Cloud Data Protection via Digital License Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data security technologies are inadequate for the cloud office era, as they rely on static boundaries for data flow, failing to manage and control access effectively in a geographically unrestricted environment, leading to increased security risks.
Innovation Solution
A data protection method and system that manages usage authority by verifying digital licenses, allowing only authorized parties to decrypt encrypted data by transmitting the necessary keys or related data based on valid licenses, ensuring secure access and control in the cloud office environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data flow boundaries are established to protect data security, then data security is improved, but data accessibility and flexibility deteriorate
Solution Approach 1:
The patent segments data into multiple encrypted parts and distributes them across different storage locations. Each part alone is insufficient to decrypt the original data, providing security while allowing flexible access when authorized. The segmentation is implemented through dividing data into first and second encrypted data parts stored in different locations.
Solution Approach 2:
The patent introduces a license verification system as an intermediary between data storage and data access. The verification component checks digital licenses before permitting decryption, enabling controlled access without physical boundaries. This mediator allows data to be accessed from any location while maintaining security through authorization validation.
2Reliability
If data is encrypted and stored in fixed locations, then data security is improved, but data mobility and cloud-based access deteriorate
Solution Approach 1:
The patent implements dynamic data protection where encrypted data parts can be moved and accessed from different locations without compromising security. The system transitions from static boundary-based security to dynamic authorization-based security, allowing data parts to be stored and accessed flexibly in cloud environments while maintaining protection through license verification.
Solution Approach 2:
The patent changes the security parameter from physical location constraints to digital authorization constraints. Instead of relying on fixed storage locations, the system uses digital licenses and verification mechanisms that remain valid regardless of where data is stored or accessed from, enabling cloud-based mobility while maintaining security.
3Reliability
If traditional boundary-based security is used, then data protection within boundaries is improved, but control over data usage authority deteriorates
Solution Approach 1:
The patent implements a universal license verification mechanism that can control data access across multiple platforms, locations, and storage systems. The digital license system provides a single unified approach to authorization that works regardless of where data is stored or from where it is accessed, simplifying usage authority control while maintaining comprehensive protection.
4Adaptability or versatility
If data is made accessible from any location, then data flexibility is improved, but security risks increase
Solution Approach 1:
The patent performs preliminary license verification before allowing data decryption and access. By checking authorization credentials in advance, the system enables flexible remote access while preventing unauthorized access. The verification of digital licenses occurs before data is made accessible, mitigating security risks while maintaining flexibility.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
An embodiment of the present invention discloses a data protection method, comprising: checking whether a data receiving party has a valid digital license generated by the data transmitting party, at a time when the data receiving party is to decrypt the encrypted data from a data transmitting party; and if so, permitting the data receiving party to use at least one key required in the data decryption process. Also disclosed in the embodiment of the present invention is a data protection system. The embodiments of the invention realize secure usage of shared data in cloud office era.