System and method for maintaining immutable data access logs with privacy - Patents.com
The system addresses the risks of key mishandling and log manipulation in cloud services by encrypting and committing data access logs to a distributed ledger, ensuring immutability, privacy, and cryptographic verifiability.
Patent Information
- Application Number
- JP2024124717
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-04-26
- Filing Date
- 2024-07-31
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2040-03-12
AI Technical Summary
Current cloud services that do not implement 'Hyok' (Holding Your Own Key) put client data at risk due to mishandling of keys by cloud providers, and lack of visibility into key management systems, which can lead to manipulation or withholding of access logs.
A system and method for maintaining an immutable data access log using privacy, where data from clients is received, stored, and actions affecting the data generate log entries, which are then encrypted using the client's public key and committed to a distributed ledger like blockchain, ensuring immutability and cryptographic verifiability.
This approach ensures that data access logs are immutable, cryptographically verifiable, and private, protecting client data from unauthorized access and manipulation, while providing auditable logs that enhance security and trust in cloud services.
Smart Images

Figure 0007675909000001 
Figure 0007675909000002 
Figure 0007675909000003
Abstract
Description
[Technical field]
[0001] The present disclosure relates generally to systems and methods for maintaining an immutable data access log with privacy. [Background technology]
[0002]
[0002] Bring Your Own Key (BYOK) or Hall Cloud services that do not actually enforce hold your own key (HYOK) may expose their clients to unnecessary risks: mishandling of the keys stored and used by the cloud service provider may compromise all data stored in the cloud, potentially undetectable by the client.
[0003]
[0003] The next best control available is visibility into the key management system in the cloud environment, but it also relies on the cloud provider not to manipulate or withhold the access logs. Additionally, cloud providers need to protect themselves and other clients from exposing too much information in the logs themselves. This requires cloud providers to strictly limit access and, optionally, redact some of the log entries. Summary of the Invention [Means for solving the problem]
[0004]
[0004] A system and method for maintaining an immutable data access log with privacy is disclosed. In one embodiment, a method for maintaining an immutable data access log with privacy in a cloud provider having at least one computer processor and a plurality of clients may include: (1) receiving data from a data owner, where the data owner is one of the clients; (2) storing the data in a cloud storage; (3) performing an action or condition that affects the data stored in the cloud storage; (4) generating a log entry associated with the action or condition; (5) encrypting at least a portion of the log entry with the data owner's public key; and (6) committing the log entry, including the encrypted portion, to a distributed ledger such that the committed log entry is immutable and cryptographically verifiable.
[0005] In one embodiment, the data received from the data owner may be encrypted.
[0006] In one embodiment, the action or condition may include accessing data stored in cloud storage.
[0006]
[0007] In one embodiment, the action or condition may include encrypting or decrypting data stored in cloud storage.
[0008] In one embodiment, the action or condition may include an environmental change to the data stored in the cloud storage.
[0007]
[0009] In one embodiment, the action or condition may include a security event involving data stored in cloud storage.
[0010] In one embodiment, the action or condition may be part of a service offered by a cloud provider.
[0008]
[0011] In one embodiment, the public key may be maintained in a public key infrastructure by the cloud provider.
[0012] In one embodiment, the log entry may include a timestamp of the action or condition, an identification of the system associated with the action or condition, an identification of at least a portion of the data that was accessed, and the like.
[0009]
[0013] In one embodiment, the distributed ledger may be a blockchain-based distributed ledger or an Ethereum-based distributed ledger.
[0014] According to another embodiment, a system for maintaining an immutable data access log with privacy is disclosed. The system may include a cloud provider with at least one computer processor, a cloud provider with a plurality of clients, and a distributed ledger. The cloud provider may receive data from a data owner, one of the clients, store the data in a cloud storage, perform an action or condition that affects the data stored in the cloud storage, generate a log entry associated with the action or condition, encrypt at least a portion of the log entry with the data owner's public key, and commit the log entry including the encrypted portion to the distributed ledger such that the committed log entry is immutable and cryptographically verifiable.
[0010]
[0015] In one embodiment, the data received from the data owner may be encrypted.
[0016] In one embodiment, the action or condition may include accessing data stored in cloud storage.
[0011]
[0017] In one embodiment, the action or condition may include encrypting or decrypting data stored in cloud storage.
[0018] In one embodiment, the action or condition may include an environmental change to the data stored in the cloud storage.
[0012]
[0019] In one embodiment, the action or condition may include a security event involving data stored in cloud storage.
[0020] In one embodiment, the action or condition may be part of a service offered by a cloud provider.
[0013]
[0021] In one embodiment, the public key may be maintained in a public key infrastructure by the cloud provider.
[0022] In one embodiment, the log entry may include a timestamp of the action or condition, an identification of the system associated with the action or condition, an identification of at least a portion of the data that was accessed, and the like.
[0014]
[0023] For a more complete understanding of the present invention, its objects and advantages, reference is now made to the following descriptions taken in conjunction with the accompanying drawings, in which: [Brief description of the drawings]
[0015] [Figure 1]
[0024] FIG. 1 illustrates a system for maintaining an immutable data access log with privacy according to one embodiment. [Diagram 2]
[0025] FIG. 2 illustrates a method for creating an immutable data log with privacy according to one embodiment. [Diagram 3]
[0026] FIG. 3 illustrates a method for accessing an immutable data log with privacy according to one embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0016]
[0027] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Embodiments relate to systems and methods for immutable logs with privacy.
[0028] Embodiments may apply a system of cryptographically guaranteed guarantees to log collection, storage, and access systems that support cloud architectures, for example using distributed ledgers such as blockchain, Ethereum, or other suitable distributed ledgers that can use a consensus model to store log entries in a tamper-evident (e.g., cryptographically verifiable) and immutable manner. Additionally, embodiments may use policies to determine which portions of log entries need to be encrypted and then encrypt those portions (or the entire entry) using private key encryption before committing them to the distributed ledger.
[0017]
[0029] In embodiments, the implementation of software and technical controls becomes auditable by a third party, which adds a layer of assurance previously unattainable with cloud services.
[0018]
[0030] 1, according to one embodiment, a system for immutable logs with privacy is disclosed. The system 100 may include a cloud provider 150, which may include a public key infrastructure 155, a distributed ledger 160, log entries 165, and cloud storage 170.
[0019]
[0031] System 100 may further include clients 110, 120, and 130, each of which may maintain or be associated with a distributed ledger 115, 125, and 135, respectively. It should be noted that while FIG. 1 shows three clients 110, 120, and 130, a fewer or greater number of clients may be provided, as needed and / or desired.
[0020]
[0032] Cloud provider 150 may be any suitable cloud provider and may provide services such as software-as-a-service. Cloud provider 150 may provide one or more worker systems (not shown) that provide the services.
[0021]
[0033] Cloud provider 150 may receive data from clients 110, 120, 130 and may maintain the data in cloud storage 170. In one embodiment, the data may be received in any suitable manner. For example, the data may be encrypted by one of clients 110, 120, 130, transferred to cloud provider 150, and decrypted when received by cloud provider 150.
[0022]
[0034] In another embodiment, data maintained by cloud provider 150 may be generated by cloud provider 150 or by a third party (not shown). Examples of such data may include aggregated / processed data feeds from other systems, information specific to cloud provider 150's systems (e.g., configuration data), etc.
[0023]
[0035] Data stored in cloud storage may be encrypted at rest using keys maintained by the cloud provider 150. In one embodiment, data for each client 110, 120, 130 may be encrypted with a different key for each client 110, 120, 130.
[0024]
[0036] The public key infrastructure 155 comprises clients 110, 120, and 1 The public key infrastructure 155 may maintain up to 30 public keys. The public keys stored in the public key infrastructure 155 may be used to encrypt log entries 165.
[0025]
[0037] Log entries 165 may reflect any action or condition that may affect the availability or access to data stored in cloud storage 170. Examples may include data received by cloud provider 150, data generated by cloud provider 150 or a third party, encryption and / or decryption of data, attempts to access data, environmental changes, security events, etc. In one embodiment, actions related to any other virtual resources (e.g., virtual desktops, server infrastructure, etc.) managed by cloud provider 150 on behalf of clients 110, 120, 130 may be logged.
[0026]
[0038] In one embodiment, log entry 165 may include a timestamp of the access, the accessing system, the data accessed, the requested action (e.g., read, write, delete), the resulting action (e.g., allow, deny, invalid), the destination system (e.g., the system that processed the request), etc.
[0027]
[0039] In one embodiment, certain portions or all of the log entries may be encrypted using the public key of the data owner (e.g., client 110, 120, 130). In one embodiment, data that is deemed sensitive to cloud provider 150 and does not need to be disclosed, etc., may be further encrypted. For example, the IP addresses of working systems in cloud storage 150 may be encrypted or prevented from being disclosed to clients 110, 120, 130. Other examples include logging of activity of other customers or tenants of the cloud service, access to customer data by law enforcement (e.g., a gag order may be issued against cloud provider 150 to restrict access to the public key), and other data protection measures. This may include cases where disclosure of the quality is prohibited.
[0028]
[0040] As shown with reference to FIG. 2, according to one embodiment, a method for creating immutable data logs with privacy is disclosed.
[0041] At step 205, the cloud provider may receive the data from the client. In one embodiment, the cloud provider may be any suitable cloud provider, including a software-as-a-service cloud provider.
[0029]
[0042] In one embodiment, the data may be stored in cloud storage, for example, the data may be encrypted and stored in cloud storage.
[0043] In one embodiment, the data may be encrypted using the key of the client that provided the data.
[0030]
[0044] At step 210, actions or conditions may occur that may affect the availability or access to data stored in the cloud storage. Examples of such actions or conditions include receipt of data by the cloud provider, encryption and / or decryption of data, attempts to access data, environmental changes, security events, etc. In one embodiment, actions related to any other virtual resources (e.g., virtual desktops, server infrastructure, etc.) managed by the cloud provider on behalf of the client may be logged.
[0031]
[0045] In step 215, the cloud provider system creating the action or condition may generate a log entry. In one embodiment, the worker system (i.e., the cloud system running a service on the data) may generate a log entry. The log entry may include a timestamp of the access, the accessing system ... The request may include the requested data, the requested action (e.g., read, write, delete), the resulting action (e.g., allow, deny, invalid), the destination system (e.g., the system that will process the request), and any other information that may be necessary and / or desirable.
[0032]
[0046] At step 220, a portion of the log entry may be encrypted. For example, the data may be encrypted using the data owner's public key. In one embodiment, data that is considered sensitive to the cloud provider, does not need to be disclosed, etc. may be further encrypted.
[0033]
[0047] In step 225, the log entry may be signed with a private key for the system creating the log entry and / or for the cloud provider.
[0048] At step 230, the log entry may be committed to a distributed ledger, such as a blockchain-based distributed ledger, an Ethereum-based distributed ledger, or a similar distributed ledger. In one embodiment, other nodes in the distributed ledger network (e.g., distributed ledgers associated with clients of the cloud provider) may further commit the log entry to their distributed ledgers.
[0034]
[0049] In one embodiment, each log entry may have a one-to-one commitment to the distributed ledger, in another embodiment, log entries may be batched, collected, and / or transmitted periodically or as otherwise necessary and / or desired to prevent frequency analysis of their commitments.
[0035]
[0050] In one embodiment, it may not be necessary to commit all of the content of a log entry directly to the distributed ledger: instead, a cryptographic signature of the content may be provided to the distributed ledger, and all of the content, which may be encrypted, may be stored elsewhere.
[0036]
[0051] Hence the use of these two techniques: Frequency analysis is not possible by a third party who has access to the ledger but not to all the logs in the data store.
[0037]
[0052] As shown with reference to FIG. 3, according to one embodiment, a method for accessing immutable data logs with privacy is disclosed.
[0053] In step 305, the data owner may retrieve log entries, such as data access log entries, from the distributed ledger. In one embodiment, some of the log entries may be in clear text, some may be encrypted with a key for the data owner, some may be encrypted with a key for another data owner, and some may be masked or redacted with a key for the cloud provider.
[0038]
[0054] In another embodiment, the cryptographic signature or digest may be retrieved from the distributed ledger.
[0055] In step 310, the encrypted portion of the log entry that was encrypted with the data owner's key (eg, the data owner's public key) may be decrypted using, for example, the data owner's private key.
[0039]
[0056] Other portions of the log entry, which are encrypted, masked, or otherwise obscured using other data owners' keys in step 315, may not be available to the data owners.
[0040]
[0057] In step 320, an audit process may be used to ensure the validity of the log entries. In one embodiment, the audit process audits all This may include verifying the integrity of the records (eg, verifying cryptographic signatures within and between each record) and verifying the decryption of the record contents and any signatures included.
[0041]
[0058] The embodiments disclosed herein are not mutually exclusive, and features and elements from one embodiment may be used with another, as required and / or desired.
[0042]
[0059] Below, general aspects of embodiments of the systems and methods of the present invention are described.
[0060] The inventive system or a portion of the inventive system may be in the form of a "processing machine", such as, for example, a general purpose computer. The term "processing machine" as used herein should be understood to include at least one processor using at least one memory. The at least one memory stores a set of instructions. The instructions may be permanently or temporarily stored in one or more memories of the processing machine. The processor executes the instructions stored in the one or more memories to process data. The set of instructions may include various instructions to perform a particular task or tasks, such as those described above. Such a set of instructions to perform a particular task may be characterized as a program, a software program, or simply software.
[0043]
[0061] In one embodiment, the processing machine may be a special purpose processor.
[0062] As noted above, a processing machine executes instructions stored in one or more memories to process data. This processing of data may, for example, be in response to commands by one or more users of the processing machine, in response to previous processing, in response to requests by another processing machine, and / or other input.
[0044]
[0063] As mentioned above, the processing machine used to implement the present invention can be a general-purpose computer. However, the processing machine described above can utilize any of a wide variety of other technologies, including special purpose computers, e.g., computer systems including microcomputers, minicomputers, or mainframes, programmable microprocessors, microcontrollers, peripheral integrated circuit elements, CSICs (customer specific integrated circuits) or ASICs (application specific integrated circuits) or other integrated circuits, logic circuits, digital signal processors, programmable logic devices such as FPGAs, PLDs, PLAs, or PALs, or other devices or configurations of devices capable of implementing the steps of the process of the present invention.
[0045]
[0064] The processing machine used to implement the present invention may utilize any suitable operating system. Thus, embodiments of the present invention may be implemented using any suitable operating system, including, but not limited to, the iOS operating system, the OS X operating system, the Android operating system, the Microsoft Windows operating system, the Unix operating system, the Linux operating system, the Xenix operating system, the IBM AIX operating system, the Hewlett-Packard UX operating system, the Novell This may include processing machines running the Netware™ operating system, the Sun Microsystems Solaris™ operating system, the OS / 2™ operating system, the BeOS operating system, the Macintosh operating system, the Apache operating system, the OpenStep™ operating system, or another operating system or platform.
[0046]
[0065] It is understood that in order to implement the method of the present invention as described above, it is not necessary that the processor and / or memory of the processing machine are physically located at the same geographic location. That is, each of the processors and memories used by the processing machine may be located at geographically separate locations and communicatively connected in any suitable manner. In addition, it is understood that each of the processors and / or memories may be configured in different physical devices. Thus, it is not necessary that the processor is a single device at one location and the memory is another single device at another location. That is, it is contemplated that the processor may be two devices at two different physical locations. The two separate devices may be connected in any suitable manner. In addition, the memory may include two or more portions of the memory at two or more physical locations.
[0047]
[0066] To further explain, the processing as described above is performed by various components and various memories. However, it is understood that the processing performed by two separate components as described above may be performed by a single component according to further embodiments of the present invention. Furthermore, the processing performed by one separate component as described above may be performed by two separate components. Similarly, the memory storage performed by two separate memory portions as described above may be performed by a single memory portion according to further embodiments of the present invention. Furthermore, the memory storage performed by one separate memory portion as described above may be performed by two memory portions.
[0048]
[0067] Further, various technologies may be used to provide communication between the various processors and / or memories, and to enable the processors and / or memories of the present invention to communicate with any other entity, i.e., to obtain further instructions or to access and use a remote memory store. Such technologies used to provide such communication may include, for example, a network, the Internet, an intranet, an extranet, a LAN, Ethernet, wireless communication via a cell tower or satellite, or any client-server system that provides communication. Such communication technologies may use any suitable protocol, such as, for example, TCP / IP, UDP, or OSI.
[0049]
[0068] As mentioned above, a set of instructions may be used in the process of the present invention. The set of instructions may be in the form of a program or software. The software may be in the form of, for example, system software or application software. The software may also be in the form of, for example, a collection of separate programs, a program module within a larger program, or a portion of a program module. The software used may also include modular programming in the form of object-oriented programming. The software tells the processing machine what to do with the data being processed.
[0050]
[0069] It is further understood that the instructions or sets of instructions used in the implementation and operation of the present invention may be in any suitable form such that a processing machine can read the instructions. For example, the instructions forming a program may be in the form of a suitable programming language that is converted into machine code or object code to enable one or more processors to read the instructions. That is, written lines of programming code or source code in a particular programming language are converted into machine code using a compiler, assembler, or interpreter. The machine code is, for example, binary coded machine instructions that are specific to a particular type of processing machine, i.e., a particular type of computer. The computer understands the machine code.
[0051]
[0070] Any suitable programming language may be used in accordance with various embodiments of the present invention. By way of example, programming languages used may include, for example, assembly language, Ada, APL, Basic, C, C++, COBOL, dBase, Forth, Fortran, Java, Modula-2, Pascal, Prolog, REXX, Visual Basic, and / or JavaScript. Furthermore, it is not necessary that a single type of instruction or a single programming language be utilized in connection with the operation of the systems and methods of the present invention. Rather, any number of different programming languages may be utilized as needed and / or desired.
[0052]
[0071] Similarly, the instructions and / or data used in practicing the present invention may utilize any compression or encryption technique or algorithm, as may be desired. An encryption module may be used to encrypt the data. Additionally, files or other data may be decrypted using, for example, an appropriate decryption module.
[0053]
[0072] As mentioned above, the present invention can be embodied in the form of a processing machine, including, for example, a computer or computer system including at least one memory, by way of example. It should be understood that the set of instructions, i.e., software, that enables the computer operating system to carry out the above-mentioned operations, may be included in any of a wide variety of one or more media, as desired. Furthermore, the data processed by the set of instructions may also be included in any of a wide variety of one or more media. That is, the particular medium within the processing machine utilized to hold the set of instructions and / or data used in the present invention, i.e., memory, may take, for example, any of a variety of physical forms or transmission media. By way of example, the medium may be in the form of paper, transparency, compact disc, DVD, integrated circuit, hard disk, floppy disk, optical disk, magnetic tape, RAM, ROM, PROM, EPROM, wire, cable, fiber, communication channel, satellite transmission, memory card, SIM card, or other remote transmission, as well as any other medium or source of data that can be read by the processor of the present invention.
[0054]
[0073] Furthermore, the memory or memories used in a processing machine implementing the present invention may be in any of a wide variety of forms that enable the memory to hold instructions, data, or other information, as desired. Thus, the memory may be in the form of a database for holding data. The database may use any desired file organization, such as, for example, a flat file organization or a relational database organization.
[0055]
[0074] In the systems and methods of the present invention, various "user interfaces" are utilized to allow a user to interface with one or more processing machines used to implement the present invention. As used herein, a user interface includes any hardware, software, or combination of hardware and software used by a processing machine that allows a user to interact with the processing machine. A user interface may be in the form of, for example, a dialog screen. A user interface may further include any of a mouse, a touch screen, a keyboard, a keypad, a voice reader, a voice recognizer, a dialog screen, a menu box, a list, a check box, a toggle switch, a push button, or any other device that allows a user to receive information regarding the operation of the processing machine as the other device processes a set of instructions and / or provides information to the processing machine. Thus, a user interface is any device that provides communication between a user and a processing machine. Information provided by a user to a processing machine through a user interface may include, for example, commands, data, or the like. It may be a selection, or some other form of input.
[0056]
[0075] As discussed above, a user interface is utilized by a processing machine that executes a set of instructions, such that the processing machine processes data for a user. A user interface is generally used by a processing machine to interact with a user to convey information or receive information from the user. However, it should be understood that in accordance with some embodiments of the systems and methods of the present invention, it is not necessary for a human user to actually interact with a user interface utilized by a processing machine of the present invention. Rather, it is also contemplated that a user interface of the present invention may interact, i.e., convey information and receive information, with another processing machine rather than a human user. Thus, the other processing machine may be considered a user. Additionally, it is contemplated that a user interface utilized in the systems and methods of the present invention may interact partially with another processing machine or machines and partially with a human user.
[0057]
[0076] It will be readily understood by those skilled in the art that the present invention is susceptible to a wide range of utility and applications. Numerous embodiments and adaptations of the present invention other than those described herein, as well as numerous variations, modifications, and equivalents, will be apparent from, or will reasonably be suggested by, the present invention and the foregoing description of the invention without departing from the spirit or scope of the invention.
[0058]
[0077] Thus, while the present invention has been described in detail herein with reference to exemplary embodiments, it should be understood that the disclosure is merely illustrative and exemplary of the invention, and is made to provide an enabling disclosure of the invention. Thus, the foregoing disclosure is not intended to be construed as limiting the invention or otherwise excluding any other such embodiments, adaptations, variations, modifications, or equivalents.
Claims
1. 1. A method for maintaining a privacy immutable data access log, comprising: A cloud provider having at least one computer processor and a plurality of clients, comprising: receiving data from a data owner, the data owner being one of the clients; storing the data in a cloud storage; executing an action or condition that affects the data stored in the cloud storage; generating a log entry associated with the action or condition, the log entry comprising a timestamp of the action or condition, an identification of a system associated with the action or condition, and an identification of the data associated with the action or condition; encrypting at least a portion of the timestamp, the identification of the system associated with the action or condition, and the identification of the data associated with the action or condition with a public key of the data owner; committing a cryptographic signature of the encrypted portion of the log entry to a distributed ledger such that the committed log entry is immutable and cryptographically verifiable; and storing the log entry, including the encrypted portion, in a location separate from the distributed ledger.
2. The method of claim 1 , wherein the data received from the data owner is encrypted.
3. The method of claim 1 , wherein the action or condition comprises accessing the data stored in the cloud storage.
4. The method of claim 1 , wherein the action or condition comprises encrypting or decrypting the data stored in the cloud storage.
5. The method of claim 1 , wherein the action or condition comprises an environmental change to the data stored in the cloud storage.
6. The method of claim 1 , wherein the action or condition comprises a security event involving the data stored in the cloud storage.
7. The method of claim 3 , wherein the action or condition is part of a service offered by the cloud provider.
8. 2. The method of claim 1 , wherein the distributed ledger comprises a blockchain-based distributed ledger or an Ethereum-based distributed ledger.
9. 1. A system for maintaining an immutable data access log with privacy, comprising: A cloud provider having at least one computer processor and a plurality of clients; It has a distributed ledger. the cloud provider receives data from a data owner, the data owner being one of the clients; The cloud provider stores the data in a cloud storage; the cloud provider executes an action or condition that affects the data stored in the cloud storage; the cloud provider generates a log entry associated with the action or condition, the log entry comprising a timestamp of the action or condition, an identification of a system associated with the action or condition, and an identification of the data associated with the action or condition; the cloud provider encrypts at least a portion of the timestamp of the log entry, the identification of the system associated with the action or condition, and the identification of the data associated with the action or condition with a public key of the data owner; the cloud provider commits a cryptographic signature of the encrypted portion of the log entry to a distributed ledger such that the committed log entry is immutable and cryptographically verifiable; The cloud provider stores the log entries, including the encrypted portions, in a location separate from the distributed ledger.
10. The system of claim 9 , wherein the data received from the data owner is encrypted.
11. The system of claim 9 , wherein the action or condition comprises accessing the data stored in the cloud storage.
12. The system of claim 9 , wherein the action or condition comprises encrypting or decrypting the data stored in the cloud storage.
13. The system of claim 9 , wherein the action or condition comprises an environmental change to the data stored in the cloud storage.
14. The system of claim 9 , wherein the action or condition comprises a security event involving the data stored in the cloud storage.
15. The system of claim 11 , wherein the action or condition is part of a service offered by the cloud provider.
16. The system of claim 9 , wherein the public key is maintained in a public key infrastructure by the cloud provider.
17. 10. The system of claim 9, wherein the distributed ledger comprises a blockchain-based distributed ledger or an Ethereum-based distributed ledger.
Citation Information
Patent Citations
Video screening apparatus
JP2008228127A
Systems and methods for distributed identity verification
US20170250972A1
Securely storing content within public clouds
US20190087597A1
Key exchange system and key exchange method
WO2018235845A1