Two-Tier Cryptographic Key System for Secure Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure content distribution systems face limitations in controlling access and billing, particularly in environments requiring differentiated access and secure data sharing, as they often rely on cumbersome DRM implementations and key management systems that are not scalable or effective in protecting sensitive information.

Innovation Solution

A system utilizing layered, two-tier double cryptographic keys to create a closed cryptosystem for secure content distribution, where a first-tier key is publicly accessible within a secured walled region for network nodes registered to an authentication database, and a second-tier key is generated for further secured access, enabling step-wise controlled and billed data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional DRM implementations and key management systems are used, then security control is provided, but system complexity and operational difficulty increase

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cryptographic key is divided into two separate tiers: a first-tier key for initial content encryption and distribution, and a second-tier key for subsequent access control. This segmentation allows the system to maintain strong security controls while simplifying key management operations, as each tier handles specific security functions rather than requiring a single complex key management system

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the first-tier key serves as a bridge between public content distribution and private second-tier key access. This intermediary layer enables secure content sharing without requiring direct implementation of complex traditional DRM systems, as the two-tier structure mediates between security requirements and operational simplicity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional key management systems are used, then access control is provided, but scalability and effectiveness in protecting sensitive information decrease

Engineering Contradiction:
Improveaccess controlVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The two-tier cryptographic system is designed to be universally applicable across multiple platforms and content types. The first-tier key enables broad content distribution while the second-tier key provides universal access control mechanisms that can be implemented across different devices and systems, enhancing scalability without compromising access control effectiveness

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent adds a dimensional layer to key management by introducing the second-tier key structure. This dimensional change allows the system to scale effectively, as the hierarchical key structure can accommodate growing numbers of users and content types without requiring fundamental changes to the access control mechanism

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If usernames and passwords are used for authentication, then access control is provided, but security effectiveness decreases due to forgotten or compromised credentials

Engineering Contradiction:
ImproveauthenticationVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical authentication system (usernames and passwords) with a cryptographic key-based system. Instead of relying on human-remembered credentials, the system uses machine-managed cryptographic keys that cannot be forgotten or easily compromised, thereby maintaining ease of operation while significantly improving security effectiveness

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Productivity

If symmetric keys are used for encryption, then encryption efficiency is improved, but key distribution and storage security worsen

Engineering Contradiction:
Improveencryption efficiencyVSAvoidkey distribution and storage
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The encryption system is segmented into two key tiers where the first-tier symmetric key handles efficient content encryption, while the second-tier key manages secure distribution and storage. This segmentation allows the system to maintain encryption efficiency while simplifying key distribution, as the hierarchical structure separates the computational efficiency requirements from the security-sensitive distribution requirements

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10523644B2System and method for secure digital sharing based on an inter-system exchange of a two-tier double encrypted digital information key
Publication Date: 2019.12.31 SWISS REINSURANCE CO LTD
  • US10523644B2 patent drawing
  • US10523644B2 patent drawing
  • US10523644B2 patent drawing

AI summary

A system based on layered, two-tier double cryptographic keys providing a closed cryptosystem within a secured network environment, the system including a digital key management device and a network node. The digital key management device generates a first-tier cryptographic key, a second-tier cryptographic key and makes the first-tier and second-tier cryptographic keys publicly accessible within a first and a second secured walled regions that are accessible to a network node registered to a first authentication database associated with an access server of the system, encrypts a first and second content with the first-tier and second-tier cryptographic keys, and generates encrypted first and second content. The network node requests access to the first secured walled region, accesses the first-tier and the second-tier cryptographic keys, decrypts the first and second content, generates first and second data containers based on the decrypted content, and transfers the data containers to a client device.