Distributed Policy Proofs for Encrypted Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing public-key cryptography systems face challenges in ensuring secure access to encrypted data without compromising the private key, particularly in scenarios involving blind subpoenas where unauthorized access needs to be prevented while allowing access to authorized entities.

Innovation Solution

A zero-trust distributed architecture is employed, using encrypted secret shares and policy proofs to validate access requests from multiple entities, ensuring that access criteria are met before granting access to encrypted data, without decrypting the secret shares.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional public-key cryptography is used to protect encrypted data, then data security is maintained, but access control becomes complex and computationally intensive when multiple entities need to validate access requests

Engineering Contradiction:
Improvedata securityVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the access control process by introducing policy proofs that are divided into multiple components, each validated by different entities. The policy proof is split into a first portion and second portion, allowing distributed validation without requiring all entities to process the entire proof, thus reducing computational complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where policy proofs serve as mediators between the encrypted data and the entities seeking access. Rather than direct complex interactions between multiple entities and the encrypted data, the policy proof acts as an intermediary that encapsulates access criteria, simplifying the validation process while maintaining strong security guarantees.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple entities validate access requests with full policy proofs, then access security is ensured, but compute resources are wasted by processing complete proofs when only partial validation is needed

Engineering Contradiction:
Improveaccess securityVSAvoidcompute resource wastage
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies segmentation by dividing the policy proof into multiple portions, where each entity validates only the relevant portion rather than processing the entire proof. This reduces computational energy consumption while maintaining security, as each entity performs minimal validation on its assigned segment of the policy proof.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements partial action by allowing entities to validate only the necessary portion of the policy proof required for their specific access request, rather than processing the complete proof. This partial validation approach reduces computational overhead and energy consumption while still ensuring adequate security verification for each entity's access needs.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If blind subpoena access is granted without user notification, then authorized access is enabled, but user privacy and control are compromised

Engineering Contradiction:
Improveaccess granting capabilityVSAvoiduser notification
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent introduces policy proofs as intermediaries that enable blind subpoena access without directly compromising user privacy. The policy proof serves as a mediator that verifies access criteria are met while allowing the access process to proceed without notifying the user, thus balancing operational ease with privacy preservation through cryptographic verification rather than direct communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250291947A1Policy proof validation utilizing secret shares
Publication Date: 2025.09.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20250291947A1 patent drawing
  • US20250291947A1 patent drawing
  • US20250291947A1 patent drawing

AI summary

Embodiments described herein enable at least one of a plurality of entities to access data protected by a security policy in response to validating respective digital access requests from the entities. The respective digital access requests are received, each comprising a proof. For each request, an encrypted secret share is obtained from a respective ledger database. Each request is validated based at least on the respective encrypted secret share and the proof, without decrypting the respective encrypted secret share. In response to validating all of the requests, a verification that an access criteria of a security policy is met is made. If so, at least one of the entities is provided with access to data protected by the security policy. In an aspect, embodiments enable a blind subpoena to be performed. In another aspect, embodiments enable the at least one entity to access the data for an isolated purpose.