Hierarchical Key Rings for Blockchain Data Segregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current blockchain networks face challenges in securely and efficiently sharing data between organizations due to limitations in data access control and privacy, particularly under high network churn and connectivity issues.
Innovation Solution
A method involving the generation of hierarchical keys through a pseudorandom function to create access rings, allowing only authorized nodes to access specific data collections, ensuring secure data segregation and encryption within the blockchain network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is shared across organizations in a blockchain network, then data accessibility and collaboration are improved, but data privacy and security control deteriorate
Solution Approach 1:
The patent segments data access control by organizing nodes into hierarchical rings (first ring, second ring, etc.) where each ring has specific access permissions. Data is encrypted with different keys for different rings, allowing fine-grained control over which organizations can access which data collections. This resolves the contradiction by enabling selective data sharing (improving accessibility) while maintaining strict access control boundaries (preserving privacy).
Solution Approach 2:
The patent implements local quality by assigning different encryption keys and access permissions to different rings and data collections. Each organization's nodes have specific key pairs that grant them access only to authorized data collections. This allows data to be accessible to appropriate parties (improving versatility) while maintaining localized security control for each data collection (preserving reliability).
2Reliability
If traditional encryption methods are used for data sharing, then security is maintained, but scalability and performance deteriorate under high network churn
Solution Approach 1:
The patent applies preliminary action by pre-distributing encryption keys to nodes before data sharing operations. Nodes in each ring receive their encryption keys in advance through key derivation from root keys. This preliminary key distribution establishes security boundaries upfront, allowing the system to scale efficiently (improving productivity) while maintaining security through pre-configured access controls (preserving reliability).
Solution Approach 2:
The patent changes the encryption parameter structure by using hierarchical key derivation where root keys generate child keys for different rings. This parameter organization allows efficient key management and scalability (improving productivity) while maintaining strong cryptographic security through the mathematical relationships between keys (preserving reliability).
3Device complexity
If all nodes have access to all data collections, then network simplicity is maintained, but data segregation and organizational privacy deteriorate
Solution Approach 1:
The patent segments the network into multiple rings with different access permissions. Each ring contains nodes from specific organizations with authorized access to particular data collections. This segmentation maintains relative network simplicity through standardized ring structures (improving device complexity) while preventing unauthorized access to organizational data (preserving information privacy).
Solution Approach 2:
The patent introduces rings as intermediary layers between nodes and data collections. Rather than direct node-to-data access, nodes access data through their assigned rings which enforce access control policies. This intermediary structure simplifies access management (improving device complexity) while protecting organizational privacy through enforced access boundaries (preventing information loss).
Data Source
AI summary
A node in a blockchain network may generate a key for a first ring, wherein the key unlocks a first collection of data, defining a second ring including a second node of a second organization, derive a second key for a second collection of data, wherein the first key and the second key access the second collection of data, and distributing the second key to the second node.


