Hierarchical Secret Splitting for Flexible Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secret splitting technologies face challenges in allowing flexible access control, where secret information may be accessed without consent, either due to lack of agreement from required users or unintended access to private information.

Innovation Solution

An information processing apparatus and method that generates shares from a first key, restores the key, and encrypts shares to enable flexible access control, allowing decoding of secret information exclusively by specific users through hierarchical secret splitting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secret splitting is executed to distribute key access among multiple users, then security is improved by requiring agreement from multiple users, but flexibility of access control deteriorates as specific users cannot decode secret information exclusively

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility of access control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The secret key is segmented into multiple shares distributed to different users. The patent applies hierarchical secret splitting where the first key is divided into first shares, and the second key is divided into second shares. This segmentation allows different access control policies to be applied at different hierarchical levels, resolving the contradiction between security and flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical dimension to the secret splitting system. By creating multiple levels of secret sharing (first key with first shares, second key with second shares), the system adds a dimensional layer that enables flexible access control. Specific users can be granted exclusive decoding rights at certain hierarchical levels while maintaining overall security through the multi-user agreement requirement at higher levels.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If hierarchical secret splitting is executed to enable flexible access control, then adaptability of access control is improved, but device complexity increases due to multiple key generation and encryption operations

Engineering Contradiction:
Improveflexibility of access controlVSAvoidcomplexity of key management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a nested structure where the second key and its shares are embedded within the hierarchical framework of the first key and its shares. The control unit generates shares from the first key, then generates the second key from selected first shares, and subsequently generates second shares from the second key. This nesting allows flexible access control while organizing the complexity in a structured, manageable manner.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The control unit performs preliminary key generation and share distribution operations in advance. The first key is generated and split into shares beforehand, and the second key is pre-generated from selected first shares. This preliminary action reduces the computational complexity during actual access operations, as the heavy cryptographic operations are performed in advance rather than in real-time during decoding operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11290263B2Information processing apparatus and information processing method
Publication Date: 2022.03.29 SONY GROUP CORP
  • US11290263B2 patent drawing
  • US11290263B2 patent drawing
  • US11290263B2 patent drawing

AI summary

Provided is a technology for performing flexible access control to permit decoding of secret information exclusively with a specific user in a case where secret splitting is hierarchically executed. There is provided an information processing apparatus including a control unit that generates, from a first key with which first data is decodable, a plurality of shares based on the first key in response to a first-key generation request, restores the first key from the shares based on the first key in response to a second-key generation request, encrypts, with the first key, a part of a plurality of shares based on a part or all of the first key as a second key with which second data is decodable, and generates a plurality of shares based on the second key.