Selective Encryption Service Interface for Third-Party Cloud Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The shift towards cloud, SaaS, and web applications exposes security issues due to the storage of confidential information outside the corporate firewall, necessitating mechanisms for independent security of these systems.

Innovation Solution

A computer system that selectively encrypts and decrypts data based on historical analysis of client computers, using a server system to perform cryptographic operations and provide encryption as a service, with a service interface conforming to SOAP or REST, to manage encryption and decryption of data elements communicated between client computers and third-party network services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is stored in cloud services outside corporate firewall, then accessibility and convenience are improved, but security and control over confidential information deteriorate

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments data into encrypted and unencrypted portions, allowing selective encryption of sensitive data elements while leaving other data accessible. This enables cloud storage to maintain accessibility while enhancing security for confidential information through granular encryption control

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an encryption service as an intermediary between client computers and third-party network services. This service performs cryptographic operations on data elements, acting as a mediator that enables secure cloud storage while maintaining controlled access to confidential information

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If selective encryption is implemented based on historical analysis, then security is improved, but system complexity and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs historical analysis of client computers in advance to identify security risks and determine which data elements should be encrypted. By conducting this analysis beforehand, the system establishes encryption requirements before data is stored in the cloud, reducing real-time complexity while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables the system to automatically perform historical analysis and determine encryption needs without requiring manual intervention. The system self-manages the identification of sensitive data elements and applies appropriate encryption, reducing operational complexity while enhancing security

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250097202A1Selective encryption service interface for use with third-party network services
Publication Date: 2025.03.20 STRATOKEY PTY LTD
  • US20250097202A1 patent drawing
  • US20250097202A1 patent drawing
  • US20250097202A1 patent drawing

AI summary

A network computer system implements a service interface to provide encryption as a service, performs cryptographic operations on a plurality of data elements communicated between client computers of an enterprise and a third-party network service, and stores decryption logic in association with the plurality of data elements. The network computer system receives a decryption request via the service interface from a programmatic entity implemented by the third-party network service, the decryption request specifying an encrypted form of a data element. The network computer system decrypts the encrypted form of the data element to generate a decrypted form of the data element using a decryption key, of the one or more decryption keys that is associated with the data element. The network computer system provides a response to the decryption request to the programmatic entity, the response including the decrypted form of the data element.