Hierarchical Re-Encryption Key Management for File Trees

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection methods in cloud computing, such as proxy re-encryption and conditional proxy re-encryption, lack flexibility in managing access rights to data stored on a storage server, particularly when dealing with file trees, as they do not allow for fine-tuning of access rights or easy updating of file and folder structures.

Innovation Solution

A method that generates re-encryption keys for each element in a file tree, allowing for hierarchical re-encryption and enabling users to manage access conditions for specific files and folders, enabling secure storage while allowing for fine-tuning of access rights and easy updating of file and folder structures by using a two-phase re-encryption mechanism.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proxy re-encryption is used to store encrypted data on a storage server, then data security is improved, but access right management flexibility deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidaccess right management flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the file system into a hierarchical tree structure where each node (file or folder) can have independent access control. Users can grant access rights to specific folders or files without affecting other parts of the file system, enabling fine-grained access management while maintaining encrypted storage security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical dimension to access control by organizing files and folders in a tree structure. This allows access rights to be managed at multiple levels (root folder, subfolders, individual files), providing flexibility in granting selective access to different portions of the file system while maintaining overall security.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Manufacturing precision

If conditional proxy re-encryption is implemented for specific access conditions, then access control precision is improved, but system complexity deteriorates

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-defining access conditions and associated re-encryption keys during the key generation phase. When a user requests access to a specific folder or file, the system retrieves the pre-configured re-encryption key corresponding to that access condition, avoiding complex real-time conditional evaluation and reducing system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces re-encryption keys as intermediaries between the encrypted data and the users. These keys act as mediators that enable selective decryption and access without requiring the server to evaluate complex access conditions in real-time, simplifying the system architecture while maintaining precise access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If re-encryption keys are generated for each element in a file tree, then access right fine-tuning is improved, but computational overhead deteriorates

Engineering Contradiction:
Improveaccess right fine-tuningVSAvoidcomputational overhead
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent merges the access control mechanism with the existing file system hierarchy. By associating re-encryption keys with folders and files in the tree structure, the system enables fine-tuned access control without requiring separate key management infrastructure, reducing computational overhead while maintaining flexibility.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If traditional proxy re-encryption is used, then data confidentiality is improved, but access right updating ease deteriorates

Engineering Contradiction:
Improvedata confidentialityVSAvoidaccess right updating ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic access control by allowing users to modify re-encryption keys and access conditions at any time. When access rights need to be updated, the system generates new re-encryption keys and re-encrypts the relevant data, maintaining confidentiality while enabling flexible updates without requiring plaintext data access.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10050777B2Method of updating a file tree stored on a storage server
Publication Date: 2018.08.14 ORANGE SA
  • US10050777B2 patent drawing
  • US10050777B2 patent drawing
  • US10050777B2 patent drawing

AI summary

One embodiment relates to a method of updating, by an electronic device of a first user of a tree of data files and/or folders of the first user stored in a storage server configured to implement a re-encryption mechanism, this tree comprising at least one target folder that the first user has authorized a second user to access by providing the storage server with a re-encryption key for this target folder from the first user to the second user.