Client-Side Encryption with DRM for Secure Cloud Data Collaboration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based data storage systems face security issues due to lack of control over data and vulnerabilities, as cloud operators have access to sensitive information, and traditional access control methods are not trustworthy.
Innovation Solution
A technique combining group key-based client-side encryption with digital rights management (DRM) to secure data objects during collaboration, allowing users to manage access rights and maintain control over data even when stored in the cloud, using a service provider's platform for secure sharing and synchronization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If cloud-based data storage systems are used, then data accessibility and flexibility are improved, but data security and control are worsened
Solution Approach 1:
The patent extracts the decryption capability from the cloud storage system and places it exclusively on client devices. Only authorized users possess the decryption keys locally, while the cloud storage system merely stores encrypted data without access to decryption capabilities. This extraction resolves the contradiction by maintaining cloud-based accessibility while eliminating cloud-based security vulnerabilities.
Solution Approach 2:
The system segments the security model into distinct components: encryption keys are segmented from cloud storage, decryption capabilities are segmented to specific authorized users, and data is segmented into encrypted blocks. This segmentation ensures that compromising the cloud storage system does not compromise data security, as the critical security elements remain distributed and inaccessible to the cloud provider.
2Device complexity
If traditional access control lists are used, then access management is simplified, but trust in the reference monitor is worsened
Solution Approach 1:
The patent replaces the mechanical trust-based access control system (where a central reference monitor enforces policies) with a cryptographic system based on mathematical principles. Instead of relying on a trusted reference monitor to enforce access control lists, the system uses cryptographic keys and digital signatures to mathematically guarantee access rights. This substitution eliminates the trust requirement while maintaining access control functionality.
3Reliability
If cryptographic protection mechanisms are used, then data security is improved, but key management complexity is worsened
Solution Approach 1:
The patent introduces a key management service as an intermediary that handles the complexity of cryptographic key management. This service enables users to securely store, retrieve, and manage encryption keys without requiring users to directly implement complex key management protocols. The intermediary absorbs the management complexity while maintaining strong cryptographic protection, resolving the contradiction between security and complexity.
Data Source
AI summary
A technique for extending security to a data object (e.g., a document, a file, a message, etc.) once it has been shared and during collaboration with others who have access rights to that data object. The approach advantageously combines group key-based client-side encryption to secure the data object as it travels from a user's computer, to the cloud, and to a chosen collaborator's computer, together with a digital rights management (DRM) layer that provides permission management that associates a set of permission rights that travel with the data object.


