Selective IoT Data Sharing With Recipient-Specific Wrapped Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems do not allow the owner of an IoT device to separately control the provision of IoT data to multiple selected data recipients, necessitating robust key management and secure encryption in transit and at rest.

Innovation Solution

A method involving encryption of data with a data encryption key, followed by encryption of this key using a dedicated key encryption key for each recipient, and storage of a data access authorization comprising the wrapped encryption key and recipient identifier, enabling independent control over data provision to different recipients.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If data is encrypted with a single data encryption key and stored centrally, then storage and retrieval are simplified, but the data provider cannot separately control access to different recipients

Engineering Contradiction:
Improvekey management systemVSAvoidgranular access control
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the single data encryption key into multiple wrapped encryption keys, each encrypted with a different key encryption key specific to a recipient. This allows the data provider to grant selective access to different recipients without sharing the original data encryption key, thereby achieving granular access control while maintaining a relatively simple key management structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces key encryption keys as intermediaries between the data encryption key and individual recipients. Each key encryption key acts as a mediator that enables a specific recipient to decrypt their portion of the encrypted data without exposing the main data encryption key to them, thus providing controlled access while preserving system simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If the data provider maintains control over all decryption keys, then access control is simplified, but security is reduced as the provider must trust the security of all key storage locations

Engineering Contradiction:
Improvekey distribution systemVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent extracts the data encryption key from the control domain of individual recipients by encrypting it separately for each recipient using their own key encryption key. The original data encryption key remains solely with the data provider, while recipients receive only their specific wrapped encryption keys, thereby distributing security responsibilities without complicating the key distribution system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different encryption properties to different key distributions - each recipient receives a wrapped encryption key encrypted with their specific key encryption key, tailored to their security requirements and access needs. This local customization of encryption properties enhances overall system security without requiring a complex centralized key management system.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If multiple wrapped encryption keys are generated and stored for each recipient, then selective access control is enabled, but the complexity of key management and storage increases

Engineering Contradiction:
Improveselective data sharingVSAvoidkey storage system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a nested key structure where the data encryption key is encrypted within each wrapped encryption key, which in turn is encrypted with the recipient's key encryption key. This nested arrangement enables selective access control for multiple recipients while organizing keys in a hierarchical manner that manages complexity through structured nesting rather than flat management.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent performs preliminary encryption of the data encryption key with each recipient's key encryption key before data transmission or storage. This preliminary action creates the wrapped encryption keys in advance, allowing recipients to independently decrypt their assigned data portions without requiring real-time key generation or complex runtime key management operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12438717B2Selective data sharing
Publication Date: 2025.10.07 BRITISH TELECOM PLC
  • US12438717B2 patent drawing
  • US12438717B2 patent drawing
  • US12438717B2 patent drawing

AI summary

A method and distributed system for exclusively sharing data between a data provider and one or more selected data recipients is disclosed. Known systems for exclusively sharing data with one or more selected data recipients involve the encryption of the data at a central storage service and limiting use of one or more centrally stored decryption keys to decrypt the data in accordance with an access control list maintained by the remote storage service provider. Ensuring robustness of key management in such systems requires the expenditure of a great deal of resource. This problem is addressed by a combination of two co-operating facilities in the disclosed distributed data sharing system. Firstly, a symmetric key exchange facility is provided which enables each data provider to exclusively derive 182 dedicated key encryption keys with respective selected data clients. Secondly, a device controlled by the data provider is arranged to encrypt the data using a data encryption key and, for each selected data recipient, publish or share188 a wrapped data encryption key (the data encryption key encrypted with the key encryption key dedicated to the selected recipient). Each selected data recipient is then able to unwrap the wrapped data encryption key using its dedicated key encryption key to decrypt the data. The method and distributed system has particular utility in the selective sharing of Internet of Things data between consumers and enterprises.