Selective Data Encryption for Unsecured Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems fail to effectively secure data communications across unsecured networks, particularly in environments where sensitive information is transmitted or stored, as they lack robust mechanisms to prevent unauthorized access, especially from insiders and when accessing open or public networks.
Innovation Solution
A method and system for providing a thin client that utilizes a programmable circuit with a memory-based filter to define access lists for communities of interest, enabling selective encryption and transmission of data packets, along with an authorization system that provides encryption keys and filters to ensure secure access to network-based services, even over unsecured networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is transmitted in plaintext format across networks, then communication efficiency and ease of operation are improved, but security and protection against unauthorized access deteriorate
Solution Approach 1:
The patent segments data into multiple portions and transmits them through different networks (secured and unsecured). This allows the system to maintain communication efficiency while improving security, as the complete data cannot be reconstructed without all portions. The segmentation principle directly resolves the contradiction by enabling plaintext transmission of individual segments (maintaining ease of operation) while protecting the complete information (improving reliability).
Solution Approach 2:
The patent introduces an intermediary system that manages the segmentation, encryption, and reassembly of data portions. This intermediary handles the complex security operations, allowing end users to communicate efficiently without manual security management while the system automatically ensures data protection through its intermediary mechanisms.
2Reliability
If physical networks are segregated by security level to protect sensitive data, then data security is improved, but device complexity and infrastructure expense increase
Solution Approach 1:
The patent merges multiple network types (secured and unsecured networks) into a single infrastructure that can handle both sensitive and non-sensitive communications. By combining networks rather than maintaining separate physical infrastructures, the system reduces device complexity and infrastructure expense while maintaining data security through logical segmentation and selective encryption of data portions.
Solution Approach 2:
The patent creates a universal network infrastructure that can simultaneously handle both secured and unsecured communications. The system allows a single network to serve multiple security levels by dynamically applying encryption and segmentation to different data portions, eliminating the need for separate physical networks for each security level and thereby reducing overall system complexity.
3Reliability
If encryption is applied to all data transmissions, then data security is improved, but processing time and energy consumption increase
Solution Approach 1:
The patent applies encryption selectively rather than universally - only encrypting specific portions of data that require protection, while leaving other portions in plaintext. This partial application of encryption maintains data security for sensitive information while minimizing the processing time and energy overhead associated with encrypting all data transmissions.
4Reliability
If access control is implemented to prevent unauthorized access to networks, then security is improved, but ease of operation and user accessibility deteriorate
Solution Approach 1:
The patent implements self-service mechanisms where the system automatically manages access control, segmentation, and encryption without requiring user intervention. Users can access resources seamlessly while the system autonomously handles security operations, thereby maintaining both strong access control security and ease of operation through automated security management.
Data Source
AI summary
An endpoint, method, and authorization server are disclosed which can be used to allow concurrent secure and clear text communication. An endpoint includes a computing system including a programmable circuit operatively connected to a memory and a communication interface, the communication interface configured to send and receive data packets via a data communications network. The endpoint also includes a filter defined in the memory of the computing system, the filter configured to define one or more access lists, each access list defining a group of access permissions for a community of interest. The community of interest includes one or more users, and an access list from among the one or more access lists defines a set of clear text access permissions associated with a community of interest. The endpoint also includes a driver executable by the programmable circuit, the driver configured to cooperate with the communication interface to send and receive data packets via the data communications network. The driver is also configured to selectively split and encrypt data into a plurality of data packets to be transmitted via the data communications network based at least in part upon the contents of the one or more access lists.


