Identity Encapsulated Cryptography for Cloud Data Jurisdiction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data encryption methods are inadequate for managing access to data across multiple devices and ensuring data security when stored in a public cloud, particularly when data is physically stored in a country different from the user's country of citizenship or residence, as they fail to securely isolate and decrypt user data based on geographical jurisdiction.

Innovation Solution

Identity encapsulated cryptography is implemented, where a user's top-level identity is associated with subordinate identities and unique encryption keys, allowing secure access and encryption on a per-device basis, with a country-specific key ensuring that only data from a specific country can be decrypted, thereby isolating data from foreign jurisdictions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single encryption key is used across multiple devices, then ease of operation is improved, but data security and jurisdictional control are worsened

Engineering Contradiction:
Improveaccess to dataVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the single encryption key into multiple device-specific subordinate encryption keys, where each device has its own unique key. This allows each device to access data independently while maintaining security isolation between devices, resolving the contradiction between ease of multi-device access and data security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by associating each device with its own specific encryption key and jurisdictional rules. Each device's data access is controlled by its local encryption key, which is derived from or associated with the user's top-level identity and the device's specific identifiers, ensuring that security properties are localized to each device-context.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If data is stored in a public cloud, then adaptability and service accessibility are improved, but control over data decryption and jurisdictional compliance are worsened

Engineering Contradiction:
Improvedata storage flexibilityVSAvoiddecryption control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the decryption control capability from the cloud storage system and places it in the user's hands through device-specific encryption keys. The cloud stores encrypted data without having the ability to decrypt it, while the user's devices hold the specific keys needed for decryption, thus maintaining both cloud storage flexibility and user control over decryption.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies preliminary action by encrypting data with device-specific keys before storing it in the cloud. The encryption process incorporates the user's top-level identity and device-specific information in advance, so that when data is retrieved from the cloud, only the authorized device with the corresponding key can decrypt it, ensuring jurisdictional control is maintained throughout the data lifecycle.

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If data is encrypted with a single key, then ease of manufacture and implementation are improved, but the ability to isolate data by jurisdiction is worsened

Engineering Contradiction:
Improveencryption implementationVSAvoidjurisdictional data isolation
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent segments the single encryption key into multiple subordinate keys, each associated with specific jurisdictional rules and device identifiers. This segmentation allows the system to maintain a simple top-level identity structure while creating differentiated access controls for different jurisdictions and devices, thus achieving both ease of implementation and jurisdictional isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements universality through the top-level identity that serves multiple functions: it acts as the root for generating all device-specific encryption keys, stores the user's country information for jurisdictional determination, and provides the foundation for both simple and differentiated access controls. This multi-functional design achieves jurisdictional isolation without requiring completely separate encryption systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8621220B2Systems and methods for identity encapsulated cryptography
Publication Date: 2013.12.31 EBAY INC
  • US8621220B2 patent drawing
  • US8621220B2 patent drawing
  • US8621220B2 patent drawing

AI summary

A method and a system to provide identity encapsulated cryptography are provided. A method may comprise receiving a user key to access a service. The service may be provided by an enterprise and hosted within a public cloud. A request for a country key assigned to a country of a user is transmitted and the country key is received. Session data resulting from the use of the service hosted within the public cloud is encrypted using the user key and the user key is encrypted using the country key. The encrypted session data and the encrypted user key are stored in the public cloud. The country key may be provided to a legal agency of the country of the user to decrypt session data of the user and to not decrypt session data of other users of another country.