Selective Data Encryption for Unsecured Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems fail to effectively secure data communications across unsecured networks, particularly in environments where sensitive information is transmitted or stored, as they lack robust mechanisms to prevent unauthorized access, especially from insiders and when accessing open or public networks.

Innovation Solution

A method and system for providing a thin client that utilizes a programmable circuit with a memory-based filter to define access lists for communities of interest, enabling selective encryption and transmission of data packets, along with an authorization system that provides encryption keys and filters to ensure secure access to network-based services, even over unsecured networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is transmitted in plaintext format across networks, then communication efficiency and ease of operation are improved, but security and protection against unauthorized access deteriorate

Engineering Contradiction:
Improvecommunication efficiencyVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments data into multiple portions and transmits them through different networks (secured and unsecured). This allows the system to maintain communication efficiency while improving security, as the complete data cannot be reconstructed without all portions. The segmentation principle directly resolves the contradiction by enabling plaintext transmission of individual segments (maintaining ease of operation) while protecting the complete information (improving reliability).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary system that manages the segmentation, encryption, and reassembly of data portions. This intermediary handles the complex security operations, allowing end users to communicate efficiently without manual security management while the system automatically ensures data protection through its intermediary mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical networks are segregated by security level to protect sensitive data, then data security is improved, but device complexity and infrastructure expense increase

Engineering Contradiction:
Improvedata securityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple network types (secured and unsecured networks) into a single infrastructure that can handle both sensitive and non-sensitive communications. By combining networks rather than maintaining separate physical infrastructures, the system reduces device complexity and infrastructure expense while maintaining data security through logical segmentation and selective encryption of data portions.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal network infrastructure that can simultaneously handle both secured and unsecured communications. The system allows a single network to serve multiple security levels by dynamically applying encryption and segmentation to different data portions, eliminating the need for separate physical networks for each security level and thereby reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If encryption is applied to all data transmissions, then data security is improved, but processing time and energy consumption increase

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies encryption selectively rather than universally - only encrypting specific portions of data that require protection, while leaving other portions in plaintext. This partial application of encryption maintains data security for sensitive information while minimizing the processing time and energy overhead associated with encrypting all data transmissions.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If access control is implemented to prevent unauthorized access to networks, then security is improved, but ease of operation and user accessibility deteriorate

Engineering Contradiction:
Improveaccess control securityVSAvoiduser accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where the system automatically manages access control, segmentation, and encryption without requiring user intervention. Users can access resources seamlessly while the system autonomously handles security operations, thereby maintaining both strong access control security and ease of operation through automated security management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9525666B2Methods and systems for managing concurrent unsecured and cryptographically secure communications across unsecured networks
Publication Date: 2016.12.20 UNISYS CORP
  • US9525666B2 patent drawing
  • US9525666B2 patent drawing
  • US9525666B2 patent drawing

AI summary

An endpoint, method, and authorization server are disclosed which can be used to allow concurrent secure and clear text communication. An endpoint includes a computing system including a programmable circuit operatively connected to a memory and a communication interface, the communication interface configured to send and receive data packets via a data communications network. The endpoint also includes a filter defined in the memory of the computing system, the filter configured to define one or more access lists, each access list defining a group of access permissions for a community of interest. The community of interest includes one or more users, and an access list from among the one or more access lists defines a set of clear text access permissions associated with a community of interest. The endpoint also includes a driver executable by the programmable circuit, the driver configured to cooperate with the communication interface to send and receive data packets via the data communications network. The driver is also configured to selectively split and encrypt data into a plurality of data packets to be transmitted via the data communications network based at least in part upon the contents of the one or more access lists.