Indexed Data Pad Encryption for Long-Term Storage Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in securely storing data for varying durations in network computing and network data storage systems, where existing encryption methods may become insecure over long periods due to advancements in computing resources, making it difficult to maintain long-term data security.

Innovation Solution

The use of modifications of one-time pads combined with layered encryption methods, where multiple iterations of encryption processes are performed, using different random data pads for each encryption, and periodically re-encrypting base data pads with state-of-the-art cryptography to increase the difficulty of decryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing encryption methods are used for long-term data storage, then data can be stored and retrieved efficiently, but the encryption becomes insecure over time due to advancements in computing resources

Engineering Contradiction:
Improvelong-term data securityVSAvoidresistance to computing resource advancements
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic encryption by periodically re-encrypting data with updated cryptographic keys and algorithms. The encryption scheme adapts over time by incorporating current state-of-the-art cryptography, ensuring that even as computing resources advance, the encrypted data remains secure through continuous key rotation and algorithm updates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes cryptographic parameters over time by using different encryption algorithms, key lengths, and cryptographic protocols as they become more secure. The system transitions from older encryption standards to newer, more robust standards, effectively changing the security parameters to counteract advancements in computing power that could otherwise break earlier encryption methods.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If multiple encryption iterations are performed with different random data pads, then decryption complexity increases significantly, but the encryption process becomes more computationally intensive

Engineering Contradiction:
Improvedifficulty of decryption for attackersVSAvoidcomputational resources for encryption
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The patent segments the encryption process into multiple independent iterations, each using a different random data pad. Instead of applying one complex encryption scheme, the data undergoes sequential encryption rounds with varying parameters. This segmentation increases decryption difficulty because an attacker would need to reverse multiple independent encryption layers, while the computational overhead is distributed across manageable iterations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces random data pads as intermediary elements between the plaintext and the final ciphertext. These intermediate random pads act as additional layers of obfuscation that must be eliminated during decryption. Each random data pad serves as a mediator that adds complexity to the decryption process without fundamentally changing the core encryption mechanism, thereby increasing security with moderate computational cost.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11356254B1Encryption using indexed data from large data pads
Publication Date: 2022.06.07 AMAZON TECH INC
  • US11356254B1 patent drawing
  • US11356254B1 patent drawing
  • US11356254B1 patent drawing

AI summary

Techniques for encrypting data using a randomly selected data block from a set of data are described herein. An index indicates a subset of data within a data object. The data block is selected based at least in part on the index, an input to a cryptographic operation is generated from the data block, and the input to the cryptographic operation is provided to the cryptographic operation.