Cryptocontainer Access Control for User Data Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data security mechanisms fail to provide transparent and effective protection against improper dissemination and misuse of user data collected from devices, offering weak protection against tracking by third-party applications and lacking user transparency.
Innovation Solution
A method and system that utilize a cryptocontainer to store user data, where access is granted through a secure access structure involving encryption keys, ensuring that only authorized user data processors can access and manage the data, with rights defined for specific actions like reading and writing, and using a combination of private and public keys for encryption and decryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is collected and distributed around the network without clear consent, then data availability for processing is improved, but user privacy and data security deteriorate
Solution Approach 1:
The system performs preliminary encryption of user data before distribution, creating a cryptocontainer that maintains data availability for authorized processing while protecting privacy from the outset. The data is encrypted with a first key and access structures are prepared in advance, so that when data is distributed across the network, it remains secure even without explicit user consent for each distribution action.
Solution Approach 2:
The patent introduces an intermediary encryption layer (cryptocontainer with access structures) between the user data and the processing systems. This intermediary structure controls access to encrypted data elements, allowing data to be distributed and processed by multiple parties while maintaining user privacy through cryptographic protection and access control mechanisms.
2Productivity
If third-party access to user data is granted through existing mechanisms, then data processing capability is improved, but transparency and user control deteriorate
Solution Approach 1:
The patent segments user data into encrypted data elements within a cryptocontainer structure, with separate access structures for different parties. This segmentation allows multiple third parties to access specific encrypted elements based on predefined rights without revealing the overall data structure or user control mechanisms to them, maintaining transparency for the user while enabling distributed processing.
Solution Approach 2:
Different access structures are created with different qualities of access rights for different third parties. Each access structure contains encrypted keys and permissions tailored to specific processing needs, allowing fine-grained control over what each third party can access and process, while maintaining user transparency and control through the centralized cryptocontainer management.
3Reliability
If existing security mechanisms are used to protect user data, then data security is improved, but ease of access and operational flexibility deteriorate
Solution Approach 1:
The cryptocontainer system provides self-service security through automated encryption and access control. Once the cryptocontainer is created with access structures, the system automatically manages encryption keys and access permissions without requiring manual security interventions. Third parties can access data by presenting their identifiers, and the system automatically verifies permissions and decrypts appropriate encrypted elements, maintaining high security while improving ease of access.
Data Source
Figure 1
Figure 2
Figure 2a
AI summary
Disclosed herein are systems and methods for granting a user data processor access to a cryptocontainer of user data. In one example, an exemplary method comprises, creating a cryptocontainer for user's data, wherein the cryptocontainer receives at least one element of the user's data and encrypts the element; for the user data processor, establishing rights for accessing the element using a first key, and forming at least one access structure, the forming including, placing the first key in the access structure based on the established rights, receiving, from the user data processor, a second key linked to the user data processor which is to be used for accessing the first key, and encrypting the first key with the second key; and when a request for access to the cryptocontainer is received, granting, to the user data processor, access to the cyptocontainer based on the formed at least one access structure.