Log Data Encryption via Bidirectional Key Sequences
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge lies in managing log data generated in information processing systems, particularly in balancing the need for data mining and potential know-how protection between operators and equipment vendors. Existing technologies struggle to determine sensitive data within log data before system operation, leading to potential conflicts and difficulties in handling data disclosures, especially during audits.
Innovation Solution
A data protection apparatus is introduced that employs an encryption process using a one-way function to generate key sequences for encrypting log data. This apparatus selectively discloses encrypted data by generating forward and backward key sequences, allowing for secure decryption of specific data sections while maintaining confidentiality of sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If log data is disclosed for data mining purposes, then the value of log data as big data increases, but the risk of sensitive information leakage increases
Solution Approach 1:
The patent segments log data into multiple sections based on timestamps, where each section can be independently encrypted and managed. This allows selective disclosure of specific time periods while maintaining security of other periods, resolving the contradiction between data utility and security.
Solution Approach 2:
The patent performs preliminary encryption of log data sections before storage, using hierarchical keys generated in advance. This preliminary security measure enables later selective disclosure without compromising sensitive information, as the encryption structure is already in place.
2Reliability
If confidentiality agreements are established for sensitive data, then know-how protection is improved, but the ability to use log data for data mining is reduced
Solution Approach 1:
The patent implements dynamic key management where encryption keys can be selectively provided to different parties based on their authorization level and the specific data section requested. This dynamic approach allows data mining activities while maintaining know-how protection through controlled access.
Solution Approach 2:
The patent introduces a data protection apparatus as an intermediary that manages the encryption and selective disclosure process. This intermediary enables data mining by authorized parties while protecting sensitive information, resolving the contradiction between protection and utility.
3Object-affected harmful factors
If all log data is encrypted for security, then sensitive information protection is improved, but the ability to selectively disclose specific sections is reduced
Solution Approach 1:
The patent divides encrypted log data into multiple time-based sections, each with its own encryption key. This segmentation enables selective disclosure of specific time periods while maintaining security of other sections, resolving the contradiction between comprehensive encryption and selective access.
Solution Approach 2:
The patent performs preliminary hierarchical key generation and data sectioning before encryption. This preliminary structuring enables efficient selective disclosure operations later, as the encryption framework is already organized to support granular access control.
4Reliability
If log data handling rules are determined before system operation, then data protection is improved, but the ability to respond to unforeseen circumstances like audits is reduced
Solution Approach 1:
The patent implements a dynamic key management system that can adapt to different disclosure scenarios. Authorized keys can be generated and provided on-demand for specific situations such as audits, while maintaining pre-established security protocols. This dynamic capability resolves the contradiction between predetermined protection and flexible response.
Data Source
AI summary
According to one embodiment, a data protection apparatus includes a processor configured to execute an encryption process on log data including a data frame including a plurality of pieces of data generated along a time sequence. The processor is configured to encrypt each of the pieces of data with a corresponding encryption key among a first initial key and a first encryption keys generated in a forward direction to a time sequence of the pieces of data. The processor is configured to encrypt each of a plurality of pieces of data encrypted with the corresponding encryption key with a corresponding encryption key among a second initial key and a second encryption keys generated in a backward direction to a time sequence of the pieces of data.


