Multilayer Encryption for IHS Privacy Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional virtualization techniques in Information Handling Systems (IHS) are inadequate for modern computing, as they fail to account for the specific context of user access and usage, leading to complex and resource-intensive security measures that burden system performance and productivity.

Innovation Solution

Implementing multilayer encryption using a controlvault key for initial encryption and an enterprise-issued cryptographic key for a second level of encryption, with the option to use AES and lattice-based quantum computing resistant algorithms, to securely manage and access documents across various devices and networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional virtualization techniques are used to isolate protected data, then security is improved, but system complexity and resource consumption increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidvirtualization environment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security function from the complex virtualization environment by implementing encryption at the application layer. Instead of relying on the entire virtualization infrastructure for security, the solution isolates and implements encryption specifically for protected data access, removing the burden of complex security management from the virtualization layer.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different security measures to different data types and access scenarios. Rather than implementing uniform security across all virtualized environments, the solution dynamically adjusts encryption requirements based on the specific data being accessed and the user's context, reducing unnecessary complexity in low-risk scenarios while maintaining high security where needed.

Inventive Principle:
Principle #3Local quality

2Reliability

If comprehensive security protocols are implemented for all users and devices, then data protection is improved, but system performance and productivity deteriorate

Engineering Contradiction:
Improvedata protectionVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic security that adapts to changing contexts. The encryption requirements and security protocols are adjusted in real-time based on user behavior, device trust level, and data sensitivity, rather than applying static comprehensive security to all scenarios. This reduces overhead for trusted users while maintaining protection against threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security parameters such as encryption key requirements and protocol strictness based on contextual factors including user role, device security posture, and data classification. This allows the system to optimize between security and performance by adjusting parameters rather than maintaining fixed comprehensive security measures.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If encryption overhead is reduced for better performance, then productivity is improved, but security coverage and reliability worsen

Engineering Contradiction:
Improvesystem performanceVSAvoidsecurity coverage
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements partial encryption actions based on risk assessment. Instead of applying full encryption overhead to all data access operations, the system applies encryption selectively to protected data based on contextual risk factors. This reduces unnecessary encryption overhead for low-risk operations while ensuring comprehensive security coverage when needed.

Inventive Principle:
Principle #16Partial or excessive action

4Adaptability or versatility

If context-aware security is implemented, then adaptability is improved, but computational overhead and complexity increase

Engineering Contradiction:
Improvecontext adaptationVSAvoidsecurity system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service security where the system automatically assesses context and determines appropriate encryption requirements without requiring complex external security management. The context-aware security engine autonomously evaluates user behavior, device state, and data sensitivity to determine encryption needs, reducing the complexity burden on administrators while maintaining high adaptability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12003623B2Multilayer encryption for user privacy compliance and corporate confidentiality
Publication Date: 2024.06.04 DELL PROD LP
  • US12003623B2 patent drawing
  • US12003623B2 patent drawing
  • US12003623B2 patent drawing

AI summary

Systems and methods for multilayer encryption for user privacy compliance and corporate confidentiality are described. In some embodiments, an Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the IHS to: transmit, from a workspace instantiated by a local management agent to a portal managed by an enterprise: (i) a request to store a once-encrypted document, and (ii) an indication that the once-encrypted document is encrypted with a controlvault key; receive, from the portal at the workspace, a request to encrypt the once-encrypted document with an enterprise-issued cryptographic key to produce a twice-encrypted document; and transmit, from the workspace to the portal, a copy of the twice-encrypted document.