IP Library › Granted Patent US 12,732,348
Granted Patent B1
US 12,732,348 · App. 18/622,041 · Granted Sep 8, 2026

Group encryption using unbalanced binary tree architecture

Inventors: Jason Gluckman (Encinitas, CA); John Strandberg (Phoenix, AZ); Zakiuddin Mohammed Zaheer (Irvine, CA)
Assignee: Amazon Technologies, Inc.
H04L9/0833H04L63/0428H04L63/102H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,348
App. No.
18/622,041
Granted
Sep 8, 2026
Kind
B1
Abstract

A system configured to improve encryption architecture for camera video data. By using an unbalanced binary tree architecture, the system enables group encryption that prioritizes a constrained device (e.g., embedded camera device), thereby reducing an amount of processing required for the constrained device to encrypt video data. For example, placing the constrained device near the root of the unbalanced binary tree offloads processing from the constrained device to other group members. At each device operating as a member of the group, a privacy enforcement policy operates to authorize/authenticate messages, using time-sensitive encryption keys that enable refined control over decrypted content. In some examples, the architecture can enable end-to-end encryption by removing any cloud services from the group. Alternatively, the architecture can include a cloud service with high or low privileges, enabling refined control over decrypted content while providing additional functionality.

Claims (88)

1 . A computer-implemented method comprising:

storing, at a first user device, binary tree data representing a binary ratchet tree where each leaf node represents a member of a first group associated with a first camera device;

displaying, on an electronic display of the first user device, a graphical user interface including one or more interface elements prompting a user to enable end to end encryption for the first camera device, wherein enabling end to end encryption causes removal of cloud services from the first group;

receiving, at the first user device, user input indicating to enable end to end encryption for the first camera device;

in response to the receiving of the user input indicating to enable end to end encryption for the first camera device, sending a first message from the first user device to a remote system;

based on the first message:

determining, at the remote system, that a first user profile is authorized to remove members from the first group, and

sending, from the remote system to the first camera device, an indication to remove a first node from the binary ratchet tree, the first node corresponding to a cloud service;

modifying, at the first user device, the binary tree data to remove the first node from the binary ratchet tree;

following removal of the first node from the binary ratchet tree, determining, at the first user device, an updated node secret corresponding to a root node of the binary ratchet tree;

receiving, at the remote system from the first camera device, encrypted first image data encrypted using a key determined based on the updated node secret corresponding to the root node of the binary ratchet tree; and

sending the encrypted first image data to the first user device.

2 . The computer-implemented method of claim 1 , further comprising:

receiving, at the first user device, the encrypted first image data from the remote system;

generating, at the first user device using the updated node secret, a first encryption key; and

decrypting the encrypted first image data using the first encryption key to produce decrypted image data.

3 . The computer-implemented method of claim 1 , wherein both prior to and following removal of the first node from the binary ratchet tree:

the binary ratchet tree is an unbalanced binary tree;

the unbalanced binary tree includes a first child node descending from a root node and a second child node descending from the root node;

the second child node corresponds to the first camera device;

the second child node does not have any descendant nodes; and

the unbalanced binary tree includes more than three leaf nodes that are descendants of the first child node.

4 . A computer-implemented method comprising:

storing, at a first user device, binary tree data representing a binary ratchet tree where each leaf node represents a member of a first group associated with a first camera device;

displaying, on an electronic display of the first user device, a graphical user interface including one or more interface elements prompting a user to enable end to end encryption for the first camera device, wherein enabling end to end encryption causes removal of cloud services from the first group;

receiving, at the first user device, user input indicating to enable end to end encryption for the first camera device;

based on the receiving of the user input indicating to enable end to end encryption for the first camera device:

sending a first message from the first user device to a remote system, and

modifying, at the first user device, the binary tree data to remove a first node from the binary ratchet tree, the first node corresponding to a cloud service;

determining, at the first user device following removal of the first node from the binary ratchet tree, an updated node secret corresponding to a root node of the binary ratchet tree;

receiving, at the first user device, first image data from the remote system;

generating, at the first user device using the updated node secret, a first encryption key; and

decrypting the first image data using the first encryption key to produce decrypted image data.

5 . The computer-implemented method of claim 4 , wherein both prior to and following removal of the first node from the binary ratchet tree:

the binary ratchet tree is an unbalanced binary tree.

6 . The computer-implemented method of claim 5 , wherein both prior to and following removal of the first node from the binary ratchet tree:

the unbalanced binary tree includes a first child node descending from a root node and a second child node descending from the root node;

the second child node corresponds to the first camera device;

the second child node does not have any descendant nodes; and

the unbalanced binary tree includes more than three leaf nodes that are descendants of the first child node.

7 . The computer-implemented method of claim 5 , wherein the first camera device is a security camera device mounted on a building.

8 . The computer-implemented method of claim 5 , wherein the first camera device is a video doorbell device mounted on a building proximate a door.

9 . The computer-implemented method of claim 5 , wherein the first user device is a phone.

10 . The computer-implemented method of claim 5 , wherein the first user device is a tablet.

11 . The computer-implemented method of claim 5 , wherein the first user device is a television.

12 . The computer-implemented method of claim 5 , wherein the first user device is a personal assistant device with a display screen.

13 . The computer-implemented method of claim 5 , further comprising:

receiving, at the first user device, second user input indicating to disable end to end encryption for the first camera device;

in response to the receiving of the second user input indicating to disable end to end encryption for the first camera device, sending a second message from the first user device to the remote system;

based on the second message:

determining, at the remote system, that a first user profile is authorized to add members to the first group,

sending, from the remote system to the first camera device, an indication to add a second node to the binary ratchet tree, the second node corresponding to the cloud service, and

storing, at the remote system, second binary tree data representing the binary ratchet tree;

determining, at the remote system, a second node secret corresponding to the root node of the binary ratchet tree;

receiving, at the remote system from the first camera device, encrypted second image data encrypted using a second key determined based on the second node secret corresponding to the root node of the binary ratchet tree;

generating, at the remote system using the second node secret, a second encryption key;

decrypting, at the remote system, the encrypted second image data using the second encryption key to produce decrypted second image data;

analyzing the decrypted second image data using a first machine learning model; and

based on the analyzing of the decrypted second image data using the first machine learning model, sending an alert to the first user device.

14 . A computer-implemented method comprising:

storing, at a first user device, first binary tree data representing a binary ratchet tree where each leaf node represents a member of a first group associated with a first camera device;

displaying, on an electronic display of the first user device, a graphical user interface including one or more interface elements prompting a user to disable end to end encryption for the first camera device, wherein disabling end to end encryption causes a cloud service to be added to the first group;

receiving, at the first user device, user input indicating to disable end to end encryption for the first camera device;

in response to the receiving of the user input indicating to disable end to end encryption for the first camera device, sending a first message from the first user device to a remote system;

based on the first message,

determining, at the remote system, that a first user profile is authorized to add members to the first group,

sending, from the remote system to the first camera device, an indication to add a first node to the binary ratchet tree, the first node corresponding to the cloud service, and

storing, at the remote system, second binary tree data representing the binary ratchet tree;

determining, at the remote system, a node secret corresponding to a root node of the binary ratchet tree;

receiving, at the remote system from the first camera device, encrypted first image data encrypted using a key determined based on the node secret corresponding to the root node of the binary ratchet tree;

generating, at the remote system using the node secret, a first encryption key;

decrypting, at the remote system, the encrypted first image data using the first encryption key to produce decrypted image data;

analyzing the decrypted image data using a first machine learning model; and

based on the analyzing of the decrypted image data using the first machine learning model, sending an alert to a user device.

15 . The computer-implemented method of claim 14 , further comprising:

detecting, based on the analyzing of the decrypted image data using the first machine learning model, a package, and wherein the alert comprises a package alert.

16 . The computer-implemented method of claim 14 , further comprising:

detecting, based on the analyzing of the decrypted image data using the first machine learning model, a person, and wherein the alert comprises a person alert.

17 . The computer-implemented method of claim 14 , wherein the first camera device is a security camera device mounted on a building.

18 . The computer-implemented method of claim 14 , wherein the first camera device is a video doorbell device mounted on a building proximate a door.

19 . The computer-implemented method of claim 5 , wherein both prior to and following removal of the first node from the binary ratchet tree:

the binary ratchet tree is an unbalanced binary tree;

the first camera device corresponds to a first leaf node;

a root node of the binary ratchet tree is a parent node to the first leaf node; and

the unbalanced binary tree includes more than three leaf nodes that are not direct children of the root node.

20 . The computer-implemented method of claim 5 , wherein determining the updated node secret further comprises:

determining, at the first user device following removal of the first node from the binary ratchet tree, an updated path secret corresponding to the root node of the binary ratchet tree; and

deriving the updated node secret from the updated path secret using a key derivation function.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2024
From: GLUCKMAN, JASON; STRANDBERG, JOHN; ZAHEER, ZAKIUDDIN MOHAMMED
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 068261/0754 →
References Cited (19)
US 11405789B1 · Wei · 2022 [cited by examiner]
US 20030200448A1 · Foster · 2003 [cited by examiner]
US 20090063867A1 · Granados · 2009 [cited by examiner]
US 20090136030A1 · Xie · 2009 [cited by examiner]
US 20110222687A1 · Mori · 2011 [cited by examiner]
US 20130307971A1 · Ganesan · 2013 [cited by examiner]
US 20170126672A1 · Jang · 2017 [cited by examiner]
US 20170337813A1 · Taylor · 2017 [cited by examiner]
US 20230362251A1 · Tang · 2023 [cited by examiner]
US 20240323013A1 · Dillon · 2024 [cited by examiner]
US 20250111764A1 · Ramesh · 2025 [cited by examiner]
US 20250342477A1 · DeBellis · 2025 [cited by examiner]
WO WO0208850A2 · 2002 [cited by examiner]
Radha et al, Image Compression Using Binary Space Partitioning Trees, Dec. 1996, IEEE, pp. 1-15. (Year: 1996). [cited by examiner]
Barnes, et al., “RFC 9420 The Messaging Layer Security (MLS) Protocol”, IETF Trust, Jul. 2023, p. 1-132. [cited by applicant]
Beurdouche, et al., “The Messaging Layer Security (MLS) Architecture”, IETF Trust, Jul. 2023, p. 1-53. [cited by applicant]
Beurdouche, et al., “Messaging Layer Security Towards a new era of secure messaging”, BlackHat, 2019, p. 1-44. [cited by applicant]
Bossuat, et al., “Secure Messaging Apps and Group Protocols, Part 1”, Quarkslab Blog, May 24, 2022, p. 1-13. [cited by applicant]
Bossuat, et al., “Secure Messaging Apps and Group Protocols, Part 2”, Quarkslab Blog, Jun. 16, 2022, p. 1-18. [cited by applicant]