User-Centric Data Management via Single Aggregate Key
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data management methods compromise user sovereignty and privacy as they rely on central management systems or clouds for data access control, leading to security issues and loss of control over encrypted data when these systems fail or are compromised.
Innovation Solution
A data owner terminal and method for user-centric data management using a single aggregate key, allowing users to encrypt and manage their data independently, with a communication module, memory, and processor for secure data storage and key transmission, enabling direct control over encrypted data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a central management system or cloud is used for data access control, then data management convenience is improved, but user data sovereignty and security are compromised
Solution Approach 1:
The patent implements self-service by enabling users to independently generate, manage, and control their own encryption keys and aggregate keys without relying on a central management system. Users can directly encrypt their data, manage access control lists, and revoke permissions autonomously, thus maintaining data sovereignty while achieving convenient data management.
Solution Approach 2:
The patent introduces cryptographic intermediaries (encryption algorithms and key management protocols) that mediate between users and their data. These intermediaries enable secure data sharing and access control without requiring a trusted central authority, resolving the contradiction by providing both convenience and user-controlled security.
2Device complexity
If a single encryption key is used for all data, then encryption simplicity is improved, but security is worsened as key leakage compromises all data
Solution Approach 1:
The patent segments the single encryption key into multiple individual encryption keys, each dedicated to specific data items or data groups. This segmentation allows fine-grained access control where compromise of one key does not affect other data, resolving the security risk while maintaining manageable complexity through hierarchical key organization.
Solution Approach 2:
The patent adds a hierarchical dimension to key management by introducing aggregate keys that operate at a higher level than individual encryption keys. This dimensional structure enables users to manage multiple keys systematically through aggregate keys, maintaining simplicity in key management while enhancing security through layered protection.
3Reliability
If users directly manage encryption keys for their data, then user data sovereignty is improved, but key management complexity increases
Solution Approach 1:
The patent merges multiple individual encryption keys under a single aggregate key, allowing users to manage numerous keys through a unified interface. This combining approach maintains user sovereignty over individual keys while reducing management complexity through hierarchical organization and batch operations.
Solution Approach 2:
The aggregate key serves multiple functions: it can generate individual encryption keys, decrypt data encrypted with those keys, and manage access control permissions. This multi-functionality reduces key management complexity by providing a universal interface for diverse cryptographic operations while maintaining user sovereignty.
Data Source
AI summary
Provided is a data management method of user-centric data management through authentication and key agreement based on a single aggregate key. The method includes adding a keyword to data and encrypting the data according to a predetermined encryption technique; storing the encrypted data in a personal storage; receiving a data request from a data user terminal; and transmitting a single aggregate key required for the encrypted data to the data user terminal in response to the data request.


