Hierarchical Secret Splitting for Flexible Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secret splitting technologies face challenges in allowing flexible access control, where secret information may be accessed without consent, either due to lack of agreement from required users or unintended access to private information.
Innovation Solution
An information processing apparatus and method that generates shares from a first key, restores the key, and encrypts shares to enable flexible access control, allowing decoding of secret information exclusively by specific users through hierarchical secret splitting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secret splitting is executed to distribute key access among multiple users, then security is improved by requiring agreement from multiple users, but flexibility of access control deteriorates as specific users cannot decode secret information exclusively
Solution Approach 1:
The secret key is segmented into multiple shares distributed to different users. The patent applies hierarchical secret splitting where the first key is divided into first shares, and the second key is divided into second shares. This segmentation allows different access control policies to be applied at different hierarchical levels, resolving the contradiction between security and flexibility.
Solution Approach 2:
The patent introduces a hierarchical dimension to the secret splitting system. By creating multiple levels of secret sharing (first key with first shares, second key with second shares), the system adds a dimensional layer that enables flexible access control. Specific users can be granted exclusive decoding rights at certain hierarchical levels while maintaining overall security through the multi-user agreement requirement at higher levels.
2Adaptability or versatility
If hierarchical secret splitting is executed to enable flexible access control, then adaptability of access control is improved, but device complexity increases due to multiple key generation and encryption operations
Solution Approach 1:
The patent implements a nested structure where the second key and its shares are embedded within the hierarchical framework of the first key and its shares. The control unit generates shares from the first key, then generates the second key from selected first shares, and subsequently generates second shares from the second key. This nesting allows flexible access control while organizing the complexity in a structured, manageable manner.
Solution Approach 2:
The control unit performs preliminary key generation and share distribution operations in advance. The first key is generated and split into shares beforehand, and the second key is pre-generated from selected first shares. This preliminary action reduces the computational complexity during actual access operations, as the heavy cryptographic operations are performed in advance rather than in real-time during decoding operations.
Data Source
AI summary
Provided is a technology for performing flexible access control to permit decoding of secret information exclusively with a specific user in a case where secret splitting is hierarchically executed. There is provided an information processing apparatus including a control unit that generates, from a first key with which first data is decodable, a plurality of shares based on the first key in response to a first-key generation request, restores the first key from the shares based on the first key in response to a second-key generation request, encrypts, with the first key, a part of a plurality of shares based on a part or all of the first key as a second key with which second data is decodable, and generates a plurality of shares based on the second key.


