IP Library Granted Patent US 8,458,799
Granted Patent B2
US 8,458,799 · App. 12/495,071 · Granted Jun 4, 2013

Method and apparatus for providing a scalable service platform using a network cache

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,458,799
App. No.
12/495,071
Granted
Jun 4, 2013
Kind
B2
Abstract

An approach is provided for building a scalable service platform by initiating transmission of encrypted data from a public network cache. An access control server platform determines a first authorization key for a user and a second authorization key for a resource, and then encrypts the resource with the second authorization key, and encrypts the second authorization key with the first authorization key. The access control server platform initiates distribution of the encrypted second authorization key with the encrypted resource over a network. The access control server platform further initiates caching the encrypted second authorization key with the encrypted resource that meets a predefined threshold value (e.g., a data size, an access frequency, a modification frequency, or an auditing requirement) in a cache in the network, and initiates transmission of the cached and encrypted second authorization key with the cached and encrypted resource from the cache to at least one authorized entity.

Claims (62)

1. A method comprising:

determining a first authorization key for a user and a second authorization key for a resource;

encrypting the resource with the second authorization key;

encrypting the second authorization key with the first authorization key;

encrypting a text known to at least one authorized entity with the second authorization key;

initiating distribution of the encrypted text with the encrypted second authorization key and the encrypted resource over a network;

initiating caching of the encrypted text with the encrypted second authorization key and the encrypted resource in a cache in the network; and

initiating transmission of the cached and encrypted text with the cached and encrypted second authorization key and the cached and encrypted resource from the cache to the authorized entity, wherein the encrypted second authorization key is decrypted with the first authorization key, the encrypted text is decrypted with the decrypted second authorization key, and the encrypted resource is decrypted with the decrypted second authorization key when the decrypted text matches with the text known to the authorized entity.

2. A method according to claim 1 , further comprising:

decrypting the encrypted second authorization key with the first authorization key; and

decrypting the encrypted resource with the decrypted second authorization key.

3. A method according to claim 1 , wherein the at least one authorized entity is associated with the first authorization key, and wherein the at least one entity includes at least one of an owner of the resource, a contact of the owner, or a social group the owner belongs to.

4. A method according to claim 1 , further comprising:

categorizing a plurality of resources by at least one of a data size, an access frequency, a modification frequency, an auditing requirement, or a combination thereof; and

determining a threshold value within each category for the caching step to apply to the resources,

wherein the caching step is applied to resources that meet the threshold values within the respective category, and

the encrypted second authorization key with the encrypted resource remain cached when the resources remain meeting the threshold value in the respective category.

5. A method according to claim 3 , further comprising:

removing one authorized entity to prevent subsequent transmission of the cached and encrypted second authorization key as well as the cached and encrypted resource from the cache.

6. A method according to claim 3 , wherein members of the social group share an identical first authorization key specific for the social group.

7. An apparatus comprising:

at least one processor; and

at least one memory including computer program code,

wherein the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to perform at least the following:

determine a first authorization key for a user and a second authorization key for a resource;

encrypt the resource with the second authorization key;

encrypt the second authorization key with the first authorization key;

encrypt a text known to at least one authorized entity with the second authorization key;

initiate distribution of the encrypted text with the encrypted second authorization key and the encrypted resource over a network;

initiate caching of the encrypted text with the encrypted second authorization key and the encrypted resource in a cache in the network; and

initiate transmission of the cached and encrypted text with the cached and encrypted second authorization key and the cached and encrypted resource from the cache to the authorized entity, wherein the encrypted second authorization key is decrypted with the first authorization key, the encrypted text is decrypted with the decrypted second authorization key, and the encrypted resource is decrypted with the decrypted second authorization key when the decrypted text matches with the text known to the authorized entity.

8. An apparatus of claim 7 , wherein the apparatus is further caused to:

decrypt the encrypted second authorization key with the first authorization key; and

decrypt the encrypted resource with the decrypted second authorization key.

9. An apparatus of claim 7 , wherein the at least one authorized entity is associated with the first authorization key, and wherein the at least one entity includes at least one of an owner of the resource, a contact of the owner, or a social group the owner belongs to.

10. An apparatus of claim 7 , wherein the apparatus is further caused to:

categorize a plurality of resources by at least one of a data size, an access frequency, a modification frequency, an auditing requirement, or a combination thereof;

determine threshold values within each category for the caching step to apply to the resources; and

cache resources that meet the threshold values in the respective category,

wherein the encrypted second authorization key with the encrypted resource remain cached when the resources remain meeting the threshold values in the respective category.

11. An apparatus of claim 9 , wherein the apparatus is further caused to:

remove one authorized entity to prevent subsequent transmission of the cached and encrypted second authorization key as well as the cached and encrypted resource from the cache.

12. An apparatus of claim 9 , wherein members of the social group share an identical first authorization key specific for the social group.

13. A non-transitory computer-readable storage medium carrying one or more sequences of one or more instructions which, when executed by one or more processors, cause an apparatus to perform at least the following:

determining a first authorization key for a user and a second authorization key for a resource;

encrypting the resource with the second authorization key;

encrypting the second authorization key with the first authorization key;

encrypting a text known to at least one authorized entity with the second authorization key;

initiating distribution of the encrypted text with the encrypted second authorization key and the encrypted resource over a network;

initiating caching of the encrypted text with the encrypted second authorization key and the encrypted resource in a cache in the network; and

initiating transmission of the cached and encrypted text with the cached and encrypted second authorization key and the cached and encrypted resource from the cache to the authorized entity, wherein the encrypted second authorization key is decrypted with the first authorization key, the encrypted text is decrypted with the decrypted second authorization key, and the encrypted resource is decrypted with the decrypted second authorization key when the decrypted text matches with the text known to the authorized entity.

14. A non-transitory computer-readable storage medium of claim 13 , wherein the apparatus is caused to further perform:

decrypting the encrypted second authorization key with the first authorization key; and

decrypting the encrypted resource with the decrypted second authorization key.

15. A non-transitory computer-readable storage medium of claim 13 , wherein the at least one authorized entity is associated with the first authorization key, and wherein the at least one entity includes at least one of an owner of the resource, a contact of the owner, or a social group the owner belongs to.

16. A non-transitory computer-readable storage medium of claim 13 , wherein the apparatus is caused to further perform:

categorizing a plurality of resources by at least one of a data size, an access frequency, a modification frequency, an auditing requirement, or a combination thereof;

determining a threshold value within each category for the caching step to apply to the resources; and

caching resources that meet the threshold value in the respective category,

wherein the encrypted second authorization key with the encrypted resource remain cached when the resources remain meeting the threshold value in the respective category.

17. A non-transitory computer-readable storage medium of claim 15 , wherein the apparatus is caused to further perform:

removing one authorized entity to prevent subsequent transmission of the cached and encrypted second authorization key as well as the cached and encrypted resource from the cache.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED AT REEL: 035512 FRAME: 0482. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 3, 2015
From: NOKIA CORPORATION
To: NOKIA TECHNOLOGIES OY
Reel/Frame 035819/0988 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2015
From: NOKIA CORPORATION
To: NOKIA TECHNOLOGIES OY
Reel/Frame 035512/0482 →