Re-Encryption Server for Secure Cross-Apparatus ID Auditing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cooperation service providing systems face challenges in verifying and auditing the transmission and reception of cooperation information between apparatuses, as IDs for identifying the same information are different across apparatuses, leading to difficulties in linking and managing cooperation information.

Innovation Solution

A cooperation service providing system that utilizes a re-encryption key issuing apparatus and a cooperation apparatus to generate and manage re-encryption keys, allowing ciphertext data to be re-encrypted without decryption, ensuring secure transmission and enabling auditing and verification processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a common bus with ID conversion function and log function is used to connect apparatuses, then centralized management and auditability of cooperation information is improved, but device complexity increases

Engineering Contradiction:
Improveauditability of cooperation informationVSAvoidcomplexity of common bus system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a server as an intermediary component that manages ID conversion and stores cooperation information. This mediator handles the complexity of ID mapping between different apparatuses and provides centralized logging, thereby improving auditability without requiring each apparatus to implement complex ID conversion and logging functions locally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If direct connection between apparatuses is used, then device complexity is reduced, but ability to verify and audit transmitted contents deteriorates

Engineering Contradiction:
Improvesimplicity of direct connectionVSAvoidverify/audit capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The server acts as a mediator that receives cooperation information from apparatuses, performs ID conversion, and stores the information centrally. This allows apparatuses to maintain simple direct connections while the server provides the necessary verification and audit capabilities through centralized logging and ID management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If IDs for identifying information are made different across apparatuses, then security is improved, but ability to link and verify same information deteriorates

Engineering Contradiction:
Improvesecurity of information exchangeVSAvoidlinkability of same information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements ID conversion functionality that transforms IDs between different apparatuses while maintaining the ability to link the same information. The server stores mapping relationships between different ID formats, allowing secure differentiation of IDs across apparatuses while preserving linkability through the conversion function that can translate between ID systems.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9813386B2Cooperation service providing system and server apparatus
Publication Date: 2017.11.07 TOSHIBA DIGITAL SOLUTIONS CORP
  • US9813386B2 patent drawing
  • US9813386B2 patent drawing
  • US9813386B2 patent drawing

AI summary

Upon receiving ciphertext data transmitted by each service apparatus, a cooperation apparatus according to an embodiment generates re encrypted data by performing re encryption processing for the ciphertext data using are encryption key. Each of the service apparatuses transmits, to the cooperation apparatus, a request to acquire user information of a user specified by an identification (ID) indicated by the ciphertext data and stored in the other service apparatus, together with the ciphertext data. Upon receiving the re encrypted data transmitted by the cooperation apparatus, the service apparatus acquires an ID by decrypting the re encrypted data using a private key, reads out user information, and transmits the user information to the other service apparatus.