Secure Data Sharing via Trust Boundary Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data security methods for sharing sensitive information are complex, costly, and require significant infrastructure and user expertise, leading to low adoption and willingness to use them, especially among regular computing device users who need to share data securely across different organizations and locations.

Innovation Solution

A method and system for secure data sharing that employs a 'Trust Boundary' concept, where data is encrypted using a first encryption key and the key is further encrypted with a unique key derived from a third encryption key and a cryptographic salt, allowing secure sharing within defined trust boundaries without requiring extensive infrastructure or user expertise, using a system that includes components for encryption, trust boundary management, and transparent data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional data security methods are used for sharing sensitive information, then data protection is achieved, but system complexity and infrastructure requirements increase significantly

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables users to automatically encrypt and share data through simple drag-and-drop operations. The encryption process is handled transparently by the system itself, requiring no manual key management or complex configuration from users. The trust boundary mechanism automatically manages encryption keys and access control, making security self-service rather than requiring expert intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a trust boundary as an intermediary layer between data and users. This trust boundary acts as a mediator that automatically handles encryption, key management, and access control. Instead of users directly managing complex encryption systems, the trust boundary intermediary simplifies the interaction while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional data security methods are implemented, then data sharing protection is achieved, but user expertise and infrastructure requirements increase

Engineering Contradiction:
Improvedata sharing protectionVSAvoiduser expertise requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Users can securely share data through intuitive drag-and-drop operations without needing to understand encryption mechanisms. The system automatically handles all security operations including key generation, encryption, and access control, making security features self-service oriented and eliminating the need for user expertise.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the operational parameters from manual key management to automatic trust boundary-based encryption. Users interact with simplified parameters (drag-and-drop operations) rather than complex cryptographic parameters, making the system easier to operate while maintaining strong security.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If secure data sharing is implemented across organizations and locations, then data security is improved, but workflow interruptions increase

Engineering Contradiction:
Improvedata securityVSAvoidworkflow continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system maintains workflow continuity by enabling secure data sharing without interrupting user operations. The encryption and access control happen transparently in the background, allowing users to continue their workflows uninterrupted while data remains securely protected across organizations and locations.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The trust boundary intermediary handles security operations transparently, acting as a mediator that doesn't disrupt the user workflow. Instead of requiring users to manually manage security processes that would interrupt their work, the intermediary automatically manages security in the background, maintaining workflow continuity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If encryption keys are managed manually, then data protection is achieved, but time consumption and operational complexity increase

Engineering Contradiction:
Improvedata protectionVSAvoidkey management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically generates, manages, and rotates encryption keys without requiring manual intervention. The trust boundary mechanism self-manages key lifecycle operations including generation, storage, and distribution, eliminating the time-consuming manual key management process while maintaining strong data protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs key generation and management actions in advance automatically. Instead of requiring users to manually create and manage keys at the time of need, the system preliminarily establishes the trust boundary and key management infrastructure beforehand, saving time during actual data sharing operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10637833B2Method and system for secure data sharing
Publication Date: 2020.04.28 CRYPTOMILL
  • US10637833B2 patent drawing
  • US10637833B2 patent drawing
  • US10637833B2 patent drawing

AI summary

A method of protecting data is disclosed herein. The method comprises: encrypting a data in a protected data item using a first encryption key; and encrypting the first encryption key in the protected data item using a second encryption key that is unique to the protected data item, wherein the unique second encryption key is derived from a third encryption key in the protected data item and to a plurality of protected data items comprising a common characteristic shared with the protected data item.