Domain Key Mediator for Secure Multi-Device Network Storage Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage networks face challenges in securely managing cryptographic keys within authorized domains, particularly in balancing high security with complex key management and enabling simultaneous access to sensitive data by multiple trusted devices without direct communication.

Innovation Solution

Establishing an authenticated channel between domain member devices and candidate devices for key exchange, where a confidential domain key is encrypted with the candidate device's encryption key and stored on the network, allowing encrypted data access without manual key entry, and implementing a system for key management and access control that includes domain lists and message authentication codes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a high level of security is implemented using complex key management operations, then security is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a domain key as an intermediary element that mediates between multiple device-specific encryption keys and the encrypted data. Instead of managing complex key relationships directly, devices use the domain key as a mediator to encrypt and decrypt data, significantly simplifying key management while maintaining high security levels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the key management system by introducing a hierarchical structure where a domain key is separate from device-specific keys. This segmentation allows the domain key to handle data encryption/decryption independently, while device keys only need to manage the domain key distribution, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple devices need to access the same data simultaneously without direct communication, then accessibility is improved, but key distribution complexity increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidkey distribution
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The domain key serves as a universal key that enables all authorized devices to access encrypted data independently. Each device can use the domain key to encrypt or decrypt data without needing to communicate with other devices or know their encryption keys,实现ing multi-functional access control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If passwords are used for security, then ease of operation is improved, but security deteriorates due to vulnerability to attacks

Engineering Contradiction:
Improveaccess methodVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical password entry system with an automated cryptographic system using encryption keys and the domain key. Instead of manually entering passwords, devices automatically perform cryptographic operations using stored keys, eliminating the security weaknesses of passwords while maintaining ease of operation through automation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8059818B2Accessing protected data on network storage from multiple devices
Publication Date: 2011.11.15 NOKIA TECHNOLOGIES OY
  • US8059818B2 patent drawing
  • US8059818B2 patent drawing
  • US8059818B2 patent drawing

AI summary

The present invention relates to a method and a system of securely storing data on a network (100) for access by an authorized domain (101, 102, 103), which authorized domain includes at least two devices that share a confidential domain key (K), and an authorized domain management system for securely storing data on a network for access by an authorized domain. The present invention enables any member device to store protected data on the network such that any other member device can access the data in plaintext without having to communicate with the device that actually stored the data.