Attribute-Based Encryption for Selective Data Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for sharing sensitive data lack fine-grained access control, requiring manual removal of sensitive information and maintenance of multiple document versions, which is cumbersome and often leads to non-sharing due to the absence of centralized systems for selective access control.
Innovation Solution
The implementation of attribute-based encryption (ABE) systems and methods that enable selective encryption and decryption of unstructured data containers based on security attributes or policies, allowing for secure sharing of sensitive data by generating encryption and decryption keys according to specific access controls, thereby enabling multiple parties to access only authorized portions of a document.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual removal of sensitive information is used to achieve selective access control, then data security is improved, but device complexity and ease of operation deteriorate due to maintaining multiple document versions
Solution Approach 1:
The patent segments the document into multiple data containers, each with its own encryption key and access policy. This allows different portions of the document to be selectively encrypted and accessed by different users without creating multiple document versions, thereby improving security while reducing complexity.
Solution Approach 2:
The patent changes the encryption parameters dynamically based on user attributes and access policies. By modifying encryption keys and access controls at the data container level rather than creating document versions, the system achieves fine-grained access control without the complexity of version management.
2Reliability
If centralized trusted systems are used to achieve selective access control, then data security is improved, but ease of operation deteriorates due to lack of autonomy
Solution Approach 1:
The patent implements self-service access control where encryption and decryption operations are performed autonomously by the system based on predefined policies and user attributes. This eliminates the need for centralized trusted systems while maintaining security and operational autonomy.
Solution Approach 2:
The patent establishes access policies and encryption schemes in advance, allowing the system to automatically determine and execute appropriate access control actions without requiring centralized coordination during operation. This preliminary configuration enables both security and autonomy.
3Reliability
If multiple document versions are maintained to achieve selective sharing, then data security is improved, but productivity deteriorates due to manual management overhead
Solution Approach 1:
The patent merges the concepts of selective access control and document sharing into a single automated system. By combining encryption, access policies, and user attribute verification into one integrated process, it eliminates the need for manual version management while maintaining security, thereby improving productivity.
4Ease of operation
If attribute-based encryption is implemented to achieve fine-grained access control, then ease of operation is improved, but device complexity increases due to cryptographic key management
Solution Approach 1:
The patent introduces an intermediary layer of access policies and attribute-based verification mechanisms that simplify key management. Instead of directly managing complex cryptographic keys, the system uses policies and attributes as intermediaries to automatically determine access rights, reducing operational complexity while maintaining fine-grained control.
Data Source
AI summary
Systems and methods for selectively sharing of portion of unstructured data containers/documents based on security attributes or policies used to encrypt/decrypt data within the unstructured data containers using attribute-based encryption (ABE) are provided herein. In some embodiments, a system includes a key generation authority to generate encryption keys based on a selected cryptographic security scheme and one or more security attributes or security policies; an encryption service to selectively encrypt one or more data subgroups using the one or more public keys and based on one or more security attributes or security policies assigned to the one or more data subgroups with the unstructured data containers; and a decryption service to decrypt the one or more data subgroups within unstructured data containers using the one or more secret keys and the one or more public keys.


