Group Access Vector Encryption for Record-Level Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for distributing business information face challenges in efficiently and securely managing access rights for multiple users, particularly when there are a large number of users and complex access rules, leading to impractical and resource-intensive encryption methods.
Innovation Solution
Implementing record or row-level security using group access vectors, where each record is encrypted with a unique encryption key based on user group membership, and a separate keys file is used, encrypted with a master key, to ensure secure access while minimizing additional data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If different encrypted data reports are created and transmitted to different users to ensure secure access, then information security is improved, but device complexity and resource requirements increase substantially
Solution Approach 1:
The patent segments the data report into individual records, each encrypted with a specific encryption key. Instead of creating separate encrypted reports for each user, the system divides the data into record-level segments that can be selectively decrypted based on user credentials, thereby maintaining security while reducing system complexity.
Solution Approach 2:
The patent applies local quality by assigning different encryption keys to different records based on their sensitivity and access requirements. Each record has its own encryption characteristics tailored to its specific security needs, rather than applying a uniform encryption scheme to the entire data report, which optimizes both security and resource utilization.
2Manufacturing precision
If record-level encryption with unique keys is implemented for each user, then access control precision is improved, but loss of time and computational resources increase
Solution Approach 1:
The patent implements preliminary action by pre-computing and storing encryption keys associated with user credentials before actual data access occurs. When a user requests data, the system quickly retrieves the appropriate pre-computed keys based on user authentication, avoiding time-consuming key generation during the access process itself.
Solution Approach 2:
The patent uses copying by creating and storing multiple encrypted versions of records with different encryption keys in advance. These encrypted copies are stored in the data structure, allowing users to access pre-encrypted data without requiring real-time encryption operations, thus reducing processing time while maintaining precise access control.
3Reliability
If complex access rules are enforced to govern user access to information, then information security is improved, but ease of operation and administrative burden worsen
Solution Approach 1:
The patent applies universality by designing a multi-functional encryption system where a single data structure with integrated encryption keys can serve multiple access control purposes. The same encrypted data structure supports various user credentials and access rules simultaneously, eliminating the need for separate complex access control mechanisms and simplifying administration.
Solution Approach 2:
The patent implements self-service by enabling the encrypted data structure to automatically determine which records to decrypt and display based on user credentials provided at access time. The system autonomously handles access control logic by matching user credentials with stored encryption keys, eliminating the need for manual administrative intervention in access decisions.
Data Source
AI summary
According to some embodiments, a system, method, means, and/or computer program code are provided to facilitate an appropriate access to secure information by a plurality of users categorized into a plurality of groups. For example, a group access vector may be determined for each of a plurality of records in a data report, each group access vector including a plurality of indicators that indicate if an associated group is authorized to access that record. It may then be arranged for an encryption key to be assigned to each unique group access vector associated with the data report. It may further be arranged for each record in the data report to be encrypted in accordance with the encryption key assigned to the group access vector of that record, the combined encrypted records comprising an encrypted data report.


