Distributed Trust-Based Attribute Encryption for Secure Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face challenges in providing secure communications in a distributed manner without a centralized server, especially in scenarios like disasters or military activities, where traditional centralized solutions are impractical and vulnerable to attacks, and existing encryption methods are inefficient for dynamic trust level management in pervasive social networking.

Innovation Solution

Implementing an attribute-based encryption (ABE) scheme that encrypts communication keys with public attribute keys associated with trust levels, allowing only eligible devices with sufficient trust levels to decrypt the data, and dynamically updating keys based on re-evaluated trust levels to ensure secure and flexible access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized server is used for key management, then security control is simplified, but the system becomes vulnerable to attacks and impractical in distributed scenarios

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the centralized key management function from the system, allowing each user device to independently manage its own encryption keys and perform trust evaluations locally. This eliminates the single point of failure (centralized server) while maintaining security control through distributed key management and attribute-based encryption mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of manufacture

If traditional encryption methods are used, then implementation is simple, but they are inefficient for dynamic trust level management

Engineering Contradiction:
Improveimplementation simplicityVSAvoiddynamic trust management
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic trust level management by allowing trust attributes to be evaluated, updated, and revoked in real-time based on user behavior and system policies. The attribute-based encryption scheme enables flexible adaptation of access rights without requiring system reconfiguration, making the encryption approach adaptable to changing trust conditions while maintaining implementation feasibility through standardized cryptographic operations.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If attribute-based encryption is implemented, then access control flexibility is improved, but computational overhead increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidcomputational overhead
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent performs trust attribute evaluations and generates encryption keys in advance, before actual data transmission occurs. By pre-computing trust levels and establishing encryption relationships beforehand, the system reduces real-time computational overhead during data communication while maintaining the flexibility of attribute-based access control.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10362001B2Method and apparatus for providing secure communications based on trust evaluations in a distributed manner
Publication Date: 2019.07.23 NOKIA TECHNOLOGIES OY
  • US10362001B2 patent drawing
  • US10362001B2 patent drawing
  • US10362001B2 patent drawing

AI summary

An approach is provided for providing secure communications based on trust evaluation in a distributed manner. A method can comprises: sending data to a plurality of devices, the data being encrypted with a communication key; encrypting the communication key with public attribute keys associated with attributes, wherein the attributes comprising at least one trust level related attribute representing an access condition for the data based on a trust level; evaluating a trust level of each device of the plurality of devices, to identify eligible devices of the plurality of devices whose trust levels satisfy the access condition; sending the encrypted communication key to the plurality of devices; and sending secret attribute keys associated with the attributes to each device of the eligible devices for decrypting the encrypted communication key, the secret attribute keys being personalized for the each device of the eligible devices.