Cryptocontainer Access Control for User Data Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data security mechanisms fail to provide transparent and effective protection against improper dissemination and misuse of user data collected from devices, offering weak protection against tracking by third-party applications and lacking user transparency.

Innovation Solution

A method and system that utilize a cryptocontainer to store user data, where access is granted through a secure access structure involving encryption keys, ensuring that only authorized user data processors can access and manage the data, with rights defined for specific actions like reading and writing, and using a combination of private and public keys for encryption and decryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is collected and distributed around the network without clear consent, then data availability for processing is improved, but user privacy and data security deteriorate

Engineering Contradiction:
Improvedata availabilityVSAvoiduser privacy violation
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary encryption of user data before distribution, creating a cryptocontainer that maintains data availability for authorized processing while protecting privacy from the outset. The data is encrypted with a first key and access structures are prepared in advance, so that when data is distributed across the network, it remains secure even without explicit user consent for each distribution action.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary encryption layer (cryptocontainer with access structures) between the user data and the processing systems. This intermediary structure controls access to encrypted data elements, allowing data to be distributed and processed by multiple parties while maintaining user privacy through cryptographic protection and access control mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If third-party access to user data is granted through existing mechanisms, then data processing capability is improved, but transparency and user control deteriorate

Engineering Contradiction:
Improvedata processing capabilityVSAvoiduser control information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent segments user data into encrypted data elements within a cryptocontainer structure, with separate access structures for different parties. This segmentation allows multiple third parties to access specific encrypted elements based on predefined rights without revealing the overall data structure or user control mechanisms to them, maintaining transparency for the user while enabling distributed processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different access structures are created with different qualities of access rights for different third parties. Each access structure contains encrypted keys and permissions tailored to specific processing needs, allowing fine-grained control over what each third party can access and process, while maintaining user transparency and control through the centralized cryptocontainer management.

Inventive Principle:
Principle #3Local quality

3Reliability

If existing security mechanisms are used to protect user data, then data security is improved, but ease of access and operational flexibility deteriorate

Engineering Contradiction:
Improvedata securityVSAvoiddata access ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The cryptocontainer system provides self-service security through automated encryption and access control. Once the cryptocontainer is created with access structures, the system automatically manages encryption keys and access permissions without requiring manual security interventions. Third parties can access data by presenting their identifiers, and the system automatically verifies permissions and decrypts appropriate encrypted elements, maintaining high security while improving ease of access.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3975024A1System and method of granting a user data processor access to a container of user data
Publication Date: 2022.03.30 AO KASPERSKY LAB
  • EP3975024A1 patent drawingFigure 1
  • EP3975024A1 patent drawingFigure 2
  • EP3975024A1 patent drawingFigure 2a

AI summary

Disclosed herein are systems and methods for granting a user data processor access to a cryptocontainer of user data. In one example, an exemplary method comprises, creating a cryptocontainer for user's data, wherein the cryptocontainer receives at least one element of the user's data and encrypts the element; for the user data processor, establishing rights for accessing the element using a first key, and forming at least one access structure, the forming including, placing the first key in the access structure based on the established rights, receiving, from the user data processor, a second key linked to the user data processor which is to be used for accessing the first key, and encrypting the first key with the second key; and when a request for access to the cryptocontainer is received, granting, to the user data processor, access to the cyptocontainer based on the formed at least one access structure.