Client-Side Encryption with DRM for Secure Cloud Data Collaboration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based data storage systems face security issues due to lack of control over data and vulnerabilities, as cloud operators have access to sensitive information, and traditional access control methods are not trustworthy.

Innovation Solution

A technique combining group key-based client-side encryption with digital rights management (DRM) to secure data objects during collaboration, allowing users to manage access rights and maintain control over data even when stored in the cloud, using a service provider's platform for secure sharing and synchronization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud-based data storage systems are used, then data accessibility and flexibility are improved, but data security and control are worsened

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the decryption capability from the cloud storage system and places it exclusively on client devices. Only authorized users possess the decryption keys locally, while the cloud storage system merely stores encrypted data without access to decryption capabilities. This extraction resolves the contradiction by maintaining cloud-based accessibility while eliminating cloud-based security vulnerabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the security model into distinct components: encryption keys are segmented from cloud storage, decryption capabilities are segmented to specific authorized users, and data is segmented into encrypted blocks. This segmentation ensures that compromising the cloud storage system does not compromise data security, as the critical security elements remain distributed and inaccessible to the cloud provider.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If traditional access control lists are used, then access management is simplified, but trust in the reference monitor is worsened

Engineering Contradiction:
Improveaccess control simplicityVSAvoidreference monitor trust
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent replaces the mechanical trust-based access control system (where a central reference monitor enforces policies) with a cryptographic system based on mathematical principles. Instead of relying on a trusted reference monitor to enforce access control lists, the system uses cryptographic keys and digital signatures to mathematically guarantee access rights. This substitution eliminates the trust requirement while maintaining access control functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If cryptographic protection mechanisms are used, then data security is improved, but key management complexity is worsened

Engineering Contradiction:
Improvedata securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key management service as an intermediary that handles the complexity of cryptographic key management. This service enables users to securely store, retrieve, and manage encryption keys without requiring users to directly implement complex key management protocols. The intermediary absorbs the management complexity while maintaining strong cryptographic protection, resolving the contradiction between security and complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10178075B2Client-side encryption with DRM
Publication Date: 2019.01.08 TRESORIT KFT
  • US10178075B2 patent drawing
  • US10178075B2 patent drawing
  • US10178075B2 patent drawing

AI summary

A technique for extending security to a data object (e.g., a document, a file, a message, etc.) once it has been shared and during collaboration with others who have access rights to that data object. The approach advantageously combines group key-based client-side encryption to secure the data object as it travels from a user's computer, to the cloud, and to a chosen collaborator's computer, together with a digital rights management (DRM) layer that provides permission management that associates a set of permission rights that travel with the data object.