Query Transformer Annotations for Multi-Domain Encryption Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity and inefficiency of managing different encryption mechanisms across multiple physical locations for data processing, particularly in client-server communication, lead to errors and reduced efficiency in data processing, compromising security and complicating data-analyst tasks.

Innovation Solution

A transformer module that analyzes client queries, identifies appropriate encryption mechanisms, and adds security-specific annotations, allowing seamless data access and processing across different domains and schemes, using a lattice-based security policy to ensure compatibility and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If different encryption mechanisms are used for different data, then security is improved, but device complexity increases and ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidencryption mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a transformer module as an intermediary component between the query interface and the data storage system. This transformer automatically selects and applies appropriate encryption mechanisms based on data sensitivity labels, eliminating the need for users to manually manage multiple encryption schemes. The transformer acts as a mediator that handles the complexity of encryption mechanism selection and application, thereby improving security while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes encryption parameters based on data sensitivity labels. Different data elements are assigned different sensitivity levels (e.g., public, internal, confidential, restricted), and the encryption mechanism automatically adjusts its parameters accordingly. This allows the system to apply stronger encryption only where necessary, improving overall security posture while avoiding the complexity of uniformly applying maximum encryption to all data.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If all data is encrypted according to the highest standard, then security is improved, but productivity decreases due to increased complexity and processing overhead

Engineering Contradiction:
ImprovesecurityVSAvoiddata processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements local quality by applying different encryption standards to different data elements based on their specific sensitivity requirements. Rather than uniformly encrypting all data with the highest standard, the system assigns encryption levels locally to each data element according to its sensitivity label. This selective approach maintains high security for sensitive data while reducing processing overhead for less sensitive data, thereby improving overall productivity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system applies partial encryption action by encrypting only the portions of data that require protection based on their sensitivity labels. Not all data needs maximum encryption strength - the system applies encryption selectively and proportionally to the actual security needs of each data element. This partial action approach avoids the excessive processing overhead of encrypting everything at maximum strength while still providing adequate security where needed.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If encryption mechanisms are differentiated for different data types, then security is improved, but ease of operation deteriorates as data-analysts must account for multiple mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoidquery formulation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The transformer module implements self-service by automatically selecting and applying the appropriate encryption mechanism based on the sensitivity labels of the data being accessed. Data analysts no longer need to manually determine which encryption scheme to use - the system autonomously handles this decision-making process. The transformer examines the query, identifies the sensitivity requirements of the target data, and automatically applies the correct encryption mechanism, thereby maintaining security while dramatically improving ease of operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The transformer serves as an intermediary layer between the simple query interface and the complex encryption infrastructure. Data analysts formulate straightforward queries without needing to understand or specify encryption details. The transformer mediates between these simple queries and the underlying encryption mechanisms, automatically translating user intent into appropriately encrypted data access operations. This intermediary layer shields users from encryption complexity while ensuring security requirements are met.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If data is accessed across networks from different physical locations, then productivity is improved through distributed processing, but security risks increase due to transmission vulnerabilities

Engineering Contradiction:
Improvedistributed data processing efficiencyVSAvoidnetwork transmission security risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary encryption actions on data before it leaves the storage system. Data is encrypted at the source according to its sensitivity labels before being transmitted across networks to distributed processing locations. This preliminary security measure ensures that data remains protected during transmission and processing, mitigating network security risks while enabling distributed processing productivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption parameters are dynamically adjusted based on data sensitivity requirements. Highly sensitive data receives stronger encryption parameters before network transmission, while less sensitive data uses lighter encryption. This parameter adaptation allows the system to maintain strong security for critical data during network transmission while minimizing overhead for less sensitive data, thereby supporting distributed processing efficiency.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250371012A1Accessing data via a transformer module that adds security-specific annotations to a query
Publication Date: 2025.12.04 UNIVERSITÀ DELLA SVIZZERA ITALIANA (USI)
  • US20250371012A1 patent drawing
  • US20250371012A1 patent drawing
  • US20250371012A1 patent drawing

AI summary

In a computer system with multiple physical computers at different physical locations, a transformer module receives an original query from a client-side computer, analyzes the query statements and annotates the query. The transformer module forwards the annotated query to server-computers. This approach allows a data-analyst 190-ALPHA to use a query that is relatively simple, wherein a data-analyst 190-BETA who does not benefit from the transformer module would have to write a more complex query.