File Sync Privacy via Segmented Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud file synchronization systems face challenges in providing secure data storage and sharing, as personal encryption keys are unwieldy for consumer users and managed keys are not feasible for collaborative sharing with external partners, leading to loss of control over sensitive data.

Innovation Solution

Implementing a file synchronization system with folders associated with non-shared encryption keys, including managed keys and shared keys, where the encryption keys are not shared with the data storage service, allowing secure storage and sharing while maintaining user control over privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If personal encryption keys are used for cloud file synchronization, then data privacy is improved, but ease of operation deteriorates due to unwieldy key management

Engineering Contradiction:
Improvedata privacyVSAvoidkey management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a key management service as an intermediary between users and their encryption keys. This service handles key generation, storage, rotation, and distribution automatically, eliminating the need for users to directly manage complex cryptographic keys while maintaining strong encryption. The intermediary absorbs the operational complexity, allowing users to benefit from robust privacy without the burden of key management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The key management service operates autonomously to perform security functions without requiring user intervention. It automatically manages the encryption keys for user files, handles key rotation, and ensures secure access without user involvement in the technical details. This self-service approach resolves the contradiction by providing strong encryption while completely removing the operational burden from users.

Inventive Principle:
Principle #25Self-service

2Reliability

If managed encryption keys are used for business cloud storage, then data privacy is improved, but adaptability deteriorates for external collaborative sharing

Engineering Contradiction:
Improvedata privacyVSAvoidexternal sharing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the encryption key hierarchy into multiple levels: a root managed key at the organization level, child keys for different departments or teams, and leaf keys for individual files. This segmentation allows the root key to remain secure and controlled by the key management service while enabling selective sharing of child keys or file keys with external partners. The segmented structure resolves the contradiction by maintaining centralized control for privacy while enabling flexible adaptability for external collaboration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The key management system dynamically adjusts key access permissions based on sharing requirements. When external collaboration is needed, the system can temporarily grant access to specific child keys or file keys to external users without compromising the root managed key. This dynamic key access control allows the system to adapt to external sharing needs while maintaining the security benefits of managed encryption keys.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If personal encryption keys are shared with invitees, then sharing capability is improved, but security deteriorates due to loss of key control

Engineering Contradiction:
Improvesharing capabilityVSAvoidkey security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The key management service acts as an intermediary that mediates between the key owner and the invitee. Instead of directly sharing the personal encryption key, the system provides secure key exchange mechanisms where the invitee can obtain access to specific files or folders without receiving the master key. The intermediary handles the sensitive key exchange process, maintaining security while enabling sharing capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the encryption key from the file data structure, separating the key management function from the data storage function. Files are stored encrypted with keys that are managed independently by the key management service. This extraction allows the system to provide file access to invitees without transferring the master encryption key, maintaining key security while enabling sharing. The key is extracted and managed separately, allowing selective disclosure of data without compromising the key.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8996884B2High privacy of file synchronization with sharing functionality
Publication Date: 2015.03.31 EMC IP HLDG CO LLC
  • US8996884B2 patent drawing
  • US8996884B2 patent drawing
  • US8996884B2 patent drawing

AI summary

Systems and methods for providing privacy of file synchronization with sharing functionality are presented. In embodiments, a file synchronization system comprises one or more folders associated with one or more non-shared encryption keys, which may be a managed key shared across an organization, and/or a personal key that is not shared or has limited third-party sharing. The one or more non-shared encryption keys are not known to the data storage service. The file synchronization system may also include one or more folders associated with a shared encryption key that is shared with the data storage service, and in embodiments, with a set of users of the service. The system may include a mapping correlating folders to encryption type so items in each folder can be handled appropriately. The system may have additional folders, such as one or more public folders that may be available with limited or no restrictions.