Inline Data Encryptor for Secure Cloud Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Ensuring the security of computing resources and associated data across multiple geographic networks is challenging, especially as configurations grow in size and complexity, due to the need for secure data transmission and storage while reducing infrastructure costs.
Innovation Solution
The implementation of an Inline Data Encryptor (IDE) that connects to user devices to encrypt data before storage with a service provider, using a physical key or Crypto Ignition Key (CIK) for authentication and encryption, operating as a proxy between the user and the service provider to protect data both in transit and at rest.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is transmitted across multiple geographic networks, then accessibility and service provision are improved, but data security and protection against unauthorized access deteriorate
Solution Approach 1:
The patent applies preliminary action by encrypting data before it is transmitted across networks and before it is stored. The Inline Data Encryptor performs encryption in advance, transforming readable data into ciphertext that cannot be understood without the decryption key. This preliminary encryption ensures that even if data is intercepted during transmission or accessed during storage, it remains unintelligible to unauthorized parties.
Solution Approach 2:
The patent introduces an intermediary device called the Inline Data Encryptor that sits between the user's computing device and the service provider's storage system. This intermediary performs the critical function of encrypting data before it leaves the user's control and decrypting it before delivery to the user, thereby mediating the data transmission process while maintaining security throughout the entire chain.
2Object-affected harmful factors
If encryption is implemented to protect data in transit and at rest, then data security is improved, but device complexity and infrastructure requirements worsen
Solution Approach 1:
The patent implements self-service by enabling the user's computing device to perform encryption and decryption operations locally using its own cryptographic capabilities. The user's device generates and stores encryption keys, and uses them to encrypt data before transmission and decrypt data upon receipt. This eliminates the need for complex centralized encryption infrastructure while maintaining strong security.
Solution Approach 2:
The patent extracts the encryption and decryption functions from a centralized infrastructure and places them directly on the user's computing device. By taking out these cryptographic operations from the server-side infrastructure, the system reduces the complexity of the service provider's infrastructure while maintaining data security through client-side processing.
3Object-affected harmful factors
If centralized encryption infrastructure is used, then data protection is improved, but loss of user control over cryptographic keys worsens
Solution Approach 1:
The patent implements self-service by enabling the user's computing device to perform encryption and decryption operations locally using its own cryptographic capabilities. The user's device generates and stores encryption keys, and uses them to encrypt data before transmission and decrypt data upon receipt. This eliminates the need for complex centralized encryption infrastructure while maintaining strong security.
Solution Approach 2:
The patent applies segmentation by dividing the encryption key management function between the user's device and the service provider's infrastructure. The user's device holds the private decryption keys locally, while the service provider maintains only the encryption capability. This segmentation ensures that no single entity controls both encryption and decryption, giving users full control over their data while maintaining provider protection capabilities.
Data Source
AI summary
Organizations maintain and generate large amount of sensitive information that needs to be saved electronically and there is a need to store that data remotely with a data storage service provider. To prevent unauthorized access to the information stored by organizations on storage provided by the service provider special cryptographic devices, such as an Inline Data Encryptor, can be used to ensure that the information remains secret. The Inline Data Encryptor uses a fill device with secret cryptographic information to encrypt data.


