Functional Encryption System Span Program Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current functional encryption schemes lack the ability to provide diversified cryptographic functions securely, limiting their application in advanced access control and data protection scenarios.

Innovation Solution

A cryptographic processing system is developed, incorporating a key generation device, encryption device, and decryption device that utilize a span program and inner-product predicate to generate and manage decryption keys and encrypted data, allowing for flexible and secure access control based on attribute vectors and identification information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional functional encryption schemes are used, then basic encryption functionality is provided, but the system lacks diversified cryptographic functions and high security

Engineering Contradiction:
Improvecryptographic function diversityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a functional encryption system that provides multiple cryptographic functions including key-policy functional encryption, ciphertext-policy functional encryption, and inner-product functional encryption within a single framework. The system uses a common public key and supports diverse decryption capabilities through different types of decryption keys, achieving multi-functionality while maintaining a unified security structure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent divides the functional encryption system into distinct functional modules: key generation for different encryption types, encryption processes for various data formats, and decryption processes for different key types. Each module handles specific cryptographic operations independently, allowing the system to provide diversified functions while maintaining modular security verification.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If functional encryption with high adaptability is implemented, then diversified cryptographic functions are achieved, but system complexity increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidsystem structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent employs a universal functional encryption framework that handles multiple encryption schemes (key-policy, ciphertext-policy, inner-product) through a common mathematical structure. The system uses a single public key generation process and unified encryption interface, reducing structural complexity while maintaining high adaptability through configurable decryption key types and access policies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent achieves diverse cryptographic functions by changing parameters within the same mathematical framework. Different decryption key types (KP-FE keys, CP-FE keys, IPE keys) are generated from the same public key by varying generation parameters. The system flexibly adjusts encryption and decryption parameters to support different access control scenarios without requiring separate system structures.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2565862B1Encryption processing system, key generation device, encryption device, decryption device, signature processing system, signature device and verification device
Publication Date: 2018.08.01 MITSUBISHI ELECTRIC CORP
  • EP2565862B1 patent drawingFigure 1
  • EP2565862B1 patent drawingFigure 2
  • EP2565862B1 patent drawingFigure 3

AI summary

The object is to provide a secure functional encryption scheme having a large number of cryptographic functions. An access structure is constituted by applying the inner-product of attribute vectors to a span program. The access structure has a degree of freedom in design of the span program and design of the attribute vectors, thus having a large degree of freedom in design of access control. A secure functional encryption process having a large number of cryptographic functions is implemented by employing the concept of secret sharing for the access structure.