Encrypted Product Data Access via Tag Re-encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In production logistics, complex products with confidential data stored in encrypted form on a cloud server face challenges in allowing multiple production stations to access and modify this data securely, especially across company boundaries, as existing solutions require trust in a single security instance and complex key management.

Innovation Solution

A system using asymmetric key pairs stored in both product tags and production stations, where the product data is encrypted with a document key, allowing re-encryption and secure access without revealing the key to the cloud server, ensuring data remains secure and accessible only to authorized stations physically interacting with the product.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If product data are stored encrypted on a cloud server, then data confidentiality is improved, but access complexity increases for multiple production stations

Engineering Contradiction:
Improvedata confidentialityVSAvoidaccess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-distributing asymmetric key pairs to each production station and tag before the actual data access occurs. The public keys are stored in advance in the cloud server, enabling encrypted data to be decrypted by any authorized station without requiring real-time key management or trust in a central security instance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses asymmetric cryptography as an intermediary mechanism between the cloud server and production stations. The encrypted product data acts as a mediator that can be selectively decrypted by any station possessing the corresponding private key, eliminating the need for direct trust relationships or complex authentication protocols between stations and the server.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a single security instance manages keys for all production stations, then key management is simplified, but trust requirements across company boundaries increase

Engineering Contradiction:
Improvekey management complexityVSAvoidcross-company trust compatibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the centralized key management into distributed asymmetric key pairs, where each production station and tag has its own independent private key. This eliminates the need for a single trusted security instance while maintaining simplified key management through the use of public key infrastructure that works autonomously across organizational boundaries.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If all production stations can access encrypted product data, then production flexibility is improved, but security risks increase without a universal trust authority

Engineering Contradiction:
Improveproduction flexibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent enables self-service security where each production station autonomously decrypts product data using its own private key without requiring authentication or trust verification from a central authority. The security model is self-sufficient, with each station independently verifying its authority to access data through possession of the corresponding private key.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10764260B2Distributed processing of a product on the basis of centrally encrypted stored data
Publication Date: 2020.09.01 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • US10764260B2 patent drawing
  • US10764260B2 patent drawing
  • US10764260B2 patent drawing

AI summary

The invention provides a system for encryptedly storing product data of a product having an attached tag centrally on a product data server, and reading out the centrally stored product data by production stations which are to process the product. The product data are encrypted with a document key which in turn is encrypted with a public key of the tag. The tag contains access information for the centrally stored product data. When a production station accesses product data on the product data server, the tag carries out a re-encryption of the document key from the key system of the tag to that of the accessing production station.