Category-Specific Encryption Keys for Privacy Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection methods in open or distributed networks lack strong differentiation of security levels for various types of data, leading to potential unauthorized access and compromised security if one category of data is breached.

Innovation Solution

The method involves dividing user private data into multiple categories based on privacy levels, encrypting each category with a unique category key, and authorizing stakeholders with specific category keys for decryption, ensuring that access to one category does not compromise others.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data are encrypted with a single centralized key, then access control is simplified, but security is compromised if the key is breached

Engineering Contradiction:
Improveaccess control simplicityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the single encryption key into multiple category-specific keys (first category key, second category key, etc.). Each key encrypts only its corresponding data category, so that compromise of one key does not affect security of other categories. This segmentation resolves the contradiction by maintaining simple key management through structured organization while improving security through key isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security properties to different parts of the data system by assigning unique encryption keys to different data categories. Each category receives localized security treatment tailored to its specific protection needs, rather than applying a uniform security approach to all data. This allows simplified access control within each category while ensuring overall system security.

Inventive Principle:
Principle #3Local quality

2Device complexity

If all user data are stored in a centralized database, then data management is simplified, but access control granularity is reduced

Engineering Contradiction:
Improvedata management complexityVSAvoidaccess control granularity
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments user data into multiple categories (first category data, second category data, etc.) with different privacy levels and encryption requirements. This segmentation enables fine-grained access control where different stakeholders can be granted access to specific categories based on their authorization, while the centralized database structure maintains simple data management. The segmentation resolves the contradiction by enabling both centralized management and granular control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different access control policies and encryption methods to different data categories within the centralized database. Each category can have its own security characteristics, authorization rules, and encryption keys, allowing the system to adapt to diverse access requirements while maintaining a unified data management architecture. This local quality approach enables both simplicity and granularity simultaneously.

Inventive Principle:
Principle #3Local quality

3Reliability

If strong authentication is required for all data access, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements differentiated authentication requirements based on data category and stakeholder authorization. Authorized stakeholders accessing their permitted data categories experience convenient access without repeated strong authentication, while the system maintains strong security for unauthorized access attempts. This local quality approach applies strong authentication selectively rather than uniformly, resolving the contradiction between security and convenience.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11397829B2Method for handling privacy data
Publication Date: 2022.07.26 NAGRAVISION SRL
  • US11397829B2 patent drawing
  • US11397829B2 patent drawing

AI summary

The present invention aims to improve data protection against illegal access by a strong differentiation of the security level specific on a type of data so that when the protection on a part of the data is violated, the remaining data are still inaccessible. A method for controlling access, via an open communication network, to user private data, comprising steps of: dividing the user private data into a plurality of categories, each category defining a privacy level of the data, encrypting the user private data of each category with a category key pertaining to the category of the data, attributing to a stakeholder an entity configured for accessing to at least one category of user private data, and authorizing the access to the at least one category of user private data for the entity of the stakeholder, by providing the stakeholder with the category keys required for decrypting the user private data of the corresponding category.