expose any pilot keys outside the data safe in clear form nor in encrypted form. The pilot keys are used to encrypt information that is subsequently stored in a storage system. One embodiment uses pilot keys to encrypt data that is subsequently stored in a storage system. One embodiment uses data cryptographic keys to encrypt data, uses the pilot keys to cryptographically-wrap (encrypt) the data cryptographic keys, and stores the cryptographically wrapped data keys and encrypted data in a storage system.