Obfuscated Policy Encryption for Cloud Data Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic solutions for secure data storage in public clouds, such as attribute-based encryption (ABE) and proxy re-encryption, face challenges like policy leakage, key management complexity, and inability to choose recipients appropriately, compromising data privacy and security, especially for sensitive medical data.
Innovation Solution
An obfuscated policy data encryption system that allows users to specify a private data-sharing policy, generating an obfuscated version to ensure only authorized entities can access data, with a cloud data management system re-encrypting data without learning the policy, maintaining confidentiality and compliance with regulations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If attribute-based encryption (ABE) is used to enable selective data access, then data access control is improved, but key management complexity increases and policy changes require redistributing keys to all recipients
Solution Approach 1:
The patent introduces a cloud server as an intermediary that performs proxy re-encryption operations. Instead of requiring complex key management on client devices, the server acts as a mediator that can translate ciphertexts between different recipients using re-encryption keys, thereby reducing key management complexity while maintaining adaptability in data access control
Solution Approach 2:
The patent segments the key management functionality by separating master key generation from re-encryption key generation. The data owner holds the master key, while the cloud server holds re-encryption keys for specific recipients. This segmentation allows policy changes to be made by the data owner without requiring distribution of new keys to all recipients, thus reducing key management complexity
2Device complexity
If proxy re-encryption is implemented to allow server-based ciphertext translation, then key management is simplified, but the access policy must be revealed to the server compromising privacy
Solution Approach 1:
The patent applies local quality by making the re-encryption keys recipient-specific rather than policy-wide. Each re-encryption key is generated for a specific recipient and only enables translation to that recipient's ciphertext format. This allows the server to perform proxy re-encryption without needing to know the overall access policy, as it only needs the specific re-encryption key for the requested recipient, thereby preserving policy privacy while simplifying key management
3Adaptability or versatility
If the cloud server implements access policy directly, then data access control is enforced, but the server learns the access policy revealing sensitive information about data owners
Solution Approach 1:
The patent uses the cloud server as an intermediary that enforces access control without learning the policy. The server receives encryption/decryption requests and uses the obfuscated policy and associated keys to determine whether to grant access. The server never receives or processes the actual policy rules, only the obfuscated version, thereby maintaining policy confidentiality while still enforcing access control adaptability
Solution Approach 2:
The patent creates an obfuscated copy of the access policy that is functionally equivalent for access control purposes but reveals no sensitive information. This obfuscated policy copy is stored on the cloud server and used for access decisions, allowing the server to enforce access control while the original sensitive policy remains confidential on the data owner's device
Data Source
AI summary
An obfuscated policy data encryption system and method for re-encrypting data to maintain the confidentiality and integrity of data about a user when the data is stored in a public cloud computing environment. The system and method allow a user to specify in a data-sharing policy who can obtain the data and how much of the data is available to them. This policy is obfuscated such that it is unintelligible to the cloud operator and others processing and storing the data. In some embodiments, a patient species with whom his health care data should be shared with and the encrypted health care data is stored in the cloud in an electronic medical records system. The obfuscated policy allows the electronic medial records system to dispense the health care data of the patient to those requesting the data without disclosing the details of the policy itself.


