IP Library Granted Patent US 9,224,005
Granted Patent B2
US 9,224,005 · App. 14/570,808 · Granted Dec 29, 2015

Cloud key directory for federating data exchanges

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,224,005
App. No.
14/570,808
Granted
Dec 29, 2015
Kind
B2
Abstract

Methods, systems, and computer program products for providing attribute-based data access. Embodiments include receiving a data request specifying search data attributes describing requested data that is to be found in an anonymous directory. The anonymous directory provides access to secured data of clients according to access controls, including secured data comprising a first portion that is unencrypted and readable by the anonymous directory and a second portion that is encrypted and unreadable by the anonymous directory. The second portion is encrypted using multi-authority attribute-based encryption that associates the second portion with encryption data attributes. The anonymous directory provides the first acid second portions of data f conditions in the access controls are met. The first and second portions of data are provided, based on determining that the conditions in the access controls are met, and that at least one data attribute is relevant to at least one encryption data attribute.

Claims (31)

1. At a computer system including at least one processor and a memory, in a computer networking environment including a plurality of computing systems, a computer-implemented method for providing attribute-based data access, the method comprising:

receiving a data request, the data request specifying one or more search data attributes describing requested data that is to be found in an anonymous directory, wherein the anonymous directory is configured to provide access to secured data of one or more clients according to access controls, the secured data for at least one client including a first portion of data that is unencrypted and readable by the anonymous directory and a second portion of data that is encrypted and unreadable by the anonymous directory, the second portion of data being encrypted using multi-authority attribute-based encryption that associates the second portion of data with one or more encryption data attributes, the anonymous directory being configured to provide the first and second portions of data if conditions in the access controls are met;

determining that the first and second portions of data should be provided based on determining that the conditions in the access controls are met, and that at least one of the search data attributes of the data request is determined to be relevant to at least one of the encryption data attributes; and

providing the first and second portions of data in response to the data request.

2. The computer-implemented method of claim 1 , wherein the anonymous directory is configured to enable discovery of the secured data for at least one client, based on a threshold number of encryption data attributes being requested in the data request.

3. The computer-implemented method of claim 1 , wherein the access controls correspond to each client.

4. The computer-implemented method of claim 3 , wherein the access controls are defined by the corresponding client.

5. The computer-implemented method of claim 1 , wherein the access controls define which secured data is to be provided in response to data requests, based on one or more of user identity or user type of a requesting user.

6. The computer-implemented method of claim 1 , wherein a client is enabled to dynamically change which of their secured data is provided in response to data requests by changing a corresponding access control.

7. The computer-implemented method of claim 1 , wherein the anonymous directory is configured to enable requests for secured data without a prior knowledge of what secured data is available through the anonymous directory and without a prior knowledge of the one or more clients.

8. A computer program product comprising one or more hardware storage devices having stored thereon computer-executable instructions that are structured such that, when executed by one or more processors of a computer system, the computer-executable instructions configure the computer system to provide attribute-based data access, including computer-executable instructions that configure the computer system to perform at least the following:

receive a data request, the data request specifying one or more search data attributes describing requested data that is to be found in an anonymous directory, wherein the anonymous directory is configured to provide access to secured data of one or more clients according to access controls, the secured data for at least one client including a first portion of data that is unencrypted and readable by the anonymous directory and a second portion of data that is encrypted and unreadable by the anonymous directory, the second portion of data being encrypted using multi-authority attribute-based encryption that associates the second portion of data with one or more encryption data attributes, the anonymous directory being configured to provide the first and second portions of data if conditions in the access controls are met;

determine that the first and second portions of data should be provided based on determining that the conditions in the access controls are met, and that at least one of the search data attributes of the data request is determined to be relevant to at least one of the encryption data attributes; and

provide the first and second portions of data in response to the data request.

9. The computer program product of claim 8 , wherein the anonymous directory is configured to enable discovery of the secured data for at least one client, based on a threshold number of encryption data attributes being requested in the data request.

10. The computer program product of claim 8 , wherein the access controls correspond to each client.

11. The computer program product of claim 10 , wherein the access controls are defined by the corresponding client.

12. The computer program product of claim 8 , wherein the access controls define which secured data is to be provided in response to data requests, based on one or more of user identity or user type of a requesting user.

13. The computer program product of claim 8 , wherein a client is enabled to dynamically change which of their secured data is provided in response to data requests by changing a corresponding access control.

14. The computer program product of claim 8 , wherein the anonymous directory is configured to enable requests for secured data without a prior knowledge of what secured data is available through the anonymous directory and without a prior knowledge of the one or more clients.

15. A computer system, comprising:

one or more processors; and

one or more hardware storage devices having stored thereon computer-executable instructions that are structured such that, when executed by the one or more processors of the computer system, the computer-executable instructions configure the computer system to provide attribute-based data access, including being configured to perform at least the following:

receive a data request, the data request specifying one or more search data attributes describing requested data that is to be found in an anonymous directory, wherein the anonymous directory is configured to provide access to secured data of one or more clients according to access controls, the secured data for at least one client including a first portion of data that is unencrypted and readable by the anonymous directory and a second portion of data that is encrypted and unreadable by the anonymous directory, the second portion of data being encrypted using multi-authority attribute-based encryption that associates the second portion of data with one or more encryption data attributes, the anonymous directory being configured to provide the first and second portions of data if conditions in the access controls are met;

determine that the first and second portions of data should be provided based on determining that the conditions in the access controls are met, and that at least one of the search data attributes of the data request is determined to be relevant to at least one of the encryption data attributes; and

provide the first and second portions of data in response to the data request.

16. The computer system of claim 15 , wherein the anonymous directory is configured to enable discovery of the secured data for at least one client, based on a threshold number of encryption data attributes being requested in the data request.

17. The computer system of claim 15 , wherein the access controls correspond to each client.

18. The computer system of claim 17 , wherein the access controls are defined by the corresponding client.

19. The computer system of claim 15 , wherein the access controls define which secured data is to be provided in response to data requests, based on one or more of user identity or user type of a requesting user.

20. The computer system of claim 15 , wherein a client is enabled to dynamically change which of their secured data is provided in response to data requests by changing a corresponding access control.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2015
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034819/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PTO ERROR OF INVENTOR'S NAME ROY PETER D?SOUZA TO ROY PETER D'SOUZA PREVIOUSLY RECORDED ON REEL 034510 FRAME 0197. ASSIGNOR(S) HEREBY CONFIRMS THE ENTIRE RIGHT, TITLE AND INTEREST. Recorded Jan 13, 2015
From: D'SOUZA, ROY PETER; PANDEY, OMKANT
To: MICROSOFT CORPORATION
Reel/Frame 034757/0168 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2014
From: D?SOUZA, ROY PETER; PANDEY, OMKANT
To: MICROSOFT CORPORATION
Reel/Frame 034510/0197 →