Cloud Data Security via Key Management Center Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud data security, existing methods face challenges in protecting encryption keys from leakage during data sharing, leading to potential data insecurity.

Innovation Solution

A key management center encrypts original data and stores it, then processes and sends encrypted data to a second terminal for decryption using a key owned by that terminal, preventing direct exposure of the encryption key and reducing key leakage risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If terminal B requests a key from terminal A to decrypt cloud data, then data sharing is enabled, but key leakage risk increases

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidkey security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the encryption key from the data sharing process. Instead of terminal B requesting terminal A's key, the system uses re-encryption where terminal A's key never leaves terminal A. The key management center extracts only the necessary decryption capability through cryptographic protocols, leaving the actual key secured at its origin.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a key management center as an intermediary that facilitates data sharing without exposing keys. The KMC mediates between terminal A (data owner) and terminal B (data requester) using cryptographic protocols to enable secure access while maintaining key confidentiality at all times.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the encryption key is stored securely at terminal A, then key security is maintained, but data sharing becomes complex

Engineering Contradiction:
Improvekey securityVSAvoiddata sharing process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The key management center serves as a mediator that simplifies the data sharing process. Instead of direct key exchange between terminals, the KMC handles the cryptographic operations, managing key generation, storage, and distribution transparently to reduce system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary cryptographic setup where terminal A's key is pre-secured and the KMC pre-configures the encryption infrastructure. When data sharing is needed, the pre-established cryptographic protocols enable seamless re-encryption without requiring real-time key management complexity.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If terminal B obtains the original encryption key, then decryption is simplified, but security risk increases

Engineering Contradiction:
Improvedecryption processVSAvoidkey leakage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the decryption capability from the original key. Terminal B never obtains terminal A's key; instead, the KMC extracts only the necessary decryption information through secure cryptographic protocols, providing terminal B with the ability to decrypt without exposing the original key.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the cryptographic parameters dynamically. Instead of using a static key that terminal B would need to obtain, the system uses re-encryption where the ciphertext is transformed into a form that terminal B can decrypt with its own key, changing the security parameters without compromising the original key.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3229436B1Retrieving data stored securely in the cloud
Publication Date: 2018.07.25 HUAWEI TECH CO LTD
  • EP3229436B1 patent drawingFigure 1~2
  • EP3229436B1 patent drawingFigure 3
  • EP3229436B1 patent drawingFigure 4

AI summary

The present invention relates to the field of IT technologies, and in particular to a method, an apparatus, and a system for protecting cloud data security. According to the method for protecting cloud data security provided in the present invention, a key management center encrypts original data M sent by a first terminal; uploads encrypted data C1 that is obtained through encryption to a cloud server; and when receiving a request for decrypting data or a request for downloading data sent by a second terminal, obtains encrypted data C2 and sends the encrypted data C2 to the second terminal, so that the second terminal decrypts the encrypted data C2 according to a key owned by the second terminal, so as to obtain the original data M. The method provided in embodiments of the present invention not only ensures that the second terminal can decrypt the encrypted data C2 according to a key owned by the second terminal, so as to obtain the original data M, but also ensures that a key of the encrypted data C1 stored in the cloud server may not be leaked, thereby reducing a risk of key leakage and enhancing security of data sharing.