Encrypted Data Management Device for Key Invalidation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The functional encryption scheme lacks an effective secret key invalidation mechanism, as existing schemes are not applicable and result in the need to re-encrypt vast amounts of data when a secret key is lost, leading to significant costs and inefficiencies.

Innovation Solution

An encrypted data management device that acquires and manages encrypted data by determining if the attribute information and key information correspond, setting different key information values based on user validity, and transmitting the updated data to prevent decryption using an invalid secret key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing invalidation schemes are applied to functional encryption, then secret key invalidation can be achieved, but all encrypted data must be re-encrypted which causes tremendous cost

Engineering Contradiction:
Improvesecret key invalidation capabilityVSAvoidre-encryption cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the key information into two parts: original key information and invalidation information. The encrypted data contains only the original key information, while the invalidation information is stored separately in invalidation information management. This segmentation allows invalidation without re-encrypting the data, as the decryption process now requires checking both the original key and the invalidation information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary invalidation information management component that stores invalidation information and coordinates the decryption process. This intermediary checks whether the secret key should be invalidated before allowing decryption, without requiring modification of the encrypted data itself. This mediator enables key invalidation while avoiding the tremendous cost of re-encryption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If secret key is lost and invalidation is not considered in the algorithm, then the functional encryption scheme cannot handle secret key loss, but adding invalidation requires re-encryption of vast amount of data

Engineering Contradiction:
Improvesecret key loss handling capabilityVSAvoidinvalidation mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary action by pre-storing invalidation information in the invalidation information management before any key loss or invalidation event occurs. This pre-prepared invalidation information allows the system to quickly handle secret key loss without requiring complex real-time processing or re-encryption operations when actual invalidation is needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copy of the key information validation process by introducing invalidation information that mirrors the structure and purpose of original key information. This copying approach allows the system to check key validity without duplicating the entire encryption/decryption process, thereby handling secret key loss without excessive complexity.

Inventive Principle:
Principle #26Copying

3Reliability

If conventional invalidation schemes are used, then secret key can be invalidated, but the scheme is not applicable to functional encryption which uses different encryption mechanisms

Engineering Contradiction:
Improvesecret key invalidationVSAvoidcompatibility with functional encryption
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal invalidation mechanism that works with functional encryption by designing the invalidation information structure to be compatible with the functional encryption's attribute-based access control. The invalidation information management can handle both traditional encryption and functional encryption scenarios, making the invalidation capability universally applicable across different encryption schemes without requiring scheme-specific implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9237013B2Encrypted data management device, encrypted data management method, and encrypted data management program
Publication Date: 2016.01.12 MITSUBISHI ELECTRIC CORP
  • US9237013B2 patent drawing
  • US9237013B2 patent drawing
  • US9237013B2 patent drawing

AI summary

An invalidation scheme of a secret key is implemented, which is usable for a functional encryption scheme. In a cryptographic processing system 10 employing an encryption scheme with which if attribute information and key information set in encrypted data do not correspond to attribute information and key information set in a secret key, the encrypted data cannot be decrypted using the secret key, an encrypted data management device 200 is provided, which carries out a relay between a user terminal 100 carrying out encryption and decryption of data and an encrypted data storage device 300 storing encrypted data. The encrypted data management device 200 determines whether or not a user whose secret key is invalid is included in users having attribute information set in the encrypted data acquired from the encrypted data storage device 300, and sets a different value as key information in the encrypted data based on the determination result. Then, the encrypted data management device 200 sends the encrypted data in which the key information is set to the user terminal 100.