IP Library Granted Patent US 11,361,088
Granted Patent B2
US 11,361,088 · App. 17/397,315 · Granted Jun 14, 2022

Zero trust communication system for freight shipping organizations, and methods of use

Inventors: Shun Hok Wong (San Jose, CA); Wei Ming Belinda So (Hong Kong, HK)
Assignee: OOCL (INFOTECH) HOLDINGS LIMITED
G06F21/602G06F16/93G06F21/6218G06F21/64G06Q10/083H04L9/14H04L9/30H04L9/3242G06Q2220/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,361,088
App. No.
17/397,315
Granted
Jun 14, 2022
Kind
B2
Abstract

Presented herein are systems and methods of securely sharing data from multiple sources with different client terminals. A server may establish an electronic document for defining a transaction. The electronic document may have data fields. Each data field may be from a client terminal. The server may identify encryption keys to encrypt the corresponding data fields included in the electronic document. The server may distribute the encryption keys across the client terminals in accordance with an access control policy. The access control policy may specify access permissions for a client terminal to each of the plurality of data fields based on a role of the client terminal in the transaction. The server may provide, to each client terminal with access to the data fields in the electronic document via the encryption keys distributed in accordance with the access control policy.

Claims (32)

1. A method of generating keys for accessing a plurality of data attributes having different owners as part of a zero trust communication system, wherein the plurality of data attributes are part of a shared shipping document of freight maintained on a server, the method comprising:

generating, by at least one processor, a data encryption key for a data attribute of the plurality of data attributes;

retrieving, by the at least one processor from a volatile memory, a shipment role for a shipment party;

retrieving, by the at least one processor from the volatile memory, an access control policy corresponding to the shipment role;

retrieving one or more public keys for the shipment party using the access control policy; and

encrypting, by the at least one processor, the data encryption key using the one or more public keys of the shipment party to establish an encrypted data encryption key for the data attribute of the plurality of data attributes.

2. The method of claim 1 , wherein the shipment party has two or more shipment roles.

3. The method of claim 1 , wherein the access control policy defines which of the plurality of data attributes the shipment party can access.

4. The method of claim 1 , wherein the public key is retrieved from a public key repository.

5. The method of claim 1 , wherein the access control policy includes information about which of the plurality of data attributes each shipment party can access.

6. The method of claim 1 , wherein the shared shipping document is an electronic document.

7. The method of claim 1 , wherein the shared shipping document is a booking.

8. The method of claim 1 , wherein the access control policy is dynamically updatable.

9. The method of claim 1 , further comprising:

distributing the encrypted data encryption key and an encrypted version of the data attribute to the shipment party, according to the shipment role of the shipment party.

10. The method of claim 1 , wherein the shipment party further comprises a government agency, a financial institution or trade organization with an interest in the shared shipping document of freight.

11. A method of generating keys for accessing a plurality of data attributes having different owners as part of a zero trust communication system, wherein the plurality of data attributes are part of a shared shipping document of freight maintained on a server, the method comprising:

generating, by at least one processor, a data encryption key for a data attribute of the plurality of data attributes;

retrieving, by the at least one processor from a non-volatile memory, a shipment role for a shipment party;

retrieving, by the at least one processor from the non-volatile memory, an access control policy corresponding to the shipment role;

retrieving one or more public keys for the shipment party using the access control policy; and

encrypting, by the at least one processor, the data encryption key using the one or more public keys of the shipment party to establish an encrypted data encryption key for the data attribute of the plurality of data attributes.

12. The method of claim 11 , wherein the shipment party has two or more shipment roles.

13. The method of claim 11 , wherein the access control policy defines which of the plurality of data attributes the shipment party can access.

14. The method of claim 11 , wherein the public key is retrieved from a public key repository.

15. The method of claim 11 , wherein the access control policy includes information about which of the plurality of data attributes each shipment party can access.

16. The method of claim 11 , wherein the shared shipping document is an electronic document.

17. The method of claim 11 , wherein the shared shipping document is a booking.

18. The method of claim 11 , wherein the access control policy is dynamically updatable.

19. The method of claim 11 , further comprising:

distributing the encrypted data encryption key and an encrypted version of the data attribute to the shipment party, according to the shipment role of the shipment party.

20. The method of claim 11 , wherein the shipment party further comprises a government agency, a financial institution or trade organization with an interest in the shared shipping document of freight.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2021
From: SO, WEI MING; WONG, SHUN HOK
To: OOCL (INFOTECH) HOLDINGS LIMITED
Reel/Frame 057129/0080 →
Continuity (4)
Continuation PCTUS2020019661 · Feb 25, 2020
Continuation In Part 16501399 · Apr 6, 2019
Provisional Application 62919097 · Feb 25, 2019
Related Publication 20210365570A1 · Nov 25, 2021