Domain Key Mediator for Secure Multi-Device Network Storage Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage networks face challenges in securely managing cryptographic keys within authorized domains, particularly in balancing high security with complex key management and enabling simultaneous access to sensitive data by multiple trusted devices without direct communication.
Innovation Solution
Establishing an authenticated channel between domain member devices and candidate devices for key exchange, where a confidential domain key is encrypted with the candidate device's encryption key and stored on the network, allowing encrypted data access without manual key entry, and implementing a system for key management and access control that includes domain lists and message authentication codes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a high level of security is implemented using complex key management operations, then security is improved, but device complexity and ease of operation deteriorate
Solution Approach 1:
The patent introduces a domain key as an intermediary element that mediates between multiple device-specific encryption keys and the encrypted data. Instead of managing complex key relationships directly, devices use the domain key as a mediator to encrypt and decrypt data, significantly simplifying key management while maintaining high security levels.
Solution Approach 2:
The patent segments the key management system by introducing a hierarchical structure where a domain key is separate from device-specific keys. This segmentation allows the domain key to handle data encryption/decryption independently, while device keys only need to manage the domain key distribution, reducing overall system complexity.
2Adaptability or versatility
If multiple devices need to access the same data simultaneously without direct communication, then accessibility is improved, but key distribution complexity increases
Solution Approach 1:
The domain key serves as a universal key that enables all authorized devices to access encrypted data independently. Each device can use the domain key to encrypt or decrypt data without needing to communicate with other devices or know their encryption keys,实现ing multi-functional access control.
3Ease of operation
If passwords are used for security, then ease of operation is improved, but security deteriorates due to vulnerability to attacks
Solution Approach 1:
The patent replaces the mechanical password entry system with an automated cryptographic system using encryption keys and the domain key. Instead of manually entering passwords, devices automatically perform cryptographic operations using stored keys, eliminating the security weaknesses of passwords while maintaining ease of operation through automation.
Data Source
AI summary
The present invention relates to a method and a system of securely storing data on a network (100) for access by an authorized domain (101, 102, 103), which authorized domain includes at least two devices that share a confidential domain key (K), and an authorized domain management system for securely storing data on a network for access by an authorized domain. The present invention enables any member device to store protected data on the network such that any other member device can access the data in plaintext without having to communicate with the device that actually stored the data.


