Secure Data Transfer via Untrusted Nodes Using Segmented Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional peer-to-peer transfer technologies are inefficient and insecure for streaming large amounts of data, particularly when dealing with encrypted information, as they lack scalability and resilience to network topology changes, and cannot maintain data confidentiality when using untrusted intermediate nodes.

Innovation Solution

A computerized system and method that utilizes agnostic endpoints for secure communication between multiple computers, enabling horizontal scaling and complete encryption of data across the network, using clusters to store and authenticate encrypted information with public key encryption, and an agent to manage data transfer between trusted and untrusted nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional peer-to-peer transfer technology is used to transfer data across a network, then data can be transferred between nodes, but data confidentiality is lost because all data is available for viewing by all peer subsets

Engineering Contradiction:
Improvedata confidentialityVSAvoidcompatibility with untrusted intermediate nodes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments data into discrete data units that are individually encrypted and transmitted through the network. Each data unit is processed independently by intermediate nodes, allowing the system to maintain confidentiality while enabling versatile routing through untrusted nodes. The segmentation allows encrypted data to be broken into manageable chunks that can be transmitted through multiple paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary encryption layer that mediates between the data source and intermediate nodes. This encryption intermediary ensures that data remains confidential even when passing through untrusted nodes, as the intermediate nodes only handle encrypted data units without access to the plaintext. This resolves the contradiction by allowing compatibility with untrusted intermediaries while maintaining confidentiality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is encrypted for secure transmission, then data confidentiality is maintained, but conventional peer-to-peer technology cannot accommodate the encrypted data when broadcast to large numbers of users

Engineering Contradiction:
Improvedata confidentialityVSAvoiddata transfer efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system divides encrypted data into discrete data units that can be independently transmitted and reassembled. This segmentation enables efficient broadcast of encrypted data to large numbers of users, as each user receives only the encrypted units they need without requiring the entire data set. The segmented approach maintains confidentiality while improving transfer efficiency for large-scale distribution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameter of data representation from complete encrypted files to discrete encrypted data units. This parameter change allows the system to optimize transmission for different scenarios, including efficient broadcast to multiple users. By transforming the data into units with configurable properties, the system achieves both confidentiality and improved productivity in data transfer.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If the network topology changes or nodes disconnect, then network flexibility is improved, but conventional systems cannot maintain reliable data transfer

Engineering Contradiction:
Improvenetwork topology flexibilityVSAvoiddata transfer reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements dynamic routing capabilities that automatically adapt to changing network conditions. Data units can be routed through different paths based on current network topology, and the system dynamically adjusts transmission routes when nodes disconnect or new paths become available. This dynamic approach maintains reliability while embracing network flexibility and topology changes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by pre-establishing multiple potential transmission paths and preparing redundant routing options before data transfer begins. When network topology changes occur, the system can quickly switch to pre-prepared alternative routes, maintaining reliable data transfer without interruption. This preliminary preparation ensures reliability while allowing the network to remain flexible and adaptive.

Inventive Principle:
Principle #10Preliminary action

4Productivity

If conventional peer-to-peer technology is used, then data transfer can occur, but the system cannot scale to large networks due to complexity and performance limitations

Engineering Contradiction:
Improvedata transfer capabilityVSAvoidsystem scalability
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the data transfer process into independent, standardized operations that can be performed by any node in the network. This segmentation allows the system to scale to large networks, as each node only needs to handle individual data units according to standardized protocols rather than managing complex end-to-end connections. The segmented approach reduces system complexity while maintaining high data transfer capability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9912644B2System and method to communicate sensitive information via one or more untrusted intermediate nodes with resilience to disconnected network topology
Publication Date: 2018.03.06 MAGENTA SECURITY HOLDINGS LLC
  • US9912644B2 patent drawing
  • US9912644B2 patent drawing
  • US9912644B2 patent drawing

AI summary

A system and method to communicate secure information between computing machines using an untrusted intermediate with resilience to disconnected network topology. The system and method utilize agnostic endpoints that are generalized to be interoperable among various systems, with their functionality based on their location in a network. The system and method enable horizontal scaling on the network. One or more clusters may be set up in a location within a network or series of networks in electronic communication, e.g., in a cloud or a sub-network, residing between a secure area of the network(s) and an unsecure area such as of an external network or portion of a network. The horizontal scaling allows the system to take advantage of a capacity of a local network. As long as an agent has connectivity to at least one locale of the network, the agent is advantageously operable to move data across the system.