Encrypted Data Revocation Without Re-encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current file encryption systems struggle to handle complex personnel transfer events, such as secondment or temporary retirement, without re-encrypting encrypted data, and fail to manage temporary revocations effectively.
Innovation Solution
A data storage apparatus that includes an encrypted data receiving unit, a data storage unit, and a revocation processing unit, which adds revocation information to the embedded decryption condition of encrypted data, allowing for temporary revocation without re-encrypting the data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If re-encryption is performed to handle personnel transfer events, then access control reliability is improved, but processing time and system complexity increase
Solution Approach 1:
The patent applies preliminary action by pre-embedding decryption conditions directly into the encrypted data structure during the initial encryption process. This allows the system to handle personnel transfers by simply updating conditional parameters without performing time-consuming re-encryption operations, thus resolving the contradiction between maintaining access control reliability and reducing processing time.
Solution Approach 2:
The patent implements dynamics by making decryption conditions dynamic and modifiable within the encrypted data structure. Instead of static encryption keys, the system uses conditional parameters that can be updated to reflect personnel transfer events, allowing flexible access control management without re-encryption and thereby reducing processing time while maintaining security reliability.
2Adaptability or versatility
If re-encryption is performed to handle complex personnel transfer events, then access control adaptability is improved, but device complexity increases
Solution Approach 1:
By pre-embedding multiple decryption conditions and parameters into the encrypted data structure during initial encryption, the system is prepared to handle various personnel transfer scenarios (secondment, temporary retirement, reinstatement) without requiring complex re-encryption logic. This preliminary preparation enables high adaptability while keeping the system relatively simple.
Solution Approach 2:
The patent utilizes parameter changes by modifying conditional parameters within the encrypted data structure to adapt to different personnel transfer events. Instead of implementing complex re-encryption algorithms, the system simply updates parameters such as user attributes and decryption conditions, achieving high adaptability with minimal increase in system complexity.
3Reliability
If re-encryption is performed to manage temporary revocations, then security reliability is improved, but processing time and operational complexity increase
Solution Approach 1:
The patent applies preliminary action by embedding revocation conditions and temporary access parameters directly into the encrypted data structure during initial encryption. This allows temporary revocations to be managed by simply updating or disabling specific conditional parameters without performing complex re-encryption operations, thereby maintaining security reliability while simplifying operations.
Solution Approach 2:
The system implements dynamics by making decryption conditions dynamic and temporarily modifiable. For temporary revocations, the system can dynamically adjust conditional parameters to grant or revoke access without permanent changes to the encrypted data structure, enabling easy reversal when needed. This dynamic approach maintains security while significantly reducing operational complexity compared to permanent re-encryption solutions.
Data Source
AI summary
An encrypted data receiving unit (201) receives encrypted data which has been encrypted, in which a decryption condition to define a user attribute of a decryption-permission user who is permitted to decrypt the encrypted data is embedded. A data storage unit (202) stores the encrypted data received by the encrypted data receiving unit (201) in an encrypted state. A revocation processing unit (209) adds revocation information in which a user attribute of a revoked user who is no longer the decryption-permission user is indicated, to an embedded decryption condition that is embedded in the encrypted data, while the encrypted data remains in an encrypted state.


