Token Key Infrastructure for Cloud Digital Information Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The advancement of Cloud Computing and Cloud Services poses a challenge in protecting digital information, including digital data and executable codes, from being tapped or reused, as traditional methods are inadequate for the new model of service provision, and existing polymorphic executable solutions limit usage to one unique computer, making it difficult to charge for repeated use or protect privacy and confidentiality.

Innovation Solution

Implementing a dynamic and polymorphic approach by encrypting digital information using unique hardware keys and variable keys, combined with biometric identifiers, and employing a Token Key Infrastructure (TKI) to ensure that digital information appears differently across devices and over time, making it extremely difficult for hackers to decipher, while also integrating with Public Key Infrastructure (PKI) for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional encryption methods are used to protect digital information, then security is improved, but the information cannot be dynamically adapted to different devices or reused in cloud services

Engineering Contradiction:
ImprovesecurityVSAvoiddevice adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic encryption where the encryption key changes based on device-specific identifiers and time variables. The cryptographic key is not static but dynamically generated using a hash function that incorporates device ID, timestamp, and other variable parameters, allowing the same digital information to be encrypted differently for each device and time period.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of the encryption system by using variable inputs (device ID, time, random numbers) to generate different encryption keys. This allows the encryption method to adapt to different devices and time periods while maintaining security, resolving the contradiction between fixed security and adaptive versatility.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If polymorphic executable methods are used to protect digital information, then security against copying is improved, but the solution is limited to one unique computer and cannot support cloud service models

Engineering Contradiction:
Improveprotection against copyingVSAvoidcloud service compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal encryption system that works across multiple devices and cloud service models. By using device-specific identifiers combined with time-based and random variables, the same encryption framework can securely serve multiple devices and cloud service scenarios, making it universally applicable rather than limited to single-device polymorphic executables.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The encryption system dynamically adapts to different cloud service models and devices by incorporating variable parameters such as device ID, timestamp, and random numbers into the key generation process, enabling the same digital information to be securely delivered across diverse cloud service scenarios.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If digital information is delivered in the same form across all devices, then delivery simplicity is improved, but security against tapping and hacking is worsened

Engineering Contradiction:
Improvedelivery simplicityVSAvoidvulnerability to tapping
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by customizing the encryption for each specific device using device-specific identifiers. Each device receives digitally information encrypted with a key unique to that device, making the delivery process secure without requiring complex manual configuration for each device, thus maintaining simplicity while enhancing security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces an intermediary encryption layer that transforms the digital information before delivery. The encryption key acts as an intermediary that protects the information during transmission, making tapping ineffective while keeping the delivery process automated and simple through programmatic key generation and application.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If strong encryption is used to protect digital information, then security is improved, but the complexity of key management and distribution is worsened

Engineering Contradiction:
Improveencryption securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling each device to automatically generate its own encryption key using its unique device identifier and current timestamp. The device autonomously computes the cryptographic key through a hash function without requiring manual key distribution or complex key management infrastructure, thus maintaining strong security while simplifying key management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses a hash function as an intermediary mechanism that automatically transforms device identifiers and time variables into secure encryption keys. This intermediary process eliminates the need for manual key distribution and simplifies key management while maintaining strong cryptographic security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10411893B2Token key infrastructure and method
Publication Date: 2019.09.10 CHAN KAM FU

AI summary

A Token Key Infrastructure and a method using Polymorphic Executable or its variants for the exchange of digital information, including digital data and digital executable codes, over network or internet in a secure way with the use of Dynamism, Polymorphism and Dynamic Polymorphism, as well as integrating with Public Key Infrastructure where considered appropriate for the protection of intellectual property rights, privacy and confidentiality of digital information.