Smart Contract Data Circulation via Attribute-Based Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data circulation methods lack discoverability, supervisability, and protectability, leading to 'isolated data islands' and 'data chimneys,' which hinder data value generation and pose significant security risks, necessitating a wide-area scenario-oriented security protection system throughout the data life cycle.

Innovation Solution

A cloud-side collaborative multi-mode private data circulation method using smart contracts and attribute-based encryption (CP-ABE) for secure data sharing between Data Owners and Users, enabling discoverable, superviseable, and protectable data circulation through Key-Policy as a Service (KaaS) and blockchain technology.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is shared and circulated freely to enable data value generation, then data utility and accessibility are improved, but data security and privacy protection deteriorate

Engineering Contradiction:
Improvedata value generationVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments data access control into fine-grained attribute-based permissions. Data owners can specify different access levels for different attributes (e.g., department, role, clearance level), allowing data to be divided into accessible segments for authorized users while maintaining security. This resolves the contradiction by enabling partial data sharing that generates value without exposing sensitive portions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a blockchain-based smart contract intermediary that mediates between data owners and data users. The smart contract automatically enforces access policies, verifies user credentials, and controls data sharing without requiring direct trust between parties. This intermediary mechanism enables secure data circulation while maintaining privacy protection, resolving the security-utility contradiction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional data circulation methods are used, then implementation simplicity is maintained, but discoverability, supervisability, and protectability of data deteriorate

Engineering Contradiction:
Improveimplementation simplicityVSAvoiddata circulation supervision
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements automated feedback mechanisms through smart contracts that continuously monitor data access and circulation. The system automatically logs access events, verifies compliance with access policies, and provides real-time feedback to data owners and regulators. This feedback loop enables easy supervision of data circulation without complicating the implementation, as the monitoring is embedded in the automated contract execution.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent enables data circulation systems to self-manage security and supervision through automated smart contracts. The system automatically enforces access policies, manages credentials, and records transactions without requiring manual intervention for each data access event. This self-service approach maintains implementation simplicity while dramatically improving supervisability and detectability of data circulation.

Inventive Principle:
Principle #25Self-service

3Reliability

If fine-grained access control is implemented to protect private data, then data security is improved, but system complexity and operational overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal attribute-based access control system that handles multiple data types, access scenarios, and user roles through a single unified framework. The same smart contract infrastructure and attribute-based policy mechanism serve diverse data circulation needs, reducing overall system complexity despite fine-grained control requirements. This multi-functional approach eliminates the need for separate complex systems for different access control scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transforms access control from a static permission model to a dynamic attribute-based parameter system. Instead of hardcoding complex permission matrices, the system uses flexible attributes (department, role, clearance level) that can be dynamically assigned and modified. This parameter change approach simplifies the system architecture while enabling fine-grained security, as access decisions are made through simple attribute matching rather than complex rule evaluation.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If data is encrypted to protect privacy, then data security is improved, but data discoverability and usability deteriorate

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata discoverability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts metadata and attribute information from encrypted data that can be publicly visible on the blockchain without revealing the actual data content. The smart contracts can query and filter data based on these extracted attributes (e.g., data type, department, availability status) while the actual data remains encrypted. This extraction approach maintains privacy protection while improving data discoverability through attribute-based search capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11777745B2Cloud-side collaborative multi-mode private data circulation method based on smart contract
Publication Date: 2023.10.03 ZHEJIANG LAB
  • US11777745B2 patent drawing
  • US11777745B2 patent drawing

AI summary

The present invention discloses a cloud-side collaborative multi-mode private data circulation method based on a smart contract, including: S1, a system is initialized; S2, the original data are encrypted into private data, an encryption certificate z′ for storage is generated, and z′ includes metadata and a data certificate key′; S3, the DO calls a smart contract program to realize uplink of the encryption certificate z′ and releases z′ to a block chain through a smart contract, wherein the smart contract is open to all user accounts; S4, rapid data circulation is realized: when DO releases the data certificate, DU has been identified, a DU's account IDDU is set through an access policy, the DU obtains an encryption key for data access by executing a smart contract and a key algorithm, private data are obtained through metadata and decrypted to obtain a plaintext; and S5, the data circulation is confirmed.