Cloud Data Security via Key Management Center Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud data security, existing methods face challenges in protecting encryption keys from leakage during data sharing, leading to potential data insecurity.
Innovation Solution
A key management center encrypts original data and stores it, then processes and sends encrypted data to a second terminal for decryption using a key owned by that terminal, preventing direct exposure of the encryption key and reducing key leakage risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If terminal B requests a key from terminal A to decrypt cloud data, then data sharing is enabled, but key leakage risk increases
Solution Approach 1:
The patent extracts the encryption key from the data sharing process. Instead of terminal B requesting terminal A's key, the system uses re-encryption where terminal A's key never leaves terminal A. The key management center extracts only the necessary decryption capability through cryptographic protocols, leaving the actual key secured at its origin.
Solution Approach 2:
The patent introduces a key management center as an intermediary that facilitates data sharing without exposing keys. The KMC mediates between terminal A (data owner) and terminal B (data requester) using cryptographic protocols to enable secure access while maintaining key confidentiality at all times.
2Reliability
If the encryption key is stored securely at terminal A, then key security is maintained, but data sharing becomes complex
Solution Approach 1:
The key management center serves as a mediator that simplifies the data sharing process. Instead of direct key exchange between terminals, the KMC handles the cryptographic operations, managing key generation, storage, and distribution transparently to reduce system complexity.
Solution Approach 2:
The system performs preliminary cryptographic setup where terminal A's key is pre-secured and the KMC pre-configures the encryption infrastructure. When data sharing is needed, the pre-established cryptographic protocols enable seamless re-encryption without requiring real-time key management complexity.
3Ease of operation
If terminal B obtains the original encryption key, then decryption is simplified, but security risk increases
Solution Approach 1:
The patent extracts the decryption capability from the original key. Terminal B never obtains terminal A's key; instead, the KMC extracts only the necessary decryption information through secure cryptographic protocols, providing terminal B with the ability to decrypt without exposing the original key.
Solution Approach 2:
The system changes the cryptographic parameters dynamically. Instead of using a static key that terminal B would need to obtain, the system uses re-encryption where the ciphertext is transformed into a form that terminal B can decrypt with its own key, changing the security parameters without compromising the original key.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The present invention relates to the field of IT technologies, and in particular to a method, an apparatus, and a system for protecting cloud data security. According to the method for protecting cloud data security provided in the present invention, a key management center encrypts original data M sent by a first terminal; uploads encrypted data C1 that is obtained through encryption to a cloud server; and when receiving a request for decrypting data or a request for downloading data sent by a second terminal, obtains encrypted data C2 and sends the encrypted data C2 to the second terminal, so that the second terminal decrypts the encrypted data C2 according to a key owned by the second terminal, so as to obtain the original data M. The method provided in embodiments of the present invention not only ensures that the second terminal can decrypt the encrypted data C2 according to a key owned by the second terminal, so as to obtain the original data M, but also ensures that a key of the encrypted data C1 stored in the cloud server may not be leaked, thereby reducing a risk of key leakage and enhancing security of data sharing.