Multi-Level Data Encryption for Adaptive Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data access control systems lack a dynamic and robust encryption method to manage multiple levels of security, particularly in network environments where different sections of data require varying levels of encryption, and users need specific clearance levels to access secured data.

Innovation Solution

A method where a network device encrypts data with multiple levels of encryption, using a combination of encryption keys to secure different sections of data, allowing progressive encryption and decryption based on user access levels, enabling secure transmission and storage of data with varying sensitivity levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single encryption key is used for all data, then the encryption process is simple, but all data sections have the same security level which is not suitable for different sensitivity levels

Engineering Contradiction:
Improvesecurity level adaptabilityVSAvoidencryption key management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides data into multiple sections (first section, second section, third section) and applies different encryption keys to each section. This segmentation allows each data portion to have its own security level, enabling adaptability for different sensitivity requirements while managing complexity through organized key assignment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different encryption keys (first encryption key, second encryption key, third encryption key) are applied to different sections of data based on their specific security requirements. This local quality approach ensures that each data section receives the appropriate security level rather than applying a uniform encryption strategy to all data.

Inventive Principle:
Principle #3Local quality

2Reliability

If multiple encryption keys are used for different data sections, then data security is enhanced, but the encryption and decryption process becomes more complex

Engineering Contradiction:
Improvedata securityVSAvoidencryption process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By segmenting data into distinct sections and applying different encryption keys to each, the system enhances security through multiple encryption layers while managing complexity through systematic organization of encrypted sections and their corresponding keys.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nested encryption where the first section is encrypted with the first encryption key, then the second section is encrypted with the second encryption key, and finally the third section is encrypted with the third encryption key. This nested approach allows progressive decryption based on access levels, enhancing security while providing structured access control.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If all data is encrypted with the highest security level, then maximum security is achieved, but access efficiency decreases as users need multiple decryption keys

Engineering Contradiction:
Improvedata securityVSAvoiddata access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Different sections of data are assigned different encryption keys based on their sensitivity levels. Users with appropriate clearance can access only the sections they are authorized for, improving access efficiency while maintaining security. This avoids the inefficiency of requiring all users to decrypt all sections at the highest security level.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The encryption system is made dynamic by allowing different decryption keys to access different sections of encrypted data. This dynamic access control enables efficient data retrieval for authorized users while maintaining security, as users only need to decrypt the specific sections they are authorized to access rather than all sections.

Inventive Principle:
Principle #15Dynamics

4Adaptability or versatility

If data is divided into multiple encrypted sections, then selective access control is improved, but the data structure becomes more complex

Engineering Contradiction:
Improveaccess control flexibilityVSAvoiddata structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments data into distinct sections (first section, second section, third section) that can be independently encrypted and accessed. This segmentation provides flexible access control where different users can access different sections based on their authorization, improving adaptability while managing structural complexity through clear organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encrypted data structure is designed to serve multiple functions: it provides selective access control, maintains data security, and allows for efficient retrieval of authorized sections. The same encrypted batch structure can accommodate different numbers of sections and different encryption keys, providing universal applicability across various access control scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10686765B2Data access levels
Publication Date: 2020.06.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10686765B2 patent drawing
  • US10686765B2 patent drawing
  • US10686765B2 patent drawing

AI summary

A method, computer system, and a computer program product for securing and accessing a plurality of data levels is provided. The present invention may include gathering, by a network device, data. The present invention may also include encrypting, by a network device, a first section of data within the gathered data with a level 1 encryption key. The present invention may then include encrypting, by a network device, a second section of data within the gathered data with a level 2 encryption key. The present invention may further include transmitting, by a network device, the data to a recipient device. The present invention may also include decrypting, by the recipient device, the second section of data with the level 2 encryption key. The present invention may then include decrypting, by the recipient device, the first section of data with the level 1 encryption key.