Offsite Key Storage Encryption System for Quantum-Resistant Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data storage systems face challenges in securely separating encryption keys from ciphertext, particularly in large and complex systems, where key theft can compromise data security, and existing cryptographic technologies are vulnerable to quantum computer attacks.

Innovation Solution

An encrypted data storage system utilizing offsite key storage with a key control center, offsite key storage system, and data encryption/decryption storage system, employing quantum key distribution technology to securely generate and manage quantum keys for encryption and decryption processes, ensuring keys are stored separately from data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption keys are stored in the same database as ciphertext, then key transmission security is improved, but key theft risk increases due to external terminal connections

Engineering Contradiction:
Improvekey transmission securityVSAvoidkey theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the key storage function from the database system and creates a separate key storage device. The key storage device is physically isolated from external networks, while the database remains connected for data operations. This separation eliminates the vulnerability where external terminals could potentially steal keys through the database connection, while still allowing encrypted data to be stored and accessed securely.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If encryption keys are stored separately from ciphertext in a strictly secured location, then data security is improved, but system complexity and key management difficulty increase

Engineering Contradiction:
Improvedata securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key control device as an intermediary between the key storage device and the database system. This key control device manages key distribution, updates, and retrieval operations, abstracting the complexity of secure key management from the overall system. The intermediary handles cryptographic operations and key lifecycle management, making the system easier to operate while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If traditional cryptographic technologies are used for key protection, then implementation simplicity is maintained, but security vulnerability to quantum computer attacks increases

Engineering Contradiction:
Improveimplementation simplicityVSAvoidquantum attack vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent changes the fundamental parameter of cryptographic security from classical mathematical problems to quantum mechanical principles. By using quantum key distribution, the system achieves security based on the laws of quantum physics rather than computational complexity. This parameter change makes the system resistant to quantum computer attacks while maintaining implementation feasibility through established quantum cryptographic protocols.

Inventive Principle:
Principle #35Parameter changes

4Productivity

If plaintext storage is used for data, then storage speed and accessibility are improved, but data leakage and theft risks increase dramatically

Engineering Contradiction:
Improvestorage speedVSAvoiddata leakage risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the data storage system into two distinct components: a database for storing encrypted data and a separate key storage device for storing decryption keys. This segmentation allows the database to operate at high speed for data access while the keys remain protected in isolation. The separation ensures that even if the database is compromised, the actual data remains protected without the keys, maintaining both productivity and security.

Inventive Principle:
Principle #1Segmentation

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution securely and reliably separates encryption keys from data, enhancing data storage security by preventing simultaneous key and data theft, and is resistant to quantum computer attacks, applicable to structured and unstructured data, cloud storage, and disaster recovery scenarios.

Implementation Method 1

employing quantum key distribution technology to securely generate and manage quantum keys for encryption and decryption processes

Methodology Applied
Scientific EffectQuantum key distribution:

Data Source

PatentEP3691216B1Key offsite storage-based data encryption storage system and method
Publication Date: 2023.08.30 ANHUI QASKY QUANTUM SCI & TECH CO LTD
  • EP3691216B1 patent drawingFigure 1~2
  • EP3691216B1 patent drawingFigure 3
  • EP3691216B1 patent drawingFigure 4

AI summary

The present disclosure provides an encrypted data storage system and method based on offsite key storage, comprising a key control center, an offsite key storage system, and a data encryption / decryption storage system. The offsite key storage system comprises a first key control device, a key storage device, and a first quantum key distribution device. The data encryption / decryption storage system comprises a second key control device, a data encryption / decryption storage device, and a second quantum key distribution device. The first quantum key distribution device is in quantum communication connection with the second quantum key distribution device. The first key control device is communicatively connected with the key storage device and the first quantum key distribution device, respectively. The second key control device is communicatively connected with the data encryption / decryption storage device and the second quantum key distribution device, respectively. The present disclosure is capable of securely and reliably setting the offsite key storage system and the data encryption / decryption storage system separately at any distance, so that encryption / decryption keys are stored separately and securely from data.