Anonymized Confidential Data Flow Across User Terminals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face complexity in handling partly confidential and partly open data sets, leading to unnecessary complexity in data flow analysis and lack of complete confidentiality.
Innovation Solution
A communication system with a central terminal and user terminals uses asymmetric encryption, where each pair of terminals has a public and private key, enabling encrypted confidential data to be transmitted with unencrypted open data, ensuring only the intended recipient can decrypt the confidential data, while the central terminal remains unaware of the data's origin or destination.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If confidential data is transmitted separately from open data, then confidentiality is maintained, but system complexity increases due to multiple data flow management
Solution Approach 1:
The patent combines confidential data and open data into a single composite data structure that is transmitted together through the same communication channel. The confidential portion is encrypted while the open portion remains unencrypted, allowing both types of data to be managed through a unified system rather than separate systems, thereby reducing overall system complexity while maintaining confidentiality.
2Reliability
If data flow analysis is performed to track confidential data, then security monitoring is improved, but anonymity of users is compromised
Solution Approach 1:
The patent extracts and separates the identification information from the confidential data transmission process. User identities are not included in the transmitted data packets, and the system does not track which specific users are exchanging confidential information. Only the open data portions may be analyzed, while the confidential encrypted portions maintain complete anonymity of the communicating parties.
3Reliability
If encryption is applied to all data transmissions, then confidentiality is ensured, but processing efficiency decreases due to computational overhead
Solution Approach 1:
The patent applies encryption selectively only to the confidential portions of data while leaving the open data portions unencrypted. This localized application of encryption means that only the necessary portions of data undergo computational encryption/decryption processing, while the open data can be processed and transmitted without the computational overhead of encryption, thereby maintaining overall processing efficiency while ensuring confidentiality where needed.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a communication system having a central terminal 1 and a plurality of user terminals 2, 3, 4, which is configured to operate an anonymized flow of confidential data records 6, 9 between the central terminal 1 and the user terminals 2, 3, 4, wherein first confidential data records 6 are sent by means of first messages 5 from a user terminal 2, 3, 4 to the central terminal 1 and, after receipt of a first message 5 by the central terminal 1, are sent simultaneously to all user terminals 2, 3, 4 by means of second messages 8 corresponding to the first message 5, wherein each second message 8 contains a second confidential data record 9 identical to the first confidential data record 6 and wherein each two user terminals 2, 3, 4 are connected via a pair of keys 11, 12, 13, 14, 15, 16 comprising a first key 12, 13,14 for encrypting the first confidential data records 6 in respective first messages 5 and a second key 11, 15, 16 for decrypting second confidential data records 9 from respective second messages 8, and each pair of keys 11, 12, 13, 14, 15, 16 enables a flow of confidential data records 6, 9 from one user terminal 2, 3, 4 to exactly one other user terminal 2, 3, 4. Each user terminal 2, 3, 4 is configured to combine the encrypted first confidential data record 6 with an unencrypted first open data record 7 in each first message 5, and the central terminal 1 is configured, after receiving a first message 5, to send a second message 8 corresponding to the first message 5, which contains the second confidential data record 9 and a second open data record 10 identical to the first open data record 7, to all user terminals 2, 3,4. The invention also relates to a corresponding method, a corresponding computer program product and a corresponding combination with at least one computer-readable data carrier.