Hierarchical Re-Encryption Key Management for File Trees
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data protection methods in cloud computing, such as proxy re-encryption and conditional proxy re-encryption, lack flexibility in managing access rights to data stored on a storage server, particularly when dealing with file trees, as they do not allow for fine-tuning of access rights or easy updating of file and folder structures.
Innovation Solution
A method that generates re-encryption keys for each element in a file tree, allowing for hierarchical re-encryption and enabling users to manage access conditions for specific files and folders, enabling secure storage while allowing for fine-tuning of access rights and easy updating of file and folder structures by using a two-phase re-encryption mechanism.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If proxy re-encryption is used to store encrypted data on a storage server, then data security is improved, but access right management flexibility deteriorates
Solution Approach 1:
The patent segments the file system into a hierarchical tree structure where each node (file or folder) can have independent access control. Users can grant access rights to specific folders or files without affecting other parts of the file system, enabling fine-grained access management while maintaining encrypted storage security.
Solution Approach 2:
The patent introduces a hierarchical dimension to access control by organizing files and folders in a tree structure. This allows access rights to be managed at multiple levels (root folder, subfolders, individual files), providing flexibility in granting selective access to different portions of the file system while maintaining overall security.
2Manufacturing precision
If conditional proxy re-encryption is implemented for specific access conditions, then access control precision is improved, but system complexity deteriorates
Solution Approach 1:
The patent implements preliminary action by pre-defining access conditions and associated re-encryption keys during the key generation phase. When a user requests access to a specific folder or file, the system retrieves the pre-configured re-encryption key corresponding to that access condition, avoiding complex real-time conditional evaluation and reducing system complexity.
Solution Approach 2:
The patent introduces re-encryption keys as intermediaries between the encrypted data and the users. These keys act as mediators that enable selective decryption and access without requiring the server to evaluate complex access conditions in real-time, simplifying the system architecture while maintaining precise access control.
3Adaptability or versatility
If re-encryption keys are generated for each element in a file tree, then access right fine-tuning is improved, but computational overhead deteriorates
Solution Approach 1:
The patent merges the access control mechanism with the existing file system hierarchy. By associating re-encryption keys with folders and files in the tree structure, the system enables fine-tuned access control without requiring separate key management infrastructure, reducing computational overhead while maintaining flexibility.
4Reliability
If traditional proxy re-encryption is used, then data confidentiality is improved, but access right updating ease deteriorates
Solution Approach 1:
The patent implements dynamic access control by allowing users to modify re-encryption keys and access conditions at any time. When access rights need to be updated, the system generates new re-encryption keys and re-encrypts the relevant data, maintaining confidentiality while enabling flexible updates without requiring plaintext data access.
Data Source
AI summary
One embodiment relates to a method of updating, by an electronic device of a first user of a tree of data files and/or folders of the first user stored in a storage server configured to implement a re-encryption mechanism, this tree comprising at least one target folder that the first user has authorized a second user to access by providing the storage server with a re-encryption key for this target folder from the first user to the second user.


