Secure Data Migration Between Terminals With Different Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies for migrating confidential data between terminals face challenges due to mismatches in security authentication levels and encryption algorithms, leading to potential security vulnerabilities when terminals use different encryption methods and authentication standards.
Innovation Solution
A migration apparatus that identifies the encryption algorithms used by both terminals, re-protects the data according to a security policy table, and ensures secure transmission by matching encryption strengths and authentication levels, preventing data from being migrated to terminals with lower security specifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If confidential data is migrated between terminals using different encryption algorithms, then data compatibility between terminals is improved, but security strength mismatch occurs between terminals
Solution Approach 1:
The migration apparatus serves as an intermediary between the first terminal and second terminal, receiving encrypted confidential data from the first terminal, identifying its encryption algorithm, re-encrypting it with a different algorithm, and transmitting to the second terminal. This intermediary process enables compatibility between terminals using different encryption algorithms while maintaining security through controlled transformation.
Solution Approach 2:
The system changes the encryption algorithm parameter from the first algorithm used in the source terminal to a second algorithm used in the destination terminal. The migration apparatus identifies the source encryption algorithm, selects an appropriate target algorithm based on the second terminal's capabilities, and performs re-encryption, thereby adapting the data to the destination environment while maintaining security equivalence.
2Adaptability or versatility
If terminals with different security authentication levels exchange confidential data, then system versatility is improved, but security authentication level mismatch occurs
Solution Approach 1:
The migration apparatus acts as a security intermediary that verifies the credentials and security authentication level of both terminals before enabling data migration. It identifies the encryption algorithms and security levels of both source and destination terminals, and only permits migration when security equivalence is confirmed, preventing authentication level mismatches while allowing versatile terminal compatibility.
3Reliability
If confidential data is protected with strong encryption, then data security is improved, but ease of migration between terminals with different algorithms deteriorates
Solution Approach 1:
The migration apparatus automatically changes the encryption algorithm parameter from the source terminal's algorithm to the destination terminal's algorithm. It identifies the source encryption method, selects an appropriate target algorithm, and performs re-encryption without requiring manual intervention, thereby maintaining strong security while facilitating easy migration between terminals with different cryptographic implementations.
Solution Approach 2:
The migration apparatus serves as an automated intermediary that handles the complex re-encryption process between terminals using different encryption algorithms. It receives encrypted data from the first terminal, automatically identifies the encryption algorithm, performs the transformation to the second algorithm, and transmits to the second terminal, making the migration process easy despite security complexity.
Data Source
AI summary
Provided is a migration system considering security authentication levels and data protection strength levels of the both security devices between which data is migrated. A first terminal includes a mechanism for protecting data by a private key in the public key method held by TPM, and a second terminal includes a key in the private key method encrypted by the private key in the public key method held by TPM and a mechanism for protecting the data by the key. A Migration Authority holds a security policy table describing a security policy and judges whether data movement from the first terminal to the second terminal is enabled according to the security policy table.


