Encrypted Data Management via Segmented Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional building management systems face security and privacy issues due to the storage of sensitive data in cloud services, which can reveal personal and confidential information, and outsourcing data analysis to third parties poses additional threats.

Innovation Solution

A method and system for managing encrypted data using one or more computing entities, where data is encrypted based on policies using encryption keys, stored as ciphertext, and decryption keys are computed and provided by a security management entity based on access rights, allowing clients to decrypt specific subsets of data while maintaining control over sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is stored in cloud services for building management, then data storage and accessibility are improved, but security and privacy protection deteriorate due to exposure of personal and confidential information

Engineering Contradiction:
Improvedata storage and accessibilityVSAvoidsecurity and privacy risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments data into multiple encrypted subsets, where each subset alone is insufficient to reconstruct the original information. This segmentation approach allows cloud storage to be used while preventing unauthorized parties from gaining meaningful information even if they access the stored data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary decryption system that controls access to the encrypted data subsets. This intermediary layer between the cloud storage and the data user ensures that even if cloud storage is compromised, the actual data remains protected unless the intermediary explicitly provides decryption keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If all collected data is initially stored as a whole, then data collection completeness is improved, but security threats increase when outsourcing data analysis to third parties

Engineering Contradiction:
Improvedata completenessVSAvoidsecurity threats from third-party access
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent divides complete data sets into multiple encrypted subsets before storage. When third parties need to analyze data, they can only access specific subsets with limited decryption capabilities, ensuring data completeness for analysis while preventing unauthorized reconstruction of the complete data set.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements partial decryption where third parties can decrypt and analyze only the specific data subsets they are authorized to access, rather than providing access to the complete data set. This partial action approach maintains data completeness for authorized analysis while limiting security risks.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10567511B2Method and system for managing encrypted data of devices
Publication Date: 2020.02.18 NEC CORP
  • US10567511B2 patent drawing
  • US10567511B2 patent drawing
  • US10567511B2 patent drawing

AI summary

A method for managing data of devices using one or more computing entities includes encrypting, by one or more encrypting entities, the data based on encryption policies using encryption keys; storing the encrypted data as ciphertext at a storing entity; requesting decryption keys to decrypt the stored ciphertext by one or more clients; computing restricted decryption keys based on access right policies for the requesting clients by a security management entity; and providing the generated decryption keys to the requesting clients for decrypting the stored ciphertext.