IP Library Granted Patent US 11,126,742
Granted Patent B2
US 11,126,742 · App. 16/781,169 · Granted Sep 21, 2021

Encrypted search cloud service with cryptographic sharing

Inventors: Kevin Yeo (Mountain View, CA); Sarvar Patel (Montville, NJ); Giuseppe Persiano (New York, NY)
Assignee: Google LLC
G06F21/6227H04L9/0631H04L9/085H04L9/0819H04L9/0866H04L9/0894H04L9/3234H04L63/0435H04L63/062H04L63/10H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,126,742
App. No.
16/781,169
Granted
Sep 21, 2021
Kind
B2
Abstract

A method for sharing read access to a document stored on memory hardware. The method includes receiving a shared read access command from a sharor sharing read access to a sharee for a document stored on memory hardware in communication with the data processing hardware, and receiving a shared read access request from the sharee. The shared read access command includes an encrypted value and a first cryptographic share value based on a write key, a read key, a document identifier, and a sharee identifier. The method also includes multiplying the first and second cryptographic share values to determine a cryptographic read access value. The cryptographic read access value authorizes read access to the sharee for the document. The method also includes storing a read access token for the sharee including the cryptographic read access value and the encrypted value in a user read set of the memory hardware.

Claims (48)

1. A method comprising:

receiving, at data processing hardware, a search query from a sharee for a keyword in a document stored on memory hardware in communication with the data processing hardware, the search query comprising a cryptographic search value based on a read key for the document, the keyword, and a sharee cryptographic key associated with the sharee;

retrieving, by the data processing hardware, a read access token for the sharee from a user read set of the memory hardware, the user read set comprising a list of sharee identifiers associated with sharees having read access to the document;

computing, by the data processing hardware, a cryptographic word set token based on the received cryptographic search value and the retrieved read access token for the sharee;

determining, by the data processing hardware, whether the computed cryptographic word set token matches a corresponding cryptographic word set token of a word set stored in the memory hardware; and

when the computed cryptographic word set token matches the corresponding cryptographic word set token of the word set:

retrieving, by the data processing hardware, encrypted word metadata of the document associated with the keyword from the memory hardware; and

sending, by the data processing hardware, a search result set to the sharee, the search result set comprising the encrypted value and the encrypted word metadata.

2. The method of claim 1 , wherein the sharee is configured to:

decrypt the encrypted value using the read key; and

decrypt the encrypted word metadata using the read key.

3. The method of claim 2 , wherein the sharee is further configured to sort and display the decrypted metadata on a display of a user device.

4. The method of claim 1 , wherein the search query further comprises a user identifier identifying the sharee and a document identifier identifying the document.

5. The method of claim 4 , wherein the cryptographic search value comprises a generator to the power of a pseudorandom function of the read key of the document and the keyword multiplied by a pseudorandom function of the sharee cryptographic key associated with the sharee and the document identifier.

6. The method of claim 5 , wherein the generator corresponds to a group where Diffie-Hellman is hard.

7. The method of claim 1 , wherein:

the document comprises a set of documents; and

the search query comprises a cryptographic search value for each document in the set of documents.

8. The method of claim 1 , wherein:

the read access token comprises a cryptographic read access value, and

the cryptographic word set token is further based on the cryptographic read access value.

9. The method of claim 8 , wherein computing the cryptographic word set token comprises raising the cryptographic search value to a power of the cryptographic read access value.

10. The method of claim 1 , wherein the search result set further comprises a document identifier identifying the document.

11. A system comprising:

data processing hardware; and

memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:

receiving a search query from a sharee for a keyword in a document stored on the memory hardware, the search query comprising a cryptographic search value based on a read key for the document, the keyword, and a sharee cryptographic key associated with the sharee;

retrieving a read access token for the sharee from a user read set of the memory hardware, the user read set comprising a list of sharee identifiers associated with sharees having read access to the document;

computing a cryptographic word set token based on the received cryptographic search value and the retrieved read access token for the sharee,

determining whether the computed cryptographic word set token matches a corresponding cryptographic word set token of a word set stored in the memory hardware; and

when the computed cryptographic word set token matches the corresponding cryptographic word set token of the word set:

retrieving encrypted word metadata of the document associated with the keyword from the memory hardware; and

sending a search result set to the sharee, the search result set comprising the encrypted value and the encrypted word metadata.

12. The system of claim 11 , wherein the sharee is configured to:

decrypt the encrypted value using the read key; and

decrypt the encrypted word metadata using the read key.

13. The system of claim 12 , wherein the sharee is further configured to sort and display the decrypted metadata on a display of a user device.

14. The system of claim 11 , wherein the search query further comprises a user identifier identifying the sharee and a document identifier identifying the document.

15. The system of claim 14 , wherein the cryptographic search value comprises a generator to the power of a pseudorandom function of the read key of the document and the keyword multiplied by a pseudorandom function of the sharee cryptographic key associated with the sharee and the document identifier.

16. The system of claim 15 , wherein the generator corresponds to a group where Diffie-Hellman is hard.

17. The system of claim 11 , wherein:

the document comprises a set of documents; and

the search query comprises a cryptographic search value for each document in the set of documents.

18. The system of claim 11 , wherein:

the read access token comprises a cryptographic read access value; and

the cryptographic word set token is further based on the cryptographic read access value.

19. The system of claim 18 , wherein computing the cryptographic word set token comprises raising the cryptographic search value to a power of the cryptographic read access value.

20. The system of claim 11 , wherein the search result set further comprises a document identifier identifying the document.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2020
From: YEO, KEVIN; PATEL, SARVAR; PERSIANO, GIUSEPPE
To: GOOGLE LLC
Reel/Frame 051767/0255 →
Continuity (6)
Continuation 15878871 · Jan 24, 2018
Provisional Application 62597781 · Dec 12, 2017
Provisional Application 62508523 · May 19, 2017
Provisional Application 62508374 · May 18, 2017
Provisional Application 62490804 · Apr 27, 2017
Related Publication 20200175192A1 · Jun 4, 2020
Cited By (1)
US 12,647,256