Attribute-Level Encryption for Remote Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing encryption systems lack flexibility and user-defined control over encryption types for different data fields, leading to inconsistent access management and security across various assets, especially in remote storage and communication scenarios.

Innovation Solution

An encryption system that allows user-defined encryption for each data field, associating metadata with encryption types, and a decryption system that provides access to remotely stored data items based on specific access conditions, enabling selective attribute-level encryption and secure data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional encryption systems are used with uniform encryption for all data fields, then implementation simplicity is maintained, but flexibility and user-defined control over encryption types are lost

Engineering Contradiction:
Improveflexibility and user-defined control over encryption typesVSAvoidsystem complexity for managing different encryption types
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments encryption control to the data field level, allowing different encryption types to be applied to different fields within the same record. Each data field can have its own encryption type designation, enabling fine-grained control over encryption applied to specific attributes while maintaining a unified system architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by allowing different encryption types to be applied to different data fields based on their specific security requirements. Each field can have customized encryption parameters while the overall system maintains consistent access management, enabling security policies to be tailored to local data sensitivity needs.

Inventive Principle:
Principle #3Local quality

2Reliability

If selective attribute-level encryption is implemented for different data fields, then security compliance and access control are improved, but access management complexity increases

Engineering Contradiction:
Improvesecurity compliance and access controlVSAvoidaccess management operations
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system provides a universal access management interface that handles multiple encryption types through a single consistent mechanism. The access condition evaluation and decryption processes work uniformly across different encryption types, allowing users to access encrypted data through the same operations regardless of the specific encryption type applied to each field.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary layer that manages the complexity of selective attribute-level encryption. This layer handles encryption type determination, key management, and decryption coordination, shielding users from the underlying complexity while maintaining robust security compliance and access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If encryption is applied to remotely stored data in the cloud, then data security is improved, but transparent access to decrypted data becomes more difficult

Engineering Contradiction:
Improvedata security for remote storageVSAvoidtransparent access to decrypted data
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary decryption actions remotely in the cloud before data transfer to the user. Encryption keys are securely managed and decryption operations are executed in advance during the data access process, so users receive decrypted data transparently without needing to manually handle encryption/decryption operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An intermediary decryption service is introduced between the encrypted data stored in the cloud and the user application. This service automatically handles key retrieval, decryption, and data delivery, maintaining transparency for users while enabling secure remote storage with automated decryption capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10949555B2Encryption and decryption system and method
Publication Date: 2021.03.16 EXATE TECH
  • US10949555B2 patent drawing
  • US10949555B2 patent drawing
  • US10949555B2 patent drawing

AI summary

A system and method for encryption and decryption of data is disclosed. The decryption system provides access to remotely stored data items, each of the data items being independently accessible. At least a subset of the remotely stored data items are encrypted and each encrypted data item has an associated access condition. Upon a client requesting access to a remotely stored data item, the decryption system is arranged provide non-encrypted data items and for encrypted data items provide a decrypted data item if the associated access condition is met.