- identity-based encryption of data items for secure access thereto
Abstract
The present invention utilizes the concept of identity-based encryption according to data-centric protection of electronic health records, where each data item is encrypted using its own identifier as a public key. Corresponding decryption keys are managed, in particular, by trusted entities that distribute the keys to authorized parties and provide log facilities. This method has the particular advantage that emergency access mechanisms can be implemented in a secure and highly efficient manner. Unlike previous methods, this does not require a large distribution of secret decryption keys. In addition, the above method limits the impact of the included decryption key as one key used only to decrypt one single document.

Term
Projected expiry 18 May 2029.
- Priority
- Filed
- Published
- Today
- Projected expiry
11 claims: 4 independent, 7 dependent
- 1데이터 아이템(100)을 식별하는 식별자(101)를 갖는 상기 데이터 아이템(100)을 암호화하는 방법에 있어서, - 암호화된 데이터 아이템(104)을 획득하기 위하여, 대칭 암호화키(102)를 이용하여 상기 데이터 아이템(100)을 암호화하는 단계(103);및 - 암호화된 암호화 키(106)를 획득하기 위하여, 상기 데이터 아이템(100)의 상기 식별자(101)를 암호화 키로 이용하여 상기 대칭 암호화 키(102)를 암호화하는 단계(105)를 포함하는, 데이터 아이템 암호화 방법.
- 2암호화되는(106) 암호화 키(102)를 이용하여 암호화되는(103) 상기 암호화된 데이터 아이템(104)을 복호화하는 방법에 있어서, - 상기 암호화된 암호화 키(106)를 복호화하기 위한 복호화 키(201)를 제공하는 단계;- 상기 암호화 키(102)를 획득하기 위해 상기 암호화된 암호화 키(106)를 복호화(202)하기 위해 상기 제공된 복호화 키(201)를 이용하는 단계;및 - 상기 데이터 아이템(100)을 획득하기 위해 상기 암호화된 데이터 아이템(104)을 복호화(203)하기 위해 상기 획득된 암호화 키(102)를 이용하는 단계를 포함하는, 암호화된 데이터 아이템 복호화 방법.
- 3제 2 항에 있어서, 상기 암호화된 암호화 키(106)는 상기 데이터 아이템(100)을 암호화 키로서 식별하는 식별자(101)를 이용하여 암호화되는(105), 암호화된 데이터 아이템 복호화 방법.
- 4제 2 항에 있어서, 제공되는 상기 복호화 키(201)를 로그하는(logging) 단계를 더 포함하는, 암호화된 데이터 아이템 복호화 방법.
- 5연관된 데이터 저장 수단(302)을 갖는 적어도 하나의 컴퓨터(301)를 포함하는 컴퓨터 시스템(300)으로 하여금 제 1 항에 따른 데이터 아이템(100)의 암호화 방법을 수행하게 하도록 구성되는, 컴퓨터 프로그램 제품(305).
- 6연관된 데이터 저장 수단(302)을 갖는 적어도 하나의 컴퓨터(301)를 포함하는 컴퓨터 시스템(300)으로 하여금 제 2 항에 따른 암호화된 데이터 아이템(104)의 복호화 방법을 수행하게 하도록 구성되는, 컴퓨터 프로그램 제품(305).
- 7연관된 데이터 저장 수단(302)을 갖는 적어도 하나의 컴퓨터(301)를 포함하는 컴퓨터 시스템(300)으로서, 상기 적어도 하나의 컴퓨터(301)는 제 1 항에 따른 데이터 아이템(100)의 암호화 방법을 수행하도록 인에이블되는, 컴퓨터 시스템(300).
- 8연관된 데이터 저장 수단(302)을 갖는 적어도 하나의 컴퓨터(301)를 포함하는 컴퓨터 시스템(300)으로서, 상기 적어도 하나의 컴퓨터(301)는 제 2 항에 따른 데이터 아이템(100)의 암호화 방법을 수행하도록 인에이블되는, 컴퓨터 시스템(300).
- 9디지털 저작권 관리(DRM;Digital Rights Management) 방법에 있어서, - 암호화된 데이터 아이템(104)을 획득하기 위해, 데이터 아이템(100)을 식별하는 식별자(101)를 갖는 상기 데이터 아이템(100)을 대칭 암호화 키(102)를 이용하여 암호화하는 단계(103);- 암호화된 암호화 키(106)를 획득하기 위해, 상기 데이터 아이템(100)의 상기 식별자(101)를 암호화 키로서 이용하여, 상기 대칭 암호화 키(102)를 암호화하는 단계(105);- 상기 암호화된 데이터 아이템(104)을 복호화하도록 요청자에게 발행될 라이센스에 대한 요청을 수신하는 단계;- 상기 요청자가 적절히 인증되는지 여부를 검증하는 단계;- 상기 요청자가 적절히 인증되면, 상기 암호화된 암호화 키(106)를 복호화하기 위한 복호화 키(201)를 포함하는 라이센스를 제공하는 단계;- 상기 요청자 및 상기 라이센스에 관한 데이터를 로그하는 단계;및 - 상기 라이센스를 상기 요청자에게 발행하는 단계를 포함하는, 디지털 저작권 관리 방법.
- 10연관된 데이터 저장 수단(302)을 갖는 적어도 하나의 컴퓨터(301)를 포함하는 컴퓨터 시스템(300)으로 하여금 제 9 항에 따른 디지털 저작권 관리(DRM) 방법을 수행하게 하도록 구성되는, 컴퓨터 프로그램 제품(305).
- 11연관된 데이터 저장 수단(302)을 갖는 적어도 하나의 컴퓨터(301)를 포함하는 컴퓨터 시스템(300)으로서, 상기 적어도 하나의 컴퓨터(301)는 제 9 항에 따른 디지털 저작권 관리(DRM) 방법을 수행하도록 인에이블되는, 컴퓨터 시스템(300).
Independent claims11
18 paragraphs in 1 section, as filed
IDENTITY-BASED ENCRYPTION OF DATA ITEMS FOR SECURE ACCESS THERETO
FIELD OF THE INVENTION The present invention relates generally to Digital Rights Management (DRM), and more particularly to encryption and decryption of data items and granting access to encrypted data items.
Advances in information and communication technologies provide all their advantages, which are also considered along with security concerns. Data no longer resides in mainframes, where physical security measures are taken to defend the data and system, which are physically located separately within the appliance. Modern solutions are directed towards an open, interconnected environment where storage outsourcing and operations to untrusted servers occur frequently. The old server-centric protection model locks the data to the database server and uses the traditional access control model to allow access to the data. To solve this security problem, grid computing, or other distributed/peer-to-peer data management system, data-centric protection (such as DRM) model, which is emphasized in the field of enterprise data management system, is proposed and , where the data is cryptographically protected and either outsourced or freely floated over the network. Rather than relying on different networks to provide confidentiality, integrity and authenticity of data, unstable networks are assumed and data is protected at the ends of the communication channel. The data will be encrypted and only authorized users who need access to the data will receive a decryption key allowing them to decrypt the data. The DRM system ensures end-to-end confidentiality, which is a significant improvement regarding data distribution and control over the privacy of different users from a security point of view, especially in the field of medical healthcare.
However, in healthcare, data access is very often given on an ad-hoc basis, for example in emergencies. For these solutions accepted in the medical field, it is important to include emergency accessibility, where sometimes a patient's life depends on the ability of the care providers to access the data. Although security is an important characteristic, it is not more important than the patient's life. Any healthcare provider caring for a patient must gain access to the relevant data. In the data-centric protection model, this means that he needs the keys that are used to encrypt the data. Previously proposed solutions are based on the use of a trusted agent that publishes data keys for medical data in emergency situations.
Usually, the published DRM-protected data is encrypted and the license server only issues licenses, ie, decryption keys, to the requesting users if the requesting users have sufficient rights to access the data. Thus, emergency access is difficult to handle if it represents an exception to the normal operation of the system: the emergency medical staff must be granted a license to decode the data he is trying to access, even if he does not normally have legitimate rights. Therefore, the legitimacy of access must be proved later so that the privacy of the data is still guaranteed in the end. Logging of emergency accesses is necessary at this time.
<p>The emergency access control problem in the previously proposed solution is how to issue emergency licenses and log these events. An infrastructure of trusted agents is deployed to issue emergency licenses on request for emergency access. Thus, there is a need for a new reliable and usable component that is responsible for handling emergencies and still enforces data confidentiality. In fact, it consists of a similar infrastructure that can be deployed concurrently as a traditional DRM system.</p><p>Emergency authorization generates a new emergency key pair that is sent to all emergency agents. Additionally, only public keys can be sent to license servers to generate emergency licenses for the newly protected data. In addition to encrypting the content key, the intended user's public key, the license server also encrypts the content key along with the emergency key. All secret emergency keys must be announced to all emergency agents to ensure data availability.</p><p>However, this solution has some problems. First, if one of the emergency keys is compromised, multiple data items are affected, ie the data items are also compromised. To reduce the consequences the number of emergency keys is increased (until using one emergency key per data item), which in turn has to be managed and stored by trusted agents (up to one key per data item). to increase Obviously, this method is not tailored.</p><p>Another problem is that the (suggested secret) emergency key must be announced when establishing data protection and generating emergency licenses.</p><p>Accordingly, an improved and simplified method of managing encrypted data items is desirable, and a simpler and/or reliable method of issuing decryption keys to healthcare providers, particularly in emergency situations.</p>
<p>Accordingly, the present invention preferably seeks to alleviate, alleviate or eliminate one or more of the problems described above, alone or in any combination. In particular, it may seem like an object of the present invention to provide a method for encrypting and/or decrypting data items such as health care documents, which solves the above problems of the prior art.</p><p>This and some other objects provide a method of encrypting the data item having an identifier identifying the data item, the method comprising: encrypting the data item using a symmetric encryption key to obtain an encrypted data item; It is achieved in a first aspect of the present invention by providing a method of encrypting a data item, comprising: encrypting the symmetric encryption key using the identifier of the data item as an encryption key to obtain an encrypted encryption key.</p><p>In one aspect of the present invention, there is provided a method of decrypting the encrypted data item that is encrypted using an encrypted encryption key, the method comprising: providing a decryption key for decrypting the encrypted encryption key; obtaining the encrypted key using the provided decryption key to decrypt the encrypted encryption key to: and using the obtained encryption key to decrypt the encrypted data item to obtain the data item. A data item decryption method is provided.</p><p>The present invention is particularly, but not exclusively, preferred for use in healthcare to protect patient related healthcare data items such as records, images, and the like.</p><p>In one aspect, the invention relates to a computer program product configured to cause a computer system comprising at least one computer having associated data storage means to control encryption and decryption of data items and management of associated keys and licenses. Such a computer program product may be provided on any kind of computer-readable medium, for example, a magnetic or optical-based medium, or over a computer-based network such as the Internet.</p><p>Each aspect of the invention may be combined with any other aspect. These and other aspects of the present invention will be apparent from and elucidated with reference to the embodiments set forth below.</p>
1 schematically shows a method for encrypting a data item according to a first aspect of the present invention; Fig. 2 schematically shows a method for decrypting an encrypted data item according to a second aspect of the present invention; 3 is a computer system for employing the present invention;
BRIEF DESCRIPTION OF THE DRAWINGS The invention will now be described by way of example with reference to the accompanying drawings.
The present invention is described, for example, in Identity based encryption from the Weil pairing by D. Boneh and M. Franklin, SIAM J. of Computing, Vol. 32, No. 3, pp. 586-615, 2003 using the concept of identity-based encryption as previously disclosed.
In the context of the present invention, an "emergency agent" is a person, authority or organization or other entity that manages protected data items. There may be one or more emergency agents. A "healthcare provider" is a person, authority or organization or other entity that provides health care to one or more patients or individuals.
Each emergency agent has a pair of master public key and master private key pair of identity-based encryption method. It is assumed that only one such pair is used throughout the system; However, the present invention may be generalized in a simple manner to operate with a limited number of such pairs. The emergency agent maintains a protected secret master key. The corresponding public master key is publicly available to all involved parties, such as healthcare providers.
1 shows a data item 100 to be protected by encryption. The data item 100 may be, for example, any data, such as a document or image relating to a patient. The data item 100 includes an identifier 101 identifying the data item. The identifier may be the title of the data item, for example a general or specific title. The data item 100 is first encrypted in step 103 by a symmetric encryption scheme under the key 102 to obtain an encrypted data item 104 . This key 102 is also encrypted in step 105 by the license server under an identity-based encryption scheme together with the identifier 101 of the data item 100 such as a public key ("identity") and the master public key. do. This encrypted key 106 is stored as part of the emergency license.
2 shows the process steps for decrypting the encrypted data item 104 . When a healthcare provider needs access to one or more encrypted data items 104 or ideally their decrypted equivalents 100, he or she contacts the emergency agent with an identifier, and he or she Authenticates itself and requests a corresponding decryption key to decrypt the requested one or more data items. The emergency agent in turn logs the request, generates a corresponding secret key 201 and submits this key to the healthcare provider. The healthcare provider uses the received key 201 to decrypt the encrypted key 106 included in the emergency licenses in step 202 . The decrypted encryption key 102 may in turn be used to decrypt the encrypted data items 104 in step 203 . The requested decrypted data item 100 is thereby available to the healthcare provider.
The emergency agents should log all emergency transactions and perform periodic reviews to ensure proper use of the emergency method. The logged data includes the requested license; requested data items; issued licenses; It should include relevant data such as the identity of the health care provider with date and time, etc.
Note that the use of identity-based encryption allows the use of a different key 102 for each data item 100 . Thus, if the key 102 is accidentally leaked, only that data item 100 is affected, and all other data items in the system are still secure. Even if the key is leaked to a non-compliant, unauthorized person, he cannot use this key to decrypt other documents. Further, the security characteristics of the identity-based encryption scheme ensure that the key 102 can only be obtained by interaction with an emergency agent, which in turn must log these events for auditing purposes. The scheme is very space efficient, since only public and private master keys need to be permanently stored. All other keys 102 and 201 are calculated randomly or on the fly from the identifier of the requested radio.
3 shows a computer system 300 comprising at least one computer 301 having an associated data storage means 302 . The computer 301 receives an input 303 and provides an output 304 and resides on a suitable computer program product 305, such as a CD ROM, for controlling encryption and decryption of data items and management of the associated keys and licenses. programmed by instructions.
The present invention may be implemented in any suitable form including hardware, software, firmware, or any combination thereof. The invention or some features of the invention may be implemented as computer software running on one or more data processors and/or digital signal processors. The elements and components of the embodiment of the present invention may be physically, functionally and logically implemented in any suitable way. Indeed, functionality may be implemented as a single unit, as a plurality of units, or as part of other functional units. As such, the present invention may be implemented in a single unit, or may be physically and functionally distributed among different units and processors.
Although the present invention has been described in connection with specific embodiments, it is not intended to be limited to the specific form set forth herein. Rather, the scope of the invention is limited only by the appended claims. In the claims, the term "comprising" does not exclude the presence of other elements or steps. Additionally, although individual features may be included in different claims, they may possibly be advantageously combined, and the inclusion of different claims does not imply that a combination of features is not feasible and/or advantageous. Additionally, singular references do not exclude pluralities. Accordingly, references to "a", "a first", "second", etc. do not exclude a plurality. Also, reference numerals in the claims should not be construed as limiting the scope.
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2019132069A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
14 members in 9 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 081567836 | European Patent Office (EPO) | – | |
| 08156783 | European Patent Office (EPO) | A | |
| 2009052060 | International Bureau of the World Intellectual Property Organization (WIPO) | W |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| WO2009141784A1 | World Intellectual Property Organization (WIPO) | A1 | |
| MX2010012645A | Mexico | A | |
| EP2283451A1 | European Patent Office (EPO) | A1 | |
| US2011066863A1 | United States of America | A1 | |
| KR20110033137A | Republic of Korea | A | |
| CN102037474A | China | A | |
| JP2011521584A | Japan | A | |
| RU2010152642A | Russian Federation | A | |
| US8627103B2 | United States of America | B2 | |
| RU2505855C2 | Russian Federation | C2 | |
| CN102037474B | China | B | |
| BRPI0908621A2 | Brazil | A2 | |
| KR20160130512AThis record | Republic of Korea | A | |
| KR101687945B1 | Republic of Korea | B1 |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Changes to party contact information recordedST27 STATUS EVENT CODE: A-3-3-R10-R18-OTH-X000 (AS PROVIDED BY THE NATIONAL OFFICE)R18 | R18 | |
| Application deemed withdrawn, e.g. because no request for examination was filed or no examination fee was paidWithdrawnWITN | WITN | |
| Divisional application of patentA107 | A107 |
Numbers
- Publication
- 10-2016-0130512
- Application
- 1020167029933
Titles5
- Korean
- 데이터 아이템들에 대한 보안 액세스를 위한 데이터 아이템들의 아이덴티티-기반 암호화
- English
- IDENTITY-BASED ENCRYPTION OF DATA ITEMS FOR SECURE ACCESS THERETO
- English
- Identity-based encryption of data items for secure access to data items
- Unlabeled
- 데이터 아이템들에 대한 보안 액세스를 위한 데이터 아이템들의 아이덴티티-기반 암호화{IDENTITY-BASED ENCRYPTION OF DATA ITEMS FOR SECURE ACCESS THERETO}
- Unlabeled
- IDENTITY-BASED ENCRYPTION OF DATA ITEMS FOR SECURE ACCESS THERETO
Classification
- CPC, 5
- G06F21/62
- G06F21/6245
- G06F21/6218
- G06F21/602
- H04L9/30
- IPC, 2
- G06F21 62
- G06F21 60