Full-Link Data Security With Proxy Re-Encryption and DHT Self-Destruction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security protection technologies are narrowly focused on isolated stages of the data lifecycle, lacking a comprehensive strategy for full-link security protection that includes access control, data encryption, and data destruction, and do not consider data security attributes or integrity verification.

Innovation Solution

A full-link data security protection method and system that uses attribute-based proxy re-encryption for encryption, implementing fine-grained access control, verifying data integrity, and enabling on-demand and automatic data destruction through a distributed hash table network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If existing data security protection technologies are designed narrowly towards isolated stages, then the protection for specific stages is simplified, but the overall comprehensive security protection is insufficient

Engineering Contradiction:
Improveprotection technology complexityVSAvoidfull-link security protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the data lifecycle into six distinct stages (collection, transmission, storage, processing, exchange, destruction) and applies security protection measures tailored to each stage. This segmentation allows comprehensive coverage while maintaining manageable complexity through stage-specific implementations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a unified data security protection system that handles multiple functions across all lifecycle stages through integrated mechanisms including attribute-based access control, proxy re-encryption, integrity verification, and automated destruction. This multi-functional approach ensures comprehensive security without requiring separate isolated systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If data sharing is enabled across multiple participants and institutions, then business demands and innovative applications are supported, but security risks increase due to multiple access points

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies attribute-based access control that assigns different security attributes and access rights to different participants and institutions based on their specific needs. This allows flexible data sharing while maintaining security by tailoring protection levels to each participant's role and requirements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces a trusted third party (key generation center and attribute authority) that mediates between data owners and participants. This intermediary manages key distribution, attribute assignment, and access control decisions, reducing the security burden on individual participants while enabling secure multi-party data sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If data encryption is applied to protect data confidentiality, then data security is improved, but data integrity verification becomes more difficult

Engineering Contradiction:
Improvedata confidentialityVSAvoidintegrity verification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent combines data encryption with integrity verification mechanisms by attaching digital signatures and hash values to encrypted data. This merging allows the system to simultaneously provide confidentiality through encryption and integrity verification through cryptographic signatures, eliminating the trade-off between the two security objectives.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If comprehensive full-link data protection is implemented, then security coverage is improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements nested security mechanisms where attribute-based access control frameworks enclose encryption protocols, which in turn enclose integrity verification and destruction mechanisms. This nested structure organizes complex security functions into hierarchical layers, making the system more manageable while maintaining comprehensive coverage.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS12362926B1Full-link data security protection method and system
Publication Date: 2025.07.15 JINAN UNIVERSITY
  • US12362926B1 patent drawing
  • US12362926B1 patent drawing
  • US12362926B1 patent drawing

AI summary

A full-link data security protection method and a system are provided. The method includes: at a data creation and collection stage: building a data security identification; at a data transmission and storage stage: dividing the ciphertext file into blocks to generate ciphertext components; calculating a virtual index and a data label; transmitting the ciphertext components to a distributed hash table (DHT) network; uploading a tuple including the virtual index, the data block, and the data label to a cloud server; at a data processing and exchange stage: applying re-encryption based on a re-encryption key generation algorithm; performing decryption to obtain the signed identifier and a secret value; acquiring a tuple having a ciphertext component associated with the virtual index. Attribute-based proxy re-encryption is used to achieve fine-grained access control for the cloud storage. In the data destruction stage, the DHT network automatic updating utility is leveraged to realize data self-destructing.