Predicate Encryption Protocol Switching via Universal Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
ID-based encryption schemes require different key information and ciphertexts for different protocols, leading to complex management and switching processes, as each protocol has a unique identifier and corresponding key information or ciphertext.
Innovation Solution
The solution allows the use of the same second information for multiple first information pieces, enabling switching among protocols based on a chosen identifier without the need for complex key information or ciphertext management by employing a predicate encryption scheme where attribute information and predicate information vectors are used to determine decryption correctness, allowing a single piece of second information to handle multiple protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If different key information is used for different protocols in ID-based encryption schemes, then protocol-specific security requirements are met, but key information management complexity increases
Solution Approach 1:
The patent employs a universal key information structure that can serve multiple protocol types. By designing key information with flexible identifier components, a single key information set can support Forward-secure encryption, Key-Insulated encryption, Keyword search encryption, and Timed-Release encryption protocols simultaneously, eliminating the need for separate key information management for each protocol while maintaining protocol-specific security requirements
2Reliability
If different ciphertexts are generated for different protocols, then protocol-specific encryption requirements are satisfied, but ciphertext management complexity increases
Solution Approach 1:
The patent creates a universal ciphertext generation mechanism that can produce protocol-specific ciphertexts from a common encryption framework. By using flexible identifier components in the encryption process, the same encryption apparatus can generate ciphertexts suitable for different protocols (Forward-secure, Key-Insulated, Keyword search, Timed-Release) without requiring separate ciphertext storage or management systems for each protocol
3Adaptability or versatility
If protocol switching is enabled through identifier selection, then system flexibility improves, but key information generation and management becomes complicated
Solution Approach 1:
The patent implements dynamic protocol switching through identifier selection within a unified key information management framework. The system allows the encryption apparatus to dynamically choose which protocol to apply based on the identifier components, while the key information management remains centralized and simplified. This dynamic capability enables flexible protocol selection without requiring separate key information sets for each protocol, resolving the contradiction between adaptability and management complexity
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An information output apparatus identifies, according to a rule established for each of functional encryption protocols or a rule established for each combination of the protocols, one or more identifiers corresponding to a particular functional encryption protocol or a combination of the particular protocols, sets a particular piece of first correspondence information corresponding to the identifier or identifiers, and outputs first information which is a ciphertext or key information of the functional encryption scheme that corresponds to the particular piece of first correspondence information. An information processing apparatus inputs the first information and second information which is key information or a ciphertext of the functional encryption scheme that corresponds to a particular piece of second correspondence information into a decryption function of the functional encryption scheme and, when the truth value of a logical formula corresponding to the combination of the particular piece of first correspondence information corresponding to the first information and the particular piece of second correspondence information corresponding to the second information is true, generates a decryption result