Encrypted Data Anonymization in Cloud Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing anonymization technologies in cloud systems face challenges in maintaining data confidentiality, as they require disclosing user data to external organizations for processing, leading to potential information leakage, especially when handling highly confidential data.
Innovation Solution
A data processing system that encrypts data and queries, allowing the management server to retrieve and anonymize encrypted data without decryption, ensuring that only encrypted data is processed, and the plaintext remains confidential, even when managed by a third-party organization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is disclosed to an external cloud system for anonymization processing, then anonymization service can be obtained, but information leakage risk increases
Solution Approach 1:
The patent applies preliminary action by encrypting the data before it is transmitted to the cloud system for anonymization processing. The encryption is performed in advance on the user's side, ensuring that the data remains confidential even when processed externally. This resolves the contradiction by enabling anonymization service while preventing information leakage through pre-encryption.
Solution Approach 2:
The patent introduces encryption as an intermediary mechanism between the user data and the cloud system. The encrypted data serves as a mediator that allows the cloud system to perform anonymization operations without directly accessing the plaintext sensitive information, thus enabling service while maintaining security.
2Object-affected harmful factors
If encryption is applied to data before cloud processing, then data confidentiality is maintained, but processing complexity increases
Solution Approach 1:
The encryption is performed as a preliminary action before data transmission, consolidating the complexity into a one-time operation rather than during processing. This approach maintains data confidentiality while managing processing complexity by establishing security upfront.
Solution Approach 2:
The system enables self-service encryption where the user's device performs the encryption locally before transmission. This distributes the processing complexity to the user's end rather than requiring the cloud system to handle complex encryption operations, thus maintaining confidentiality while managing overall system complexity.
Data Source
AI summary
Provided is a data processing system having a processor and a storage apparatus coupled to the processor, wherein: the storage apparatus holds a plurality of encrypted data that are generated by encrypting a plurality of plain text data, and a plurality of encrypted queries for retrieving the plurality of encrypted data directly in an encrypted state; and the processor retrieves each of the encrypted data using each of the encrypted queries and thereby calculates the number of appearances of encrypted data that are retrieved using each of the encrypted queries, changes at least two of the plurality of encrypted data on the basis of the number of appearances of encrypted data that are retrieved using each of the encrypted queries so that predetermined anonymity is satisfied, and outputs a plurality of encrypted data.


