IP Library Patent Application 19015187
Patent Application
App. No. 19/015,187

SYSTEMS AND METHODS FOR SELECTIVE ACCESS TO LOGS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/015,187
Abstract

Systems are provided for managing access to a log of dataset that is generated when the dataset is accessed. A system stores, with respect to each of a log producer and a log accessor, an encrypted symmetric key for dataset that is encrypted using a corresponding public key. The system returns the encrypted symmetric key for the log producer, such that the log producer can decrypt the dataset that is encrypted using the symmetric key. A log of the dataset is generated when the log producer accesses the dataset.

Claims (55)

1 . A system, comprising:

one or more processors; and

a memory storing instructions that, when executed by the one or more processors, cause the system to perform:

receiving an indication of an access to a dataset, the access corresponding to a first access privilege;

in response to receiving the indication of the access, generating a log, wherein the log records one or more accesses to the dataset, and the log comprises different portions having different security parameters or different access privileges;

encrypting the log using a dataset key, wherein the dataset key is configured to decrypt the dataset; and

storing the encrypted log with the dataset or a copy of the dataset in a storage.

2 . The system of claim 1 , wherein the instructions that, when executed by the one or more processors, cause the system to perform:

receiving a request to access at least a portion of the encrypted log, wherein the request corresponds to a second access privilege; and

based on the second access privilege, selectively providing access to at least a portion of the encrypted log.

3 . The system of claim 2 , wherein the receiving of the request comprises:

receiving, at a dataset key server configured to store encrypted dataset keys, a request for a particular encrypted dataset key corresponding to the second access privilege;

upon authentication of the second access privilege, transmitting the particular encrypted dataset key;

accessing, at a secret key server configured to store secret keys, a particular secret key corresponding to the second access privilege; and

decrypting, using the particular secret key, the particular encrypted dataset key, where the decrypting causes generation of the dataset key.

4 . The system of claim 2 , wherein the selectively providing access to at least a portion of the encrypted log comprises decrypting at least a portion of the encrypted log using the dataset key.

5 . The system of claim 2 , wherein the first access privilege corresponds to a privilege to generate the log and full access privilege to the log, and wherein the second access privilege corresponds to at least a partially restricted access privilege to the log.

6 . The system of claim 1 , wherein the instructions further cause the system to perform:

deactivating the dataset key upon the log being encrypted.

7 . The system of claim 1 , wherein the instructions further cause the system to perform:

deactivating the dataset key within a threshold time duration of the log being encrypted.

8 . A method comprising:

receiving an indication of an access to a dataset, the access corresponding to a first access privilege;

in response to receiving the indication of the access, generating a log, wherein the log records one or more accesses to the dataset, and the log comprises different portions having different security parameters or different access privileges;

encrypting the log using a dataset key, wherein the dataset key is configured to decrypt the dataset; and

storing the encrypted log with the dataset or a copy of the dataset in a storage.

9 . The method of claim 8 , further comprising:

receiving a request to access at least a portion of the encrypted log, wherein the request corresponds to a second access privilege; and

based on the second access privilege, selectively providing access to at least a portion of the encrypted log.

10 . The method of claim 9 , wherein the receiving of the request comprises:

receiving, at a dataset key server configured to store encrypted dataset keys, a request for a particular encrypted dataset key corresponding to the second access privilege;

upon authentication of the second access privilege, transmitting the particular encrypted dataset key;

accessing, at a secret key server configured to store secret keys, a particular secret key corresponding to the second access privilege; and

decrypting, using the particular secret key, the particular encrypted dataset key, where the decrypting causes generation of the dataset key.

11 . The method of claim 9 , wherein the selectively providing access to at least a portion of the encrypted log comprises decrypting at least a portion of the encrypted log using the dataset key.

12 . The method of claim 9 , wherein the first access privilege corresponds to a privilege to generate the log and full access privilege to the log, and wherein the second access privilege corresponds to at least a partially restricted access privilege to the log.

13 . The method of claim 8 , further comprising deactivating the dataset key upon the log being encrypted.

14 . The method of claim 8 , further comprising deactivating the dataset key within a threshold time duration of the log being encrypted.

15 . A non-transitory computer readable medium comprising instructions that, when executed, cause one or more processors to perform:

receiving an indication of an access to a dataset, the access corresponding to a first access privilege;

in response to receiving the indication of the access, generating a log, wherein the log records one or more accesses to the dataset, and the log comprises different portions having different security parameters or different access privileges;

encrypting the log using a dataset key, wherein the dataset key is configured to decrypt the dataset; and

storing the encrypted log with the dataset or a copy of the dataset in a storage.

16 . The non-transitory computer readable medium of claim 15 , wherein the instructions that, when executed by the one or more processors, cause the one or more processors to perform:

receiving a request to access at least a portion of the encrypted log, wherein the request corresponds to a second access privilege; and

based on the second access privilege, selectively providing access to at least a portion of the encrypted log.

17 . The non-transitory computer readable medium of claim 16 , wherein the receiving of the request comprises:

receiving, at a dataset key server configured to store encrypted dataset keys, a request for a particular encrypted dataset key corresponding to the second access privilege;

upon authentication of the second access privilege, transmitting the particular encrypted dataset key;

accessing, at a secret key server configured to store secret keys, a particular secret key corresponding to the second access privilege; and

decrypting, using the particular secret key, the particular encrypted dataset key, where the decrypting causes generation of the dataset key.

18 . The non-transitory computer readable medium of claim 16 , wherein the selectively providing access to at least a portion of the encrypted log comprises decrypting at least a portion of the encrypted log using the dataset key.

19 . The non-transitory computer readable medium of claim 16 , wherein the first access privilege corresponds to a privilege to generate the log and full access privilege to the log, and wherein the second access privilege corresponds to at least a partially restricted access privilege to the log.

20 . The non-transitory computer readable medium of claim 15 , wherein the instructions that. when executed by the one or more processors, cause the one or more processors to perform:

deactivating the dataset key upon the log being encrypted.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2025
From: SHANKS, VAUGHAN; LAMPERT, ANDREW
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 069806/0214 →