WO2016167407A1 - 암호화 데이터 관리 방법 및 장치 - Google Patents
암호화 데이터 관리 방법 및 장치 Download PDFInfo
- Publication number
- WO2016167407A1 WO2016167407A1 PCT/KR2015/005691 KR2015005691W WO2016167407A1 WO 2016167407 A1 WO2016167407 A1 WO 2016167407A1 KR 2015005691 W KR2015005691 W KR 2015005691W WO 2016167407 A1 WO2016167407 A1 WO 2016167407A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- data
- encrypted
- search
- type
- data type
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/30—Services specially adapted for particular environments, situations or purposes
- H04W4/38—Services specially adapted for particular environments, situations or purposes for collecting sensor information
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
- G06F21/6245—Protecting personal data, e.g. for financial or medical purposes
-
- G—PHYSICS
- G11—INFORMATION STORAGE
- G11B—INFORMATION STORAGE BASED ON RELATIVE MOVEMENT BETWEEN RECORD CARRIER AND TRANSDUCER
- G11B20/00—Signal processing not specific to the method of recording or reproducing; Circuits therefor
- G11B20/00086—Circuits for prevention of unauthorised reproduction or copying, e.g. piracy
- G11B20/0021—Circuits for prevention of unauthorised reproduction or copying, e.g. piracy involving encryption or decryption of contents recorded on or reproduced from a record carrier
- G11B20/00485—Circuits for prevention of unauthorised reproduction or copying, e.g. piracy involving encryption or decryption of contents recorded on or reproduced from a record carrier characterised by a specific kind of data which is encrypted and recorded on and/or reproduced from the record carrier
- G11B20/00492—Circuits for prevention of unauthorised reproduction or copying, e.g. piracy involving encryption or decryption of contents recorded on or reproduced from a record carrier characterised by a specific kind of data which is encrypted and recorded on and/or reproduced from the record carrier wherein content or user data is encrypted
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/008—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols involving homomorphic encryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0894—Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2107—File encryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/42—Anonymization, e.g. involving pseudonyms
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
- H04L2209/805—Lightweight hardware, e.g. radio-frequency identification [RFID] or sensor
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W84/00—Network topologies
- H04W84/18—Self-organising networks, e.g. ad-hoc networks or sensor networks
Definitions
- the present invention relates to a method and apparatus for managing encrypted data. More particularly, the present invention relates to an encrypted data management method and apparatus for managing encrypted data.
- the information collected by a number of things around us may include personal privacy information, and indiscriminate collection, storage, and use of such information may lead to anxiety of personal information leakage. May lead to invasion of privacy and privacy.
- One way to improve security is to encrypt and decrypt data when needed.
- An object of the present invention is to provide an encrypted data management method and apparatus capable of performing search and analysis without decrypting encrypted data.
- Another object of the present invention is to provide a method and apparatus for managing encrypted data capable of performing a search at an improved speed.
- a method for managing encrypted data comprising: receiving data encrypted in different ways for each of the divided data types divided into at least two data types; Storing the received data; And retrieving the stored data.
- the storing may include storing the received data in a storage space storing data corresponding to a data type of the received data from among storage spaces classified for each data type. have.
- the searching may include: receiving the search word; Classifying a data type corresponding to the search word; And searching only in a storage space in which the divided data type is stored.
- the storing may include storing the received data in an encrypted state without performing decryption, and retrieving the stored data may be performed by using a preset search method. Retrieving the stored data in an encrypted state.
- a different search method is set for each of the storage spaces, and the searching using the preset search method is performed by using the different search methods for each storage space. It may include the step.
- the encrypted data management method may further include performing analysis using the stored data.
- the performing of the analysis may include using the stored data in an encrypted state without decrypting the stored data.
- the performing of the analysis in the encrypted state may include: obtaining information from encrypted data to be used for the analysis by using a table storing information matching the encrypted data; And performing analysis using the obtained information.
- the obtaining of the information may include obtaining information matching the encrypted value of the encrypted data from the table. .
- the obtaining of the information may include obtaining information matching the encrypted pattern of the encrypted data from the table. It may include.
- At least one piece of information stored in a table storing information matching the encrypted data may be matched with two or more different encrypted data.
- a method of managing encrypted data comprising: dividing data received from a plurality of sensors into at least two data types according to a preset method; Determining an encryption method according to the distinguished data type; Encrypting data corresponding to the distinguished data type by the determined encryption method; And transmitting the encrypted data.
- the dividing into data types may include dividing one data into two or more data types according to the preset method.
- the dividing into data types may include: dividing first data into a first data type according to the preset method; And dividing second data different from the first data into a second data type, and encrypting the data comprises encrypting the first data classified into the first data type using a first encryption method. Making; And encrypting the second data classified into the second data type by a second encryption method.
- An apparatus for managing encrypted data according to a third aspect of the present invention for achieving the above technical problem is divided into at least two or more data types and receiving a data encrypted in different ways for each of the divided data types. ;
- the apparatus for managing encrypted data further includes a search term receiving unit for receiving a search word, wherein the data search unit includes two or more sub-search units dedicated to each storage space to perform a search; And a master search unit for classifying a data type corresponding to the search word, wherein the master search unit may transmit a search command to a sub search unit dedicated to a storage space for storing the divided data type to perform a search.
- the data retrieval unit may include: at least two sub retrieval units dedicated to each storage space to perform a search; And a master search unit which transmits a search command to the sub search unit and aggregates the results searched by the sub search unit, wherein each sub search unit may perform a search by different search methods.
- a network intermediary apparatus comprising: a data type separator configured to classify data received from a plurality of sensors into at least two data types according to a preset method; An encryption method determination unit that determines an encryption method according to the classified data type; A data encryption unit for encrypting data corresponding to the divided data type by the determined encryption method; And it may include a data transmission unit for transmitting the encrypted data.
- An encryption sensor for each data type according to a fifth aspect of the present invention for achieving the technical problem the data type classification unit for classifying the data corresponding to the collected information into at least two or more data types according to a predetermined method ;
- An encryption method determination unit that determines an encryption method according to the classified data type;
- a data encryption unit for encrypting data corresponding to the divided data type by the determined encryption method;
- it may include a data transmission unit for transmitting the encrypted data.
- a computer program according to the fifth aspect of the present invention for achieving the above technical problem, in combination with hardware, may be stored in a medium for performing an encrypted data management method.
- the security since there is no data that decrypts the encrypted data, the security may be improved and information may not leak even when the data is leaked.
- FIG. 1 is a block diagram of an encrypted data management system according to an embodiment of the present invention.
- FIG. 2 is a block diagram of a data management apparatus according to an embodiment of the present invention.
- 3 and 4 are diagrams for describing encrypted data for each data type received by the data receiver.
- FIG. 5 is a diagram illustrating a data storage unit including storage spaces classified according to data types.
- FIG. 6 is a block diagram illustrating an example of a data search unit.
- FIG. 8 is a diagram illustrating an example of a hardware configuration of an apparatus for managing encrypted data according to another embodiment of the present invention.
- FIG. 9 is a flowchart illustrating a method of managing encrypted data according to an embodiment of the present invention.
- FIG. 10 is a flowchart illustrating an encrypted data management method according to another embodiment of the present invention.
- FIG. 11 is a flowchart illustrating an encrypted data management method according to another embodiment of the present invention.
- 'Sensor' used in the description of the present invention means that the information can be collected and transmitted using wired or wireless communication. 'Sensors' also include things included in the Internet of Things (IOT).
- IOT Internet of Things
- a wearable device that is worn on a human body and collects information about a human body temperature, heart rate, and the like may also be included in the sensor of the present invention.
- FIG. 1 is a block diagram of an encrypted data management system according to an embodiment of the present invention.
- a data management system 1000 may include a plurality of sensors 310, 320, 330, 340, and the like, at least one network intermediate apparatus 210, 220, and encryption.
- the data management apparatus 100 is included.
- Each sensor 310, 320, 330, 340, etc. may collect and transmit information. Some of the sensors may have a bidirectional communication function, and some of the sensors may have a communication function only in one direction.
- Each of the sensors 310, 320, 330, 340, and the like may transmit the collected information to the encrypted data management apparatus 100 through a network intermediate apparatus 210, 220, etc., such as a gateway.
- a network intermediate apparatus 210, 220, etc. such as a gateway.
- the network intermediate apparatus 210, 220, etc. exists between the sensors 310, 320, 330, 340, etc., and the encrypted data management apparatus 100 to receive data transmitted from the sensor and transmit the received data to the encrypted data management apparatus 100. Can be.
- the apparatus 100 for managing encrypted data receives data regarding information collected by the sensors 310, 320, 330, 340, and the like.
- the encrypted data management apparatus 100 may search for necessary information in the stored data.
- the apparatus 100 for managing encrypted data may perform analysis for deriving information or deriving information for providing a service.
- the encryption data management apparatus 100 will be described in more detail with reference to FIG. 2.
- FIG. 2 is a block diagram of an apparatus for managing encrypted data according to an embodiment of the present invention.
- the apparatus 100 for encrypting data management includes a data receiver 110, a data storage unit 120, a search term receiver 150, a data search unit 130, and data analysis. It may include a portion 140.
- the data receiver 110 receives data regarding information collected by the sensor.
- the data received by the data receiver 110 is data that is classified into at least two or more data types and encrypted in different ways.
- the data receiver 110 may receive data of the first data type encrypted by the first encryption method, data of the second data type encrypted by the second encryption method, and the like.
- the data receiver 110 receives first data including a data portion corresponding to the first data type encrypted by the first encryption method and a data portion corresponding to the second data type encrypted by the second encryption method. You may.
- Data types may be classified according to preset criteria.
- data types may be classified based on data types, types of data, and / or data transmission methods.
- the data type may be divided into numeric data, text data, format data, stream data, and the like.
- the method for encryption for each data type may be different.
- the numeric data type may be encrypted using the first encryption method, and the text data may be encrypted using the second encryption method.
- the encryption method for each data type may use existing encryption methods.
- an encryption method suitable for encrypting numeric data among the existing encryption methods may be set as an encryption method for data corresponding to the numeric data type.
- 3 and 4 are diagrams for describing encrypted data for each data type received by the data receiver.
- one data 30 may be divided into two or more data types based on a preset data type (31, 32, 33).
- the data area 31 divided into the first data type may be encrypted by the first encryption method.
- the data area 32 divided into the second data type may be encrypted by the second encryption method.
- the data area 33 divided into the third data type may be encrypted by a third encryption method.
- first data 41 classified into a first data type based on a preset data type is encrypted using a first encryption method.
- the second data 42 classified into the second data type on the basis of the preset data type is encrypted using the second encryption method.
- the data storage unit 120 may store data received by the data receiver 110.
- the data storage unit 120 may have storage spaces classified according to data types.
- the data storage unit 120 may have a plurality of storage spaces. Each storage space may be divided into one storage space and physically spaced and separated storage spaces.
- FIG. 5 is a diagram illustrating a data storage unit including storage spaces classified according to data types.
- encrypted data corresponding to the first data type may be stored in the first storage space 121.
- Encrypted data corresponding to the second data type may be stored in the second storage space 122.
- Encrypted data corresponding to the third data type may be stored in the third storage space 123.
- Encrypted data corresponding to the fourth data type may be stored in the first storage space 124.
- encrypted data corresponding to the numeric data type may be stored in the first storage space 121
- encrypted data corresponding to the text data type may be stored in the second storage space 121.
- the storage space may exist as many as can be classified according to the preset data type criteria.
- Data stored in the data storage unit 120 is encrypted data.
- the search term receiver 150 may receive a search term.
- the search word may be a received search word input by a user, or a suitable search word may be generated and input by a user's request.
- the search word may be a search word generated according to a preset program.
- the data search unit 130 may search for data corresponding to the search word among the stored data.
- the data search unit 130 performs a search without decrypting the data.
- the data retrieval unit 130 may perform a search in an encrypted data state.
- a data search unit will be described with reference to FIG. 6.
- FIG. 6 is a block diagram illustrating an example of the data search unit 130.
- the data search unit 130 may include a plurality of sub search units 132 and a master search unit 131.
- the master search unit 131 may transmit a command to search for data corresponding to the search word to each of the sub search units 132a, 132b, 132c, and 132d.
- the master search unit 131 may receive and synthesize the results searched by the sub search unit 132.
- the sub search units 132a, 132b, 132c, and 132d respectively store the stored data.
- the search can be performed with the encrypted search word.
- the search word is a pattern or a range of numbers
- a search may be performed according to the contents of a predefined table (for example, a table for matching information) rather than a search for the search word.
- the encrypted result from the sub retrieval unit 132 may be transmitted to the master retrieval unit 131 without decrypting or decrypting it.
- the sub search unit 132 may transmit the encrypted results.
- One sub-search unit 132 may exist for each storage space.
- one sub-search unit 132 is connected to one storage space to perform a search.
- the first sub-search unit 132a may perform a search for the first storage space.
- the second sub-search unit 132b may perform a search for the second storage space.
- the third sub-search unit 132c may perform a search for the third storage space.
- the fourth sub-search unit 132d may perform a search for the fourth storage space.
- two or more storage spaces may be connected to one sub retrieval unit 132.
- the first sub-search unit 132a may perform a search for the first storage space and the second storage space.
- the second and fourth storage spaces may be dedicated by the second sub-search unit 132b to perform a search.
- Each sub retrieval unit 132 may perform a retrieval using a different retrieval method.
- the first storage space is a storage space for storing encrypted data corresponding to a numeric data type.
- a method of encrypting data corresponding to a numeric data type is called a first encryption method.
- the first sub retrieval unit 132a dedicated to the first storage space performs a search using a retrieval method capable of retrieving the encrypted data in the encrypted data state according to the first encryption method. do.
- the second storage space is a space for storing encrypted data corresponding to the text data type.
- the method of encrypting data corresponding to the text data type is called a second encryption method.
- the second sub retrieval unit 132b which performs a search dedicated to the second storage space performs a search using a search method that can search the encrypted data in the encrypted data state according to the second encryption method. do.
- the method for retrieving encrypted data may use existing known techniques.
- Each sub retrieval unit 132 performs a search using a search method suitable for each data type stored in a storage space in which a search is performed. Therefore, the sub retrieval unit 132 performs a search at a faster speed than a general encrypted data search method. can do.
- the master search unit 131 may distinguish a data type corresponding to a search word.
- the master search unit 131 may transmit a search command to the sub search unit 132 which performs a search by dedicating a storage space for storing the data type of the divided search word.
- the master search unit 131 classifies a data type corresponding to a search word into a first data type that is a numeric data type and a second data type that is a text data type.
- the master retrieval unit 131 is dedicated to the first sub retrieval unit 132a for exclusively retrieving the first storage space where the data of the first data type is stored and the second storage space for the data of the second data type.
- the search command may be transmitted to the second sub search unit 132b for searching.
- Each sub retrieval unit 132 may perform a retrieval according to a retrieval command transmitted from the master retrieval unit 131. Each sub retrieval unit 132 may transmit the search result to the master retrieval unit 131.
- the master search unit 131 may receive the search results of each sub search unit 132 and combine them to derive the search results.
- the data analyzer 140 may analyze the data using the search result or the stored data.
- the data analyzer 140 may analyze the data in an encrypted state without decrypting the encrypted data.
- the data analyzing unit 140 may use the matching information table, which is a table including specific encrypted data and information matching the specific encrypted data, and use the encrypted portion without analyzing the encrypted portion.
- the matching information table which is a table including specific encrypted data and information matching the specific encrypted data
- the data analyzer 140 obtains information matching the encrypted data from the matching information table.
- the data analyzer 140 may obtain information matching the encrypted value of the encrypted data from the matching information table.
- the data analyzer 140 may obtain information matching the encrypted pattern of the encrypted data from the matching information table.
- processing may be performed in a separate manner according to a non-structured format and a structured format.
- the plain text data may be encrypted using searchable encryption, and the encrypted data may be searched using an encryption key.
- the structured format is different from the encryption applied according to the format type, and a pattern of encrypted data may be generated according to the encryption.
- the search can be performed according to the pattern.
- the stream data when the stream data is transmitted to the encrypted data management apparatus 100, the stream data may be encrypted in a form capable of extracting only necessary specific data (eg, a key frame) without encrypting the entire stream data.
- the encrypted data management apparatus 100 receives stream data in which a specific frame portion is encrypted, only the encrypted specific frame may be stored separately from the original stream data.
- the encrypted data management apparatus 100 may perform a search using only encrypted specific frames when searching for stream data.
- the storage and retrieval process described may be performed by the encrypted data management apparatus 220, and the encryption process may be performed by the sensors 310, 320, 330, 340, or the like. Can be.
- sensors 310, 320, 330, 340, etc., or network intermediate devices 210, 220, etc. may use searchable encryption of data of plain text type.
- the encrypted data management apparatus 220 stores encrypted data.
- the encrypted data management apparatus 220 may search for data stored after being encrypted using Searchable Encryption using an encrypted keyword.
- Homomorphic encryption can be used to deliver the result of combining encrypted data. For example, if you want to combine Hello and world to deliver Helloworld's output, using quasi-homogenous encryption, Hello is encrypted with Uryyrjbeyq, with Hryyr world being jbeyq. Decrypting the encrypted one leads to Helloworld.
- Numerical plaintext can be used to perform calculations such as addition (+) and multiplication (X) in encrypted state using either quasi-homogenous or Diffie-Hellman encryption.
- calculations may be performed in a distributed encrypted state using a multi-party computation method on the cloud to obtain a result.
- Feature-based indexing by converting data from Structured Format into graph-structured data format, and tightly encapsulating the data part to filter or search patterns for specific features
- the data portion can only be detected by the encrypted keyword to retrieve the result.
- Structured data such as web graphs or social networks can be encrypted using symmetric searchable encryption to find search results for specific encrypted keywords.
- the structured data may be changed based on matrix-structured data to transmit encrypted data based on a query for the labeled data.
- the data can be classified into an identity, an attribute, or the like according to a format, it can perform function-based encryption. Encryption can be performed according to the type of data by using property-preserving encryption, order-preserving encryption, orthogonality-preserving encryption, etc., which encrypts a specific field to be encrypted by separating the specific data field according to a format.
- the data analyzer 140 may use the obtained information for analysis.
- the data analyzer 140 may obtain data of 'normal pressure' 72a and use it for analysis.
- the data analyzer 140 may acquire data of 'normal pressure' 52a.
- the data analyzer 140 may acquire data of 'low humidity' 52b.
- the matching information table may be set such that different encrypted data matches one same information.
- Different encrypted data is set to match one piece of the same information, and the data analyzer 140 may strengthen the protection of the collected information by obtaining and analyzing the matching information.
- the encrypted data management apparatus 100 may perform analysis without decrypting the encrypted data. Therefore, the encrypted data management apparatus 100 (does not have a decryption key necessary for decrypting the encrypted data. That is, there is no method for decrypting the original encrypted data. The exact meaning it represents is not known.
- the matching information table used in the analysis is not the matching information of the one-to-one relationship, but different encrypted data matches the same information, so that even if the matching information table is leaked, each encrypted data knows the correct information. Can't.
- FIG. 8 is a diagram illustrating an example of a hardware configuration of an apparatus for managing encrypted data according to another embodiment of the present invention.
- the encrypted data management apparatus 100 may have the configuration of FIG. 8.
- the encrypted data management apparatus 100 may include an encrypted data management processor 81, a storage 82, a memory 83, and a network interface 84.
- the encrypted data management apparatus 100 may include a system bus 85 connected to the encrypted data management processor 81 and the memory 83 to serve as a data movement path.
- Another computing device may be connected to the network interface 84.
- another computing device connected to the network interface 84 may be a display device, a user terminal, or the like.
- the network interface 84 may be Ethernet, FireWire, USB, or the like.
- the storage 82 may be implemented as a nonvolatile memory device such as a flash memory, a hard disk, or the like, but is not limited thereto.
- the storage 82 stores data of the computer program 82a for managing encrypted data.
- the data of the encrypted data management computer program 82a may include binary executable files and other resource files.
- the storage 82 may store the matching information table 82b.
- the memory 83 loads a computer program 82a for managing encrypted data.
- the encrypted data management computer program 82a is provided to the encrypted data management processor 81 and executed by the encrypted data management processor 81.
- the encrypted data management processor 81 is a processor capable of executing the encrypted data management computer program 82a. However, the encrypted data management processor 81 may not be a processor capable of executing only the encrypted data management computer program 82a. For example, the encrypted data management processor 81 may execute other programs besides the encrypted data management computer program 82a.
- the computer program 82a for managing encrypted data is divided into at least two data types and performs a series of receiving data encrypted in different ways, storing the received data, and retrieving the stored data. It may include the operation of.
- the encryption data may include a series of operations for storing the received data for each storage space classified for each data type.
- the encrypted data management computer program 82a performs a process of storing the received data without decryption and a process of searching using a preset search method capable of performing a search without decrypting the stored data. It can contain a series of operations.
- the computing device may be, for example, an encrypted data management apparatus 100 or an encrypted data management system according to an embodiment of the present invention.
- the configuration and operation of the encryption management apparatus or the encryption data management system can be understood through the contents described with reference to FIGS. 1 to 8.
- FIG. 9 is a flowchart illustrating a method of managing encrypted data according to an embodiment of the present invention.
- the computing device receives encrypted data for each data type (S910).
- the data received by the computing device is classified for each data type and stored in each storage space (S920).
- the storage space may exist by data type.
- the computing device does not decrypt the received encrypted data and stores the encrypted data in the storage space in an encrypted state.
- the computing device performs a search in an encrypted state without decrypting the encrypted data (S930).
- the computing device may use the encrypted data without decrypting the retrieved data to perform analysis for deriving necessary information (S940).
- FIG. 10 is a flowchart illustrating an encrypted data management method according to another embodiment of the present invention.
- the first sensor 310 collects information (S1010).
- Data about the information collected by the first sensor 310 is classified into a data type according to a preset method.
- the first sensor 310 determines an encryption method according to the divided data type.
- the first sensor 310 encrypts data corresponding to data types classified by the determined encryption method (S1020).
- the first sensor 310 transmits the encrypted data to the encrypted data management apparatus 100 through the first network intermediate apparatus 210 (S1030 and S1040).
- the encrypted data management apparatus 100 stores the encrypted data received in different storage spaces for each data type (S1050).
- the encrypted data management apparatus 100 receives a search word (S1060).
- the search word received by the encrypted data management apparatus 100 may be an encrypted search word or may undergo an encryption process.
- the encrypted data management apparatus 100 may distinguish a data type of the received search word (S1070). Alternatively, the apparatus 100 for managing encrypted data may select a storage space in which a data type to be searched is stored.
- the encrypted data management apparatus 100 may perform a search only in a storage space in which data corresponding to a data type of a divided search word is stored (S1080).
- the search term used for the search may be an encrypted search term.
- the encrypted data management apparatus 100 may search by using a search word only in the selected storage space.
- the encrypted data management apparatus 100 may search for the encrypted data file without decrypting the data.
- the encrypted data management apparatus 100 may use the encrypted data for analysis without decrypting the searched data (S1090). Alternatively, the encrypted search result can be decrypted and used for analysis. The encrypted data management apparatus 100 may obtain information matching the retrieved data and use the same for analysis.
- FIG. 11 is a flowchart illustrating an encrypted data management method according to another embodiment of the present invention.
- the first network management device encrypts data received from the sensor.
- the first sensor 310 collects information (S1105).
- the first sensor 310 transmits first data corresponding to the collected information to the first network intermediate apparatus 210 (S1115).
- the second sensor 320 collects information (S1110).
- the second sensor 320 transmits second data corresponding to the collected information to the first network intermediate apparatus 210 (S1120).
- the first network management apparatus encrypts using a first encryption method that is an encryption method corresponding to the data type of the first data (S1125).
- the first network management apparatus encrypts the data using the second encryption method, which is an encryption method corresponding to the data type of the second data.
- the first network management apparatus transmits the encrypted first data and the encrypted second data to the encrypted data management apparatus 100 (S1135 and S1140).
- the encrypted data management apparatus 100 stores the encrypted first data in a first storage space in which data corresponding to a data type of the first data is stored (S1145).
- the encrypted data management apparatus 100 stores the encrypted second data in a second storage space in which data corresponding to the data type of the second data is stored (S1150).
- the encrypted data management apparatus 100 receives a search word (S1155).
- the search word received by the encrypted data management apparatus 100 may be an encrypted search word or may undergo an encryption process.
- the encrypted data management apparatus 100 may classify the data type of the received search word in operation S1160. Alternatively, the apparatus 100 for managing encrypted data may select a storage space in which a data type to be searched is stored.
- the encrypted data management apparatus 100 may perform a search only in a storage space in which data corresponding to the data type of the divided search word is stored (S1165).
- the search term used for the search may be an encrypted search term.
- the encrypted data management apparatus 100 may search by using a search word only in the selected storage space.
- the encrypted data management apparatus 100 may search for the encrypted data file without decrypting the data.
- the encrypted data management apparatus 100 may use the encrypted data for analysis without decrypting the searched data (S1170). Alternatively, the encrypted search result can be decrypted and used for analysis.
- the methods according to the embodiments of the present invention described above with reference to FIGS. 9 to 11 may be performed by executing a computer program implemented in computer readable code.
- the computer program may be transmitted from the first computing device to the second computing device via a network such as the Internet and installed in the second computing device, thereby being used in the second computing device.
- the first computing device and the second computing device include both a server device, a stationary computing device such as a desktop PC, a mobile computing device such as a laptop, a smartphone, a tablet PC, and a wearable computing device such as a smart watch and smart glasses. do.
- each component of FIG. 2 may refer to software or hardware such as a field-programmable gate array (FPGA) or an application-specific integrated circuit (ASIC).
- FPGA field-programmable gate array
- ASIC application-specific integrated circuit
- the components are not limited to software or hardware, and may be configured to be in an addressable storage medium and may be configured to execute one or more processors.
- the functions provided in the above components may be implemented by more detailed components, or may be implemented as one component that performs a specific function by combining a plurality of components.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Bioethics (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Theoretical Computer Science (AREA)
- Computing Systems (AREA)
- Medical Informatics (AREA)
- Databases & Information Systems (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
- Storage Device Security (AREA)
Abstract
본 발명의 일 실시예에 따른 암호화 데이터 관리 방법은, 적어도 둘 이상의 데이터 타입으로 구분되어 상기 구분된 데이터 타입 별로 서로 다른 방식으로 암호화된 데이터를 수신하는 단계; 상기 수신한 데이터를 저장하는 단계; 및 상기 저장된 데이터를 검색하는 단계를 포함할 수 있다.
Description
본 발명은 암호화 데이터 관리 방법 및 장치에 관한 것이다. 보다 자세하게는, 암호화된 데이터를 관리하는 암호화 데이터 관리 방법 및 장치 에 관한 것이다.
최근 빅데이터를 이용한 정보 분석이 활발하게 이루어 지고 있다.
또한, 사물끼리 인터넷으로 연결되어 정보를 주고 받는 사물 인터넷에 대한 기술 개발 및 적용도 활발하게 이루어 지고 있다.
사물 인터넷에 대한 기술 개발 및 적용이 이루어 지면, 현재보다도 방대한 양의 빅데이터가 발생되고 이용될 것이다.
즉, 수많은 사물에 의하여 수많은 형태의 정보들이 수집되고 분석되어 다양한 서비스를 제공하고 다양한 정보를 도출할 수 있을 것이다.
다만, 우리가 흔히 사용하는 스마트폰을 포함하여 우리 주변에 존재하는 수많은 사물에 의하여 수집되는 정보에는 개인의 프라이버시 정보가 포함될 수 있으며, 이러한 정보를 무분별하게 수집하여 저장하고 이용하는 것은 개인의 정보 유출 불안감 조성 및 사생활 침해로 연결될 수 있다.
따라서, 빅데이터를 관리하고 이용하는 기술에는 데이터에 대한 보안이 중요하다.
보안성을 향상시키는 방안 중 하나로는 데이터를 암호화하고 필요할 때 복호화하여 이용하는 방식이 존재한다.
그러나, 암호화된 데이터를 복호화하는데는 많은 시간과 비용이 소모된다.
본 발명이 해결하고자 하는 기술적 과제는 암호화된 데이터를 복호화하지 않고 검색 및 분석을 수행할 수 있는 암호화 데이터 관리 방법 및 장치를 제공하는 것을 목적으로 한다.
또한, 본 발명이 해결하고자 하는 기술적 과제는 보다 향상된 속도로 검색을 수행할 수 있는 암호화 데이터 관리 방법 및 장치를 제공하는 것을 목적으로 한다.
본 발명의 기술적 과제들은 이상에서 언급한 기술적 과제들로 제한되지 않으며, 언급되지 않은 또 다른 기술적 과제들은 아래의 기재로부터 통상의 기술자에게 명확하게 이해 될 수 있을 것이다.
상기 기술적 과제를 달성하기 위한 본 발명의 제1 태양(Aspect)에 따른 암호화 데이터 관리 방법은, 적어도 둘 이상의 데이터 타입으로 구분되어 상기 구분된 데이터 타입 별로 서로 다른 방식으로 암호화된 데이터를 수신하는 단계; 상기 수신한 데이터를 저장하는 단계; 및 상기 저장된 데이터를 검색하는 단계를 포함할 수 있다.
일 실시예에 따르면, 상기 저장하는 단계는, 상기 데이터 타입 별로 구분된 저장 공간 중에서 상기 수신한 데이터의 데이터 타입에 해당하는 데이터를 저장하는 저장 공간에 상기 수신한 데이터를 저장하는 단계를 포함할 수 있다.
일 실시예에 따르면, 상기 검색하는 단계는, 상기 검색어를 수신하는 단계; 상기 검색어에 해당하는 데이터 타입을 구분하는 단계; 및 상기 구분된 데이터 타입이 저장된 저장 공간에서만 검색하는 단계를 포함할 수 있다.
일 실시예에 따르면, 상기 저장하는 단계는, 상기 수신한 데이터를 복호화를 수행하지 않고 암호화된 상태로 저장하는 단계를 포함하며, 상기 저장된 데이터를 검색하는 단계는, 기 설정된 검색 방법을 이용하여 상기 저장된 데이터를 암호화된 상태로 검색하는 단계를 포함할 수 있다.
일 실시예에 따르면, 상기 기 설정된 검색 방법은 상기 저장 공간 별로 서로 다른 검색 방법이 설정되며, 상기 기 설정된 검색 방법을 이용하여 검색하는 단계는, 상기 저장 공간 별로 상기 서로 다른 검색 방법을 이용하여 검색하는 단계를 포함할 수 있다.
일 실시예에 따르면, 상기 암호화 데이터 관리 방법은, 상기 저장된 데이터를 이용하여 분석을 수행하는 단계를 더 포함할 수 있다.
일 실시예에 따르면, 상기 분석을 수행하는 단계는, 상기 저장된 데이터를 복호화하지 않고 암호화된 상태로 분석에 이용하는 단계를 포함할 수 있다.
일 실시예에 따르면, 상기 암호화된 상태로 분석을 수행하는 단계는, 상기 암호화된 데이터와 매칭되는 정보가 저장된 테이블을 이용하여 상기 분석에 이용하고자 하는 암호화된 데이터로부터 정보를 획득하는 단계; 및 상기 획득된 정보를 이용하여 분석을 수행하는 단계를 포함할 수 있다.
일 실시예에 따르면, 상기 암호화된 데이터의 데이터 타입이 숫자인 경우, 상기 정보를 획득하는 단계는, 상기 암호화된 데이터의 암호화된 값과 매칭되는 정보를 상기 테이블로부터 획득하는 단계를 포함할 수 있다.
일 실시예에 따르면, 상기 암호화된 데이터의 데이터 타입이 포맷 데이터(Format Data)인 경우, 상기 정보를 획득하는 단계는, 상기 암호화된 데이터의 암호화된 패턴과 매칭되는 정보를 상기 테이블로부터 획득하는 단계를 포함할 수 있다.
일 실시예에 따르면, 상기 암호화된 데이터와 매칭되는 정보가 저장된 테이블에 저장된 적어도 하나의 정보는 둘 이상의 서로 다른 암호화된 데이터와 매칭될 수 있다.
상기 기술적 과제를 달성하기 위한 본 발명의 제2 태양(Aspect)에 따른 암호화 데이터 관리 방법은, 복수 개의 센서들로부터 수신되는 데이터들을 기 설정된 방식에 따라서 적어도 둘 이상의 데이터 타입으로 구분하는 단계; 상기 구분된 데이터 타입에 따라서 암호화 방식을 결정하는 단계; 상기 결정된 암호화 방식으로 상기 구분된 데이터 타입에 해당하는 데이터를 암호화하는 단계; 및 상기 암호화된 데이터를 전송하는 단계를 포함할 수 있다.
일 실시예에 따르면, 상기 데이터 타입으로 구분하는 단계는, 상기 기 설정된 방식에 따라서 하나의 데이터에서 둘 이상의 데이터 타입으로 구분하는 단계를 포함할 수 있다.
일 실시예에 따르면, 상기 데이터 타입으로 구분하는 단계는, 상기 기 설정된 방식에 따라서 제1 데이터를 제1 데이터 타입으로 구분하는 단계; 및 상기 제1 데이터와 상이한 제2 데이터를 제2 데이터 타입으로 구분하는 단계를 포함하며, 상기 데이터를 암호화하는 단계는, 상기 제1 데이터 타입으로 구분된 상기 제1 데이터를 제1 암호화 방식으로 암호화하는 단계; 및 상기 제2 데이터 타입으로 구분된 상기 제2 데이터를 제2 암호화 방식으로 암호화하는 단계를 포함할 수 있다.
상기 기술적 과제를 달성하기 위한 본 발명의 제3 태양(Aspect)에 따른 암호화 데이터 관리 장치는, 적어도 둘 이상의 데이터 타입으로 구분되어 상기 구분된 데이터 타입 별로 서로 다른 방식으로 암호화된 데이터를 수신하는 데이터 수신부; 상기 수신한 데이터를 저장하는 데이터 저장부; 및 상기 저장된 데이터를 검색하는 데이터 검색부를 포함할 수 있다.
일 실시예에 따르면, 상기 암호화 데이터 관리 장치는, 검색어를 수신하는 검색어 수신부를 더 포함하며, 상기 데이터 검색부는, 상기 저장 공간 별로 전담하여 검색을 수행하는 둘 이상의 서브 검색부; 및 상기 검색어에 해당하는 데이터 타입을 구분하는 마스터 검색부를 포함하며, 상기 마스터 검색부는, 상기 구분된 데이터 타입을 저장하는 저장 공간을 전담하여 검색을 수행하는 서브 검색부로 검색 명령을 전송할 수 있다.
일 실시예에 따르면, 상기 데이터 검색부는, 상기 저장 공간 별로 전담하여 검색을 수행하는 둘 이상의 서브 검색부; 및 상기 서브 검색부에 검색 명령을 전송하고 상기 서브 검색부에 의하여 검색된 결과를 종합하는 마스터 검색부를 포함하며, 상기 각각의 서브 검색부는 서로 상이한 검색 방법으로 검색을 수행할 수 있다.
상기 기술적 과제를 달성하기 위한 본 발명의 제4 태양(Aspect)에 따른 네트워크 중간 장치는, 복수 개의 센서들로부터 수신되는 데이터들을 기 설정된 방식에 따라서 적어도 둘 이상의 데이터 타입으로 구분하는 데이터 타입 구분부; 상기 구분된 데이터 타입에 따라서 암호화 방식을 결정하는 암호화 방식 결정부; 상기 결정된 암호화 방식으로 상기 구분된 데이터 타입에 해당하는 데이터를 암호화하는 데이터 암호화부; 및 상기 암호화된 데이터를 전송하는 데이터 전송부를 포함할 수 있다.
상기 기술적 과제를 달성하기 위한 본 발명의 제5 태양(Aspect)에 따른 데이터 타입 별 암호화 센서는, 수집되는 정보에 해당하는 데이터들을 기 설정된 방식에 따라서 적어도 둘 이상의 데이터 타입으로 구분하는 데이터 타입 구분부; 상기 구분된 데이터 타입에 따라서 암호화 방식을 결정하는 암호화 방식 결정부; 상기 결정된 암호화 방식으로 상기 구분된 데이터 타입에 해당하는 데이터를 암호화하는 데이터 암호화부; 및 상기 암호화된 데이터를 전송하는 데이터 전송부를 포함할 수 있다.
상기 기술적 과제를 달성하기 위한 본 발명의 제5 태양(Aspect)에 따른 컴퓨터프로그램은, 하드웨어와 결합되어, 암호화 데이터 관리 방법을 수행하기 위하여 매체에 저장될 수 있다.
상기와 같은 본 발명에 따르면, 암호화된 데이터를 복호화하지 않고 검색 및 분석을 수행할 수 있다. 따라서, 복호화에 필요한 시간과 비용을 감소시킬 수 있다.
또한, 본 발명에 따르면, 암호화된 데이터를 복호화한 데이터가 존재하지 않으므로 보안성을 향상시키고 데이터 유출 시에도 정보가 유출되지 않을 수 있다.
또한, 본 발명에 따르면, 암호화된 데이터에 대한 검색 속도를 향상시킬 수 있다.
본 발명의 효과들은 이상에서 언급한 효과들로 제한되지 않으며, 언급되지 않은 또 다른 효과들은 아래의 기재로부터 통상의 기술자에게 명확하게 이해 될 수 있을 것이다.
도 1은 본 발명의 일 실시예에 따른 암호화 데이터 관리 시스템에 관한 구성도이다.
도 2는 본 발명의 일 실시예에 따른 데이터 관리 장치에 관한 블록도이다
도 3 및 4는 데이터 수신부가 수신하는 데이터 타입 별로 암호화된 데이터를 설명하기 위한 도면이다.
도 5는 데이터 타입 별로 구분된 저장 공간을 포함하는 데이터 저장부에 관한 도면이다.
도 6은 데이터 검색부의 일 예를 나타내는 블록도이다.
도 7은 매칭 정보용 테이블에 관한 일 예이다.
도 8은 본 발명의 다른 실시예에 따른 암호화 데이터 관리 장치의 하드웨어 구성의 일 예를 나타내는 도면이다.
도 9는 본 발명의 일 실시예에 따른 암호화 데이터 관리 방법에 관한 순서도이다.
도 10은 본 발명의 다른 실시예에 따른 암호화 데이터 관리 방법에 관한 동작 흐름도이다.
도 11은 본 발명의 또 다른 실시예에 따른 암호화 데이터 관리 방법에 관한 동작 흐름도이다.
이하, 첨부된 도면을 참조하여 본 발명의 바람직한 실시예를 상세히 설명한다. 본 발명의 이점 및 특징, 그리고 그것들을 달성하는 방법은 첨부되는 도면과 함께 상세하게 후술되어 있는 실시 예들을 참조하면 명확해질 것이다. 그러나 본 발명은 이하에서 게시되는 실시 예들에 한정되는 것이 아니라 서로 다른 다양한 형태로 구현될 수 있으며, 단지 본 실시 예들은 본 발명의 게시가 완전하도록 하고, 본 발명이 속하는 기술분야에서 통상의 지식을 가진 자에게 발명의 범주를 완전하게 알려주기 위해 제공되는 것이며, 본 발명은 청구항의 범주에 의해 정의될 뿐이다. 명세서 전체에 걸쳐 동일 참조 부호는 동일 구성 요소를 지칭한다.
다른 정의가 없다면, 본 명세서에서 사용되는 모든 용어(기술 및 과학적 용어를 포함)는 본 발명이 속하는 기술분야에서 통상의 지식을 가진 자에게 공통적으로 이해될 수 있는 의미로 사용될 수 있을 것이다. 또 일반적으로 사용되는 사전에 정의되어 있는 용어들은 명백하게 특별히 정의되어 있지 않는 한 이상적으로 또는 과도하게 해석되지 않는다. 본 명세서에서 사용된 용어는 실시예들을 설명하기 위한 것이며 본 발명을 제한하고자 하는 것은 아니다. 본 명세서에서, 단수형은 문구에서 특별히 언급하지 않는 한 복수형도 포함한다.
본 명세서에서, 단수형은 문구에서 특별히 언급하지 않는 한 복수형도 포함될 수 있다. 명세서에서 사용되는 "포함한다(comprises)" 및/또는 "포함하는(comprising)"은 언급된 구성요소, 단계, 동작 및/또는 소자는 하나 이상의 다른 구성요소, 단계, 동작 및/또는 소자의 존재 또는 추가를 배제하지 않는다.
본 발명의 설명에서 사용하는 '센서'는 정보를 수집하고 유선 또는 무선 통신을 이용하여 정보를 전송할 수 있는 것을 의미한다. '센서'에는 사물 인터넷(IOT, Internet of Things)에 포함되는 사물도 포함한다.
예를 들면, 인체에 착용되어 인체의 체온, 심박수 등에 관한 정보를 수집하는 웨어러블 디바이스도 본 발명의 센서에 포함될 수 있다.
도 1은 본 발명의 일 실시예에 따른 암호화 데이터 관리 시스템에 관한 구성도이다.
도 1을 참조하면, 본 발명의 일 실시예에 따른 데이터 관리 시스템(1000)은 복수 개의 센서들(310, 320, 330, 340 등), 적어도 하나의 네트워크 중간 장치(210, 220 등) 및 암호화 데이터 관리 장치(100)를 포함한다.
복수 개의 센서들에는 다양한 종류의 센서들이 존재한다. 각각의 센서(310, 320, 330, 340 등)는 정보를 수집하여 전송할 수 있다. 센서 중 일부는 양방향 통신 기능이 존재할 수 있으며, 센서 중 다른 일부는 일방향으로만 통신 기능이 존재할 수도 있다.
각각의 센서들(310, 320, 330, 340 등)은 수집된 정보를 게이트웨이 등 네트워크 중간 장치(210, 220 등)를 통하여 암호화 데이터 관리 장치(100)로 전송할 수 있다.
네트워크 중간 장치(210, 220 등)는 센서(310, 320, 330, 340 등)와 암호화 데이터 관리 장치(100) 사이에 존재하여 센서에서 전송된 데이터를 수신하여 암호화 데이터 관리 장치(100)로 전송할 수 있다.
암호화 데이터 관리 장치(100)는 센서(310, 320, 330, 340 등)가 수집한 정보에 관한 데이터를 수신한다.
또한, 암호화 데이터 관리 장치(100)는 저장한 데이터에서 필요한 정보를 검색할 수 있다. 또한, 암호화 데이터 관리 장치(100)는 정보 도출 또는 서비스 제공을 위한 정보 도출 등을 위한 분석을 수행할 수 있다.
도 2를 참조하여 암호화 데이터 관리 장치(100)에 관한 보다 상세하게 설명한다.
도 2는 본 발명의 일 실시예에 따른 암호화 데이터 관리 장치에 관한 블록도이다
도 2를 참조하면, 본 발명의 일 실시예에 따른 암호화 데이터 관리 장치(100)는 데이터 수신부(110), 데이터 저장부(120), 검색어 수신부(150), 데이터 검색부(130) 및 데이터 분석부(140)를 포함할 수 있다.
데이터 수신부(110)는 센서가 수집한 정보에 관한 데이터를 수신한다.
구체적으로, 데이터 수신부(110)가 수신하는 데이터는 적어도 둘 이상의 데이터 타입으로 구분되어 서로 다른 방식으로 암호화된 데이터이다.
즉, 데이터 수신부(110)는 제1 암호화 방식으로 암호화된 제1 데이터 타입의 데이터, 제2 암호화 방식으로 암호화된 제2 데이터 타입의 데이터를 등을 수신할 수 있다.
또는, 데이터 수신부(110)는 제1 암호화 방식으로 암호화된 제1 데이터 타입에 해당하는 데이터 부분 및 제2 암호화 방식으로 암호화된 제2 데이터 타입에 해당하는 데이터 부분을 포함하는 제1 데이터 등을 수신할 수도 있다.
데이터 타입은 기 설정된 기준에 따라서 구분될 수 있다.
예를 들어, 데이터 타입은 데이터의 형식, 데이터의 종류 및/또는 데이터의 전송 방식 등의 기준으로 구분될 수 있다.
예를 들면, 데이터 타입은 숫자 데이터, 텍스트 데이터, 포맷 데이터(Format data) 및 스트림 데이터 등으로 구분될 수 있다. 데이터 타입 별로 암호화를 위한 방식은 상이할 수 있다.
즉, 숫자 데이터 타입은 제1 암호화 방식으로 암호화되고, 텍스트 데이터는 제2 암호화 방식으로 암호화될 수 있다.
데이터 타입 별 암호화 방식은 기존의 암호화 방식들을 이용할 수 있다. 예를 들면, 기존 암호화 방식 중에서 숫자 데이터의 암호화에 적합한 암호화 방식을 숫자 데이터 타입에 해당하는 데이터의 암호화 방식으로 설정할 수 있다.
도 3 및 4는 데이터 수신부가 수신하는 데이터 타입 별로 암호화된 데이터를 설명하기 위한 도면이다.
도 3을 참조하면, 하나의 데이터(30) 내에서도 기 설정된 데이터 타입을 기준으로 둘 이상의 데이터 타입으로 구분(31, 32, 33)될 수도 있다.
제1 데이터 타입으로 구분된 데이터 영역(31)은 제1 암호화 방식으로 암호화될 수 있다.
제2 데이터 타입으로 구분된 데이터 영역(32)은 제2 암호화 방식으로 암호화 될 수 있다.
제3 데이터 타입으로 구분된 데이터 영역(33)은 제3 암호화 방식으로 암호화 될 수 있다.
도 4를 참조하면, 기 설정된 데이터 타입 기준으로 제1 데이터 타입으로 구분된 제1 데이터(41)는 제1 암호화 방식으로 암호화된다.
기 설정된 데이터 타입 기준으로 제2 데이터 타입으로 구분된 제2 데이터(42)는 제2 암호화 방식으로 암호화된다.
다시 도 2를 참조하면, 데이터 저장부(120)는 데이터 수신부(110)가 수신한 데이터를 저장할 수 있다.
데이터 저장부(120)는 데이터 타입 별로 구분된 저장 공간이 존재할 수 있다.
즉, 데이터 저장부(120)는 복수 개로 구분된 저장 공간이 존재할 수 있다. 각각의 저장 공간은 하나의 저장 공간이 분할 되어 존재할 수도 있으며 물리적으로 이격되어 구분된 저장 공간이 존재할 수도 있다.
도 5는 데이터 타입 별로 구분된 저장 공간을 포함하는 데이터 저장부에 관한 도면이다.
도 5를 참조하면, 제1 데이터 타입에 해당하는 암호화된 데이터는 제1 저장 공간(121)에 저장될 수 있다. 제2 데이터 타입에 해당하는 암호화된 데이터는 제2 저장 공간(122)에 저장될 수 있다. 제3 데이터 타입에 해당하는 암호화된 데이터는 제3 저장 공간(123)에 저장될 수 있다. 제4 데이터 타입에 해당하는 암호화된 데이터는 제1 저장 공간(124)에 저장될 수 있다.
예를 들어, 숫자 데이터 타입에 해당하는 암호화된 데이터는 제1 저장 공간(121)에 저장되고, 텍스트 데이터 타입에 해당하는 암호화된 데이터는 제2 저장 공간(121)에 저장될 수 있다.
저장 공간은 기 설정된 데이터 타입 기준 별로 구분될 수 있는 수만큼 존재할 수 있다.
데이터 저장부(120)에 저장되는 데이터는 암호화된 데이터이다.
다시 도 2를 참조하면, 검색어 수신부(150)는 검색어를 수신할 수 있다.
검색어는 사용자에 의하여 입력된 검색어를 수신한 것일 수도 있고, 사용자의 요청에 의하여 적합한 검색어가 생성되어 입력된 것일 수도 있다. 또는, 검색어는 기 설정된 프로그램에 따라서 생성된 검색어일 수도 있다.
데이터 검색부(130)는 저장된 데이터 중에서 검색어에 부합하는 데이터를 검색할 수 있다.
데이터 검색부(130)는 데이터를 복호화하지 않고 검색을 수행한다.
*즉, 데이터 검색부(130)는 암호화된 데이터 상태로 검색을 수행할 수 있다.
도 6을 참조하여 데이터 검색부를 설명한다.
도 6은 데이터 검색부(130)의 일 예를 나타내는 블록도이다.
도 6을 참조하면, 데이터 검색부(130)는 복수 개의 서브 검색부(132) 및 마스터 검색부(131)를 포함할 수 있다.
마스터 검색부(131)는 검색어에 부합하는 데이터를 검색하라는 명령을 각각의 서브 검색부(132a, 132b, 132c, 132d)에 전송할 수 있다. 마스터 검색부(131)는 서브 검색부(132)에 의하여 검색된 결과를 수신하고 종합할 수 있다.
구체적으로, 마스터 검색부(131)에서는 하나의 검색어에 대해서 각 서브 검색부(132a, 132b, 132c, 132d)에 전송하면, 서브 검색부(132a, 132b, 132c, 132d)는 각각 저장하고 있는 데이터의 데이터 타입 별 암호화 방식을 검색어에 적용하여 암호화된 검색어를 가지고 검색을 수행할 수 있다. 그리고, 검색어가 패턴이나 숫자의 범위인 경우에는 검색어에 대한 검색 보다는 미리 정의한 테이블(예를 들면 매칭 정보용 테이블)의 내용에 따른 검색을 할 수도 있다. 그리고, 서브 검색부(132)에서 나온 암호화된 결과는 복호화하거나 복호화하지 않고 마스터 검색부(131)에 전송할 수 있다. 마스터 검색부(131)가 모든 암호화된 결과에 대하여 종합할 수 있는 기능을 가지고 있을 때에는 서브 검색부(132)는 암호화된 결과를 전송할 수도 있다.
서브 검색부(132)는 각각의 저장 공간 마다 하나씩 존재할 수 있다.
즉, 하나의 저장 공간에는 하나의 서브 검색부(132)가 연결되어 검색을 수행한다.
제1 저장 공간은 제1 서브 검색부(132a)가 전담하여 검색을 수행할 수 있다. 제2 저장 공간은 제2 서브 검색부(132b)가 전담하여 검색을 수행할 수 있다. 제3 저장 공간은 제3 서브 검색부(132c)가 전담하여 검색을 수행할 수 있다. 제4 저장 공간은 제4 서브 검색부(132d)가 전담하여 검색을 수행할 수 있다.
또는, 하나의 서브 검색부(132)에는 둘 이상의 저장 공간이 연결될 수 있다.
예를 들면, 제1 저장 공간 및 제2 저장 공간은 제1 서브 검색부(132a)가 전담하여 검색을 수행할 수 있다. 제3 저장 공간 및 제4 저장 공간은 제2 서브 검색부(132b)가 전담하여 검색을 수행할 수 있다.
각각의 서브 검색부(132)는 서로 상이한 검색 방법으로 검색을 수행할 수 있다.
예를 들어, 제1 저장 공간에는 숫자 데이터 타입에 해당하는 암호화된 데이터를 저장하는 저장 공간이라 가정한다. 숫자 데이터 타입에 해당하는 데이터를 암호화하는 방식은 제1 암호화 방식이라 한다. 이러한 경우, 제1 저장 공간을 전담하여 검색을 수행하는 제1 서브 검색부(132a)는 제1 암호화 방식에 따라서 암호화된 데이터를 암호화된 데이터 상태로 검색할 수 있는 검색 방법을 이용하여 검색을 수행한다.
다른 예를 들어, 제2 저장 공간에는 텍스트 데이터 타입에 해당하는 암호화된 데이터를 저장하는 공간이라 가정한다. 텍스트 데이터 타입에 해당하는 데이터를 암호화하는 방식은 제2 암호화 방식이라 한다. 이러한 경우, 제2 저장 공간을 전담하여 검색을 수행하는 제2 서브 검색부(132b)는 제2 암호화 방식에 따라서 암호화된 데이터를 암호화된 데이터 상태로 검색할 수 있는 검색 방법을 이용하여 검색을 수행한다. 암호화된 데이터를 검색하는 방법은 기존의 공지된 기술을 이용할 수 있다.
각각의 서브 검색부(132)는 검색을 수행하는 있는 저장 공간에 저장되는 데이터 타입 별에 적합한 검색 방법을 이용하여 검색을 수행하는 바 일반적인 암호화된 데이터를 검색하는 방법에 비하여 빠른 속도로 검색을 수행할 수 있다.
추가적으로, 마스터 검색부(131)는 검색어에 해당하는 데이터 타입을 구분할 수 있다.
마스터 검색부(131)는 구분된 검색어의 데이터 타입을 저장하는 저장 공간을 전담하여 검색을 수행하는 서브 검색부(132)로 검색 명령을 전송할 수 있다.
예를 들어, 마스터 검색부(131)가 검색어에 해당하는 데이터 타입을 구분한 결과 숫자 데이터 타입인 제1 데이터 타입과 텍스트 데이터 타입인 제2 데이터 타입으로 구분된다고 가정한다. 이러한 경우, 마스터 검색부(131)는 제1 데이터 타입의 데이터가 저장된 제1 저장 공간을 전담하여 검색하는 제1 서브 검색부(132a) 및 제2 데이터 타입의 데이터가 저장된 제2 저장 공간을 전담하여 검색하는 제2 서브 검색부(132b)로 검색 명령을 전송할 수 있다.
각각의 서브 검색부(132)는 마스터 검색부(131)로부터 전송된 검색 명령에 따라서 검색을 수행할 수 있다. 각각의 서브 검색부(132)는 검색한 결과를 마스터 검색부(131)로 전송할 수 있다.
마스터 검색부(131)는 각각의 서브 검색부(132)에서 검색한 결과를 수신하고 종합하여 검색 결과를 도출할 수 있다.
다시 도 2로 되돌아가면, 데이터 분석부(140)는 검색 결과 또는 저장된 데이터를 이용하여 데이터를 분석할 수 있다.
데이터 분석부(140)는 암호화된 데이터를 복호화하지 않고 암호화된 상태로 데이터를 분석할 수 있다.
예를 들면, 데이터 분석부(140)는 특정 암호화 데이터와 상기 특정 암호화 데이터와 매칭되는 정보를 포함하고 있는 테이블인 매칭 정보용 테이블을 이용하여 암호화된 부분을 복호화하지 않고 분석에 이용할 수 있다.
계속 하여 설명하면, 데이터 분석부(140)는 암호화된 데이터와 매칭되는 정보를 매칭 정보용 테이블로부터 획득한다.
예를 들어, 암호화된 데이터의 데이터 타입이 숫자인 경우, 데이터 분석부(140)는 암호화된 데이터의 암호화된 값과 매칭되는 정보를 매칭 정보용 테이블로부터 획득할 수 있다.
또는, 암호화된 데이터의 데이터 타입이 포맷 데이터인 경우, 데이터 분석부(140)는 암호화된 데이터의 암호화된 패턴과 매칭되는 정보를 매칭 정보용 테이블로부터 획득할 수도 있다.
예를 들면, 비구조화 포맷(non-structured format)과 구조화 포맷(structured format)에 따라 별도 방식으로 처리할 수 있다. 구체적으로 예를 들면, 데이터 포맷에 따라 일반 텍스트(plaintext) 형태의 데이터는 검색이 가능한 암호화를 이용하고, 암호화 키를 이용하여 암호화된 데이터의 검색을 수행할 수 있다.
구조화된 포맷은 그 포맷 타입에 따라 적용하는 암호화가 상이하며, 암호화에 따라서 암호화된 데이터의 패턴이 발생될 수 있다. 그 패턴에 따라서 검색을 수행할 수 있다.
스트림 데이터의 경우, 스트림 데이터가 암호화된 데이터 관리 장치(100)로 전송될 때, 전체 스트림 데이터를 암호화하지 않고 필요한 특정 데이터(예를 들면, 키 프레임)만을 추출할 수 있는 형태로 암호화될 수 있다. 암호화 데이터 관리 장치(100)가 특정 프레임 부분이 암호화된 스트림 데이터를 수신하면, 암호화된 특정 프레임만을 원본 스트림 데이터와 분리하여 저장할 수 있다. 암호화 데이터 관리 장치(100)는 스트림 데이터의 검색시에는 암호화된 특정 프레임들만을 이용하여 검색을 수행할 수 있다.
데이터 타입에 따른 암호화와 검색 과정을 구체적인 예를 들어 설명한다.
예를 들어 설명하는 저장 및 검색 과정은 암호화 데이터 관리 장치(220)에서 수행될 수 있으며, 암호화 과정은 센서(310, 320, 330, 340 등) 또는 네트워크 중간 장치(210, 220 등)에서 수행될 수 있다.
일반 텍스트(Palintext)를 암호화하고 검색을 하기 위해서, 센서(310, 320, 330, 340 등) 또는 네트워크 중간 장치(210, 220 등)는 일반 텍스트 타입의 데이터를 검색가능 암호화(Searchable Encryption)을 이용하여 암호화한다. 암호화 데이터 관리 장치(220)는 암호화된 데이터를 저장한다.
암호화 데이터 관리 장치(220)는 Searchable Encryption을 이용하여 암호화되어 저장된 데이터는, 암호화 키워드(Encryted Keyword)를 이용하여 검색할 수 있다.
암호화된 데이터들을 합쳐서 나온 결과물을 전달하고자 할 때 준동형 암호화(Homomorphic encryption)를 이용할 수 있다. 예를 들어, Hello와 world를 합쳐서 Helloworld의 결과물을 전달하고자 할 때, 준동형 암호화를 이용하면, Hello는 Hryyr world는 jbeyq가 되어 Uryyrjbeyq로 암호화된다. 암호화된 것을 복호화하면 Helloworld가 도출된다.
숫자로된 Plaintext를 준동형 암호화나 디피-헬맨(Diffie-Hellman encryption) 암호화를 이용하면 암호화된 상태에서 더하기(+), 곱하기(X)와 같은 계산을 수행할 수 있다. 분산 지역의 데이터를 암호화된 상태에서 하기 위해서는, 클라우드 상에서 다자간 계산(multi-party computation) 방식을 이용하여 분산적으로 암호화된 상태에서 계산을 수행하여 결과를 획득할 수 있다.
구조화된 포맷(Structured Format)의 데이터를 그래프 구조 데이터(graph-structured data)형식으로 변경하여 특징기반의 인덱싱을 수행하고, 긴밀한 데이터 부분은 암호화하여 특정 특징에 대하여 패턴을 필터링을 하거나 검색을 하여 긴밀한 데이터 부분은 암호화된 키워드에 의해서만 검출되어 결과를 검색할 수 있다.
웹 그래프(Web graph)나 소셜 네트워크(social network)와 같은 구조화된 데이터는 대칭 검색가능 암호화(symmetric searchable encryption) 방식을 이용하여 암호화 하여 특정 암호화된 키워드에 대해서만 검색 결과를 찾을 수 있다. 또는 구조화된 데이터를 매트릭스 구조화된 데이터(matrix-structured data) 기반으로 변경하여 라벨링된 데이터에 대해서 쿼리를 기반으로 암호화된 데이터를 전달할 수 있다.
이 외에도 데이터를 포맷에 따라서, 아이덴티티(identity)나 속성(attribute) 등으로 구분을 할 수 있으면, 이것은 기능(Function) 기반 암호화(functional encryption)를 수행할 수 있다. 특정 데이터 필드 등을 포맷에 맞춰서 분리하여 암호화를 하려고 하는 특정 필드를 대상으로 암호화하는 property-preserving encryption이나 order-preserving encryption, orthogonality-preserving encryption 등도 이용하여 데이터에 타입에 따라 암호화를 수행할 수 있다.
데이터 분석부(140)는 획득된 정보를 분석에 이용할 수 있다.
데이터 분석부(140)가 매칭 정보용 테이블을 이용하여 암호화된 데이터를 복호화하지 않고 이용하는 일 예를 도 5를 참조하여 설명한다.
도 7은 매칭 정보용 테이블에 관한 일 예이다.
도 7의 매칭 정보용 테이블을 참조하면, 암호화 데이터가 'AK245'(71a)인 경우 데이터 분석부(140)는 '기압 정상'(72a)이라는 데이터를 획득하여 분석에 이용할 수 있다.
암호화된 데이터가 'BC37A'(71b), 'TY274'(71c) 또는 'GD4KY6'(71f)인 경우에도 데이터 분석부(140)는 '기압 정상'(52a)이라는 데이터를 획득할 수 있다.
암호화된 데이터가 'CKD28T'(71d) 또는 'JXX2YT'(71e)인 경우는 데이터 분석부(140)는 '습도 낮음'(52b)이라는 데이터를 획득할 수 있다.
계속하여 도 7을 참조하면, 암호화된 서로 다른 데이터가 동일한 정보에 매칭되는 경우가 존재하는 것을 볼 수 있다.
하나의 암호화된 데이터와 하나의 정보가 매칭되도록 설정되는 경우가 존재할 수 있으나, 기본적으로 매칭 정보용 테이블은 암호화된 서로 다른 데이터가 하나의 동일한 정보에 매칭되도록 설정될 수 있다.
암호화된 서로 다른 데이터가 하나의 동일한 정보에 매칭되도록 설정되고, 데이터 분석부(140)는 이러한 매칭 정보를 획득하여 분석을 수행하면 수집된 정보에 대한 보호를 강화할 수 있다.
즉, 본 발명의 일 실시예에 따른 암호화 데이터 관리 장치(100)는 암호화된 데이터를 복호화하지 않고 분석을 수행할 수 있다. 따라서, 암호화 데이터 관리 장치(100)(는 암호화된 데이터를 복호화하는데 필요한 복호화키를 가지고 있지 않는다. 즉, 원천적으로 암호화된 데이터를 복호화할 방법이 존재하지 않는다. 따라서, 데이터가 유출되더라도 원래 데이터가 나타내는 정확한 의미를 파악할 수 없다.
또한, 분석에 이용되는 매칭 정보용 테이블은 1대 1 관계의 매칭 정보가 아니라 서로 다른 암호화된 데이터가 하나의 동일한 정보에 매칭되므로 매칭 정보용 테이블이 유출되더라도 각각의 암호화된 데이터가 정확한 정보를 알 수 없다.
도 8은 본 발명의 다른 실시예에 따른 암호화 데이터 관리 장치의 하드웨어 구성의 일 예를 나타내는 도면이다.
본 실시예에 따른 암호화 데이터 관리 장치(100)는 도 8의 구성을 가질 수 있다.
도 8에 도시된 바와 같이, 암호화 데이터 관리 장치(100)는 암호화 데이터 관리 프로세서(81), 스토리지(82), 메모리(83) 및 네트워크 인터페이스(84)를 포함할 수 있다.
또한, 암호화 데이터 관리 장치(100)는 암호화 데이터 관리 프로세서(81) 및 메모리(83)와 연결되어 데이터 이동 통로가 되는 시스템 버스(85)를 포함할 수 있다.
네트워크 인터페이스(84)에는 다른 컴퓨팅 장치가 연결 될 수 있다. 예를 들면, 네트워크 인터페이스(84)에 연결되는 다른 컴퓨팅 장치는 디스플레이 장치, 사용자 단말 등이 될 수 있다.
네트워크 인터페이스(84)는 이더넷, FireWire, USB 등이 될 수 있다.
스토리지(82)는 플래쉬 메모리(Flash memory)와 같은 비휘발성 메모리 소자, 하드 디스크 등으로 구현될 수 있으나 이에 한정되지는 않는다.
스토리지(82)는 암호화 데이터 관리용 컴퓨터 프로그램(82a)의 데이터를 저장한다. 암호화 데이터 관리용 컴퓨터 프로그램(82a)의 데이터는 바이너리 실행 파일 및 기타 리소스 파일을 포함할 수 있다.
또한, 스토리지(82)는 매칭 정보 테이블(82b)을 저장하고 있을 수 있다.
메모리(83)는 암호화 데이터 관리용 컴퓨터 프로그램(82a)를 로딩한다. 암호화 데이터 관리용 컴퓨터 프로그램(82a)은 암호화 데이터 관리 프로세서(81)에 제공 되고, 암호화 데이터 관리 프로세서(81)에 의하여 실행 된다.
암호화 데이터 관리 프로세서(81)는 암호화 데이터 관리용 컴퓨터 프로그램(82a)을 실행할 수 있는 프로세서이다. 다만, 암호화 데이터 관리 프로세서(81)는 암호화 데이터 관리용 컴퓨터 프로그램(82a)만을 실행할 수 있는 프로세서는 아닐 수 있다. 예를 들면, 암호화 데이터 관리 프로세서(81)는 암호화 데이터 관리용 컴퓨터 프로그램(82a) 외에 다른 프로그램을 실행할 수도 있다.
암호화 데이터 관리용 컴퓨터 프로그램(82a)은, 적어도 둘 이상의 데이터 타입으로 구분되어 서로 다른 방식으로 암호화된 데이터를 수신하는 과정, 수신한 데이터를 저장하는 과정 및 상기 저장된 데이터를 검색하는 과정을 수행하는 일련의 오퍼레이션을 포함할 수 있다.
또한, 암호화 데이터 상기 데이터 타입 별로 구분된 저장 공간 별로 상기 수신한 데이터를 저장하는 과정을 수행하는 일련의 오퍼레이션을 포함할 수 있다.
또한, 암호화 데이터 관리용 컴퓨터 프로그램(82a)은, 상기 수신한 데이터를 복호화하지 않고 저장하는 과정 및 상기 저장된 데이터를 복호화하지 않고 검색을 수행할 수 있는 기 설정된 검색 방법을 이용하여 검색하는 과정을 수행하는 일련의 오퍼레이션을 포함할 수 있다.
이하, 도 9 내지 11을 참조하여 본 발명의 일 실시예에 따른 암호화 데이터 관리 방법을 설명한다. 본 실시예는 연산 수단을 구비한 컴퓨팅 장치에 의하여 수행 될 수 있다. 상기 컴퓨팅 장치는, 예를 들어 본 발명의 일 실시예에 따른 암호화 데이터 관리 장치(100) 또는 암호화 데이터 관리 시스템일 수 있다. 상기 암호화 관리 장치 또는 암호화 데이터 관리 시스템의 구성 및 동작에 대하여는 도 1 내지 도 8를 참조하여 설명한 내용을 통해 이해할 수 있다.
마찬가지로, 도 1 내지 도 8을 참조하여 설명한 내용은 암호화 데이터 관리 방법에 적용될 수 있다.
도 9는 본 발명의 일 실시예에 따른 암호화 데이터 관리 방법에 관한 순서도이다.
도 9를 참조하면, 컴퓨팅 장치가 데이터 타입 별로 암호화된 데이터를 수신한다(S910).
컴퓨팅 장치가 수신한 데이터를 데이터 타입 별로 구분하여 각각의 저장 공간에 저장한다(S920).
저장 공간은 데이터 타입 별로 구분되어 존재할 수 있다. 컴퓨팅 장치는 수신한 암호화된 데이터를 복호화하지 않고 암호화된 상태로 저장 공간에 저장한다.
컴퓨팅 장치가 암호화된 데이터를 복호화하지 않고 암호화된 상태로 검색을 수행한다(S930).
컴퓨팅 장치가 검색된 데이터를 복호화하지 않고 암호화된 상태로 이용하여 필요한 정보 도출을 위하여 분석을 수행할 수 있다(S940).
도 10은 본 발명의 다른 실시예에 따른 암호화 데이터 관리 방법에 관한 동작 흐름도이다.
발명의 이해를 돕기 위하여 제1 센서(310), 제1 네트워크 중간 장치(210) 및 암호화 데이터 관리 장치(100) 간 동작 흐름을 설명한다.
도 10을 참조하면, 제1 센서(310)가 정보를 수집한다(S1010).
제1 센서(310)가 수집한 정보에 관한 데이터를 기 설정된 방식에 따라서 데이터 타입으로 구분한다. 제1 센서(310)는 구분된 데이터 타입에 따라서 암호화 방식을 결정한다. 제1 센서(310)는 결정된 암호화 방식으로 구분된 데이터 타입에 해당하는 데이터를 암호화한다(S1020).
제1 센서(310)가 암호화된 데이터를 제1 네트워크 중간 장치(210)를 통하여 암호화 데이터 관리 장치(100)로 전송한다(S1030, S1040).
암호화 데이터 관리 장치(100)가 데이터 타입 별로 서로 다른 저장 공간에 전송 받은 암호화된 데이터를 저장한다(S1050).
암호화 데이터 관리 장치(100)가 검색어를 수신한다(S1060). 또는 암호화 데이터 관리 장치(100)가 수신하는 검색어는 암호화된 검색어 이거나 암호화 과정을 거칠 수 있다.
암호화 데이터 관리 장치(100)는 수신한 검색어의 데이터 타입을 구분할 수 있다(S1070). 또는, 암호화 데이터 관리 장치(100)는 검색하고자 하는 데이터 타입이 저장된 저장공간을 선택할 수 있다.
암호화 데이터 관리 장치(100)가 구분된 검색어의 데이터 타입에 해당하는 데이터들이 저장되는 저장 공간에서만 검색을 수행할 수 있다(S1080). 검색에 이용되는 검색어는 암호화된 검색어 일 수 있다. 또는, 암호화 데이터 관리 장치(100)는 선택된 저장 공간에서만 검색어를 이용하여 검색을 수행할 수도 있다. 암호화 데이터 관리 장치(100)는 데이터의 복호화 과정 없이 암호화된 데이터 파일을 대상으로 검색을 수행할 수 있다.
암호화 데이터 관리 장치(100)는 검색된 데이터를 복호화하지 않고 암호화된 상태로 분석에 이용할 수 있다(S1090). 또는 암호화된 검색 결과를 복호화하여 분석에 이용할 수도 있다. 암호화 데이터 관리 장치(100)는 검색된 데이터에 매칭되는 정보를 획득하여 분석에 이용할 수 있다.
도 11은 본 발명의 또 다른 실시예에 따른 암호화 데이터 관리 방법에 관한 동작 흐름도이다.
도 11을 참조하면, 제1 네트워크 관리 장치가 센서로부터 수신한 데이터를 암호화하는 것을 볼 수 있다.
구체적으로 살펴보면, 제1 센서(310)가 정보를 수집한다(S1105).
제1 센서(310)가 수집된 정보에 해당하는 제1 데이터를 제1 네트워크 중간 장치(210)로 전송한다(S1115).
제2 센서(320)가 정보를 수집한다(S1110).
제2 센서(320)가 수집된 정보에 해당하는 제2 데이터를 제1 네트워크 중간 장치(210)로 전송한다(S1120).
제1 네트워크 관리 장치는 제1 데이터의 데이터 타입에 해당하는 암호화 방식인 제1 암호화 방식으로 암호화한다(S1125).
또한, 제1 네트워크 관리 장치는 제2 데이터의 데이터 타입에 해당하는 암호화 방식인 제2 암호화 방식으로 암호화한다(S1130).
제1 네트워크 관리 장치는 암호화된 제1 데이터 및 암호화된 제2 데이터를 암호화 데이터 관리 장치(100)로 전송한다(S1135, S1140).
암호화 데이터 관리 장치(100)는 암호화된 제1 데이터를 제1 데이터의 데이터 타입에 해당하는 데이터가 저장되는 제1 저장 공간에 저장한다(S1145).
암호화 데이터 관리 장치(100)는 암호화된 제2 데이터를 제2 데이터의 데이터 타입에 해당하는 데이터가 저장되는 제2 저장 공간에 저장한다(S1150).
암호화 데이터 관리 장치(100)가 검색어를 수신한다(S1155). 또는 암호화 데이터 관리 장치(100)가 수신하는 검색어는 암호화된 검색어 이거나 암호화 과정을 거칠 수 있다.
암호화 데이터 관리 장치(100)는 수신한 검색어의 데이터 타입을 구분할 수 있다(S1160). 또는, 암호화 데이터 관리 장치(100)는 검색하고자 하는 데이터 타입이 저장된 저장공간을 선택할 수 있다.
암호화 데이터 관리 장치(100)가 구분된 검색어의 데이터 타입에 해당하는 데이터들이 저장되는 저장 공간에서만 검색을 수행할 수 있다(S1165). 검색에 이용되는 검색어는 암호화된 검색어 일 수 있다. 또는, 암호화 데이터 관리 장치(100)는 선택된 저장 공간에서만 검색어를 이용하여 검색을 수행할 수도 있다. 암호화 데이터 관리 장치(100)는 데이터의 복호화 과정 없이 암호화된 데이터 파일을 대상으로 검색을 수행할 수 있다.
암호화 데이터 관리 장치(100)는 검색된 데이터를 복호화하지 않고 암호화된 상태로 분석에 이용할 수 있다(S1170). 또는 암호화된 검색 결과를 복호화하여 분석에 이용할 수도 있다.
지금까지 도 9 내지 도 11을 참조하여 설명된 본 발명의 실시예에 따른 방법들은 컴퓨터가 읽을 수 있는 코드로 구현된 컴퓨터 프로그램의 실행에 의하여 수행될 수 있다. 상기 컴퓨터 프로그램은 인터넷 등의 네트워크를 통하여 제1 컴퓨팅 장치로부터 제2 컴퓨팅 장치에 전송되어 상기 제2 컴퓨팅 장치에 설치될 수 있고, 이로써 상기 제2 컴퓨팅 장치에서 사용될 수 있다. 상기 제1 컴퓨팅 장치 및 상기 제2 컴퓨팅 장치는, 서버 장치, 데스크탑 피씨와 같은 고정식 컴퓨팅 장치, 노트북, 스마트폰, 태블릿 피씨와 같은 모바일 컴퓨팅 장치 및 스마트 와치, 스마트 안경과 같은 웨어러블 컴퓨팅 장치를 모두 포함한다.
도면에서 동작들이 특정한 순서로 도시되어 있지만, 반드시 동작들이 도시된 특정한 순서로 또는 순차적 순서로 실행되어야만 하거나 또는 모든 도시된 동작들이 실행되어야만 원하는 결과를 얻을 수 있는 것으로 이해되어서는 안된다. 특정 상황에서는, 멀티태스킹 및 병렬 처리가 유리할 수도 있다. 더욱이, 위에 설명한 실시예들에서 다양한 구성들의 분리는 그러한 분리가 반드시 필요한 것으로 이해되어서는 안되고, 설명된 프로그램 컴포넌트들 및 시스템들은 일반적으로 단일 소프트웨어 제품으로 함께 통합되거나 다수의 소프트웨어 제품으로 패키지될 수 있음을 이해하여야 한다.
지금까지 도 2 각 구성요소는 소프트웨어(software) 또는, FPGA(field-programmable gate array)나 ASIC(application-specific integrated circuit)과 같은 하드웨어(hardware)를 의미할 수 있다. 그렇지만 상기 구성요소들은 소프트웨어 또는 하드웨어에 한정되는 의미는 아니며, 어드레싱(addressing)할 수 있는 저장 매체에 있도록 구성될 수도 있고 하나 또는 그 이상의 프로세서들을 실행시키도록 구성될 수도 있다. 상기 구성요소들 안에서 제공되는 기능은 더 세분화된 구성요소에 의하여 구현될 수 있으며, 복수의 구성요소들을 합하여 특정한 기능을 수행하는 하나의 구성요소로 구현할 수도 있다.
이상 첨부된 도면을 참조하여 본 발명의 실시예들을 설명하였지만, 본 발명이 속하는 기술분야에서 통상의 지식을 가진 자는 본 발명이 그 기술적 사상이나 필수적인 특징을 변경하지 않고서 다른 구체적인 형태로 실시될 수 있다는 것을 이해할 수 있을 것이다. 그러므로 이상에서 기술한 실시예들은 모든 면에서 예시적인 것이며 한정적이 아닌 것으로 이해해야만 한다.
Claims (20)
- 적어도 둘 이상의 데이터 타입으로 구분되어 상기 구분된 데이터 타입 별로 서로 다른 방식으로 암호화된 데이터를 수신하는 단계;상기 수신한 데이터를 저장하는 단계; 및상기 저장된 데이터를 검색하는 단계를 포함하는, 암호화 데이터 관리 방법.
- 제1 항에 있어서,상기 저장하는 단계는,상기 데이터 타입 별로 구분된 저장 공간 중에서 상기 수신한 데이터의 데이터 타입에 해당하는 데이터를 저장하는 저장 공간에 상기 수신한 데이터를 저장하는 단계를 포함하는, 암호화 데이터 관리 방법.
- 제2 항에 있어서,상기 검색하는 단계는,검색어를 수신하는 단계;상기 검색어에 해당하는 데이터 타입을 구분하는 단계; 및상기 구분된 데이터 타입이 저장된 저장 공간에서만 검색하는 단계를 포함하는, 암호화 데이터 관리 방법.
- 제2 항에 있어서,상기 저장하는 단계는,상기 수신한 데이터를 복호화를 수행하지 않고 암호화된 상태로 저장하는 단계를 포함하며,상기 저장된 데이터를 검색하는 단계는,기 설정된 검색 방법을 이용하여 상기 저장된 데이터를 암호화된 상태로 검색하는 단계를 포함하는, 암호화 데이터 관리 방법.
- 제4 항에 있어서,상기 기 설정된 검색 방법은 상기 저장 공간 별로 서로 다른 검색 방법이 설정되며,상기 기 설정된 검색 방법을 이용하여 검색하는 단계는,상기 저장 공간 별로 상기 서로 다른 검색 방법을 이용하여 검색하는 단계를 포함하는, 암호화 데이터 관리 방법.
- 제1 항에 있어서,상기 암호화 데이터 관리 방법은,상기 저장된 데이터를 이용하여 분석을 수행하는 단계를 더 포함하는, 암호화 데이터 관리 방법.
- 제6 항에 있어서,상기 분석을 수행하는 단계는,상기 저장된 데이터를 복호화하지 않고 암호화된 상태로 분석에 이용하는 단계를 포함하는, 암호화 데이터 관리 방법.
- 제7 항에 있어서,상기 암호화된 상태로 분석을 수행하는 단계는,상기 암호화된 데이터와 매칭되는 정보가 저장된 테이블을 이용하여 상기 분석에 이용하고자 하는 암호화된 데이터로부터 정보를 획득하는 단계; 및상기 획득된 정보를 이용하여 분석을 수행하는 단계를 포함하는, 암호화 데이터 관리 방법.
- 제8 항에 있어서,상기 암호화된 데이터의 데이터 타입이 포맷 데이터(Format Data)인 경우,상기 정보를 획득하는 단계는,상기 암호화된 데이터의 암호화된 패턴과 매칭되는 정보를 상기 테이블로부터 획득하는 단계를 포함하는, 암호화 데이터 관리 방법.
- 제8 항에 있어서,상기 암호화된 데이터와 매칭되는 정보가 저장된 테이블에 저장된 적어도 하나의 정보는 둘 이상의 서로 다른 암호화된 데이터와 매칭되는, 암호화 데이터 관리 방법.
- 복수 개의 센서들로부터 수신되는 데이터들을 기 설정된 방식에 따라서 적어도 둘 이상의 데이터 타입으로 구분하는 단계;상기 구분된 데이터 타입에 따라서 암호화 방식을 결정하는 단계;상기 결정된 암호화 방식으로 상기 구분된 데이터 타입에 해당하는 데이터를 암호화하는 단계; 및상기 암호화된 데이터를 전송하는 단계를 포함하는, 암호화 데이터 관리 방법.
- 제11 항에 있어서,상기 데이터 타입으로 구분하는 단계는,상기 기 설정된 방식에 따라서 하나의 데이터에서 둘 이상의 데이터 타입으로 구분하는 단계를 포함하는, 암호화 데이터 관리 방법.
- 제11 항에 있어서,상기 데이터 타입으로 구분하는 단계는,상기 기 설정된 방식에 따라서 제1 데이터를 제1 데이터 타입으로 구분하는 단계; 및 상기 제1 데이터와 상이한 제2 데이터를 제2 데이터 타입으로 구분하는 단계를 포함하며,상기 데이터를 암호화하는 단계는,상기 제1 데이터 타입으로 구분된 상기 제1 데이터를 제1 암호화 방식으로 암호화하는 단계; 및상기 제2 데이터 타입으로 구분된 상기 제2 데이터를 제2 암호화 방식으로 암호화하는 단계를 포함하는, 암호화 데이터 관리 방법.
- 적어도 둘 이상의 데이터 타입으로 구분되어 상기 구분된 데이터 타입 별로 서로 다른 방식으로 암호화된 데이터를 수신하는 데이터 수신부;상기 수신한 데이터를 저장하는 데이터 저장부; 및상기 저장된 데이터를 검색하는 데이터 검색부를 포함하는, 암호화 데이터 관리 장치.
- 제14 항에 있어서,상기 데이터 저장부는,상기 데이터 타입 별로 구분된 저장 공간 중에서 상기 수신한 데이터의 데이터 타입에 해당하는 데이터를 저장하는 저장 공간에 상기 수신한 데이터를 저장하는, 암호화 데이터 관리 장치.
- 제15 항에 있어서,상기 암호화 데이터 관리 장치는,검색어를 수신하는 검색어 수신부를 더 포함하며,상기 데이터 검색부는,상기 저장 공간 별로 전담하여 검색을 수행하는 둘 이상의 서브 검색부; 및상기 검색어에 해당하는 데이터 타입을 구분하는 마스터 검색부를 포함하며,상기 마스터 검색부는,상기 구분된 데이터 타입을 저장하는 저장 공간을 전담하여 검색을 수행하는 서브 검색부로 검색 명령을 전송하는, 암호화 데이터 관리 장치.
- 제15 항에 있어서,상기 데이터 검색부는,상기 저장 공간 별로 전담하여 검색을 수행하는 둘 이상의 서브 검색부; 및상기 서브 검색부에 검색 명령을 전송하고 상기 서브 검색부에 의하여 검색된 결과를 종합하는 마스터 검색부를 포함하며,상기 각각의 서브 검색부는 서로 상이한 검색 방법으로 검색을 수행하는, 암호화 데이터 관리 장치.
- 복수 개의 센서들로부터 수신되는 데이터들을 기 설정된 방식에 따라서 적어도 둘 이상의 데이터 타입으로 구분하고, 상기 구분된 데이터 타입에 따라서 암호화 방식을 결정하고, 상기 결정된 암호화 방식으로 상기 구분된 데이터 타입에 해당하는 데이터를 암호화한 후, 상기 암호화된 데이터를 전송하는, 네트워크 중간 장치.
- 수집되는 정보에 해당하는 데이터들을 기 설정된 방식에 따라서 적어도 둘 이상의 데이터 타입으로 구분하고, 상기 구분된 데이터 타입에 따라서 암호화 방식을 결정하며, 상기 결정된 암호화 방식으로 상기 구분된 데이터 타입에 해당하는 데이터를 암호화한 후, 상기 암호화된 데이터를 전송하는, 데이터 타입 별 암호화 센서.
- 하드웨어와 결합되어,제1 항 내지 제13 항 중 어느 한 항의 방법을 수행하기 위하여 매체에 저장된 컴퓨터프로그램.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US15/561,204 US20180069696A1 (en) | 2015-04-14 | 2015-06-08 | Encrypted data management method and device |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR10-2015-0052399 | 2015-04-14 | ||
| KR1020150052399A KR101726619B1 (ko) | 2015-04-14 | 2015-04-14 | 암호화 데이터 관리 방법 및 장치 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2016167407A1 true WO2016167407A1 (ko) | 2016-10-20 |
Family
ID=57126880
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2015/005691 Ceased WO2016167407A1 (ko) | 2015-04-14 | 2015-06-08 | 암호화 데이터 관리 방법 및 장치 |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US20180069696A1 (ko) |
| KR (1) | KR101726619B1 (ko) |
| WO (1) | WO2016167407A1 (ko) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110190946A (zh) * | 2019-07-12 | 2019-08-30 | 之江实验室 | 一种基于同态加密的隐私保护多机构数据分类方法 |
Families Citing this family (18)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US10817614B2 (en) * | 2014-08-27 | 2020-10-27 | Netiq Corporation | Automatic detection of relatedness in pools of encrypted data |
| US11256828B1 (en) | 2016-07-05 | 2022-02-22 | Wells Fargo Bank, N.A. | Method and apparatus for controlling IoT devices by agent device |
| EP3270321B1 (en) * | 2016-07-14 | 2020-02-19 | Kontron Modular Computers SAS | Technique for securely performing an operation in an iot environment |
| JP6721832B2 (ja) * | 2016-08-24 | 2020-07-15 | 富士通株式会社 | データ変換プログラム、データ変換装置及びデータ変換方法 |
| KR102317598B1 (ko) * | 2017-10-11 | 2021-10-26 | 삼성전자주식회사 | 서버, 서버의 제어 방법 및 단말 장치 |
| CN109492432A (zh) * | 2018-11-08 | 2019-03-19 | 安徽太阳石科技有限公司 | 基于区块链的实时数据安全防护方法和系统 |
| US11606829B2 (en) * | 2019-06-18 | 2023-03-14 | Kyndryl, Inc. | Facilitation of data transmission in low connectivity areas |
| CN110401542A (zh) * | 2019-08-05 | 2019-11-01 | 中国工商银行股份有限公司 | 电子身份凭证生成方法、终端及服务器 |
| CN111639355B (zh) * | 2020-06-02 | 2023-06-13 | 南方电网科学研究院有限责任公司 | 一种数据安全管理方法和系统 |
| KR102819047B1 (ko) * | 2020-10-28 | 2025-06-12 | 한국전자통신연구원 | 개인 정보에 대한 보안성을 제공하는 미터링 정보 제공 방법 및 미터링 정보 제공 장치 |
| KR102742034B1 (ko) | 2021-03-26 | 2024-12-16 | 주식회사 크립토랩 | 동형 암호를 이용하는 전자 장치 및 그 방법 |
| US12386785B2 (en) | 2021-10-15 | 2025-08-12 | Lognovations Holdings, Llc | Encoding / decoding system and method |
| KR102748606B1 (ko) | 2021-12-09 | 2025-01-02 | 한양대학교 에리카산학협력단 | 프로그램 분석 시스템, 프로그램 분석용 단말 장치, 프로그램 분석 장치 및 방법 |
| KR20240028792A (ko) | 2022-08-25 | 2024-03-05 | 주식회사 스칼라웍스 | 완전 동형암호를 이용한 사물인터넷 기반의 데이터 보안 시스템 및 이를 이용한 데이터 보안 방법 |
| KR102662784B1 (ko) * | 2023-08-25 | 2024-05-03 | (주)이지서티 | 인공지능을 이용한 자동 가명처리기법 추천 방법 |
| US12619567B2 (en) | 2023-12-12 | 2026-05-05 | Mercedes-Benz Group AG | Network on chip for high performance computing and a method of using the same |
| US12517851B2 (en) * | 2024-03-08 | 2026-01-06 | Mercedes-Benz Group AG | System on chip for freedom from interference |
| CN121093351A (zh) * | 2024-06-07 | 2025-12-09 | 华为技术有限公司 | 数据保护的方法、装置和电子设备 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2006112899A1 (en) * | 2005-04-13 | 2006-10-26 | Oracle International Corporation | Method and apparatus for encrypting and decrypting data in a database table |
| US20110060918A1 (en) * | 2009-09-04 | 2011-03-10 | Gradiant | Cryptographic system for performing secure iterative computations and signal processing directly on encrypted data in untrusted environments |
| US20110113050A1 (en) * | 2009-11-10 | 2011-05-12 | Paul Youn | Data masking with an encrypted seed |
| US20140019776A1 (en) * | 2012-07-01 | 2014-01-16 | Jerzy Lewak | Methods of providing fast search, analysis, and data retrieval of encrypted data without decryption |
| US8997248B1 (en) * | 2014-04-04 | 2015-03-31 | United Services Automobile Association (Usaa) | Securing data |
-
2015
- 2015-04-14 KR KR1020150052399A patent/KR101726619B1/ko not_active Expired - Fee Related
- 2015-06-08 WO PCT/KR2015/005691 patent/WO2016167407A1/ko not_active Ceased
- 2015-06-08 US US15/561,204 patent/US20180069696A1/en not_active Abandoned
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2006112899A1 (en) * | 2005-04-13 | 2006-10-26 | Oracle International Corporation | Method and apparatus for encrypting and decrypting data in a database table |
| US20110060918A1 (en) * | 2009-09-04 | 2011-03-10 | Gradiant | Cryptographic system for performing secure iterative computations and signal processing directly on encrypted data in untrusted environments |
| US20110113050A1 (en) * | 2009-11-10 | 2011-05-12 | Paul Youn | Data masking with an encrypted seed |
| US20140019776A1 (en) * | 2012-07-01 | 2014-01-16 | Jerzy Lewak | Methods of providing fast search, analysis, and data retrieval of encrypted data without decryption |
| US8997248B1 (en) * | 2014-04-04 | 2015-03-31 | United Services Automobile Association (Usaa) | Securing data |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110190946A (zh) * | 2019-07-12 | 2019-08-30 | 之江实验室 | 一种基于同态加密的隐私保护多机构数据分类方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| US20180069696A1 (en) | 2018-03-08 |
| KR101726619B1 (ko) | 2017-04-26 |
| KR20160122471A (ko) | 2016-10-24 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2021080102A1 (en) | Method for training and testing adaption network corresponding to obfuscation network capable of processing data to be concealed for privacy, and training device and testing device using the same | |
| KR101726619B1 (ko) | 암호화 데이터 관리 방법 및 장치 | |
| WO2017047884A1 (en) | Voice recognition server and control method thereof | |
| WO2016108468A1 (en) | User terminal, service providing apparatus, driving method of user terminal, driving method of service providing apparatus, and encryption indexing-based search system | |
| WO2014030889A1 (en) | Method and apparatus for sharing content | |
| WO2018166099A1 (zh) | 信息泄露检测方法及装置、服务器及计算机可读存储介质 | |
| WO2021261719A1 (en) | Method for training obfuscation network which conceals original data to be used for machine learning and training surrogate network which uses obfuscated data generated by obfuscation network and learning device using the same and method for testing trained obfuscation network and testing device using the same | |
| WO2020082766A1 (zh) | 输入法的联想方法、装置、设备及可读存储介质 | |
| WO2021132798A1 (en) | Method and apparatus for data anonymization | |
| WO2017213281A1 (ko) | 빅데이터의 비식별화 처리 방법 | |
| WO2021107488A1 (en) | Server and method for controlling server | |
| EP3164847A1 (en) | Electronic device and method for providing content on electronic device | |
| WO2019168315A1 (en) | Trustzone graphic rendering method and display device using the same | |
| EP3821378A1 (en) | Apparatus for deep representation learning and method thereof | |
| EP3241102A1 (en) | Electronic system with access management mechanism and method of operation thereof | |
| WO2018076890A1 (zh) | 数据备份的方法、装置、存储介质、服务器及系统 | |
| WO2020141643A1 (ko) | 음성 합성 서버 및 단말기 | |
| WO2013032198A1 (ko) | 높은 연관성을 가지는 아이템을 추천하는 아이템 기반의 추천 엔진 | |
| WO2020166855A1 (en) | Electronic device and control method thereof | |
| WO2019177265A1 (ko) | 랜섬웨어 대응을 위한 데이터 처리 방법, 이를 실행시키는 프로그램 및 상기 프로그램을 기록한 컴퓨터 판독 가능한 기록매체 | |
| WO2011068315A2 (ko) | 최대 개념강도 인지기법을 이용한 최적의 데이터베이스 선택장치 및 그 방법 | |
| WO2025244498A1 (ko) | 언어 모델을 이용한 지식 베이스 구축 방법, 지식 베이스를 이용한 응답 제공 방법 및 이를 수행하는 컴퓨팅 장치 | |
| WO2018191889A1 (zh) | 照片处理方法、装置及计算机设备 | |
| WO2024210253A1 (en) | Method for threshold secret sharing and reconstruction for multi-compartment | |
| WO2015174779A1 (en) | Method of distributing data and device supporting the same |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 15889287 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 15561204 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 15889287 Country of ref document: EP Kind code of ref document: A1 |