Identity Encapsulated Cryptography for Cloud Data Jurisdiction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data encryption methods are inadequate for managing access to data across multiple devices and ensuring data security when stored in a public cloud, particularly when data is physically stored in a country different from the user's country of citizenship or residence, as they fail to securely isolate and decrypt user data based on geographical jurisdiction.
Innovation Solution
Identity encapsulated cryptography is implemented, where a user's top-level identity is associated with subordinate identities and unique encryption keys, allowing secure access and encryption on a per-device basis, with a country-specific key ensuring that only data from a specific country can be decrypted, thereby isolating data from foreign jurisdictions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single encryption key is used across multiple devices, then ease of operation is improved, but data security and jurisdictional control are worsened
Solution Approach 1:
The patent segments the single encryption key into multiple device-specific subordinate encryption keys, where each device has its own unique key. This allows each device to access data independently while maintaining security isolation between devices, resolving the contradiction between ease of multi-device access and data security.
Solution Approach 2:
The patent implements local quality by associating each device with its own specific encryption key and jurisdictional rules. Each device's data access is controlled by its local encryption key, which is derived from or associated with the user's top-level identity and the device's specific identifiers, ensuring that security properties are localized to each device-context.
2Adaptability or versatility
If data is stored in a public cloud, then adaptability and service accessibility are improved, but control over data decryption and jurisdictional compliance are worsened
Solution Approach 1:
The patent extracts the decryption control capability from the cloud storage system and places it in the user's hands through device-specific encryption keys. The cloud stores encrypted data without having the ability to decrypt it, while the user's devices hold the specific keys needed for decryption, thus maintaining both cloud storage flexibility and user control over decryption.
Solution Approach 2:
The patent applies preliminary action by encrypting data with device-specific keys before storing it in the cloud. The encryption process incorporates the user's top-level identity and device-specific information in advance, so that when data is retrieved from the cloud, only the authorized device with the corresponding key can decrypt it, ensuring jurisdictional control is maintained throughout the data lifecycle.
3Ease of manufacture
If data is encrypted with a single key, then ease of manufacture and implementation are improved, but the ability to isolate data by jurisdiction is worsened
Solution Approach 1:
The patent segments the single encryption key into multiple subordinate keys, each associated with specific jurisdictional rules and device identifiers. This segmentation allows the system to maintain a simple top-level identity structure while creating differentiated access controls for different jurisdictions and devices, thus achieving both ease of implementation and jurisdictional isolation.
Solution Approach 2:
The patent implements universality through the top-level identity that serves multiple functions: it acts as the root for generating all device-specific encryption keys, stores the user's country information for jurisdictional determination, and provides the foundation for both simple and differentiated access controls. This multi-functional design achieves jurisdictional isolation without requiring completely separate encryption systems.
Data Source
AI summary
A method and a system to provide identity encapsulated cryptography are provided. A method may comprise receiving a user key to access a service. The service may be provided by an enterprise and hosted within a public cloud. A request for a country key assigned to a country of a user is transmitted and the country key is received. Session data resulting from the use of the service hosted within the public cloud is encrypted using the user key and the user key is encrypted using the country key. The encrypted session data and the encrypted user key are stored in the public cloud. The country key may be provided to a legal agency of the country of the user to decrypt session data of the user and to not decrypt session data of other users of another country.


