Distributed Data Reference System with Mix-Net Shuffling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing database technologies face challenges in ensuring the validity of individual data, particularly in healthcare information systems, where key management and pseudonymization processes are vulnerable to leakage and lack effective validation mechanisms, making it difficult to confirm the correctness and ownership of pseudonymized data.

Innovation Solution

A data reference system that employs distributed devices for encrypting and shuffling data sequences, using a mix-net configuration with zero-knowledge proofs to ensure consistent order shuffling and decryption, thereby validating data integrity and ownership while maintaining confidentiality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If pseudonymization is performed using a single key at one location, then the process is simple and efficient, but the key becomes vulnerable to leakage and the correspondence relationship between original and pseudonymized data can be easily obtained

Engineering Contradiction:
Improveease of pseudonymization processVSAvoidsecurity of key management
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The secret key is segmented into multiple key fragments (first key fragment, second key fragment, etc.) that are distributed to different devices. No single device possesses the complete key, making it impossible to decrypt data or obtain correspondence relationships alone. This segmentation resolves the contradiction by maintaining security through distribution while enabling collaborative pseudonymization processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A mixing device acts as an intermediary that receives encrypted data, performs shuffling and re-encryption operations, and outputs transformed encrypted data. The mixing device uses key fragments to perform zero-knowledge proofs and verify correspondence relationships without revealing actual data content or establishing direct links between original and pseudonymized data, thus enhancing security while maintaining processability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple mixing devices are used to enhance security through distributed key management, then security is improved, but the system complexity and difficulty of operation increase

Engineering Contradiction:
Improvesecurity of distributed key managementVSAvoidcomplexity of mix-net configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Each mixing device is designed with multi-functionality, capable of performing encryption, decryption, shuffling, re-encryption, and zero-knowledge proof verification. This universal design allows devices to operate independently yet collaboratively within the mix-net, reducing overall system complexity by avoiding the need for specialized components for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback mechanisms through zero-knowledge proofs that verify the correctness of operations performed by mixing devices. Each device provides cryptographic proof that it has correctly shuffled and re-encrypted data without revealing sensitive information, enabling automated verification and reducing operational complexity through self-validation.

Inventive Principle:
Principle #23Feedback

3Loss of information

If data is encrypted and shuffled through multiple devices, then confidentiality is maintained, but the ability to validate data integrity and ownership is compromised

Engineering Contradiction:
Improveprotection of data confidentialityVSAvoidvalidation of data integrity
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

Before data enters the mixing devices for encryption and shuffling, authentication information is preliminarily attached to the data. This preliminary action ensures that ownership and integrity validation capabilities are established in advance, allowing the system to verify data provenance even after multiple transformations through the mix-net without compromising confidentiality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mixing device serves as an intermediary that preserves authentication information while performing encryption and shuffling operations. It uses distributed key fragments to verify data integrity and ownership through zero-knowledge proofs without revealing confidential data content, thus maintaining both confidentiality and validation capabilities simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8468346B2Data reference system, database presentation/distribution system, and data reference method
Publication Date: 2013.06.18 NEC CORP
  • US8468346B2 patent drawing
  • US8468346B2 patent drawing
  • US8468346B2 patent drawing

AI summary

An element-data generating device encrypts respective vectors each including plural pieces of data, generates a vector including encrypted texts, and outputs such a vector as element data. A database generating system has plural first distributed devices and outputs a sequence of all pieces of element data as a database. A database presentation system has plural second distributed devices, generates, based on a reference item specifying an item to be referred, plural sequences of data to be referred from the database, and performs order shuffling of individual elements of the sequences of the data by all of the second distributed devices so that the order shuffling of the elements of the data sequence is consistent throughout all data sequences.