Data Provenance via Cryptographic Signatures in Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless communication systems, devices face challenges in verifying the provenance (authenticity and origin) of data transferred through untrusted intermediary devices, such as data management systems or cloud-based storage, without compromising data privacy.
Innovation Solution
Devices generate encrypted data packages with associated data identifiers and signatures, using encryption and signing keys, allowing receiving devices to verify provenance even when data is processed by untrusted intermediaries, while maintaining data privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is transferred through intermediary devices (data management system, cloud-based storage), then data transfer and processing capability is improved, but data provenance verification becomes impossible without trusting the intermediary devices
Solution Approach 1:
The patent applies preliminary action by embedding provenance information (digital signatures, hashes, metadata) into the data package before it is transferred through intermediary devices. This allows the receiving device to verify provenance without needing to trust the intermediaries, as the verification data is already attached to the data itself.
Solution Approach 2:
The patent uses digital signatures and cryptographic hashes as intermediaries between the data and the verification process. These cryptographic elements act as mediators that carry provenance information through untrusted intermediary devices, enabling verification without requiring trust in the intermediaries themselves.
2Object-affected harmful factors
If data is encrypted to maintain privacy, then data security is improved, but ability to verify provenance is reduced
Solution Approach 1:
The patent segments the data package into multiple components: encrypted data payload, separate provenance information (signatures, hashes), and metadata. This segmentation allows the provenance verification data to remain accessible and verifiable while the actual data remains encrypted and private, resolving the contradiction between privacy and verification.
Solution Approach 2:
The patent applies local quality by differentiating the accessibility of different parts of the data package. The provenance information (signatures, hashes) is kept in an unencrypted, accessible state for verification purposes, while the actual data content remains encrypted. This allows different parts of the same data package to have different security properties appropriate to their function.
3Reliability
If provenance information is attached to data, then data authenticity is improved, but data package size increases
Solution Approach 1:
The patent uses cryptographic hashing to create a compact representation (hash) of the data that serves as provenance information. Instead of attaching redundant copies of the actual data or extensive metadata, the hash function creates a fixed-size digital fingerprint that uniquely represents the data content, providing authenticity verification with minimal size overhead.
Data Source
AI summary
Methods, systems, and devices for wireless communications are described. Aspects include a device generating data to be sent to a receiving device and determining to provide provenance for the data. The device may generate a data identifier based on an identifier generation key and encrypt the data using an encryption key generated from a key associated with an owner of the device. The device may sign they encrypted data transmission using a signing key where the signing key is based on the encrypted data and the data identifier. In some cases, the device may send the data to a receiving device via one or more proxy devices. In some cases, multiple device may send signed data transmissions to a proxy device and the proxy device may process the multiple data transmission and send the processed data to the receiving device. The receiving device may verify provenance of the data.


