Encrypted Data Management Device for Key Invalidation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The functional encryption scheme lacks an effective secret key invalidation mechanism, as existing schemes are not applicable and result in the need to re-encrypt vast amounts of data when a secret key is lost, leading to significant costs and inefficiencies.
Innovation Solution
An encrypted data management device that acquires and manages encrypted data by determining if the attribute information and key information correspond, setting different key information values based on user validity, and transmitting the updated data to prevent decryption using an invalid secret key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing invalidation schemes are applied to functional encryption, then secret key invalidation can be achieved, but all encrypted data must be re-encrypted which causes tremendous cost
Solution Approach 1:
The patent segments the key information into two parts: original key information and invalidation information. The encrypted data contains only the original key information, while the invalidation information is stored separately in invalidation information management. This segmentation allows invalidation without re-encrypting the data, as the decryption process now requires checking both the original key and the invalidation information.
Solution Approach 2:
The patent introduces an intermediary invalidation information management component that stores invalidation information and coordinates the decryption process. This intermediary checks whether the secret key should be invalidated before allowing decryption, without requiring modification of the encrypted data itself. This mediator enables key invalidation while avoiding the tremendous cost of re-encryption.
2Adaptability or versatility
If secret key is lost and invalidation is not considered in the algorithm, then the functional encryption scheme cannot handle secret key loss, but adding invalidation requires re-encryption of vast amount of data
Solution Approach 1:
The patent performs preliminary action by pre-storing invalidation information in the invalidation information management before any key loss or invalidation event occurs. This pre-prepared invalidation information allows the system to quickly handle secret key loss without requiring complex real-time processing or re-encryption operations when actual invalidation is needed.
Solution Approach 2:
The patent creates a copy of the key information validation process by introducing invalidation information that mirrors the structure and purpose of original key information. This copying approach allows the system to check key validity without duplicating the entire encryption/decryption process, thereby handling secret key loss without excessive complexity.
3Reliability
If conventional invalidation schemes are used, then secret key can be invalidated, but the scheme is not applicable to functional encryption which uses different encryption mechanisms
Solution Approach 1:
The patent creates a universal invalidation mechanism that works with functional encryption by designing the invalidation information structure to be compatible with the functional encryption's attribute-based access control. The invalidation information management can handle both traditional encryption and functional encryption scenarios, making the invalidation capability universally applicable across different encryption schemes without requiring scheme-specific implementations.
Data Source
AI summary
An invalidation scheme of a secret key is implemented, which is usable for a functional encryption scheme. In a cryptographic processing system 10 employing an encryption scheme with which if attribute information and key information set in encrypted data do not correspond to attribute information and key information set in a secret key, the encrypted data cannot be decrypted using the secret key, an encrypted data management device 200 is provided, which carries out a relay between a user terminal 100 carrying out encryption and decryption of data and an encrypted data storage device 300 storing encrypted data. The encrypted data management device 200 determines whether or not a user whose secret key is invalid is included in users having attribute information set in the encrypted data acquired from the encrypted data storage device 300, and sets a different value as key information in the encrypted data based on the determination result. Then, the encrypted data management device 200 sends the encrypted data in which the key information is set to the user terminal 100.


