Hierarchical Decryption Key Management for Medical Data Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current medical data storage systems lack user control over access to sensitive health records, as they often require all-or-nothing access, with servers having full access to unencrypted data, which raises privacy concerns and limits granular control over who can access specific information.
Innovation Solution
A hierarchical set of decryption keys is constructed based on user-provided information, allowing users to manage access control and encrypt data in a way that only authorized parties can decrypt specific subsets, maintaining user-centric control over data accessibility without revealing unencrypted data to servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a server controls all access to medical data, then accessibility and convenience are improved, but user privacy control and security deteriorate because the server has full access to unencrypted data
Solution Approach 1:
The patent extracts the decryption keys from the server environment and places them exclusively in the user's possession. The server stores only encrypted data without the ability to decrypt it, thereby removing the security vulnerability while preserving accessibility through user-controlled key management.
Solution Approach 2:
The patent introduces cryptographic encryption as an intermediary layer between the user's data and the server. This intermediary ensures that the server can store and transmit data without having access to its meaningful content, thus maintaining accessibility while protecting privacy.
2Device complexity
If all-or-nothing access control is implemented, then server management is simplified, but user control over granular data sharing deteriorates
Solution Approach 1:
The patent segments the user's master decryption key into multiple derived decryption keys, each associated with specific data categories or subsets. This segmentation enables fine-grained control over what portions of data can be accessed by different parties, while the server continues to manage simple encryption/decryption operations.
Solution Approach 2:
The patent implements a dynamic key derivation system where the user can flexibly create, modify, and revoke decryption keys as needed. This allows the access control structure to adapt to changing user preferences and sharing requirements without complicating server management.
3Object-affected harmful factors
If data is encrypted to protect privacy, then security is improved, but accessibility and searchability deteriorate
Solution Approach 1:
The patent performs preliminary encryption of data before it is stored on the server, using the user's decryption keys. This advance preparation ensures that data is secured at rest while still allowing the user to derive specific keys for authorized access and search operations when needed.
Solution Approach 2:
The patent changes the cryptographic parameters dynamically based on the user's access requests. Different decryption keys with varying levels of access权限 are derived from the master key, allowing the system to maintain strong encryption while providing flexible search and access capabilities when authorized.
Data Source
AI summary
The claimed subject matter relates to architectures that can construct a hierarchical set of decryption keys for facilitating user-controlled encrypted data storage with diverse accessibility and hosting of that encrypted data. In particular, a root key can be employed to derive a hierarchical set of decryption keys and a corresponding hierarchical set of encryption keys. Each key derived can conform to a hierarchy associated with encrypted data of the user, and the decryption capabilities of the decryption keys can be configured based upon a location or assignment of the decryption key within the hierarchy. The cryptographic methods can be joined with a policy language that specifies sets of keys for capturing preferences about patterns of sharing. These policies about sharing can themselves require keys for access and the policies can provide additional keys for other aspects of policy and or base-level accesses.


