System and method for authorizing a user data processor to access a container of user data

By creating a password container in the user equipment and using a key mechanism, the security issues of user data during the collection and dissemination process are solved, and effective data protection and privacy protection are achieved.

CN114253660BActive Publication Date: 2025-08-22AO KASPERSKY LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111032613.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-06-01
Filing Date
2021-09-03
Publication Date
2025-08-22
Estimated Expiration
2041-09-03

AI Technical Summary

Technical Problem

The existing technology lacks an effective protection mechanism in the process of data collection and dissemination of user equipment, resulting in data leakage and abuse, and user privacy cannot be protected.

Method used

By creating a password container, encrypting the user data using the first key, and authorizing the user data processor to access the data based on the access structure and the second key, ensuring data security and privacy protection.

Benefits of technology

It realizes more efficient and effective protection of user data, ensures the security and privacy of data during transmission and access, and prevents unauthorized data use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114253660B_ABST
    Figure CN114253660B_ABST
Patent Text Reader

Abstract

Disclosed herein are systems and methods for authorizing a user data processor to access a cryptographic container of user data. In one aspect, an exemplary method includes: creating a cryptographic container for user data, wherein the cryptographic container receives at least one element of the user data and encrypts the at least one element; establishing permissions for the user data processor to access the element using a first key; forming at least one access structure; and upon receiving a request to access the cryptographic container, authorizing the user data processor to access the cryptographic container based on the at least one access structure formed; the forming includes: placing the first key in the access structure based on the established permissions, receiving from the user data processor a second key linked to the user data processor to be used to access the first key, and encrypting the first key using the second key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of data security, and in particular, to systems and methods for protecting confidentiality of user data and ensuring privacy while authorizing access to a container of user data. Background Art

[0002] The amount of data collected from user devices increases every year. There is also a growth in the variety and number of devices from which data is collected. Currently, devices include the "Internet of Things" (IoT) as well as personal computers, laptops and smartphones. Data is often collected from devices without the user's explicit consent; but even when such consent is given, the user does not always understand all the consequences of his / her decision. The data collected from the devices is then distributed around the network in an uncontrolled manner and can cause harm to the user. For example, the user may become a victim of a criminal who has obtained his / her phone number or credit card. Moreover, it is not just malicious parties that cause problems; unscrupulous employers may use data from user devices to track their employees. Another consequence of uncontrolled data collection is that the user of the device may receive annoying product advertisements targeted to the user based on the product category.

[0003] There are some mechanisms that device manufacturers use to try to protect users from hidden data collection and regulate data operations. One example is Google's Firebase system, which synchronizes data between different applications on Android devices and authorizes third parties to access this data. At Apple, there is a similar platform called the Apple Security Framework, which is used to protect information, establish trusted connections, and control access to software on the device. This platform is used to establish the user's identity, ensure the security of data in storage and in transmission over the network, and confirm the validity of the code. These mechanisms allow data from the device to be shared with third parties. However, these mechanisms are not transparent to the user, are irreversible, and only provide weak protection against tracking by third-party applications.

[0004] Therefore, there is a need for a method and system for collecting data from user devices while providing an effective way to protect the collected data from inappropriate dissemination and misuse. Summary of the Invention

[0005] Aspects of the present disclosure relate to data security, and more particularly, to systems and methods for authorizing a user data processor to access a container of user data collected from a user device. For example, user data may first be stored in a cryptographic container for access by a processor (e.g., a processor of a storage device).

[0006] In an exemplary aspect, a method for authorizing a user data processor to access a cryptographic container of user data is provided, the method comprising: creating a cryptographic container for the user data, wherein the cryptographic container receives at least one element of the user data and encrypts the at least one element; establishing permissions for the user data processor to access at least one element of the user data using a first key; forming at least one access structure for the user data processor; and when a request to access the cryptographic container is received, authorizing the user data processor to access the cryptographic container based on the at least one access structure formed; wherein the formation of the at least one access structure comprises: placing the first key in the at least one access structure based on the established permissions, receiving a second key from the user data processor that is linked to the user data processor and is to be used to access the first key, and encrypting the first key with the second key.

[0007] In one aspect, the cryptographic container encrypts at least one element using a first key.

[0008] In one aspect, the second key is a combination of at least one pair of keys, the at least one pair of keys including at least one private key and at least one public key.

[0009] In one aspect, at least one public key is received for encrypting the first key.

[0010] In one aspect, information about the second key is communicated to a user data processor.

[0011] In one aspect, at least one public key is received from a user data processor that is authorized to access.

[0012] In one aspect, each of the at least one element of the user data is encrypted using a respective separate first key.

[0013] In one aspect, permissions for accessing at least one element are established based on a set of actions that a user data processor is permitted to perform on the at least one element of user data.

[0014] In one aspect, the set of actions includes at least one of: reading data and writing data.

[0015] In one aspect, a separate first key is created for each action in the action set.

[0016] In one aspect, the created first key comprises a combination of at least one pair of keys, the at least one pair of keys comprising at least one first private key and at least one first public key.

[0017] In one aspect, a pair of keys is formed of a first private key and a first public key, such that the first private key is used to encrypt data when a write occurs, and the first public key is used to decrypt data when a read occurs.

[0018] In one aspect, when establishing permission to read data from a field, a first public key is placed in at least one access structure.

[0019] In one aspect, when establishing permission to write data to a field, a first private key is placed in at least one access structure.

[0020] In one aspect, the method further comprises, during creation of a cryptographic container for user data, adding an access structure for a data access permission manager, wherein at least one first key for the added access structure for the data access permission manager is placed in the access structure of the user data processor, wherein the at least one first key is encrypted.

[0021] In one aspect, placing at least one first key for the added access structure of the data access permission manager in the access structure of the user data processor includes extracting the first key from the access structure of the data access permission manager.

[0022] In one aspect, the method further comprises requesting, on behalf of the user data processor, permission to access elements of the user data in the created cryptographic container.

[0023] According to one aspect of the present disclosure, a system for authorizing a user data processor to access a cryptographic container of user data is provided, the system including a hardware processor configured to: create a cryptographic container for user data, wherein the cryptographic container receives at least one element of the user data and encrypts the at least one element; establish permissions for the user data processor to access at least one element of the user data using a first key; form at least one access structure for the user data processor; and when a request to access the cryptographic container is received, authorize the user data processor to access the cryptographic container based on the at least one access structure formed; wherein the formation of the at least one access structure includes: placing the first key in the at least one access structure based on the established permissions, receiving a second key from the user data processor that is linked to the user data processor and is to be used to access the first key, and encrypting the first key with the second key.

[0024] In one exemplary aspect, a non-transitory computer-readable medium storing a set of instructions is provided that authorizes a user data processor to access a cryptographic container of user data, wherein the instruction set includes instructions for: creating a cryptographic container for user data, wherein the cryptographic container receives at least one element of the user data and encrypts the at least one element; establishing permissions for the user data processor to access at least one element of the user data using a first key; forming at least one access structure for the user data processor; and when a request to access the cryptographic container is received, authorizing the user data processor to access the cryptographic container based on the at least one access structure formed; wherein the formation of the at least one access structure includes: placing the first key in the at least one access structure based on the established permissions, receiving a second key from the user data processor that is linked to the user data processor to be used to access the first key, and encrypting the first key with the second key.

[0025] The method and system of the present disclosure are designed to provide data security in a more optimal and efficient manner to protect data while also authorizing access to containers of user data. A first technical achievement is an improvement in the level of protection of user data, thereby providing security for users. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate one or more example aspects of the present disclosure and, together with the detailed description, serve to explain the principles and implementations of one or more example aspects of the present disclosure.

[0027] Figure 1 A system for exchanging data from user equipment is shown.

[0028] Figure 2 A method of authorizing a user data processor to access user data is shown.

[0029] Figure 2a Aspects of a method for providing user data to a user data processor during transfer of a data structure from a user device to a remote storage device are shown.

[0030] Figure 2b Aspects of a method for providing user data to a user data processor in transfer of a data structure from a storage device to the user data processor are shown.

[0031] Figure 3 A method for updating user data in a storage device is shown.

[0032] Figure 3a Aspects of a method for updating user data when transferring a data structure to a remote storage device are shown.

[0033] Figure 3b Aspects of a method for updating user data while transferring an updated data structure to a storage device are shown.

[0034] Figure 4 An example of configuration of data permissions is shown.

[0035] Figure 5 An exemplary system for exchanging user data is shown, which is designed to authorize access to the user data via a cryptographic container.

[0036] Figure 6a-6c An example of a container is shown.

[0037] Figure 7 An example of a method for forming a new container is shown.

[0038] Figure 8 An example of a method for authorizing a user data processor to access a previously formed container is shown.

[0039] Figure 9 An example of a system for exchanging user data is shown, which system is designed for authorizing access to a patient's medical history via a container.

[0040] Figure 10 A method for authorizing a user data processor to access a cryptographic container of user data is shown.

[0041] Figure 11 An example of a general-purpose computer system is presented upon which aspects of the present disclosure may be implemented. DETAILED DESCRIPTION

[0042] Various exemplary aspects are described herein in the context of systems, methods, and computer programs for authorizing a user data processor to access a cryptographic container of user data according to various aspects of the present disclosure. Those of ordinary skill in the art will recognize that the following description is merely illustrative and is not intended to be limiting in any way. Other aspects will readily occur to those of skill in the art having benefit of this disclosure. Reference will now be made in detail to the embodiments of the various exemplary aspects as shown in the accompanying drawings. Throughout the drawings and the following description, the same reference numerals will be used to refer to the same or similar items as much as possible.

[0043] Figure 1A system 100 for exchanging data from user devices is shown. The system 100 is designed for transparent and secure handling of data from a user of a device 101. In the context of this disclosure, "data from a user of a device" refers to data from the device in the user's environment, created on the device by various types of software, and includes both user-entered data and data created in the operation of programs and applications, for example, streams of clicks (clickstreams), communications in messaging services, location data, and data collected from smart home IoT devices or other IoT devices in the user's ecosystem (such as a personal car).

[0044] In one aspect, the system 100 includes:

[0045] User device 101 having a process blocker 110 , a data collector 120 , a data access permission manager 130 (access permission manager 130 ), and a modifier 140 ;

[0046] User data processor 102;

[0047] Storage device 150, which has an aggregator and analyzer 170 and a retrieval log 180 (a log of data retrieval); and

[0048] Anonymizer 160 , which has a search record 180 .

[0049] The process blocker 110 is designed to prevent the processing of data (including personal data) by the user data processor 102 on the user's device. Blocking can be performed on any user data processor 102, including third-party devices and those belonging to the platform through which the device on which the process blocker is installed or the device to which the process blocker is accessible (for example, Apple, Google, Huawei or Xiaomi software and services) is controlled. For example, the process blocker 110 can be installed on a router through which the user's personal device 101a and IoT device communicate with the internet, and the process blocker 110 analyzes the network traffic flowing through the router. In one aspect, the process blocker 110 only blocks the collection of critical data and does not block the collection of any data. Critical data includes data that is subject to restrictions on collection, storage, access, distribution and / or processing by law or authorized parties. Critical data is often sensitive to disclosure, distribution or leakage because the occurrence of such events can lead to violations of the rights and legally protected interests of the parties. In addition, the distribution or leakage of such data creates liability for the parties who have allowed the violation of the rules for the collection, storage, access and processing of such data.

[0050] In one aspect, critical data is data that is confidential data ("sensitive data"). It should be noted that in the context of this disclosure, confidential data and confidential information are synonymous. Confidential data is considered to include data stored under the laws of a country whose jurisdiction covers users of devices that constitute clients in the described system.

[0051] In one aspect, confidential data includes personal data (PD) and data including:

[0052] Trade secrets;

[0053] Tax secrets;

[0054] Banking secrecy;

[0055] ·Medical secrets;

[0056] Notarial secrets;

[0057] Legal secrets;

[0058] Audit confidentiality;

[0059] ·Confidential communication;

[0060] ·Secrecy of security;

[0061] · Secrecy of wills;

[0062] Adoption secrecy;

[0063] Confess secrets;

[0064] Investigate secrets;

[0065] Judicial secrecy;

[0066] information about the protected person; and

[0067] Government secrets.

[0068] In another aspect, the processing of user data for marketing purposes is blocked. In another aspect, the processing of any user data by the user data processor 102 is blocked, where the data is not related to the direct function of the application or program using these user data processors. In another aspect, blocking includes any processing performed by the user data processor 102 that is not included in the list of allowed (trusted) devices or data processors. Blocking of data processing can be performed by various methods (including direct methods and indirect methods). Direct blocking includes blocking where the action associated with the data processing itself is blocked. Indirect refers to a scenario where data processing is not directly hindered and, even if processing is performed, the processing cannot achieve its purpose. Direct blocking methods can include prohibiting user data processors from accessing user data. Indirect processing methods include, in particular, breaking the association link between data to be sent from the user device, for example by removing cookie files or spoofing user identifiers established by the network on the tracking device.

[0069] The data access rights manager 130 is designed to manage access to data. The data access rights manager 130 defines the rights of user data processors 102 to access data, revokes rights from user data processors, and maintains a list of permitted (trusted) user data processors 102. The data access rights manager 130 stores or establishes a structural format (data model) for user data designated for distribution on the storage device 150. The data access rights manager 130 can be configured via externally updateable policies, user policies, or direct user input. The data access rights manager 130 also updates the user data model designated for transmission to the storage device 150 (an operational scenario will be described below). Those skilled in the relevant art can find examples of user data models in prior literature on data organization, such as GOST 20886-85: Data Organization, Terminology, and Definitions in Data Processing Systems.

[0070] The data collector 120 is designed to collect user data from the user device that is designated for transmission to the storage device 150. The data collector 120 populates the fields of the data structure received from the data access rights manager 130. The data collector 120 then transmits the populated data structure to the modifier 140. In one aspect, the data collector 120 sends the populated data structure directly to the storage device 150. Typically, the blocking by the process blocker 110 and the data collection by the data collector 120 occur independently of the data needs of the user data processor 102. For example, according to the configuration, the process blocker 110 blocks web tracking, and the data collector 120 collects all data that was previously blocked by the process blocker 110 from being processed on the device 101 (before the user data processor 102 attempts to process it); the collected data is then stored in the storage device 150.

[0071] Device 101 includes a modifier 140 designed to: analyze data in fields of a structure received from data collector 120 to determine the composition of the data; partition the data structure into substructures; and, for the resulting substructures, select a route for sending the data to remote storage device 150. Modifier 140 determines the need to partition the structure into substructures based on the fields of the structure. There may be various criteria for partitioning a data structure into substructures. One of these criteria is the presence of personal data ("personally identifiable information" (PII)) or special categories of personal data (e.g., according to GDPR terminology). In this case, the data structure is partitioned so that one substructure contains personal data (hereinafter referred to as PD or PII) or special categories of personal data, while another substructure contains non-personal data. The relationship of the data to personal data is determined, for example, by the laws of the country / region (in other words, the location of the data source) whose jurisdiction covers the user of the device constituting a client in the described system. Another more general criterion is the presence of critical data. In one aspect, modifier 140 is designed to transform the data structure on the device before sending the data to storage device 150.

[0072] In one aspect, the method for converting a data substructure is:

[0073] Quantification

[0074] Sorting

[0075] Merge (paste);

[0076] Grouping;

[0077] Configure the dataset;

[0078] · Table replacement of values;

[0079] Calculated value;

[0080] Data encoding;

[0081] ·encryption;

[0082] Convolution; and

[0083] Normalization (scaling).

[0084] Some kind of transformation can be applied not only to individual data (fields) within a substructure, but also to the substructure as a whole, for example, by tokenization and / or encryption. In one aspect, the transformation is performed without the possibility of a reverse transformation, by any means other than modifier 140 and / or storage device 150. A "transformation" is considered to be a projection (function) of a quantity onto itself or a projection that converts a given quantity into another quantity.

[0085] A specific case of a user data processor may be a client 102b (e.g., an application) that collects user data on the device 101 in the context of a client-server interaction, upon request from a server 102a connected to the application. "Data processing" means any action (operation) or combination of actions (operations) performed by a data automation device (user data processor), including the collection, recording, arrangement, accumulation, storage, adjustment (update, change), extraction, use, transmission (distribution, provision, access), depersonalization, blocking, removal, and deletion of data.

[0086] In one aspect, modifier 140 selects a network route along which the structure or substructure is to be sent to storage device 150. This route may include an anonymizer 160. Anonymizer 160 is designed to transform the structures and substructures passing through it by both direct and reverse transformations (examples are considered below). Anonymizer 160 is not located in the same local area network or intranet (e.g., a single organization's network) to which device 101 belongs. In one aspect, anonymizer 160 is not located in the local area network or intranet to which storage device 150 belongs. Retrieval record 180 is connected to anonymizer 160 and storage device 150.

[0087] The retrieval log 180 is intended to track operations on user data and record all actions of retrieving (or transmitting) user data from the storage device 150. Based on the logs stored by the retrieval log 180, it is always possible to check whether the use of user data by a third party complies with the access rights (i.e., whether it is legal use). For example, as recorded by the retrieval log 180, it is assumed that the history of the user's search queries is transmitted to the network N without the permission to transmit to the third party. Subsequently, it is assumed that the user receives an advertising quotation from the network M based on his search query. This determination can be based on additional means ( Figure 1The system 100 of the present disclosure records an event. The event can then be processed based on supplementary features of the system 100. For example, supplementary features of the system 100 can generate complaints against network N, request data removal from network M, send information to regulatory agencies, and so on.

[0088] The storage device 150 is designed for storing user data, i.e., the storage device 150 is the location of the user data. The storage device 150 can transfer the user data to the user data processor 102 while allowing the data to be processed directly in the storage device 150 without transfer. The storage device 150 is connected to an analyzer 170, which is designed for automatic data aggregation and analysis and for building various analysis results and aggregates based on the analysis. Various analysis results and aggregates are also placed in the storage device 150 and can be transferred to the external user data processor 102 if the external user data processor 102 has permission to do so. The analyzer 170 also links data from various devices 101 of a single user / family. The storage device 150 is also connected to the data access rights manager (e.g., via the agent 130a) because the storage device 130 determines the rights of the user data processor 102 to data access to the user data. As Figure 1 As shown, storage device 150 may be located within device 101, within a local network of device 101, or remotely.

[0089] In one aspect, the storage device receives user data, including data from the user data processor 102. For example, the storage device receives data from social networks, online and offline retail stores, advertising networks, data exchanges, and other user data processors 102.

[0090] In the present disclosure, the process blocker 110, the data collector 120, the data access permission manager 130, the modifier 140, the storage device 150, the anonymizer 160, the analyzer 170, and the retrieval record 180 represent real devices, systems, components, and groups of components constructed using hardware, such as an integrated microcircuit ("Application Specific Integrated Circuit" or ASIC) or a programmable gate array ("Field Programmable Gate Array" or FPGA), or a combination of software and hardware, such as a microprocessor system and a program instruction set and also a neuromorphic chip ("neuromorphic chip" in English). The functions of the device can be implemented only by hardware, or in a combination of some functions by software and some by hardware. In some aspects, the various devices for authorizing a user data processor to access a cryptographic container of user data can be implemented on a processor of a general-purpose computer (e.g., such as Figure 11 The database may be implemented by any feasible method and may be contained on a single physical medium or on a variety of media located locally or remotely.

[0091] Figure 2 A method 200 of granting access to user data to a user data processor is shown. The system 100 described above can be used to perform the method 200.

[0092] In step 210, the process blocker 110 blocks the user data processor at the user device from processing the user data. For various user data processors, various methods of processing user data are blocked.

[0093] In one aspect, the following methods of processing user data are blocked:

[0094] Mobile and web tracking, such as through:

[0095] ■ Track and remove trackers from your device,

[0096] ■Use a VPN service to remove trackers and ads from your web traffic;

[0097] Collecting geolocation information, for example, through:

[0098] ■Use virtual operators,

[0099] ■Spoofing (deceiving) geographic location,

[0100] ■ Turn off GPS, Wi-Fi, and Bluetooth modules when the user is not using them;

[0101] Collect search queries, for example, through:

[0102] ■Use a personal search system (e.g., DuckDuckGo),

[0103] ■Proxy outgoing search queries,

[0104] ■ spoofing the search system's identifiers in outgoing traffic,

[0105] ■Removing search system identifiers from outgoing traffic; and

[0106] Collecting registration data, such as using:

[0107] ■Anonymous phone number and email address,

[0108] ■Anonymous one-time maps.

[0109] In step 220, user data is collected by the data collector 120 and transferred to the storage device 150. In one aspect, the collected user data includes data that is blocked for processing by the external user data processor 102 according to the current policy. The policy is applied by the data access rights manager 130 and implemented via the data model / structure described above. In one aspect, the transfer of the collected data to the storage device 150 is performed by the modifier 140 and / or the anonymizer 160.

[0110] In one aspect, user data processor 102 may only receive access to data from storage device 150 that is not on a list of permitted user data processors or that is not necessary to provide its basic functionality.

[0111] In step 230, system 100 receives a request to process user data on device 101. Depending on the implementation, the request may be received by various means of system 100. For example, if there is an attempt to process user data on the device, this will be detected by process blocker 110 (implicit request). For explicit requests, data access permission manager 130 will receive permission to process the request.

[0112] In one aspect, if the process blocker 110 receives a processing request, the request is redirected to the data access permissions manager 130. If the user data processor from which the request was received is known to the system 100 (e.g., if permissions have been assigned to the device), the method proceeds to step 240.

[0113] In step 240 , the request is redirected to the user data storage device 150 .

[0114] In one aspect, when the system is unaware of the user data processor 102, the access rights of the user data processor 102 are determined. The method then proceeds to step 240 to enable the user data processor 102 to process the user data without redirecting the request to the storage device 150. In other words, the user data processor 102 is allowed to process the user data without redirecting it to the storage device 150 when the user data processor 102 is on the list of trusted devices, or when access to such data is made in the context of basic functions accepted by the user, or in other situations mentioned above.

[0115] In step 250, the storage device 150 determines the access rights of the user data processor 102 to the user data. To this end, the storage device may use a copy of the access rights library of the user data processor 102 established by the data access rights manager 130 or may directly contact the data access rights manager 130, for example, through the agent 130a. After determining the rights, in step 260, the user data processor is granted access to the user data according to the determined rights.

[0116] In one aspect, access is granted by an anonymizer 160, which performs the reverse conversion of the user data located in the storage device 150. Information about this is recorded by a retrieval log 180. In one aspect, the log is based on blockchain technology. In one aspect, the technology for providing data from users to the user data processor 102 for processing can be implemented as a smart contract, where, in certain cases, the revenue offer from the owner of the user data processor 102 is the non-cash use of application / program functions (in exchange for the user data of the functions). In this example, after receiving access to the processing of user data, the user who has authorized access to their data can use the functions of a certain application or service, or he / she will be able to access any other products or services that are optionally encrypted (for example, insurance discounts in the case of remote metering from the car).

[0117] Figure 2aAspects of a method for providing user data to a user data processor are shown. This aspect can be used, for example, during the transfer of data from a user device to a remote storage device. A process blocker 110 blocks the processing of data from an advertising network M. This blocking occurs by removing cookie files containing advertising identifiers from web data 103, including data created by browser 102b, in step 211, and by spoofing the user identifier of the advertising network M in network traffic in step 212. This impedes the operation of user data processor 102, which in the present case (via a profiling device, not shown) is used for user profiling. Consequently, the advertising network is unable to make targeting decisions because it lacks a user profile, resulting in a significant reduction in conversions (clicks on advertising announcements) and, since the advertising network's operating model is CPC (cost per click), a corresponding decrease in ARPU (average revenue per user). Similar blocking is used by users who wish to avoid advertisements for certain categories of goods (e.g., pharmaceuticals, medical clinics, and other items in the "health" category) appearing in their browsers. However, the user is prepared to receive targeted advertisements for goods and services in other categories from the advertising network M. Thus, following the specified settings, in step 221, the data access rights manager 130 defines the permissions for network M as search query history and clickstream, excluding search queries and clicks related to category X. In step 222, the relevant information is sent to the system 100. Specifically, the data collector 120 receives a data structure with populated fields, the modifier 140 receives the categories of data whose transmission is prohibited, and the storage device receives the access rights for the advertising network M.

[0118] In certain circumstances, various scenarios are possible, such as:

[0119] Data collector 120 collects all search queries and clicks from user device 101, all data is sent to storage device 150, and storage device 150 independently generates (or in certain cases completes) a structure for processing by user data processor 102 of advertising network M based on data access rights, which have excluded clicks and search queries from category X;

[0120] The data collector 120 collects all search queries and clicks from the user devices 102, all data is sent to the modifier 140, and the modifier 140 removes the substructure related to category X and moves the modified structure to the storage device 150, and in this form the modified structure will be transmitted to the user data processor 102 of the advertising network M;

[0121] The data collector 120 collects search queries and clicks not related to category X and moves the structure to the storage device 150, and in this form the structure will be transmitted to the user data processor 102 of the advertising network M; and

[0122] The data collector 120 collects clicks not related to category X and search queries from all categories, and the structure is transmitted to the modifier 140, which removes search queries related to category X from the received structure and transmits the modified structure to the storage device 150, and in this form the modified structure will be transmitted to the user data processor 102 of the advertising network M (which will be considered later). Figure 2a The examples in refer to this scenario).

[0123] As a general rule, such scenarios apply not only to clicks and search queries, but also to other types of user data, it is possible that the user data processor 102 is not only involved in advertising networks, and that a user may have more than one device. In one aspect, when the storage device 150 is located in a remote unit, such as Figure 2a As shown, the modified structure from the modifier is not sent directly to the storage device 150 .

[0124] Let's further consider an example based on the final scenario. In step 221, data access rights manager 130 has defined the rights for user data processor 102 of network M. In step 222, data access rights manager 130 transmits a structure format to data collector 120 for populating fields. The structure includes at least a "search query" field and a "clickstream" field. The clickstream field, in turn, includes a category field for web resources, which does not include a field for category X.

[0125] In step 222a, the data collector 120 populates the fields. In one aspect, the data populated is selected from the retained web data 103 accumulated during the user's network activity. This data is collected by the browser 102a and by add-ons to the system 100 (such as plugins in the browser or UI interceptors (these are not in the browser). Figure 2a , and in certain cases, a module of the data collector 120 )) are formulated.

[0126] In step 223 , the data collector 120 transmits the populated structure to the modifier 140 , which in turn analyzes the fields of the search query for the presence of queries related to category X based on the structure format received from the data access rights manager 130 in step 222 . The query data is then removed.

[0127] In step 224, the modifier 140 receives the user identifier (UserIDM) in the advertising network M from the user data processor 102 (eg, from a cookie file or from a profile in the browser), and the user ID M from the data access rights manager 130 ( Figure 2a (not shown) receives a user identifier (UserID100) in the system 100.

[0128] The structure with the user data is then encrypted with the public key and a pair of identical random tokens are generated. One of the tokens is linked to the identifier and the second token is linked to the user's data structure (e.g. the second token is added to the structure in an additional field, this step is not included in the Figure 2a shown in ).

[0129] In step 225a, the user's data structure is then sent to the storage device 150, and in step 225b the identifier with the second token is sent to the anonymizer 160. In step 225c, the anonymizer 160 converts the identifier and, in step 225d, transmits the converted identifiers UserID'100 and UserID'M to the storage device 150.

[0130] In step 226, the identifier is linked to the user's data structure based on finding the same token by the storage device 150. In step 227, the storage device 150 links the received data structure with other data structures of the user.

[0131] The anonymizer 160 changes the original user identifier and the identifier of the advertising network M in the system 100 in order to protect the user data in the event that the data is leaked from the storage device 150, because the data owner cannot be identified with the changed identifier. Figure 2b As shown, a data request for processing data from advertising network M is redirected to storage device 150 via anonymizer 160 .

[0132] Figure 2b Aspects of a method for providing user data to a user data processor, such as in the transfer of a data structure from a storage device to the user data processor, are shown. Figure 2b As can be seen, in step 230, the request may be directed by the server through the client, or in step 230a and / or in step 230b, the request may be directed by the client itself according to its capabilities.

[0133] In one aspect, the request includes a user identifier UserIDM in the advertising network M. In step 240, the request is redirected to the anonymizer 160. When the request is redirected, the user identifier in the system 100 is appended to the request, and in certain cases, information about the requested data is added, such as an enumeration of the fields of a structure; various formats such as XML, JSON, etc. may be present.

[0134] In step 241 , the anonymizer 160 converts the user identifier in the system 100 and the identifier in the advertising network M, and in step 242 the anonymizer 160 transmits the converted identifier to a storage device.

[0135] In step 243, the storage device 150 detects data linked to the user according to UserID'100, and in step 250 ( Figure 2b The permissions of the advertising network M are determined in the example (not shown), and the storage device 150 prepares data according to the access permissions for processing by the user data processor 102. In this example, this is done by detecting UserID'M and a data structure associated with UserID'M.

[0136] In step 251, when the data is detected, the data is returned to the anonymizer 160 along with the UserID'M. In step 252, the anonymizer 160 returns the original value to the user identifier in the network M. The user data is transmitted to the user data processor 102 of the advertising network along with the original UserIDM, and the occurrence of the transmission is recorded by the search log 180.

[0137] In one aspect, the advertising network may contact the anonymizer 160 directly without the device 101 redirecting the request, whereas in the present case, the user data processor 102 itself redirects the request: instead of the device 101 , in certain cases the advertising network contacts the storage device 150 via the anonymizer 160 .

[0138] In another aspect, the data is not transferred to the user data processor 102, but access to a copy of the data placed in the storage device 150 is granted.

[0139] Figure 1 The system shown in is also used to implement Figure 3 The illustrated method 300 for updating user data is implemented when not all processed data is located in the storage device 150 and / or when the user has more than one device from which data can be received.

[0140] In this method, steps 210, 230, 240 and 250 are similar to Figure 2The method 300 then proceeds from step 250 to step 310 .

[0141] In step 310 , the storage device 150 detects that the data to which the user data processor has received access rights is not located in the storage device 150 .

[0142] Therefore, in step 320, the user data missing from the storage device 150 is transferred from the user device to the storage device 150. In one aspect, the storage device 150 contacts the data access permission manager 130 when the absence of data in the storage device is detected.

[0143] The data access rights manager 130 updates the data model, based on which the data collector 120 populates the new fields in the structure (in this example, those related to location). The data access rights manager 130 then sends the data to the storage device 150.

[0144] In one aspect, if the detected data requires further transformation, the data is sent using the modifier 140 and the anonymizer 160. The modifier 140 performs analysis of the data for criticality and other compliance with the permissions established by the data access permissions manager 130.

[0145] Figure 3 A method 300 for updating user data in a storage device is shown. Figure 3a Aspects of a method for updating user data when transferring a data structure to a remote storage device are shown.The example of an advertising network M will be further considered.

[0146] However, in the present case, the system 100 operates according to the following scenario:

[0147] Pre-blocking web tracking in device 101b (a PC in this example) (steps 211, 212),

[0148] In step 222a, the data collector 120 collects all users' search queries and clicks (as the most extensive data for processing),

[0149] • The collected data is sent to the storage device 150 (step 225a - step 227), which then independently creates a structure for processing by the user data processor according to its access rights.

[0150] In addition to information about search queries and clicks, ad network M in this example has requested information about location: in step 230, server 102a sends the request to client 102b, which in step 230b sends the request to data access permissions manager 130. In step 221, the user issues the permission, and data access permissions manager 130 draws up permissions that include permissions to location data.

[0151] Figure 3b One aspect of a method 300 for updating user data when transferring an updated data structure to a storage device is shown. As the storage device 150 independently creates or populates the data structure for the user data processor 102 to process.

[0152] In step 240, when redirecting the request by the user identifier UserID100, information about the data for which rights have been defined for the advertising network M is added to the request. The information about the data is added in the form of fields of a data structure. Figure 3b In , for example, this is denoted as "model".

[0153] In step 242 , the storage device 150 receives the converted user identifier UserID′ 100 and the fields of the data structure from the anonymizer 160 , and in step 243 , the storage device 150 finds the user data of the user in storage.

[0154] The storage device 150 then determines the access rights to the data, in our example, by comparing the fields of the structure attached to the request (taken from the "model") with the data located in the storage device. Then, in step 310, the storage device 150 detects ( Figure 3b (Not shown) Information about the user location UserID'100 has not yet been placed on storage device 150 (resulting, for example, in a population error). Storage device 150 contacts data access rights manager 130 with a request for data shown in the structure but not present in storage device 150. For example, data access rights manager 130 is contacted via proxy 130a, which contacts anonymizer 160 in step 311. Anonymizer 160 converts the identifier UserID'100 in the request into the original UserID 100 in step 312, and transmits the request to the data access rights manager in step 313. Based on the result of the request from storage device 150, data access rights manager 130 updates the information about the data to be collected, wherein this update includes at least the following two steps:

[0155] Detecting a device in the user equipment that can provide the requested data (in the example considered here, this device is the mobile phone 101a);

[0156] • Updating the fields of the structure for the data collector 120 , in particular in the device adding the fields containing the requested data (in this example, adding the “location” field); in this example, this is step 314 .

[0157] In step 320, the storage device receives the requested data. In the example considered, in step 320, Figure 3 Including Figure 3b . In step 320a, the updated user's data structure with information including location is sent to the storage device 150, and in step 320b, the user identifier in the system 100 with the second token is sent to the anonymizer 160. In step 320c, the anonymizer 160 converts the identifier, and in step 320d, the converted identifier UserID'100 is transmitted to the storage device 150. In step 320e, in the storage device 150, the identifier is linked to the updated user's data structure based on finding the same token. Then, in step 320f, the storage device 150 links the received data structure to other data structures for the user. The storage device can then complete the necessary fields at the request of the user data processor 102.

[0158] Now it will be based on Figure 2a to Figure 2b Consider an example of an implementation of the method 200 for providing user data to a user data processor. The process blocker 110 blocks data processing by the advertising network M; more specifically, the process blocker 110 blocks the collection of a history of URL addresses / resources visited by the user (clickstream) and search queries.

[0159] Blocking is done by:

[0160] In step 211 , a cookie file is removed from the web data 103 including the data created by the browser 102 b , the cookie file containing a temporary user identifier of the advertising network M installed by a script on the web page;

[0161] In step 212, spoofing a permanent user identifier in the advertising network M in the network traffic that is the same as the login of the user's account entered into the browser; and

[0162] Trick browsers into installing 102b identifiers in network traffic.

[0163] Based on the clickstream and the search query, the advertising network M performs a profiling, followed by the targeting of the advertising messages. As a result, the advertising network will not be able to make targeting determinations, since it does not have a profile of the user, resulting in a significant reduction in conversions (the number of clicks on the advertising announcements), and since the operating model of the advertising network is CPC (cost per click), the revenue per user ARPU (average revenue per user) decreases accordingly. The user uses a similar block, since the user wants to avoid the appearance of advertisements for products in the "health" category (e.g., drugs, medical clinics, and other items from the "health" category) in his browser. However, the user is ready to receive targeted advertisements for goods and services in other categories ("sports", "education", "books", ..., "N") from the advertising network M. The user is ready to share only the history of search queries and web resources visited for profiling.

[0164] Figure 4 An example of configuring data permissions is shown. The configuration of data permissions is specified in step 221. The system 100 also blocks any unwanted advertising announcements by the user via the process blocker 110. In step 212, the process blocker 110 removes advertising data with unwanted content from the traffic and blocks the loading of advertising data with unwanted content, i.e., advertising data and content related to the "health" category.

[0165] Thus, after specifying the settings, in step 221, the data access rights manager 130 defines the rights of the advertising network M to the entire search query history and clickstream, excluding search queries and clicks related to the "health" category. In step 222, information related thereto is sent to the system 100. Thus, in step 222, the data collector 120 receives a data structure with populated fields, and the structure includes the following fields:

[0166] Search query

[0167] Web resources accessed;

[0168] o Art;

[0169] Entertainment;

[0170] o Business;

[0171] o Games;

[0172] o General;

[0173] o Job search;

[0174] o etc.

[0175] In this step, the data collector 120 is sorted to collect all search queries and all web resources accessed that cannot be assigned to the health category. The profile analysis used to target advertising materials in the "health" category can be used by various categories of web resources, so when creating the structure for the device 120, the data access rights manager 130 reduces the general category of "health" to categories (subcategories) of more local web resources and does not include them in the fields of the structure of the device 120, such as the subcategories of web resources such as drugs, medical services, and medical information portals.

[0176]

[0177] In step 222, the modifier 140 receives a category of search queries for which transmission is prohibited. The modifier 140 uses natural language processing techniques to analyze and classify the search queries. In step 222, the storage device 150 receives access rights to the advertising network M.

[0178] Then, in step 222a, the data collector 120 collects search queries from all categories and visited web resources that are not related to the "health" category and populates the fields of the structure. The data used to populate the structure is selected by the data collector 120 from the retained web data 103 accumulated during the user's network activities. This data is created by both the browser 102a and the add-ons of the system 100, such as plug-ins in the browser or UI interceptors (these are not in the Figure 2a , and is a module of the data collector 120 ).

[0179] Example of structure format:

[0180]

[0181]

[0182] In step 223 , the populated structure is transmitted to the modifier 140 .

[0183] Based on the information about the prohibited categories received from the data access rights manager 130 in step 222, the modifier 140 analyzes the fields of the search query for the presence of queries related to the "health" category. Then, the search query related to the "health" category is removed from the received structure (in this example, this is the query R3). In step 224, the modifier 140 receives from the user data processor 102 a user identifier (UserIDM) from the advertising network M from a cookie file or from a profile in the browser and from the data access rights manager 130 ( Figure 2a(not shown) receives a user identifier (UserID100) in system 100. A structure containing user data including the search query and the URL resource is then encrypted using a public key (Rn→Rn', URLn→URLn'). Modifier 140 generates a pair of identical random tokens. One of the tokens is linked to the identifier UserIDM and the identifier UserID100:

[0184] User={"ID":[UserIDM,UserID100],"Token":token}.

[0185] The second token is linked to the user's data structure (it is added to the structure in an additional field):

[0186]

[0187]

[0188] In step 225a, the user's data structure is then sent to the storage device 150, and in step 225b the identifier with the second token is sent to the anonymizer 160. In step 225c, the anonymizer 160 transforms the identifier. The anonymizer 160 changes the original user identifier in the system 100 and the identifier of the advertising network M in order to protect the user data in the event of a data leak from the storage device 150, since the altered identifier cannot be used to identify the data owner:

[0189] User={“ID”:[UserIDM,UserID100],“Token”:token}→

[0190] User="{"ID":[UserID'M,UserID'100],"Token":token}→

[0191] In step 225d, the converted identifiers UserID'100 and UserID'M are transmitted to the storage device 150. In step 226, in the storage device 150, the identifiers are linked with the data structure of the user based on the same token.

[0192] In step 227, the storage device 150 links the received data structure with other data structures of the user:

[0193]

[0194] The data request from the advertising network M for processing data is now redirected to the storage device 150 via the anonymizer 160, as Figure 2b As shown. Figure 2bAs can be seen in FIG, in step 230, server 102a sends a request through browser 102b. The request includes the user identifier UserIDM in advertising network M. In step 240, the request is redirected to anonymizer 160. When the request is redirected, the user identifier in system 100 is appended to the request:

[0195] User="{"ID":[UserIDM,UserID100]}.

[0196] In step 241, the anonymizer 160 converts the user identifier in the system 100 and the identifier in the advertising network M:

[0197] User={"ID":[UserID'M,UserID'100],}.

[0198] Furthermore, in step 242, anonymizer 160 transmits the converted identifier to storage device 150. Storage device 150 detects data linked to the user based on UserID'100 in step 243 and determines the authority of advertising network M in step 250; in this example, this is done by searching for UserID'M and its associated data structure. In step 251, when the data is detected, it is returned to anonymizer 160 along with UserID'M. In step 252, anonymizer 160 returns the original value to the user identifier in network M and transmits the user data, along with the original UserID'M, to user data processor 102 of the advertising network, with the retrieval log 180 recording the transfer.

[0199] In one aspect, the advertising network can contact the anonymizer directly without the request being redirected by device 101, while in the present case the user data processor itself redirects the request: instead of the device, in certain cases it contacts the storage device through anonymizer 160. In another aspect, the data is not transferred to user data processor 102, but access to a copy of the data placed in storage device 150 is granted.

[0200] Figure 1 The system shown in FIG3 is also used to implement a method 300 for updating user data. This method is implemented when not all processed data are placed in the storage device and / or when the user has more than one device from which data can be received. In this method, steps 210, 230, 240, and 250 are similar to steps 300. Figure 2 The steps of the method are shown.

[0201] In step 310, the storage device detects that the data to which the user data processor has received access rights is not located in the storage device.

[0202] In step 320, the missing user data is transferred from the device to the storage device. In one aspect, when the absence of data is detected, the storage device 150 contacts the data access rights manager 130. The data access rights manager 130 updates the data model, based on which the data collector 120 populates the new fields in the structure (in this example, those related to location). The data access rights manager 130 then sends the data to the storage device 150. In certain cases, if the data is detected to require further transformation, the data is sent using the modifier 140 (which performs analysis on the data for criticality and other compliance with the permissions established by the data access rights manager 130) and the anonymizer 160.

[0203] Figure 5 An exemplary system for exchanging user data is shown, the exemplary system being designed for authorizing access to the user data via a cryptographic container.

[0204] A "cryptographic container" comprises a file having a specified structure (an example of which is described below) that includes at least a fully encrypted selection of an element of user data.

[0205] The data encryption and decryption processes are automatically performed by system 500 and are completely transparent to the user. Cryptographic containers can be used to exchange large amounts of confidential information that must be compiled for different users. In certain cases, a selection of data elements is created in the form of a file system, where each data element is a file. System 500 includes a management device 510, a data subject device 520, and a data user device 530.

[0206] In one aspect, the functions of management device 510 and data subject device 520 are performed by a single device. System 500 also includes a data collector 120a, a data access rights manager 130a, a modifier 140a, a storage device 150a, an (optional) anonymizer 160a, and a retrieval log 180.

[0207] Data collector 120a of device 510 collects data from device 520. Data collector 120a transmits the data to modifier 140a. Modifier 140a, using the received data, forms (creates) a cryptographic container (if a suitable container has not been previously created; otherwise, an existing container is modified), and transmits the cryptographic container to storage device 150a. When device 530 requests access to user data, permissions are issued via data access rights manager 130, and the cryptographic container (hereinafter referred to as "container") is modified via modifier 140a. Storage device 150a authorizes user data processor 102 of device 530 to access its copy of the container. In order to receive access to user data via the container, the container must first be formed, after which, through modification of the container by device 140a, user data processor 102 is authorized to access the data elements in the container. In another aspect, the formation of the container and the authorization of access to the user data and the copy of the container can occur in a single iteration.

[0208] Figure 6a-6c An example of a container 600 is shown. Container 600 contains at least one data element 610, which contains user data. For the purposes of the storage method, a data element is the smallest indivisible (basic) unit of data. Examples of data elements 610 include files associated with a file system (in this case, the encryption option for the data element is the file system), entries in tables associated with a relational database (the encryption option for the data element is the table), and fields associated with data structures in a non-relational database (the encryption option for the data is determined by the database structure). In a personal user profile, data element 610 can be a dedicated profile that combines information about a user associated with a single category (e.g., medical history, legal information, information about the user as a consumer, etc.). Each data element is encrypted. Various algorithms known in the art can be used for encryption. The encrypted data element or encrypted selection of data elements, along with the structure for accessing data element 620 (or, if at least two of the data elements are present, accessing the data elements), and the access structure for user data processor 630, form part of the container structure. A key (hereinafter referred to as key A) is stored with the encrypted data element and is used to decrypt the data element.

[0209] Key A is stored in the access structure of element 620. Key A is also encrypted. Key A can be encrypted using various algorithms. In one aspect, when there are at least two such elements, Key A is a combination of at least two keys, such as a public key and a private key or multiple keys used to decrypt the data element.

[0210] The key for accessing Key A (Key B) is stored in the access structure of the user data processor 630. In certain cases, Key B is a combination of at least two keys, such as a public key and a private key. Key B is used to encrypt Key A and to decrypt data when it is read or written. Key B is also encrypted.

[0211] Key B is encrypted using a key (key C) linked to user data processor 102. Each user data processor is linked to its own key C. In certain cases, key C is a combination of at least two keys, such as a public key and a private key. Key C is either created specifically by the container's modifier 140a or received from user data processor 102, where modifier 140 forms structure 630. Key C is used to divide access rights to the container between different user data processors 102. Each user data processor 102 has its own unique key Cn (key Cn is a member of a plurality of keys C) used to operate with the container. Therefore, it is recommended that each user data processor store its key Cn in a secure manner to ensure that one user data processor 102 cannot receive the key of another user data processor.

[0212] The container can be formed in various ways. In one aspect, the container can be a frame, such as Figure 6a As shown, for this frame, key A encrypts data element 610, then key A along with the encrypted data element 610 is encrypted by key B, and the result is jointly encrypted by key B and key C.

[0213] In another aspect, the container takes the form of a structure containing encrypted objects, such as Figure 6b As shown, the elements of the structure are:

[0214] (at least one) encrypted data element 610;

[0215] a structure for accessing an element 620 having at least one encryption key A; and

[0216] • An access structure 630 of the user data processor, the access structure 630 having at least one key B encrypted by a key C.

[0217] There may be more than one access structure 630 for a user data processor in a container, and the number of such structures depends on the number of user data processors 102 that are authorized to access the data in the container 600. Figure 6c In the example of a container illustrated in , there may be more than one such data element.

[0218] Figure 7 An example of a method 700 for forming (creating) a new container is shown.

[0219] In step 710 , the data element 610 is received via the data collector 120 and passed to the modifier 140 a .

[0220] In step 720, a structure for accessing data element 620 is formed via modifier 140a of data element 610. Structure 620 contains at least one key (key A) used to encrypt data element 610.

[0221] In step 730, data element 610 is encrypted using key A via modifier 140a.

[0222] Then, in step 740, an access structure is formed for the rights manager 630a via the modifier 140a (in the specific case of the access structure for the user data processor 630, this access structure contains keys accessible to the devices of the apparatus 510, since the keys in the structure are encrypted by the key C from the data access rights manager 130a). The structure 630a contains the key used for encryption / decryption of the key A, namely the key B.

[0223] In step 750 , when the structure 630 a is formed, the key B is received from the data access permission manager 130 a and the key is encrypted using the key B.

[0224] In step 760, key B is then encrypted via modifier 140a. The key (key C) from data access rights manager 130a is used to encrypt key B. The result is a container that stores data element 610, access to which is granted only to the device of management device 510. In one aspect, the formed container is located in storage device 150a.

[0225] In one aspect, Key B is a combination of keys (Public Key B and Private Key B), and Key C is a combination of keys (Public Key C and Private Key C). Private Key B is used to encrypt Key A, and Public Key C is used to encrypt Key B.

[0226] Container={ID_Container:[ID],

[0227] UAI_x:[PrivICA',PublICA'],

[0228] ICA:[PubItem'],

[0229] Item:[Data']

[0230] }

[0231] The specific situation of the shaped container 600 has been described above, wherein:

[0232] Item is a structure that stores encrypted data elements 610.

[0233] Data' is the encrypted data element Data 610;

[0234] ICA is a structure used to access data elements 620;

[0235] PubItem is the key used to encrypt the data element (Key A);

[0236] UAI_x is an access structure for the rights manager 630a;

[0237] PrivICA is the key used to encrypt the PubItem key (private key B);

[0238] PublICA is the key used to decrypt the PubItem key (public key B);

[0239] ID_Container is a structure that stores information about the container 600;

[0240] ID is the identifier of the container 600; and

[0241] PrivICA', PublICA', PubItem' indicate that the keys (PrivICA, PublICA, PubItem) are encrypted.

[0242] Figure 8 An example of a method 800 is shown for granting user data processor 102 access to a previously formed container 600. Initially, only the user data processor of device 510 has access to the data elements 610 in the formed container 600. Let us consider how user data processor 102 of third-party device 530 is granted access to the user data in the container.

[0243] In step 810 , a request is made via the user data processor 102 of the device 530 to access data in a container 600 , which was previously formed and located in the storage device 150 , for example.

[0244] In step 820 , the rights for the user data processor 102 are issued via the data access right manager 130 a , and information about the rights is transmitted to the modifier 140 a .

[0245] In step 830, an access structure 630b is formed for the user data processor 102, for which purpose the modifier 140 in the container 600 decrypts the key B in the access structure of the rights manager 630a, wherein (if the key B takes the form of at least two keys) at least one decrypted key is copied from the structure 630a to the structure 630b to be formed.

[0246] The number of keys copied depends on the permissions issued in step 820. If user data processor 102 receives permission to read data elements, key B is copied from structure 630a, enabling key A to be decrypted (key A is required to decrypt data element 610 in container 600). If user data processor 102 receives permission to write data element 610, key B is copied, allowing key A to be decrypted, which is then used to encrypt the added data element 610. When access structure 630b has been created for user data processor 102 (and key B has been copied), modifier 140a is used to receive key C for encrypting key B in the created access structure 630b. This copy of key C is different from key C used in step 750 of method 700. In this case, the received copy of key C is linked to user data processor 102 of device 530.

[0247] The key C linked to the user data processor 102 can be received by the modifier 140a in various ways. In one aspect, the key C is generated directly by the modifier 140a, while in another aspect, the key C is received directly from the user data processor 102 or a public source that has been published by the user data processor 102. For example, a certificate with a private key and a public key can be generated on behalf of an organization linked to the device 530 associated with the user data processor 102. The combination of the public key and the private key forms the organization's key C. The public key from this combination is placed in some type of resource (e.g., a public key database 540), from which the modifier 140a can receive the key.

[0248] In step 840, key B is encrypted by the received key C via the modifier. Access to the data elements in container 600 can now be obtained via the user data processor of device 510 or via user data processor 102 of device 530. Each party gains access to data elements 610 with the help of its own copy of key C. If key B was encrypted using public key C, key B is decrypted using private key C.

[0249] It should also be noted that in most cases, simply obtaining access to the user data element is not sufficient. Storage device 150a must grant access to the actual copy of the container storing the data element. If this has not already been done, then in step 850, access is granted to the copy (master) of the container in storage device 150a.

[0250] Container={ID_Container:[ID],

[0251] UAI_1:[PrivICA',PublICA'],

[0252] UAI_x:[PrivICA',PublICA'],

[0253] ICA:[PubItem'],

[0254] Item:[Data']

[0255] }

[0256] A description has been given above of the details of the formed container 600 to which the access structure for the user data processor 102 has been added, wherein:

[0257] UAI_1 is the access structure 630b of the user data processor 102.

[0258] In one aspect, as in the example associated with the following medical history, no structure for accessing element 620 is used, and the key for accessing the data (Key A) is contained in the access structure for user data processor 630. In most cases, it is logically desirable to divide the keys into two levels (the structure for accessing data element 620 and the access structure for user data processor 630) so that each key has exactly one purpose. This results in two useful properties:

[0259] High productivity; and

[0260] Password strength.

[0261] This two-level division allows keys to be rotated independently of each other. Specifically, during periodic changes to Key B, it is possible to replace Key B from the access structure of User Data Processor 630 without re-encrypting the significantly larger number of data elements themselves; re-encrypting Key A is sufficient. This is crucial in the context of a file system, for example, because access to element data is blocked during service operations. Therefore, the shorter this delay, the better. Each change to a data element requires encryption with a new Key A. This prevents the accumulation of material for key compromise.

[0262] Anonymizer 160a is used for data transfers from device 510 to storage device 150a and from apparatus 150a to device 530 and device 520. In one aspect, anonymizer 160a converts the identifier of a container when it is transferred to storage device 150a, and performs the reverse conversion when the container is transferred from storage device 150a or during execution of a request for a container in storage device 150a from devices 510, 520, and 530. This increases the robustness of system 500 to leaks.

[0263] In the following example, regarding medical history,

[0264] A copy of key A takes the form of a combination of keys PublItem and PrivItem;

[0265] The copy of the key C belonging to the service takes the form of a combination of the keys PublService and PrivService;

[0266] a copy of the key C belonging to the patient in the form of the combination of the keys PublPatient, PrivPatient; and

[0267] • The copy of the key C belonging to the clinic is in the form of the combination of the keys PublClinic, PrivClinic.

[0268] In this aspect, to simplify the example, key B is not used.

[0269] A system for exchanging data using cryptographic containers can be used in a wide range of applications. For example, it can be used for storing and transmitting passport data, for exchanging data between government agencies, for storing unified citizen profiles, and for controlling access to various parts of the profile by various organizations. Let's consider an example using a variant of the described system for storing and updating medical histories, which can form part of a unified citizen profile.

[0270] Figure 9An example of a system 900 for exchanging user data is shown, which is designed to authorize access to a patient's medical history via a container. The system 900 includes: a patient device 520a having a user data processor 102 and a local storage device 150b; a health clinic device 530a having a local storage device 150b and a user data processor 102; and a device 510a of a federal healthcare oversight service (hereinafter referred to as the "service") having a central storage device 150a for storing medical history; a search record 180; a public key database 540; and an (optional) anonymizer 160.

[0271] Here, the user data processor 102 is:

[0272] The user data processor 102 in the patient device 520a; and

[0273] • User data processor 102 in clinic device 530a.

[0274] It manages the medical history of the service. Device 510a and storage device 150a belong to this service. Data collector 120a receives the medical history (MedicalData) and transmits it to modifier 140a. Modifier 140a creates a pair of keys (PrivItem, PublItem), namely a public key (PublItem) for decrypting the data (read access) and a private key (PrivItem) for encrypting the data (write access). To simplify the example, we will consider a pair of keys, and in this case the data element will be the entire medical history. In specific cases, modifier 140a can create several pairs of keys for each medical specialty (cardiology, urology, surgery, etc.), where the history of each specialty is an independent data element. The medical history received by data collector 120a is encrypted by the private key PrivItem with the help of modifier 140a (MedicalData->MedicalData'). Information about this is recorded by retrieval record 180. The service access structure (UAI_Service) is then formed, the created key pair is placed in the service access structure and encrypted by the service's public key PublService (PrivItem->PrivItem', PublItem->PublItem'), and the service access structure is combined with the encrypted medical history to form a container:

[0275] Container={ID_Container:[IDPatient],

[0276] UAI_Service:[PrivItem',PublItem'],

[0277] Item:[MedicalData']

[0278] }

[0279] The container is transferred to storage device 150a. Any party with access to storage device 150a (e.g., a patient or health clinic) can access the container and objects. However, to gain access to the data in the container, permissions must be issued by the data access permissions manager of service 130a. Patients may only receive read permissions, while health clinics may receive both read and write permissions. Any access to the data in the container on the storage device is recorded by retrieval log 180. Entries in the medical history and any modifications thereto may be made only on storage device 150a. Reading can occur from a local copy in local storage 150b linked to user data processor 102. To receive access to the data in the container, the patient uses user data processor 102 on device 520a to contact data access permissions manager 130a. User data processor 102 on device 520a provides the patient's identification data and other data in accordance with local laws. If the data is deemed valid, data access permissions manager 130a defines read access permissions and requests the patient's public key from user data processor 102 on device 520a. In the next step, the rights manager transmits the patient's identifier and his public key to the modifier 140a. The modifier 140a contacts the storage device 150a and modifies the container, wherein:

[0280] Decrypt the public key for access history (PublItem'->PublItem) using the service's private key (PrivService) in the service's access structure.

[0281] Copy the public key;

[0282] Create an access structure for the patient and place the public key PublItem in it; and

[0283] • Encrypt the public key for access history with the patient public key PublPatient received from patient equipment device 520a (PublItem->PublItem').

[0284] The container now contains two structures for accessing medical history data:

[0285] Container={ID_Container:[IDPatient],

[0286] UAI_Patient:[PublItem'],

[0287] UAI_Service:[PrivItem',PublItem'],

[0288] Item:[MedicalData']

[0289] },in:

[0290] UAI_Service is an access structure for a service that has an encrypted public key (PublItem') for accessing an element and an encrypted private key (PrivItem') for accessing an element. These keys have been encrypted with the service's public key PublService.

[0291] UAI_Patient is an access structure for a patient with an encrypted public key (PublItem') for accessing elements.

[0292] The patient receives access to their medical history via user data processor 102 of device 520a. User data processor 120 contacts storage device 150a and receives access to the container. The patient's public key, PublItem, in the access structure is decrypted using the patient's private key, PrivPatient. The relevant fields of the medical history are decrypted using the public key, PublItem. In certain cases, the user data processor copies the container from storage device 150a using storage device 150b and stores it locally.

[0293] Let's consider an example where a health clinic receives access to medical history. In one specific scenario, when permission is requested from the user data processor 102 on a patient device 520a for the health clinic, a notification is sent, and after confirmation by the user data processor 102 on the patient device 520a, the permission is granted to the clinic. In another specific scenario, the user data processor 102 on the patient device 520a may initiate the definition of permission itself, sending an application with the request to the service's data access rights manager 130a. Let's consider a scenario in which the patient acts as the initiator of granting permission to the clinic. The system also includes the health clinic's public key database 540a, where the clinic's key is stored after approval by the service. The user data processor 102 sends a request from the patient device 520a to the service's data access rights manager 130a to grant access to the patient's medical history to the user data processor acting on behalf of the health clinic. This request contains at least the clinic's identification data. The service's data access rights manager 130a identifies the patient and checks for the health clinic's public key in database 540. If an entry with the health clinic's public key exists in the database, the service's data access rights manager 130a defines the health clinic's rights to access the identified patient's medical history. The health clinic receives read and write permissions. In the next step, the service's data access rights manager 130a transmits the patient's identifier and the clinic's public key to the modifier 140a.

[0294] The storage device 150a is contacted via the modifier 140a and the patient's container (the container corresponding to the patient identifier) ​​is modified, wherein:

[0295] The service's private key PrivService is used to decrypt the service's access structure field containing the public key for accessing the medical history: PublItem'->PublItem;

[0296] Copy the public key PublItem;

[0297] The service's public key PublService is used to encrypt the service's access structure field containing the public key for accessing the medical history: PublItem->PublItem';

[0298] The service's private key PrivService is used to decrypt the service's access structure field containing the private key for accessing the medical history: PrivlItem'->PrivlItem;

[0299] Copy the private key PrivItem;

[0300] The public key of the service, PublService, is used to encrypt the field of the service's access structure containing the private key for accessing the medical history: PrivlItem->PrivlItem';

[0301] Create the health clinic's access structure and place the public key PublItem and private key PrivItem in it.

[0302] The clinic's public key, PublClinic, is used to encrypt the field of the structure containing the public key: PublItem->PubItem'; and

[0303] The clinic’s public key, PublClinic, is used to encrypt the fields of the structure containing the private key, PrivItem.

[0304] The container now contains three structures for accessing medical history data:

[0305] Container={ID_Container:[IDPatient],

[0306] UAI_Clinic:[PrivItem',PublItem'],

[0307] UAI_Patient:[PublItem'],

[0308] UAI_Service:[PrivItem',PublItem'],

[0309] Item:[MedicalData']

[0310] },in:

[0311] UAI_Service is an access structure for a service that has an encrypted public key (PublItem') for accessing an element and an encrypted private key (PrivItem') for accessing an element. These keys have been encrypted with the service's public key PublService.

[0312] UAI_Patient is an access structure for a patient with an encrypted public key (PublItem') for accessing elements; and

[0313] UAI_Clinic is an access structure of a health clinic with an encrypted public key (PublItem') for accessing elements and an encrypted private key (PrivItem') for accessing elements, which have been encrypted with the clinic's public key PublClinic.

[0314] The health clinic receives read access to the patient's medical history via the user data processor 102 of device 530a. The user data processor 102 of device 530a contacts storage device 150a and receives access to the container. The clinic's private key, PrivClinic, is used to decrypt the public key, PublItem, in the clinic's access structure. The public key, PublItem, is used to decrypt the relevant fields of the medical history. In certain cases, the user data processor 102 copies the container from storage device 150a using storage device 150b and stores it locally.

[0315] The health clinic receives write access to the patient's medical history via user data processor 102 of device 530a. Storage device 150a is contacted via user data processor 102 and receives access to the container. The clinic's private key, PrivClinic, is used to decrypt the private key, PrivlItem, and public key, PublItem, in the clinic's access structure. The public key, PublItem, is used to decrypt the relevant fields of the medical history. Data is added to the medical history. The private key, PrivItem, is used to encrypt the data. New data elements are written to the history in the same manner.

[0316] Figure 10 A method 1000 is shown for authorizing a user data processor to access a cryptographic container of user data.

[0317] In step 1005 , method 1000 creates a cryptographic container for the user data, wherein the cryptographic container receives at least one element of the user data and encrypts the at least one element.

[0318] In step 1010 , method 1000 establishes permissions for a user data processor to access at least one element of user data using a first key.

[0319] In step 1015, method 1000 forms at least one access structure for the user data processor, wherein forming the at least one access structure includes: placing a first key in the at least one access structure based on the established permissions, receiving a second key linked to the user data processor from the user data processor to be used to access the first key, and encrypting the first key with the second key.

[0320] In step 1020, method 1000 determines whether a request to access the cryptographic container has been received. If such a request has been received, the method proceeds to step 1025. Otherwise, the method remains in step 1020 and continues to monitor for requests.

[0321] In step 1025, when a request to access the cryptographic container is received, method 1000 authorizes the user data processor to access the cryptographic container based on the at least one access structure formed. The method then proceeds to steps 1020 and 1005 as needed.

[0322] In one aspect, the cryptographic container encrypts at least one element using a first key.

[0323] In one aspect, the second key is a combination of at least one pair of keys including at least one private key and at least one public key.

[0324] In one aspect, at least one public key is received for encrypting the first key.

[0325] In one aspect, information about the second key is communicated to a user data processor.

[0326] In one aspect, at least one public key is received from a user data processor that is authorized to access.

[0327] In one aspect, each of the at least one element of the user data is encrypted using a respective separate first key.

[0328] In one aspect, permissions for accessing at least one element are established based on an action set, wherein a user data processor is permitted to perform the action set on the at least one element of the user data.

[0329] In one aspect, the set of actions includes at least one of: reading data and writing data.

[0330] In one aspect, a separate first key is created for each action in the action set.

[0331] In one aspect, the created first key comprises a combination of at least one pair of keys including at least one first private key and at least one first public key.

[0332] In one aspect, a pair of keys is formed of a first private key and a first public key, such that the first private key is used to encrypt data when a write occurs, and the first public key is used to decrypt data when a read occurs.

[0333] In one aspect, when establishing permission to read data from a field, a first public key is placed in at least one access structure.

[0334] In one aspect, when establishing permission to write data to a field, a first private key is placed in at least one access structure.

[0335] In one aspect, the method further comprises, during creation of a cryptographic container for user data, adding an access structure for a data access permission manager, wherein at least one first key for the added access structure for the data access permission manager is placed in the access structure of the user data processor, wherein the at least one first key is encrypted.

[0336] In one aspect, placing at least one first key for the added access structure of the data access permission manager in the access structure of the user data processor includes extracting the first key from the access structure of the data access permission manager.

[0337] In one aspect, the method further comprises requesting, on behalf of the user data processor, permission to access elements of the user data in the created cryptographic container.

[0338] Figure 11 is a block diagram illustrating a computer system 20 on which aspects of the system and method for authorizing a user data processor to access a cryptographic container of user data may be implemented. The computer system 20 may take the form of multiple computing devices, or the form of a single computing device, such as a desktop computer, a notebook computer, a laptop computer, a mobile computing device, a smartphone, a tablet computer, a server, a mainframe computer, an embedded device, and other forms of computing devices.

[0339] As shown, the computer system 20 includes a central processing unit (CPU) 21, a system memory 22, and a system bus 23 that connects various system components, including memory associated with the central processing unit 21. The system bus 23 may include a bus memory or bus memory controller, a peripheral bus, and a local bus capable of interacting with any other bus architecture. Examples of buses may include PCI, ISA, PCI-Express, HyperTransport™, InfiniBand™, Serial ATA, I2C, SATA, and SATA 3. 2 C and other suitable interconnections. The central processing unit 21 (also referred to as a processor) may include a single or multiple sets of processors having a single or multiple cores. The processor 21 may execute one or more computer executable codes that implement the technology of the present disclosure. The system memory 22 may be any memory for storing data used herein and / or computer programs that can be executed by the processor 21. The system memory 22 may include volatile memory (such as random access memory (RAM) 25) and non-volatile memory (such as read-only memory (ROM) 24, flash memory, etc.) or any combination thereof. The basic input / output system (BIOS) 26 may store basic programs for transferring information between elements of the computer system 20, such as those when the operating system is loaded using the ROM 24.

[0340] The computer system 20 may include one or more storage devices, such as one or more removable storage devices 27, one or more non-removable storage devices 28, or a combination thereof. The one or more removable storage devices 27 and the non-removable storage devices 28 are connected to the system bus 23 via a storage interface 32. In one aspect, the storage devices and corresponding computer-readable storage media are electrically independent modules for storing computer instructions, data structures, program modules, and other data for the computer system 20. The system memory 22, the removable storage devices 27, and the non-removable storage devices 28 may use a variety of computer-readable storage media. Examples of computer-readable storage media include machine memory (such as cache, SRAM, DRAM, zero-capacitor RAM, two-transistor RAM, eDRAM, EDO RAM, DDR RAM, EEPROM, NRAM, RRAM, SONOS, PRAM); flash memory or other storage technology (such as a solid-state drive (SSD) or flash drive); cassette, magnetic tape, and disk storage such as in a hard drive or floppy disk; optical storage such as in a compact disk (CD-ROM) or digital versatile disk (DVD); and any other medium that can be used to store the desired data and that can be accessed by the computer system 20.

[0341] The system memory 22, removable storage devices 27, and non-removable storage devices 28 of the computer system 20 can be used to store an operating system 35, additional program applications 37, other program modules 38, and program data 39. The computer system 20 may include a peripheral interface 46 for transferring data from an input device 40, such as a keyboard, mouse, stylus, game controller, voice input device, touch input device, or other peripheral device, such as a printer or scanner via one or more I / O ports (such as a serial port, parallel port, universal serial bus (USB), or other peripheral interface). A display device 47 (such as one or more monitors, projectors, or integrated displays) can also be connected to the system bus 23 across an output interface 48 (such as a video adapter). In addition to the display device 47, the computer system 20 can be equipped with other peripheral output devices (not shown), such as speakers and other audio-visual equipment.

[0342] The computer system 20 can operate in a network environment using a network connected to one or more remote computers 49. The remote computer (or computers) 49 can be a local computer workstation or server that includes most or all of the aforementioned elements in describing the properties of the computer system 20. Other devices may also be present in the computer network, such as, but not limited to, routers, network stations, peer devices, or other network nodes. The computer system 20 may include one or more network interfaces 51 or network adapters for communicating with the remote computers 49 via one or more networks, such as a local area computer network (LAN) 50, a wide area computer network (WAN), an intranet, and the Internet. Examples of network interfaces 51 may include Ethernet interfaces, frame relay interfaces, SONET interfaces, and wireless interfaces.

[0343] Aspects of the present disclosure may be systems, methods, and / or computer program products. A computer program product may include a computer-readable storage medium (or media) having computer-readable program instructions thereon, which cause a processor to perform aspects of the present disclosure.

[0344] Computer readable storage medium can be a tangible device that can keep and store program code in the form of instructions or data structures, and program code can be accessed by a processor of a computing device (such as computing system 20). Computer readable storage medium can be an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device or any suitable combination thereof. For example, such a computer readable storage medium can include a random access memory (RAM), a read-only memory (ROM), an EEPROM, a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a flash memory, a hard disk, a portable computer disk, a memory stick, a floppy disk or even a mechanically encoded device, a mechanically encoded device such as a punch card or a raised structure in a groove with instructions recorded thereon. As used herein, a computer readable storage medium should not be interpreted as a temporary signal itself, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagated by a waveguide or a transmission medium, or an electrical signal emitted by a wire.

[0345] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing device or downloaded to an external computer or external storage device via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network). The network can include copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. The network interface in each computing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions to be stored in a computer-readable storage medium within the corresponding computing device.

[0346] The computer-readable program instructions for performing the operation of the present disclosure can be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data or source code or the object code written in any combination of one or more programming languages, and one or more programming languages ​​include object-oriented programming languages ​​and conventional process programming languages.Computer-readable program instructions can be performed completely on user's computer, partly on user's computer, performed as independent software packages, partly on user's computer and partly on remote computer, or performed completely on remote computer or server.In the latter case, remote computer can be connected to user's computer through any type of network (comprising LAN or WAN), or can be connected to external computer (for example, through the Internet).In some respects, the electronic circuit comprising for example programmable logic circuit, field programmable gate array (FPGA) or programmable logic array (PLA) can carry out computer-readable program instructions so that electronic circuit is personalized, so as to perform various aspects of the present disclosure by utilizing the state information of computer-readable program instructions.

[0347] In various aspects, the systems and methods described in this disclosure may be addressed in terms of modules. As used herein, the term "module" refers to a real-world device, component, or arrangement of components implemented using hardware, or as a combination of hardware and software, such as by an application-specific integrated circuit (ASIC) or FPGA, that implements the functionality of the module through a microprocessor system and an instruction set that (when executed) converts the microprocessor system into a dedicated device. Modules may also be implemented as a combination of the two, where certain functions are facilitated by hardware alone, while other functions are facilitated by a combination of hardware and software. In some implementations, at least a portion (and in some cases, all) of a module may be implemented in a computer system (such as described above in Figure 11 Thus, each module may be implemented in a variety of suitable configurations and should not be limited to any specific implementation illustrated herein.

[0348] For the sake of clarity, not all conventional features of various aspects are disclosed herein. It should be understood that in the development of any actual implementation of the present disclosure, numerous implementation-specific decisions must be made in order to achieve the developer's specific goals, and these specific goals will vary from implementation to implementation and from developer to developer. It should be understood that such development work may be complex and time-consuming, but nonetheless, it will be a routine engineering task for those of ordinary skill in the art having the benefit of this disclosure.

[0349] Furthermore, it should be understood that the phraseology or terminology used herein is for the purpose of description rather than limitation, so that the phraseology or terminology of this specification should be interpreted by those skilled in the art in combination with the knowledge of those skilled in the relevant art in accordance with the teachings and guidance presented herein. In addition, unless expressly stated otherwise, any term in this specification or claims is not intended to be attributed with an uncommon or special meaning.

[0350] The various aspects disclosed herein encompass current and future known equivalents of the known modules mentioned herein by way of illustration. Furthermore, while various aspects and applications have been shown and described, it will be apparent to those skilled in the art having the benefit of this disclosure that more modifications than those described above may be made without departing from the inventive concepts disclosed herein.

Claims

1. A method for authorizing a user data processor to access a cryptographic container of user data, the method comprising: creating a cryptographic container for the user data, wherein the cryptographic container receives at least two elements of the user data and encrypts the at least two elements; establishing permissions for the user data processor to access each of at least two elements of the user data using a plurality of first keys, the plurality of first keys being used to separately encrypt each of the at least two elements of the user data; forming at least one access structure for the user data processor, wherein forming the at least one access structure comprises: placing each first key of the plurality of first keys in the at least one access structure based on the established permissions for accessing each of the at least two elements of the user data; and receiving, from the user data processor, a second key linked to the user data processor, the second key to be used to access the plurality of first keys, wherein the second key is a combination of at least one pair of keys, the at least one pair of keys comprising at least one private key and at least one public key, wherein each first key in the plurality of first keys is encrypted using at least one public key of the second keys, and wherein an element in the user data is encrypted using the private key of the second keys; adding an access structure for a data access permission manager during creation of the cryptographic container for user data, wherein at least one first key for the added access structure of the data access permission manager is placed in at least one access structure in the user data processor, wherein the at least one first key is encrypted; and When a request to access the cryptographic container is received from the user data processor, access to the cryptographic container is authorized based on at least one access structure formed for the user data processor.

2. The method according to claim 1, wherein The cryptographic container encrypts the at least two elements using the first key.

3. The method according to claim 1, wherein Information about the second key is transmitted to the user data processor.

4. The method according to claim 1, wherein The at least one public key is received from the user data processor to which access is granted.

5. The method according to claim 1, wherein The permissions for accessing the at least two elements are established based on an action set, wherein the user data processor is allowed to perform the action set on the at least two elements of the user data.

6. The method according to claim 5, wherein: The action set includes at least one of: reading data and writing data.

7. The method according to claim 6, wherein: A separate first key is created for each action in the action set.

8. The method according to claim 7, wherein: The created first key includes a combination of at least one pair of keys, the at least one pair of keys including at least one first private key and at least one first public key.

9. The method according to claim 8, wherein The pair of keys is formed by the first private key and the first public key, such that the first private key is used to encrypt data when a write occurs, and the first public key is used to decrypt the data when a read occurs.

10. The method according to claim 9, wherein: When establishing permission to read data from the field, the first public key is placed in the at least one access structure.

11. The method according to claim 9, wherein When permission to write data to a field is established, the first private key is placed in the at least one access structure.

12. The method according to claim 1, wherein Placing the at least one first key for the added access structure of the data access permission manager in the access structure of the user data processor includes extracting the first key from the access structure of the data access permission manager.

13. The method according to claim 1, further comprising: On behalf of the user data handler, requesting permission to access elements of the user data in the created cryptographic container.

14. A system for authorizing a user data processor to access a cryptographic container of user data, comprising: at least one processor configured to: creating a cryptographic container for the user data, wherein the cryptographic container receives at least two elements of the user data and encrypts the at least two elements; establishing permissions for the user data processor to access each of at least two elements of the user data using a plurality of first keys, the plurality of first keys being used to separately encrypt each of the at least two elements of the user data; forming at least one access structure for the user data processor, wherein forming the at least one access structure comprises: placing each first key of the plurality of first keys in the at least one access structure based on the established permissions for accessing each of the at least two elements of the user data; and receiving, from the user data processor, a second key linked to the user data processor, the second key to be used to access the plurality of first keys, wherein the second key is a combination of at least one pair of keys, the at least one pair of keys comprising at least one private key and at least one public key, wherein each first key in the plurality of first keys is encrypted using at least one public key of the second keys, and wherein an element in the user data is encrypted using the private key of the second keys; adding an access structure for a data access permission manager during creation of the cryptographic container for user data, wherein at least one first key for the added access structure of the data access permission manager is placed in at least one access structure in the user data processor, wherein the at least one first key is encrypted; and When a request to access the cryptographic container is received from the user data processor, access to the cryptographic container is authorized based on at least one access structure formed for the user data processor.

15. The system according to claim 14, wherein: The cryptographic container encrypts the at least two elements using the first key.

16. A non-transitory computer-readable medium storing computer-executable instructions for authorizing a user data processor to access a cryptographic container of user data, comprising instructions for: Create a password container for user data, where The cryptographic container receives at least two elements of the user data and encrypts the at least two elements; establishing permissions for the user data processor to access each of at least two elements of the user data using a plurality of first keys, the plurality of first keys being used to separately encrypt each of the at least two elements of the user data; forming at least one access structure for the user data processor, wherein forming the at least one access structure comprises: placing each first key of the plurality of first keys in the at least one access structure based on the established permissions for accessing each of the at least two elements of the user data; and receiving, from the user data processor, a second key linked to the user data processor, the second key to be used to access the plurality of first keys, wherein the second key is a combination of at least one pair of keys, the at least one pair of keys comprising at least one private key and at least one public key, wherein each first key in the plurality of first keys is encrypted using at least one public key of the second keys, and wherein an element in the user data is encrypted using the private key of the second keys; adding an access structure for a data access permission manager during creation of the cryptographic container for user data, wherein at least one first key for the added access structure of the data access permission manager is placed in at least one access structure in the user data processor, wherein the at least one first key is encrypted; and When a request to access the cryptographic container is received from the user data processor, access to the cryptographic container is authorized based on at least one access structure formed for the user data processor.

Citation Information

Patent Citations

  • System, method, and computer program product for providing digital rights management of protected content

    CN101014922A

  • Data storage method and device and computing equipment

    CN111414628A