Parameterizable Cryptography for Privacy-Preserving Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cryptography techniques require large storage for key management and extensive communication between systems, making them vulnerable to attacks and compromising user privacy by revealing access to protected content.
Innovation Solution
The implementation of blindable parameterizable cryptography, which determines encryption and decryption keys based on authorization policies using hashing and blinding techniques, reducing storage needs and communication, while ensuring privacy by not revealing the accessed content to the system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional key management techniques are used, then access control to protected information can be implemented, but large amounts of storage are required to keep track of keys
Solution Approach 1:
The patent extracts the key management function from traditional centralized systems and implements it through distributed cryptographic techniques. Each user holds their own keys locally without requiring centralized key storage, thereby eliminating the need for large key management storage while maintaining access control reliability
Solution Approach 2:
The patent uses cryptographic key pairs where public keys can be freely distributed and copied, while private keys remain secure with individual users. This allows multiple systems to verify access rights without requiring centralized key storage, reducing storage requirements while maintaining access control
2Reliability
If conventional key escrow techniques are used, then key management can be implemented, but extensive communication between multiple systems is required which increases vulnerability to attacks
Solution Approach 1:
The patent removes the key escrow intermediary system and enables direct cryptographic operations between users and content. Users can encrypt and decrypt content using their own key pairs without requiring communication with key escrow agents, thereby eliminating complex communication infrastructure while maintaining secure key management
Solution Approach 2:
Users perform self-service key management operations including encryption, decryption, and key generation locally on their own systems. This eliminates the need for extensive communication between multiple key management systems, reducing infrastructure complexity while maintaining security through cryptographic self-sufficiency
3Reliability
If conventional encryption techniques are used, then information can be protected, but the system can determine which protected content the user is accessing which compromises user privacy
Solution Approach 1:
The patent employs asymmetric cryptography where public keys are openly distributed and private keys are kept secret. The system can verify encrypted content using public keys without being able to decrypt or determine the actual content, thereby protecting user privacy while maintaining information protection. The asymmetry between public verification and private decryption prevents the system from knowing what users access
Solution Approach 2:
The patent distributes public keys freely across the system, allowing any user to encrypt content with any user's public key. This copying and distribution of public keys enables privacy-preserving encryption where the system can store and verify encrypted content without being able to read or identify the actual information, thus protecting user privacy while maintaining information protection
Data Source
AI summary
Some embodiments provide systems and techniques for performing parameterizable cryptography. An encryption key can be determined based at least on a string associated with an authorization policy. The encryption key can then be used to encrypt information. The decryption key can also be determined based at least on the string associated with the authorization policy. Note that the authorization policy must be satisfied to decrypt information. In some embodiments, the systems and techniques for performing parameterizable cryptography are blindable. These blindable embodiments can be used to preserve privacy.


