IP Library Granted Patent US 12,299,158
Granted Patent B2
US 12,299,158 · App. 18/012,998 · Granted May 13, 2025

Method, computer program, and data processing circuitry for access control to encrypted data using attributes of the data

Inventors: Dimitri Torfs (Stuttgart, DE); Alexandru Serbanati (Stuttgart, DE); Michele Minelli (Stuttgart, DE)
Assignee: SONY GROUP CORPORATION
G06F21/6218G06F21/602H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,299,158
App. No.
18/012,998
Granted
May 13, 2025
Kind
B2
Abstract

A method for sharing encrypted data including encrypting first data with at least one first attribute. The first attribute satisfies a first access policy of a first cryptographic key to enable one or more first users holding the first cryptographic key to decrypt the encrypted first data using the first cryptographic key. The method includes encrypting second data with at least one second attribute of the second data. The method includes generating a second cryptographic key based on a second access policy including at least one logical connective of the first attribute and the second attribute for decrypting the encrypted first data and the encrypted second data using the second cryptographic key and providing the second cryptographic key to one or more second users to enable the second users to decrypt the encrypted first data and the encrypted second data.

Claims (25)

1. A method for sharing encrypted data, the method comprising:

encrypting first data with at least one first attribute of the first data, wherein the first attribute satisfies a first access policy of a first cryptographic key to enable one or more first users holding the first cryptographic key to decrypt the encrypted first data using the first cryptographic key;

encrypting second data with at least one second attribute of the second data, wherein the second data is different from the first data and the second attribute is different from the first attribute that the first data was encrypted with;

generating a second cryptographic key based on a second access policy including at least one logical connective of the first attribute and the second attribute for decrypting the encrypted first data that was encrypted with first attribute using the second cryptographic key and for decrypting the encrypted second data that was encrypted with the second attribute of the second data using the second cryptographic key; and

providing the second cryptographic key to one or more second users to enable the second users to decrypt the encrypted first data using the second cryptographic key and to enable the second users to decrypt the encrypted second data using the second cryptographic key.

2. The method of claim 1 , wherein the first attribute and/or the second attribute comprise at least one of a date, a time, a version number, and a data type of the first data and/or the second data.

3. The method of claim 1 ,

wherein the first attribute comprises a number, and

wherein the method comprises determining the second attribute by incrementing the number.

4. The method of claim 1 , wherein the second access policy includes an inclusive disjunction of the first attribute and the second attribute.

5. The method of claim 1 , further comprising providing the second encrypted data to the second users.

6. The method of claim 1 , wherein the first data and/or the second data includes media data.

7. A non-transitory computer readable medium storing computer program comprising instructions which, when the computer program is executed by a computer, cause the computer to execute the method of claim 1 .

8. A data processing circuitry for sharing encrypted data, wherein the data processing circuitry is configured to:

encrypt first data with at least one first attribute of the first data, wherein the first attribute satisfies a first access policy of a first cryptographic key to enable one or more first users holding the first cryptographic key to decrypt the encrypted first data using the first cryptographic key;

encrypt second data with at least one second attribute of the second data, wherein the second data is different from the first data and the second attribute is different from the first attribute that the first data was encrypted with;

generate a second cryptographic key based on a second access policy including at least one logical connective of the first attribute and the second attribute for decrypting the encrypted first data that was encrypted with first attribute using the second cryptographic key and for decrypting the encrypted second data that was encrypted with the second attribute of the second data using the second cryptographic key; and

provide the second cryptographic key to one or more second users to enable the second users to decrypt the encrypted first data using the second cryptographic key and to enable the second users to decrypt the encrypted second data using the second cryptographic key.

9. The data processing circuitry of claim 8 , wherein the first attribute and/or the second attribute comprise at least one of a date, a time, a version number, and a data type of the first data and/or the second data.

10. The data processing circuitry of claim 8 ,

wherein the first attribute comprises a number, and

wherein the method comprises determining the second attribute by incrementing the number.

11. The data processing circuitry of claim 8 , wherein the second access policy includes an inclusive disjunction of the first attribute and the second attribute.

12. The data processing circuitry of claim 8 , wherein the data processing circuitry is further configured to provide the second encrypted data to the second users.

13. The data processing circuitry of claim 8 , wherein the first data and/or the second data includes media data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 27, 2022
From: TORFS, DIMITRI; SERBANATI, ALEXANDRU; MINELLI, MICHELE
To: SONY GROUP CORPORATION
Reel/Frame 062209/0683 →
Priority Claims (2)
EP 20187169 · Jul 22, 2020 · regional
EP 20210800 · Nov 30, 2020 · regional
Continuity (1)
Related Publication 20230237183A1 · Jul 27, 2023
References Cited (10)
US 9894043B2 · Khoury et al. · 2018 [cited by applicant]
US 10476863B1 · Hanlon · 2019 [cited by applicant]
US 11133926B2 · Le Van Gong · 2021 [cited by examiner]
US 20050027999A1 · Pelly et al. · 2005 [cited by applicant]
US 20120144210A1 · Yacobi · 2012 [cited by examiner]
US 20140208122A1 · Mathur et al. · 2014 [cited by applicant]
US 20150222606A1 · Yan · 2015 [cited by examiner]
US 20160140347A1 · Schaad · 2016 [cited by examiner]
International Search Report and Written Opinion mailed on Sep. 24, 2021, received for PCT Application PCT/EP2021/067080, filed on Jun. 23, 2021, 12 pages. [cited by applicant]
Attrapadung et al., “Conjunctive Broadcast and Attribute-Based Encryption”, ICIAP: International Conference on Image Analysis and Processing, 17th International Conference, Aug. 12, 2009, pp. 248-265. [cited by applicant]