Homomorphic Encryption System for Cloud Data Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption systems, particularly in cloud storage, face challenges with efficiently performing computations on encrypted data without decryption, as fully-homomorphic encryption schemes are theoretically complex and impractical, and partially homomorphic schemes restrict operations, leading to security concerns and verification issues.

Innovation Solution

A method and system that provide user-specific encryption keys, compute a common decryption key based on product groups of prime order, and perform homomorphic encryption and decryption operations, enabling efficient computation and verification of polysized functions with short ciphertext sizes, supporting poly-many additions and a single multiplication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If fully-homomorphic encryption schemes are used, then computation on encrypted data is supported, but the system complexity and impracticality increase significantly

Engineering Contradiction:
Improvecomputation capability on encrypted dataVSAvoidencryption scheme complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the encryption system into two distinct components: a key generation phase that establishes trust relationships, and a computation phase that operates on encrypted data. This segmentation allows the complex fully-homomorphic encryption to be used only during key generation, while the actual computation uses simpler encrypted operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary key generation and trust establishment before the actual computation on encrypted data. The common decryption key is computed in advance based on product groups of prime order, allowing subsequent computations to proceed without repeatedly invoking the complex fully-homomorphic encryption scheme.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If partially homomorphic encryption schemes are used, then computation operations are restricted, but implementation becomes more practical

Engineering Contradiction:
Improveimplementation feasibilityVSAvoidoperation flexibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent creates a multi-functional system where the encryption scheme supports both practical implementation (through simplified encrypted computations) and versatile operations (through the common decryption key mechanism that enables verification of any polynomial function). The system universally handles both computation and verification needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary common decryption key that mediates between the encrypted data and the verification process. This intermediary allows the system to maintain practical implementation simplicity while achieving versatile verification capabilities for polynomial functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Quantity of substance

If cloud storage is used, then data storage cost is reduced, but data privacy and security concerns increase

Engineering Contradiction:
Improvestorage costVSAvoiddata privacy
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent introduces encrypted data as an intermediary between the user data and the cloud storage system. The common decryption key acts as a mediator that allows verification of computations without exposing the actual data to the cloud provider, thus maintaining privacy while enabling cloud-based operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where the common decryption key provides verification capability for computations performed on encrypted data in the cloud. This feedback loop ensures data privacy and computational integrity without requiring the cloud provider to access the actual data contents.

Inventive Principle:
Principle #23Feedback

4Reliability

If encryption is applied to preserve data privacy, then computation on encrypted data becomes difficult, but data security is improved

Engineering Contradiction:
Improvedata securityVSAvoidcomputation difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs preliminary setup of the common decryption key and product group structures before computation. This preliminary action enables subsequent encrypted computations to proceed more easily, as the verification infrastructure is already in place rather than being constructed during each computation operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10630472B2Method and system for providing encrypted data on a client
Publication Date: 2020.04.21 NEC CORP
  • US10630472B2 patent drawing
  • US10630472B2 patent drawing
  • US10630472B2 patent drawing

AI summary

The present invention relates to a method for providing encrypted data on a client, a cloud or the like, performed in a memory available to a computation device comprising the steps of a) Providing for each user a user specific encryption key for encrypting user-specific plaintext, b) Computing a common decryption key with a pre-determined function using the user specific encryption keys as input for said function, and wherein the common decryption key is computed based on at least two product groups of the same prime order, c) Encrypting each user-specific plaintext with the corresponding user-specific encryption key resulting in user-specific ciphertexts, d) Computing a common ciphertext with said function using the user-specific ciphertexts as input for said function, e) Providing the common ciphertext and the common decryption key for decryption, preferably to a user, wherein step c) is performed such that encryption is homomorphic in the user-specific plaintext as well in the user-specific encryption keys, wherein said function is a polysized function supporting poly-many additions and a single multiplication.