Full-Link Data Security With Proxy Re-Encryption and DHT Self-Destruction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data security protection technologies are narrowly focused on isolated stages of the data lifecycle, lacking a comprehensive strategy for full-link security protection that includes access control, data encryption, and data destruction, and do not consider data security attributes or integrity verification.
Innovation Solution
A full-link data security protection method and system that uses attribute-based proxy re-encryption for encryption, implementing fine-grained access control, verifying data integrity, and enabling on-demand and automatic data destruction through a distributed hash table network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If existing data security protection technologies are designed narrowly towards isolated stages, then the protection for specific stages is simplified, but the overall comprehensive security protection is insufficient
Solution Approach 1:
The patent divides the data lifecycle into six distinct stages (collection, transmission, storage, processing, exchange, destruction) and applies security protection measures tailored to each stage. This segmentation allows comprehensive coverage while maintaining manageable complexity through stage-specific implementations.
Solution Approach 2:
The patent creates a unified data security protection system that handles multiple functions across all lifecycle stages through integrated mechanisms including attribute-based access control, proxy re-encryption, integrity verification, and automated destruction. This multi-functional approach ensures comprehensive security without requiring separate isolated systems.
2Adaptability or versatility
If data sharing is enabled across multiple participants and institutions, then business demands and innovative applications are supported, but security risks increase due to multiple access points
Solution Approach 1:
The patent applies attribute-based access control that assigns different security attributes and access rights to different participants and institutions based on their specific needs. This allows flexible data sharing while maintaining security by tailoring protection levels to each participant's role and requirements.
Solution Approach 2:
The patent introduces a trusted third party (key generation center and attribute authority) that mediates between data owners and participants. This intermediary manages key distribution, attribute assignment, and access control decisions, reducing the security burden on individual participants while enabling secure multi-party data sharing.
3Reliability
If data encryption is applied to protect data confidentiality, then data security is improved, but data integrity verification becomes more difficult
Solution Approach 1:
The patent combines data encryption with integrity verification mechanisms by attaching digital signatures and hash values to encrypted data. This merging allows the system to simultaneously provide confidentiality through encryption and integrity verification through cryptographic signatures, eliminating the trade-off between the two security objectives.
4Reliability
If comprehensive full-link data protection is implemented, then security coverage is improved, but system complexity and implementation difficulty increase
Solution Approach 1:
The patent implements nested security mechanisms where attribute-based access control frameworks enclose encryption protocols, which in turn enclose integrity verification and destruction mechanisms. This nested structure organizes complex security functions into hierarchical layers, making the system more manageable while maintaining comprehensive coverage.
Data Source
AI summary
A full-link data security protection method and a system are provided. The method includes: at a data creation and collection stage: building a data security identification; at a data transmission and storage stage: dividing the ciphertext file into blocks to generate ciphertext components; calculating a virtual index and a data label; transmitting the ciphertext components to a distributed hash table (DHT) network; uploading a tuple including the virtual index, the data block, and the data label to a cloud server; at a data processing and exchange stage: applying re-encryption based on a re-encryption key generation algorithm; performing decryption to obtain the signed identifier and a secret value; acquiring a tuple having a ciphertext component associated with the virtual index. Attribute-based proxy re-encryption is used to achieve fine-grained access control for the cloud storage. In the data destruction stage, the DHT network automatic updating utility is leveraged to realize data self-destructing.


