Secure Key Generator for Offline IT Service Continuity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge is to securely hold sensitive IT service continuity documents offline while maintaining their portability and flexibility for activation and use, especially in the context of potential cyber-attacks that may destroy data networks.

Innovation Solution

A key generator is used to create secure keys for encrypting and decrypting IT service continuity documents. The key generator generates pseudo-random numbers, shift values, and substitution numbers to create a secure key, which is then used to encrypt the documents. This system includes multiple data storage devices for encrypted documents and key storage devices for secure keys, ensuring that no single person holds both the documents and the decryption key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IT service continuity documents are stored offline to protect against cyber-attacks, then data security is improved, but portability and flexibility of activation are worsened

Engineering Contradiction:
Improvedata securityVSAvoidportability and flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the security mechanism by separating encryption keys from the documents themselves. Multiple independent key storage devices hold different keys, and documents are encrypted with multiple keys. This segmentation allows documents to be stored offline securely while enabling flexible activation through multiple authorized keys, resolving the contradiction between security and portability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces key storage devices as intermediaries between the encrypted documents and the decryption process. These intermediaries securely store encryption keys separately from the documents, allowing offline storage for security while maintaining portability through the key storage devices that can be accessed when needed, thus balancing security and flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption keys are stored separately from documents to enhance security, then data protection is improved, but system complexity is worsened

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the security architecture into segmented components: multiple key storage devices, multiple encryption keys, and encrypted documents. Each component serves a specific function and can be independently managed. This segmentation enhances data protection by ensuring that no single point of failure exists while managing complexity through modular, well-defined components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The key storage devices serve multiple functions: storing encryption keys, enabling document decryption, and providing security authentication. The encrypted documents can be accessed by multiple authorized keys. This multi-functionality reduces the need for separate dedicated components, thereby enhancing security without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multiple keys and storage devices are used to ensure security, then data integrity is improved, but ease of operation is worsened

Engineering Contradiction:
Improvedata integrityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by pre-generating multiple encryption keys and pre-distributing them to different key storage devices before the actual document storage and retrieval operations. This preliminary setup ensures that when documents need to be accessed, the decryption process can proceed smoothly using any of the pre-configured keys, maintaining data integrity while simplifying the operational process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service operation where any authorized user can access encrypted documents by presenting the correct encryption key from the key storage devices. The system automatically handles the decryption process without requiring complex manual intervention. This self-service mechanism maintains high data integrity through multiple keys while significantly improving ease of operation for authorized users.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12225122B2Method and service continuity encrypted storage solution for secure off-line distribution
Publication Date: 2025.02.11 SAUDI ARABIAN OIL CO
  • US12225122B2 patent drawing
  • US12225122B2 patent drawing
  • US12225122B2 patent drawing

AI summary

A key generator provides a secure key for distribution of Information Technology (IT) service continuity documents. The key generator generates a pseudo-random number, a pseudo-random shift value, and a pseudo-random substitution number. The key generator creates a digit of the secure key by selecting a first digit and a second digit of the pseudo-random shift value based on the pseudo-random substitution number, swapping the first digit and the second digit, calculating a modified American Standard Code for Information Interchange (ASCII) character with the pseudo-random number and the pseudo-random shift value with the first digit and the second digit swapped, and populating a digit of the secure key with the modified ASCII character. The key generator repeats creating the digit of the secure key for a length of the secure key.