Trustworthy Data Packet Creation for Zero Trust Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data transmission systems lack a comprehensive method to assess the trustworthiness of data sources beyond network segmentation, especially in a Zero Trust security context, leading to potential security vulnerabilities during data exchange across organizational boundaries.
Innovation Solution
A method for creating and storing trustworthy data packets by associating trustworthiness information, determined through integrity checks and cryptographic verification, with the data units, allowing for explicit assessment of the data source's trustworthiness, rather than relying on network zones.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If network segmentation (zones) is used to determine security levels, then data transmission between trusted connectors is simplified, but the security assessment becomes insufficient in Zero Trust contexts where device integrity must be verified
Solution Approach 1:
The patent segments the trust assessment into multiple independent components: device integrity information, connector trustworthiness, and data origin verification. Each component is evaluated separately through integrity checks and cryptographic verification, allowing comprehensive security assessment without relying on coarse network zone classifications.
Solution Approach 2:
The patent performs preliminary integrity checks and trustworthiness assessments before data transmission occurs. Device integrity information is verified in advance, and trust packets are prepared with cryptographic signatures beforehand, enabling rapid Zero Trust verification during data exchange without compromising security reliability.
2Reliability
If integrity checks and cryptographic verification are performed for every data source, then trustworthiness assessment reliability improves, but system complexity increases
Solution Approach 1:
The patent creates a universal trust packet structure that can be applied to any data source regardless of network location or device type. The same integrity check and cryptographic verification mechanisms work across diverse sources (files, streams, data units), reducing the need for source-specific complexity while maintaining reliable trustworthiness assessment.
Solution Approach 2:
The patent uses cryptographic signatures and hash values to create verified copies of integrity information. Instead of performing complex real-time verification of entire data sources, the system uses compact cryptographic representations (signatures, hashes) that efficiently prove trustworthiness without requiring proportional system complexity.
3Reliability
If trustworthiness information is stored with every data unit, then data security and traceability improve, but storage requirements and processing overhead increase
Solution Approach 1:
The patent stores compact cryptographic representations of trustworthiness information rather than extensive verification data. Hash values and digital signatures serve as concise proofs of integrity and origin, providing high security assurance with minimal storage overhead compared to storing complete device states or verification logs.
Solution Approach 2:
The patent prepares and attaches trust packets with cryptographic signatures in advance of data storage. By computing integrity hashes and generating signatures beforehand, the system minimizes processing overhead during data operations while ensuring security information is readily available for verification when needed.
4Measurement precision
If explicit trustworthiness assessment is implemented instead of network zone classification, then security precision improves, but the complexity of determining trust levels increases
Solution Approach 1:
The patent replaces manual or policy-based trust determination with automated cryptographic verification. Instead of complex human judgment or intricate policy evaluation, the system uses mathematical proofs (digital signatures, hash verification) to objectively determine trustworthiness, achieving high precision through computational rather than procedural complexity.
Solution Approach 2:
The patent enables data sources to self-verify their trustworthiness through built-in integrity checks and automatic signature generation. Devices perform their own integrity verification and attach cryptographic proofs to their data, eliminating the need for complex centralized trust determination mechanisms while achieving precise trust assessment.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a method for storing a trustworthy data packet (32, 32B), comprising the steps of: - receiving (S1) from a data source (1) of: ∘ at least one data unit (32), ∘ at least one piece of integrity information (32A) of the data source (1) which is assigned to the at least one data unit (32), - determining (S2) trustworthiness information (32B) as a function of the at least one piece of integrity information (32A), - creating (S3) the trustworthy data packet (32, 32B) by assigning the trustworthiness information (32B) to the at least one data unit (32), and - storing (S4) the trustworthy data packet (32, 32B). The invention also relates to a computer program product, a computer-readable medium, and a higher-level system.