Attribute-Level Encryption for Remote Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing encryption systems lack flexibility and user-defined control over encryption types for different data fields, leading to inconsistent access management and security across various assets, especially in remote storage and communication scenarios.
Innovation Solution
An encryption system that allows user-defined encryption for each data field, associating metadata with encryption types, and a decryption system that provides access to remotely stored data items based on specific access conditions, enabling selective attribute-level encryption and secure data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional encryption systems are used with uniform encryption for all data fields, then implementation simplicity is maintained, but flexibility and user-defined control over encryption types are lost
Solution Approach 1:
The system segments encryption control to the data field level, allowing different encryption types to be applied to different fields within the same record. Each data field can have its own encryption type designation, enabling fine-grained control over encryption applied to specific attributes while maintaining a unified system architecture.
Solution Approach 2:
The patent implements local quality by allowing different encryption types to be applied to different data fields based on their specific security requirements. Each field can have customized encryption parameters while the overall system maintains consistent access management, enabling security policies to be tailored to local data sensitivity needs.
2Reliability
If selective attribute-level encryption is implemented for different data fields, then security compliance and access control are improved, but access management complexity increases
Solution Approach 1:
The system provides a universal access management interface that handles multiple encryption types through a single consistent mechanism. The access condition evaluation and decryption processes work uniformly across different encryption types, allowing users to access encrypted data through the same operations regardless of the specific encryption type applied to each field.
Solution Approach 2:
The patent introduces an intermediary layer that manages the complexity of selective attribute-level encryption. This layer handles encryption type determination, key management, and decryption coordination, shielding users from the underlying complexity while maintaining robust security compliance and access control.
3Reliability
If encryption is applied to remotely stored data in the cloud, then data security is improved, but transparent access to decrypted data becomes more difficult
Solution Approach 1:
The system performs preliminary decryption actions remotely in the cloud before data transfer to the user. Encryption keys are securely managed and decryption operations are executed in advance during the data access process, so users receive decrypted data transparently without needing to manually handle encryption/decryption operations.
Solution Approach 2:
An intermediary decryption service is introduced between the encrypted data stored in the cloud and the user application. This service automatically handles key retrieval, decryption, and data delivery, maintaining transparency for users while enabling secure remote storage with automated decryption capabilities.
Data Source
AI summary
A system and method for encryption and decryption of data is disclosed. The decryption system provides access to remotely stored data items, each of the data items being independently accessible. At least a subset of the remotely stored data items are encrypted and each encrypted data item has an associated access condition. Upon a client requesting access to a remotely stored data item, the decryption system is arranged provide non-encrypted data items and for encrypted data items provide a decrypted data item if the associated access condition is met.


