Inline Data Encryptor for Secure Cloud Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ensuring the security of computing resources and associated data across multiple geographic networks is challenging, especially as configurations grow in size and complexity, due to the need for secure data transmission and storage while reducing infrastructure costs.

Innovation Solution

The implementation of an Inline Data Encryptor (IDE) that connects to user devices to encrypt data before storage with a service provider, using a physical key or Crypto Ignition Key (CIK) for authentication and encryption, operating as a proxy between the user and the service provider to protect data both in transit and at rest.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is transmitted across multiple geographic networks, then accessibility and service provision are improved, but data security and protection against unauthorized access deteriorate

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by encrypting data before it is transmitted across networks and before it is stored. The Inline Data Encryptor performs encryption in advance, transforming readable data into ciphertext that cannot be understood without the decryption key. This preliminary encryption ensures that even if data is intercepted during transmission or accessed during storage, it remains unintelligible to unauthorized parties.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary device called the Inline Data Encryptor that sits between the user's computing device and the service provider's storage system. This intermediary performs the critical function of encrypting data before it leaves the user's control and decrypting it before delivery to the user, thereby mediating the data transmission process while maintaining security throughout the entire chain.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If encryption is implemented to protect data in transit and at rest, then data security is improved, but device complexity and infrastructure requirements worsen

Engineering Contradiction:
Improvedata securityVSAvoidinfrastructure complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the user's computing device to perform encryption and decryption operations locally using its own cryptographic capabilities. The user's device generates and stores encryption keys, and uses them to encrypt data before transmission and decrypt data upon receipt. This eliminates the need for complex centralized encryption infrastructure while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the encryption and decryption functions from a centralized infrastructure and places them directly on the user's computing device. By taking out these cryptographic operations from the server-side infrastructure, the system reduces the complexity of the service provider's infrastructure while maintaining data security through client-side processing.

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If centralized encryption infrastructure is used, then data protection is improved, but loss of user control over cryptographic keys worsens

Engineering Contradiction:
Improvedata protectionVSAvoiduser control
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling the user's computing device to perform encryption and decryption operations locally using its own cryptographic capabilities. The user's device generates and stores encryption keys, and uses them to encrypt data before transmission and decrypt data upon receipt. This eliminates the need for complex centralized encryption infrastructure while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies segmentation by dividing the encryption key management function between the user's device and the service provider's infrastructure. The user's device holds the private decryption keys locally, while the service provider maintains only the encryption capability. This segmentation ensures that no single entity controls both encryption and decryption, giving users full control over their data while maintaining provider protection capabilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9515997B1Inline data encryption
Publication Date: 2016.12.06 AMAZON TECH INC
  • US9515997B1 patent drawing
  • US9515997B1 patent drawing
  • US9515997B1 patent drawing

AI summary

Organizations maintain and generate large amount of sensitive information that needs to be saved electronically and there is a need to store that data remotely with a data storage service provider. To prevent unauthorized access to the information stored by organizations on storage provided by the service provider special cryptographic devices, such as an Inline Data Encryptor, can be used to ensure that the information remains secret. The Inline Data Encryptor uses a fill device with secret cryptographic information to encrypt data.