Network-Based Decryption Authority Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud-key-management-type decryption technologies require individual setup and authorization for each terminal device, making the handling of decryption authorities inconvenient, especially when multiple devices are connected to a single network.

Innovation Solution

Implementing network-based identification and authentication to allow decryption authorities to be managed at the network level, enabling decryption authority distribution without individual terminal device setup and allowing decryption before terminal device configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual terminal devices are given decryption authority individually, then each terminal device can be securely authorized, but the handling of decryption authority becomes inconvenient and complex when multiple devices are connected to a single network

Engineering Contradiction:
Improvedecryption authority managementVSAvoidconvenience of handling decryption authority
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the decryption authority management from individual terminal device level to network level. Instead of managing permissions for each terminal device separately, the system assigns decryption authority to networks, allowing all terminal devices connected to a given network to automatically inherit the decryption permission. This consolidation eliminates the need for individual device authorization while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network-level decryption authority assignment provides universal access for all terminal devices connected to that network. Once a network is granted decryption authority, any terminal device connecting to this network can automatically access encrypted content without individual setup, making the system more versatile and easier to operate.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If registered permission information is stored in the key device after terminal device setup, then secure authorization is achieved, but the terminal device cannot be given decryption authority before setup

Engineering Contradiction:
Improveauthorization securityVSAvoidtiming flexibility of decryption authority assignment
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary action by assigning decryption authority to networks before terminal devices are fully set up. The key device stores network-based identification information and pre-configures decryption permissions at the network level, enabling terminal devices to gain access automatically upon connection without requiring prior individual setup or configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces network-based identification as an intermediary between the key device and terminal devices. Instead of directly managing permissions for each terminal device, the system uses network identification as a mediator to assign and manage decryption authority, allowing terminal devices to inherit permissions automatically based on their network connection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If network-based identification is used for decryption authority, then multiple terminal devices on a single network can access decryption services, but the system needs to manage network-based identification instead of device-based identification

Engineering Contradiction:
Improvemulti-device network accessVSAvoidmanagement of network-based identification
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the management of multiple terminal devices into a single network-level identifier. Instead of tracking and managing permissions for each individual device, the system manages one network-based identification that represents all devices connected to that network, significantly simplifying the management process while enabling multi-device access.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10686604B2Key device, key cloud system, decryption method, and program
Publication Date: 2020.06.16 NIPPON TELEGRAPH & TELEPHONE CORP
  • US10686604B2 patent drawing
  • US10686604B2 patent drawing
  • US10686604B2 patent drawing

AI summary

Registered network-based identification corresponding to any of networks is stored in a key device 12. A terminal device 11 sends ciphertext and network-based identification to the key device 12, using a network. The key device 12 receives the sent ciphertext and network-based identification and outputs response information corresponding to a decrypted value of the ciphertext when the network-based identification corresponds to the registered network-based identification. The terminal device 11 obtains the decrypted value from the response information.