Cloud Data Access via Identity and Attribute Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing platforms face challenges in implementing fine-grained access control, allowing authorized users to access all data once authorized, leading to difficulties in managing and securing sensitive data such as personal medical records.

Innovation Solution

A data access method using a user terminal that includes a decryption key with a user precise identity identifier and a user attribute identifier, allowing decryption of data ciphertext only when the identifiers match the access structure, enabling fine-grained access control and secure data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are authorized to access data in the cloud computing platform, then users can store and access data, but fine-grained access control becomes difficult to implement and users may access all data regardless of specific permissions

Engineering Contradiction:
Improvedata access capabilityVSAvoidaccess control management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments access control into fine-grained permissions associated with specific data items. Each data item has its own access policy that defines which users can access it and under what conditions. This segmentation allows the system to maintain simple user authorization while implementing complex access control at the data level, resolving the contradiction between ease of operation and access control management complexity.

Inventive Principle:
Principle #1Segmentation

2Ease of manufacture

If traditional access control methods are used, then implementation is simple, but security is insufficient for sensitive data such as personal medical records

Engineering Contradiction:
Improveaccess control implementationVSAvoiddata security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent applies local quality by associating different access policies with different data items. Each data item can have its own security requirements and access conditions tailored to its sensitivity and nature. For example, personal medical records can have stricter access controls compared to less sensitive data. This allows the system to maintain simple overall implementation while providing high security for sensitive data through localized access control policies.

Inventive Principle:
Principle #3Local quality

3Reliability

If fine-grained access control is implemented, then data security is improved, but system complexity and performance overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidaccess control system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-establishing access policies for data items before access requests occur. The cloud service provider configures access control policies in advance, associating them with specific data items and user groups. When access requests are made, the system simply checks whether the request conforms to the pre-defined policies rather than making complex decisions in real-time. This reduces system complexity and performance overhead while maintaining fine-grained access control and high data security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10250613B2Data access method based on cloud computing platform, and user terminal
Publication Date: 2019.04.02 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US10250613B2 patent drawing
  • US10250613B2 patent drawing
  • US10250613B2 patent drawing

AI summary

A data access method based on a cloud computing platform, and a user terminal, are provided. The method is performed by a user terminal, and the method includes obtaining an access request for a data ciphertext of the cloud computing platform, the access request including a decryption key, and the decryption key including a user precise identity identifier and a user attribute identifier. The method further includes decrypting the data ciphertext into a data plaintext, in response to the user precise identity identifier belonging to an identity identifier set included in an access structure of the data ciphertext and/or in response to the user attribute identifier belonging to a user attribute identifier set included in the access structure of the data ciphertext.