Security Record Transfer via Encrypted Queues
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security products vary in data protection and format translation, failing to reliably secure the flow of security information between scanning tools and monitoring applications, and often leave unencrypted data vulnerable to interception and modification.
Innovation Solution
A security information transfer system that encrypts all transfers of security information, minimizes unencrypted data storage time, and simplifies integration by translating tool output for monitoring applications, using a subsystem with input monitoring agents, transport processing engines, secure transfer queues, and output monitoring agents to manage and secure the flow of security records.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If security information is transferred in unencrypted form for processing, then integration and processing of security records is simplified, but data protection and security against interception are compromised
Solution Approach 1:
The system performs preliminary encryption of security information at the source (scanning tool) before transfer, and preliminary decryption only at the final destination (monitoring application). This eliminates the need for intermediate unencrypted storage or processing, resolving the contradiction by maintaining security while enabling seamless integration through automated end-to-end encryption/decryption.
Solution Approach 2:
The patent introduces secure transfer queues and transport processing engines as intermediaries that handle encrypted data transmission. These intermediaries maintain security during transfer while providing the necessary routing and processing functions, thus protecting data without complicating the integration process.
2Productivity
If security information is stored in unencrypted form for processing, then processing speed and accessibility are improved, but vulnerability to unauthorized access and modification increases
Solution Approach 1:
Encryption is performed preliminarily at the source before any transfer or processing occurs. The encrypted form is maintained throughout the entire transfer and storage process, eliminating the window of vulnerability. Decryption occurs preliminarily only at the final destination before processing, thus maintaining both security and processing efficiency.
Solution Approach 2:
The patent creates a secure 'inert environment' by maintaining security information in encrypted form throughout the system. This encrypted state acts as a protective atmosphere that prevents unauthorized access and modification, while the system's automated decryption capabilities ensure that processing speed is not compromised.
3Adaptability or versatility
If different security products use different data formats, then product versatility and functionality are enhanced, but format translation complexity and integration difficulty increase
Solution Approach 1:
The patent implements a universal secure transfer interface that can handle multiple security record formats through automated format detection and translation. The secure transfer queue and transport processing engine are designed to work with various scanning tool output formats while maintaining a standardized encrypted transfer protocol, thus providing versatility without increasing complexity for the user.
Solution Approach 2:
The system performs self-service format translation through automated detection and conversion mechanisms. When security information is transferred, the system automatically identifies the source format, translates it to the required format, and maintains encryption throughout. This eliminates the need for manual configuration or complex user-managed translation processes.
Data Source
AI summary
An input monitoring agent detects storage of a security record by a security scanning application, encrypts a copy of the security record, and deletes the security record. A secure transfer queue decrypts the encrypted security record, translates the security record for use by a security monitoring application, and encrypts the translated security record. An output monitoring agent predicts when a security monitoring application will attempt to import a new security file, decrypts and stores the encrypted translated security record as the new security file, and deletes the new security file when the security monitoring application has completed importation.


