User-Centric Data Management via Single Aggregate Key

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data management methods compromise user sovereignty and privacy as they rely on central management systems or clouds for data access control, leading to security issues and loss of control over encrypted data when these systems fail or are compromised.

Innovation Solution

A data owner terminal and method for user-centric data management using a single aggregate key, allowing users to encrypt and manage their data independently, with a communication module, memory, and processor for secure data storage and key transmission, enabling direct control over encrypted data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a central management system or cloud is used for data access control, then data management convenience is improved, but user data sovereignty and security are compromised

Engineering Contradiction:
Improvedata management convenienceVSAvoiduser data sovereignty
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements self-service by enabling users to independently generate, manage, and control their own encryption keys and aggregate keys without relying on a central management system. Users can directly encrypt their data, manage access control lists, and revoke permissions autonomously, thus maintaining data sovereignty while achieving convenient data management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces cryptographic intermediaries (encryption algorithms and key management protocols) that mediate between users and their data. These intermediaries enable secure data sharing and access control without requiring a trusted central authority, resolving the contradiction by providing both convenience and user-controlled security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a single encryption key is used for all data, then encryption simplicity is improved, but security is worsened as key leakage compromises all data

Engineering Contradiction:
Improveencryption complexityVSAvoiddata security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the single encryption key into multiple individual encryption keys, each dedicated to specific data items or data groups. This segmentation allows fine-grained access control where compromise of one key does not affect other data, resolving the security risk while maintaining manageable complexity through hierarchical key organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a hierarchical dimension to key management by introducing aggregate keys that operate at a higher level than individual encryption keys. This dimensional structure enables users to manage multiple keys systematically through aggregate keys, maintaining simplicity in key management while enhancing security through layered protection.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If users directly manage encryption keys for their data, then user data sovereignty is improved, but key management complexity increases

Engineering Contradiction:
Improveuser data sovereigntyVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple individual encryption keys under a single aggregate key, allowing users to manage numerous keys through a unified interface. This combining approach maintains user sovereignty over individual keys while reducing management complexity through hierarchical organization and batch operations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The aggregate key serves multiple functions: it can generate individual encryption keys, decrypt data encrypted with those keys, and manage access control permissions. This multi-functionality reduces key management complexity by providing a universal interface for diverse cryptographic operations while maintaining user sovereignty.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240333494A1Data owner device and its data management method for user-centric data management through authentication and key agreement based on single aggregate key
Publication Date: 2024.10.03 ELECTRONICS & TELECOMM RES INST
  • US20240333494A1 patent drawing
  • US20240333494A1 patent drawing
  • US20240333494A1 patent drawing

AI summary

Provided is a data management method of user-centric data management through authentication and key agreement based on a single aggregate key. The method includes adding a keyword to data and encrypting the data according to a predetermined encryption technique; storing the encrypted data in a personal storage; receiving a data request from a data user terminal; and transmitting a single aggregate key required for the encrypted data to the data user terminal in response to the data request.