Key Sharing Server Mediator for Secure Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing key sharing techniques, such as those used in PGP cryptography and social networking services like Facebook, face challenges in securely managing and sharing encrypted data due to the need for frequent key updates, management of multiple public keys, and vulnerabilities in password-based encryption methods.
Innovation Solution
A key sharing system that utilizes identification tokens, key disclosure permission information, and multiple types of keys to securely share encrypted data. This system includes client terminals and a server connected via the Internet or a virtual private network, where the server manages key registration, disclosure, and storage, and the client terminals handle data encryption and decryption using generated and processed keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PGP cryptography is used for secure data transmission, then data encryption and decryption can be achieved, but the system requires frequent key updates and management of multiple public keys which increases complexity
Solution Approach 1:
The patent introduces a key sharing server as an intermediary that manages public key distribution. Instead of users manually managing multiple public keys, the server acts as a mediator that stores public keys and facilitates their exchange between transmitter and receiver, significantly reducing key management complexity while maintaining encryption security
Solution Approach 2:
The key sharing server performs multiple functions: storing public keys, verifying user identities through identification tokens, managing key disclosure permissions, and facilitating secure data transmission. This multi-functional approach consolidates what would otherwise require multiple separate systems into a single service
2Ease of operation
If public keys are made public on the Internet for distribution, then key sharing is enabled, but personal information security and unauthorized access become vulnerable
Solution Approach 1:
The patent applies local quality by making key disclosure selective rather than universal. Public keys are not made globally accessible but are disclosed locally to specific users based on their relationship with the key owner. The key disclosure permission information field defines exactly which users can access which keys, creating localized access rights that prevent unauthorized access while maintaining ease of operation for authorized users
Solution Approach 2:
The system performs preliminary verification of user identity through identification tokens before allowing any key disclosure. This preliminary action ensures that only authenticated users can request keys, and the key disclosure permission information is pre-configured to control exactly who can access what, preventing unauthorized access before it can occur
3Ease of manufacture
If password-based encryption is used for file sharing, then simple encryption can be achieved, but security is compromised due to password sharing vulnerabilities
Solution Approach 1:
The patent extracts the password-based encryption approach and replaces it with public key infrastructure. Instead of using shared passwords that create security vulnerabilities, the system uses asymmetric key pairs where the public key can be freely shared and the private key remains secret. This extraction of the password requirement eliminates the security compromises associated with password sharing while maintaining the simplicity of the encryption process
4Adaptability or versatility
If a single company manages personal information for social networking, then information sharing can be facilitated, but freedom of speech and expression may be restricted
Solution Approach 1:
The patent implements self-service by enabling users to directly manage their own key pairs and control their own data sharing without requiring company intervention. Users generate their own identification tokens, manage their own public key disclosure permissions, and independently verify each other's identities. This eliminates the need for a central company to censor or control information sharing, preserving freedom of expression while maintaining security
Data Source
AI summary
To share encrypted data more securely. After a pair of an identification token 131 and key disclosure permission information 134 transmitted from a first client terminal 102 is verified by a verification unit 106, a key registration unit 107 registers a record 122 including the key 133 and the key disclosure permission information 134 in a database 121 of a key sharing server 101 and transmits key identification information 135 for identifying the record to the first client terminal 102. The first client terminal 102 transmits data 139 including encrypted data 138 obtained by encrypting transmission data by using a cipher key 136 for data encryption after first processing output by a cipher key first processing unit 109, a cipher key 137 for data decryption after first processing output by the cipher key first processing unit 109, and the key identification information 135 obtained from the key registration unit 107, to a second client terminal 103. The second client terminal 103 makes an inquiry to a key disclosure unit 110 by using the key identification information 135 acquired from the received data 139 and an identification token 132 of the terminal itself. The key disclosure unit 110 acquires the pair of key 133 and key disclosure permission information 134 corresponding to the key identification information 135, from the database 121, and notifies, when the identification token 132 is included in a key disclosure permissible range indicated by the key disclosure permission information 134, the second client terminal of the key 133. The second client terminal 103 uses the notified key 133 to generate a cipher key 140 for data decryption after second processing on the basis of the cipher key 137 for data decryption after first processing acquired from the data 139 and uses the cipher key 140 for data decryption after second processing to execute decryption on the encrypted data 138 in the data 139.


