Reversing Symmetric Encryption with Snapshot-Stored Per-File Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Ransomware encryption of data renders it unusable to the owner until a ransom is paid, compromising business operations.
Innovation Solution
A system intercepts and snapshots encrypted data and keys transmitted by ransomware processes, allowing the data owner to decrypt the data without paying a ransom by leveraging the intercepted keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ransomware encrypts data using a key, then data security is improved, but data usability deteriorates
Solution Approach 1:
The patent extracts the encryption key from the encrypted data transmission and stores it separately in a secure key store before the data is exfiltrated to the attacker. This separation allows the data to remain encrypted (maintaining security) while the key is preserved in a controlled environment (maintaining usability through potential decryption capability).
Solution Approach 2:
The system performs preliminary action by intercepting and storing the encryption key before the ransomware completes its malicious cycle. By capturing the key in advance and storing it securely, the system prepares the means for future decryption while allowing the encryption process to proceed, thus maintaining both security and potential usability.
2Reliability
If ransomware transmits encrypted data and keys to an attacker, then data control is improved for the attacker, but data availability deteriorates for the owner
Solution Approach 1:
The patent introduces an intermediary component (the security system) that sits between the ransomware process and the attacker. This intermediary intercepts the key transmission, stores the key securely in a key store, and allows the encrypted data to proceed to the attacker. The intermediary thus enables attacker control while preventing complete data unavailability by preserving decryption capability.
Solution Approach 2:
The system extracts the encryption key from the data transmission stream and separates it from the encrypted data payload. By taking out the key and storing it independently in a secure location, the system allows the encrypted data to be transmitted (maintaining attacker control) while preserving the ability to decrypt (maintaining data availability).
3Ease of operation
If the data owner pays the ransom, then data decryption is improved, but operational disruption increases due to ransom payment process
Solution Approach 1:
The system performs preliminary action by capturing and securely storing the encryption key before any ransom payment is required. This advance preparation eliminates the need for time-consuming ransom payment processes, as the decryption capability is already in place and can be immediately applied to restore data access.
Solution Approach 2:
The patent converts the harmful ransomware encryption process into a beneficial situation by intercepting the encryption key during the attack. The very act of ransomware encrypting the data and attempting to transmit the key becomes the mechanism by which the key is captured and stored securely, transforming the attack into an opportunity for key acquisition and future decryption without payment.
4Productivity
If ransomware processes are allowed to continue encrypting data, then analysis capability is improved, but data loss increases
Solution Approach 1:
The patent introduces an intermediary security system that monitors and controls the ransomware process. This intermediary allows the ransomware to continue its encryption operations (enabling analysis of the encryption methods and key generation) while simultaneously intercepting and securely storing the encryption keys. The intermediary thus enables analysis capability while preventing actual data loss through key preservation.
Solution Approach 2:
The system implements feedback by continuously monitoring the ransomware process as it encrypts files and capturing the generated keys in real-time. This feedback mechanism allows the security system to learn from the encryption process while preventing data loss, creating a controlled environment where analysis can proceed without irreversible damage.
Data Source
AI summary
One example method includes identifying a process that includes both a write operation and a transmit operation, wherein the write operation comprises performing a malicious process on data that renders the data unusable to an owner of the data, and the transmit operation comprises transmitting the data after the data has been acted upon by the malicious process, performing a snapshot operation to create a snapshot that comprises a copy of the data after the data has been acted upon by the malicious process and/or while the data is being acted upon by the malicious process, and intercepting the data before, or while, the transmit operation is performed.


