IP Library Granted Patent US 8,935,810
Granted Patent B2
US 8,935,810 · App. 14/095,130 · Granted Jan 13, 2015

Cloud key directory for federating data exchanges

Inventors: Roy Peter D'Souza (Bellevue, WA); Omkant Pandey (Seattle, WA)
Assignee: Microsoft Corporation
G06F21/6218H04L9/0894H04L9/321G06F17/30283G06F17/30566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,935,810
App. No.
14/095,130
Granted
Jan 13, 2015
Kind
B2
Abstract

Embodiments are directed to providing attribute-based data access. In an embodiment, a data request specifies one or more search data attributes describing requested data that is to be found in an anonymous directory. The anonymous directory is configured to provide access to secured data according to access controls defined one or more clients. The secured data includes data that is associated with a particular client and that is encrypted using multi-authority attribute-based encryption, which associates the data with one or more encryption data attributes and that enables the data to be provided if conditions in the corresponding access controls are met. The particular portion of data is provided based on determining that the conditions in the corresponding access controls are met, and that at least one of the search data attributes is determined to be relevant to at least one of the encryption data attributes.

Claims (32)

1. At a computer system including at least one processor and a memory, in a computer networking environment including a plurality of computing systems, a computer-implemented method for providing attribute-based data access, the method comprising:

an act of receiving a data request, the data request specifying one or more search data attributes describing requested data that is to be found in an anonymous directory, wherein the anonymous directory is configured to provide access to secured data of one or more clients according to corresponding access controls defined by each of the one or more clients, the secured data including a particular portion of data that is associated with a particular client and that is encrypted using multi-authority attribute-based encryption that associates the particular portion of data with one or more encryption data attributes and that enables the particular portion of data to be provided if conditions in the corresponding access controls are met;

an act of determining that the particular portion of data should be provided based on determining that the conditions in the corresponding access controls are met, and that at least one of the search data attributes of the data request is determined to be relevant to at least one of the encryption data attributes; and

an act of providing the particular portion of data in response to the data request.

2. The method of claim 1 , wherein the anonymous directory is configured to enable discovery of the particular client's particular portion of data, based on a threshold number of encryption data attributes being requested in the data request.

3. The method of claim 1 , wherein the anonymous directory is configured to enable the one or more clients to specify which secured data is to be provided in response to data requests, based on one or more of user identity or user type.

4. The method of claim 1 , wherein the anonymous directory is configured to enable the one or more clients to dynamically change which of their secured data is provided in response to data requests by changing the corresponding access controls.

5. The method of claim 1 , wherein the anonymous directory is configured to enable requests for secured data without a prior knowledge of what secured data is available through the anonymous directory and without a prior knowledge of the one or more clients.

6. The method of claim 1 , wherein determining that the conditions in the corresponding access controls are met comprises one or more of determining that a user making the data request is a specified user or determining that the user is of a specified user type.

7. The method of claim 1 , wherein at least a portion of secured data of the particular client remains unavailable to data requests received by the anonymous directory, based on the particular client's corresponding access controls.

8. A computer program product for implementing a method for providing attribute-based data access, the computer program product comprising one or more hardware storage devices having stored thereon computer-executable instructions that, when executed by one or more processors of the computing system, cause the computing system to perform the method, the method comprising:

an act of receiving a data request, the data request specifying one or more search data attributes describing requested data that is to be found in an anonymous directory, wherein the anonymous directory is configured to provide access to secured data of one or more clients according to corresponding access controls defined by each of the one or more clients, the secured data including a particular portion of data that is associated with a particular client and that is encrypted using multi-authority attribute-based encryption that associates the particular portion of data with one or more encryption data attributes and that enables the particular portion of data to be provided if conditions in the corresponding access controls are met;

an act of determining that the particular portion of data should be provided based on determining that the conditions in the corresponding access controls are met, and that at least one of the search data attributes of the data request is determined to be relevant to at least one of the encryption data attributes; and

an act of providing the particular portion of data in response to the data request.

9. The computer program product of claim 8 , wherein the corresponding access controls of the particular client apply one or more different encryption data attributes to different portions of secured data corresponding to the particular client and that is stored in the anonymous directory.

10. The computer program product of claim 8 , wherein the encryption data attributes applied by the particular client are user-specific, such that different users are provided different data based on their identity.

11. The computer program product of claim 8 , wherein the data request identifies a user.

12. The computer program product of claim 8 , wherein the anonymous directory is configured to provide one or more directory users access to the secured data of the one or more clients.

13. The computer program product of claim 8 , wherein the anonymous directory is configured to enable the particular portion of data of the particular client to be provided for any request that uses at least one of the encryption data attributes.

14. A computer system comprising the following:

one or more processors;

system memory; and

one or more computer-readable storage media having stored thereon computer-executable instructions that, when executed by the one or more processors, causes the computing system to perform a method for providing attribute-based data access, the method comprising the following:

an act of receiving a data request, the data request specifying one or more search data attributes describing requested data that is to be found in an anonymous directory, wherein the anonymous directory is configured to provide access to secured data of one or more clients according to corresponding access controls defined by each of the one or more clients, the secured data including a particular portion of data that is associated with a particular client and that is encrypted using multi-authority attribute-based encryption that associates the particular portion of data with one or more encryption data attributes and that enables the particular portion of data to be provided if conditions in the corresponding access controls are met;

an act of determining that the particular portion of data should be provided based on determining that the conditions in the corresponding access controls are met, and that at least one of the search data attributes of the data request is determined to be relevant to at least one of the encryption data attributes; and

an act of providing the particular portion of data in response to the data request.

15. The computer system of claim 14 , wherein the corresponding access controls of the particular client apply one or more different encryption data attributes to different portions of secured data corresponding to the particular client and that is stored in the anonymous directory.

16. The computer system of claim 14 , wherein the encryption data attributes applied by the particular client are user-specific, such that different users are provided different data based on their identity.

17. The computer system of claim 14 , wherein the data request identifies the user.

18. The computer system of claim 14 , wherein the anonymous directory is configured to provide one or more directory users access to the secured data of the one or more clients.

19. The computer system of claim 14 , wherein the anonymous directory is configured to enable the particular portion of data of the particular client to be provided to any authorized user who requests data using at least one of the encryption data attributes.

20. The computer system of claim 14 , wherein the anonymous directory is configured to enable discovery of the particular client's particular portion of data, based on a threshold number of encryption data attributes being requested in the data request.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT INVENTOR'S NAME ROY PETER D?SOUZA TO ROY PETER D'SOUZA PREVIOUSLY RECORDED ON REEL 031705 FRAME 0597. ASSIGNOR(S) HEREBY CONFIRMS THE ENITRE RIGHT, TITLE AND INTEREST. Recorded Feb 10, 2015
From: D'SOUZA, ROY PETER; PANDEY, OMKANT
To: MICROSOFT CORPORATION
Reel/Frame 034944/0396 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2014
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034544/0541 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2013
From: D?SOUZA, ROY PETER; PANDEY, OMKANT
To: MICROSOFT CORPORATION
Reel/Frame 031705/0597 →
Continuity (2)
Continuation 13162985 · Jun 17, 2011
Related Publication 20140090089A1 · Mar 27, 2014