Local Encryption Key Pre-delivery for Intranet Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption systems for preventing unauthorized data outflow from Intranet to out-connecting storage devices, such as CD-Rs, are inefficient as they require significant loading and resource occupation, leading to decreased communication velocity and increased time due to back-and-forth information delivery, and lack effective protection methods for ordinary users.

Innovation Solution

An encryption system where writable files are encrypted at the user's end using an encryption key, with a database setup at the server end, allowing secure file delivery to out-connecting storage equipment, and restoring encrypted files back to the server database, utilizing asymmetric and symmetric encryption keys like PKI/RSA and Blowfish/AES, respectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is performed through back-and-forth information delivery between user's ends and server end, then data security is improved, but communication velocity decreases and time is wasted

Engineering Contradiction:
Improvedata securityVSAvoidcommunication velocity
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The encryption key is pre-delivered from the server end to the user's ends before the actual data encryption process. This preliminary action allows the user's ends to perform encryption locally without needing to communicate back-and-forth with the server during the encryption process, thereby maintaining data security while improving communication velocity and reducing time consumption.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encryption is performed through back-and-forth information delivery, then data security is improved, but system resource occupation increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem resource occupation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption key is pre-delivered and stored locally at the user's ends, enabling local encryption operations. This eliminates the need for continuous server communication during encryption, reducing system resource occupation and device complexity while maintaining data security through local encryption processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption function is extracted from the server end and moved to the user's ends. By taking out the encryption operation from the centralized server and implementing it locally at user terminals with pre-delivered keys, the system reduces server resource occupation and communication overhead while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If encryption keys are pre-delivered to user's ends, then communication efficiency is improved, but security risk may increase

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The security model is changed by using asymmetric encryption where the encryption key and decryption key are different parameters. The encryption key can be safely pre-delivered to user's ends for efficient local encryption, while the private decryption key remains securely stored at the server end. This parameter differentiation resolves the contradiction by enabling efficient communication without compromising security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7814552B2Method and apparatus for an encryption system
Publication Date: 2010.10.12 FINEART TECH CO LTD
  • US7814552B2 patent drawing
  • US7814552B2 patent drawing
  • US7814552B2 patent drawing

AI summary

This invention relates to a method and apparatus for an encryption system. The encryption system includes a server end and user's ends, in which the whole writable action about information outflow is recorded by the server end. The method of the present invention is used for encrypting the writable file by the user's ends to avoid unauthorized information outflow through out-connecting storing equipment. Therefore, all the files are just used within the Intranet of the company and the security system. Thus, the purpose of protecting information is achieved.