Transport Envelope with Nested Encryption for Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security systems are limited in scope, often vendor-specific, and lack internal protection and visibility, failing to provide fine-grain control and auditability, especially in complex virtualization and cloud environments, and are vulnerable to data corruption and unauthorized access.

Innovation Solution

A pervasive data security system that encrypts data in transit and at rest, providing fine-grain control and auditability, with user-level recovery capabilities, extending beyond individual enterprises to partner organizations and accommodating unaffiliated users, using zero-knowledge security and asymmetric key cryptography, and incorporating behavioral analytics and artificial intelligence for enhanced security and scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is used to protect data from theft, then data security is improved, but data can be corrupted by malicious programs or hackers making it unrecoverable

Engineering Contradiction:
Improvedata securityVSAvoiddata corruption
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by maintaining multiple versions of data and pre-configuring rollback mechanisms before corruption occurs. When corruption is detected, the system automatically rolls back to previous clean versions, preventing total data loss and enabling recovery without requiring manual intervention or complex recovery procedures.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If known security systems are used, then perimeter control is provided, but internal protection and visibility are not provided

Engineering Contradiction:
Improveperimeter controlVSAvoidinternal protection capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security system is segmented into multiple independent components: data encryption modules, version control systems, rollback mechanisms, and audit logging systems. This segmentation allows internal protection capabilities to be implemented without compromising the overall perimeter control, enabling both external security and internal visibility through distributed security functions throughout the data lifecycle.

Inventive Principle:
Principle #1Segmentation

3Reliability

If vendor-specific security systems are used, then security for certain user packages is provided, but scope is limited

Engineering Contradiction:
Improvesecurity protectionVSAvoidscope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements universal security mechanisms that can protect various types of data (documents, images, videos, databases) across multiple platforms and user packages. The version control and rollback mechanisms work universally regardless of data type or user level, providing consistent security and recovery capabilities throughout the entire organization without requiring vendor-specific solutions for different user packages.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If monolithic security approaches are used, then single enterprise control is achieved, but scalability to partner organizations and unaffiliated users is restricted

Engineering Contradiction:
Improveenterprise controlVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security system dynamically adapts its scope and control mechanisms based on the user and data context. The version control and rollback systems operate independently for different enterprises and user packages, allowing the system to scale from single-enterprise control to multi-organizational and even cross-organizational scenarios. The system can be configured to provide different levels of control and visibility based on organizational boundaries and user relationships.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10505905B2Transport envelope
Publication Date: 2019.12.10 GLOBAL DATA SENTINEL INC
  • US10505905B2 patent drawing
  • US10505905B2 patent drawing
  • US10505905B2 patent drawing

AI summary

A method and system of transporting data securely. A payload comprising a first encrypted data is serialized. The serialized payload is prepended with a first header to create a first data packet. The first data packet is encrypted using the second key to create a second data packet. The second data packet is prepended with a second header to create a third data packet. The third data packet is transported to a destination via a secure data transport.