Group Delegation Computing Method for Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing delegation computing models allow malicious users to exploit pre-processing investments made by others, violating the pay-as-you-go model in cloud computing, as they can delegate computing tasks for free without significant initial investment.
Innovation Solution
A group delegation computing method that combines customers with the same computing task into a group, authorizing them as group members to use shared resources, ensuring only the group administrator can trace identities in case of misuse, and providing a framework for verifying the correctness of computing results without revealing delegator identities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If public delegation computing is used to allow anyone to delegate computing tasks, then accessibility and resource sharing are improved, but security deteriorates as malicious users can exploit pre-processing investments made by others
Solution Approach 1:
The patent segments the delegation computing system into distinct roles: delegators who invest in pre-processing, group members who utilize the pre-processing results, and a verification mechanism that ensures proper attribution. This segmentation prevents malicious users from exploiting others' investments by clearly defining who can access what resources and under what conditions.
Solution Approach 2:
The patent introduces an intermediary verification mechanism that checks whether a user is authorized to access pre-processing results before allowing computation. This intermediary layer between the delegator and the computor prevents unauthorized access while maintaining the benefits of shared computing resources.
2Productivity
If pre-processing stage is performed to generate user keys for delegation computing, then computing efficiency is improved, but cost increases due to significant initial investment requirements
Solution Approach 1:
The patent merges the pre-processing costs into a shared resource that can be utilized by multiple group members. Instead of each user bearing the full cost of their own pre-processing, the system combines pre-processing investments to serve multiple computation requests, thereby reducing individual initial investment requirements while maintaining computing efficiency.
Solution Approach 2:
The patent ensures that pre-processing results remain valid and usable across multiple computation requests. By making the pre-processing investment continuous and reusable rather than one-time and single-use, the system amortizes the initial cost over multiple computations, reducing the effective cost per computation.
3Productivity
If group delegation computing is implemented to combine customers into groups, then resource utilization is improved, but system complexity increases due to multiple algorithms and key management
Solution Approach 1:
The patent designs a universal key management system that handles multiple functions: key generation, key distribution, access control, and cost verification. By making the key management mechanism multi-functional, the system reduces the need for separate specialized components, thereby managing complexity while improving resource utilization across the group.
Solution Approach 2:
The patent changes the parameters of the delegation computing system by introducing group-based identifiers and modified key structures that encode group membership and authorization information. These parameter changes enable efficient resource allocation and cost tracking without requiring complex additional infrastructure, as the enhanced parameters can be processed within existing computational frameworks.
Data Source
AI summary
A group delegation computing method includes: executing a key generation algorithm to obtain various types of keys; executing a member joining algorithm to implement a member joining function, combining customers with the same need into a group, and delegating a blinded delegation function to a cloud server; executing a question generation algorithm to generate a group signature and delegating a computing task to the cloud server; executing a signature verification algorithm to output a verification result; executing a computing algorithm only when a signature is valid to obtain a computing result and a correctness proof; executing a blind verification algorithm to verify whether the result; if the result is correct, executing a recovery algorithm; executing a member revocation algorithm to perform a member revocation function; and when there is a dispute over the delegation computing, executing an open algorithm to trace an identity of a specific member.


