IP Library Granted Patent US 12,395,331
Granted Patent B2
US 12,395,331 · App. 17/931,733 · Granted Aug 19, 2025

Decryption key generation and recovery

Inventors: Ramarathnam Venkatesan (Redmond, WA); Nishanth Chandran (Bangalore, IN)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
H04L9/0894H04L9/0825H04L9/085
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,395,331
App. No.
17/931,733
Granted
Aug 19, 2025
Kind
B2
Abstract

A decryption key is recovered that is utilized to decrypt an encrypted resource. One or more location attribute policy (LAP) servers determine whether a user attempting to access a resource has the necessary attributes to access the resource and is in a valid location in which the user is required to be to access the resource. The attributes and location are defined by a policy assigned to the resource. To verify that the user has the required attributes, the LAP server(s) request a cryptographic proof from the user that proves that the user has the required attributes. Upon validating the proof, a first portion of the decryption key is released. The LAP server(s) release a second portion of the decryption key after verifying that the user is in the required location. The LAP server(s) generate the decryption key based on the released portions.

Claims (70)

1. A system, comprising:

a processor; and

a memory that stores program code that, when executed by the processor, performs operations to recover a decryption key, the operations comprising:

receiving a cryptographic proof that a user is associated with an attribute required to access a resource in accordance with a policy;

verifying that the cryptographic proof is valid using a zero-knowledge proof;

responsive to verifying that the cryptographic proof is valid, providing a first portion of the decryption key;

determining that the user is at a location at which access to the resource is allowed in accordance with the policy;

responsive to determining that the user is at the location, providing a second portion of the decryption key; and

combining the first portion and the second portion to generate the decryption key.

2. The system of claim 1 , wherein the attribute comprises at least one of:

a clearance level of the user;

a rank of the user within an organization; or

a role of the user within the organization.

3. The system of claim 1 , the operations further comprising:

encrypting the decryption key using a public encryption key of the user; and

providing the encrypted decryption key to a computing device associated with the user.

4. The system of claim 1 , wherein said combining comprises:

summing the first portion and the second portion.

5. The system of claim 1 , the operations further comprising:

decrypting the resource utilizing the decryption key; and

providing the decrypted resource to a computing device associated with the user.

6. The system of claim 1 , wherein the cryptographic proof is verified based on a public encryption key associated with the attribute and an encrypted shared secret associated with the attribute.

7. The system of claim 1 , the operations further comprising:

receiving a request to access the resource, the request specifying a policy identifier of the policy; and

obtaining the policy corresponding to the policy identifier.

8. A method for recovering a decryption key, comprising:

receiving a cryptographic proof that a user is associated with an attribute required to access a resource in accordance with a policy;

verifying that the cryptographic proof is valid using a zero-knowledge proof;

responsive to verifying that the cryptographic proof is valid, providing a first portion of the decryption key;

determining that the user is at a location at which access to the resource is allowed in accordance with the policy;

responsive to determining that the user is at the location, providing a second portion of the decryption key; and

combining the first portion and the second portion to generate the decryption key.

9. The method of claim 8 , wherein the attribute comprises at least one of:

a clearance level of the user;

a rank of the user within an organization; or

a role of the user within the organization.

10. The method of claim 8 , further comprising:

encrypting the decryption key using a public encryption key of the user; and

providing the encrypted decryption key to a computing device associated with the user.

11. The method of claim 8 , wherein said combining comprises:

summing the first portion and the second portion.

12. The method of claim 8 , further comprising:

decrypting the resource utilizing the decryption key; and

providing the decrypted resource to a computing device associated with the user.

13. The method of claim 8 , wherein the cryptographic proof is verified based on a public encryption key associated with the attribute and an encrypted shared secret associated with the attribute.

14. The method of claim 8 , further comprising:

receiving a request to access the resource, the request specifying a policy identifier of the policy; and

obtaining the policy corresponding to the policy identifier.

15. A computer-readable storage medium having program instructions recorded thereon that, when executed by a processor, perform a method for recovering a decryption key comprising:

receiving a cryptographic proof that a user is associated with an attribute required to access a resource in accordance with a policy;

verifying that the cryptographic proof is valid using a zero-knowledge proof;

responsive to verifying that the cryptographic proof is valid, providing a first portion of the decryption key;

determining that the user is at a location at which access to the resource is allowed in accordance with the policy;

responsive to determining that the user is at the location, providing a second portion of the decryption key; and

combining the first portion and the second portion to generate the decryption key.

16. The computer-readable storage medium of claim 15 , wherein the attribute comprises at least one of:

a clearance level of the user;

a rank of the user within an organization; or

a role of the user within the organization.

17. The computer-readable storage medium of claim 15 , the method further comprising:

encrypting the decryption key using a public encryption key of the user; and

providing the encrypted decryption key to a computing device associated with the user.

18. The computer-readable storage medium of claim 15 , wherein said combining comprises:

summing the first portion and the second portion.

19. The computer-readable storage medium of claim 15 , the method further comprising:

decrypting the resource utilizing the decryption key; and

providing the decrypted resource to a computing device associated with the user.

20. The computer-readable storage medium of claim 15 , the method further comprising:

receiving a request to access the resource, the request specifying a policy identifier of the policy; and

obtaining the policy corresponding to the policy identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2022
From: VENKATESAN, RAMARATHNAM; CHANDRAN, NISHANTH
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 061080/0579 →
Continuity (1)
Related Publication 20240089098A1 · Mar 14, 2024
References Cited (89)
US 8601549B2 · Dickerson · 2013 [cited by applicant]
US 9547771B2 · Roth · 2017 [cited by examiner]
US 10211977B1 · Roth · 2019 [cited by examiner]
US 10637855B2 · Mikulski · 2020 [cited by examiner]
US 10990689B1 · Reiner · 2021 [cited by applicant]
US 11036869B2 · Roth · 2021 [cited by examiner]
US 11139954B2 · Mercuri · 2021 [cited by examiner]
US 11424920B2 · Bursell · 2022 [cited by examiner]
US 11544409B2 · Brannon · 2023 [cited by applicant]
US 11593316B2 · Haldar · 2023 [cited by applicant]
US 11695555B2 · Roth · 2023 [cited by examiner]
US 11799630B2 · Zhang · 2023 [cited by applicant]
US 11886574B2 · Bursell · 2024 [cited by examiner]
US 12058265B2 · Khoury · 2024 [cited by examiner]
US 12107900B2 · Gargaro · 2024 [cited by applicant]
US 20020023213A1 · Walker · 2002 [cited by applicant]
US 20020138738A1 · Sames · 2002 [cited by applicant]
US 20070055867A1 · Kanungo et al. · 2007 [cited by applicant]
US 20120060207A1 · Mardikar et al. · 2012 [cited by applicant]
US 20130145151A1 · Brown · 2013 [cited by applicant]
US 20150089575A1 · Vepa · 2015 [cited by applicant]
US 20150288669A1 · Litoiu · 2015 [cited by applicant]
US 20150381575A1 · Bhargav-spantzel et al. · 2015 [cited by applicant]
US 20170041148A1 · Pearce · 2017 [cited by applicant]
US 20170111175A1 · Oberhauser et al. · 2017 [cited by applicant]
US 20190020485A1 · Uhr · 2019 [cited by applicant]
US 20190163912A1 · Kumar · 2019 [cited by applicant]
US 20190258811A1 · Ferraiolo · 2019 [cited by applicant]
US 20190370358A1 · Nation · 2019 [cited by applicant]
US 20190394175A1 · Zhang · 2019 [cited by applicant]
US 20200014537A1 · Ortiz · 2020 [cited by applicant]
US 20200082401A1 · Arora · 2020 [cited by applicant]
US 20200322342A1 · Gokhale · 2020 [cited by applicant]
US 20200374105A1 · Padmanabhan · 2020 [cited by applicant]
US 20200396222A1 · Gargaro et al. · 2020 [cited by applicant]
US 20200404023A1 · Zhu · 2020 [cited by applicant]
US 20210089676A1 · Ford · 2021 [cited by applicant]
US 20210092607A1 · Klinkner · 2021 [cited by applicant]
US 20210218742A1 · Cook · 2021 [cited by applicant]
US 20210232707A1 · Wilson · 2021 [cited by applicant]
US 20210233673A1 · Zhang · 2021 [cited by applicant]
US 20210273931A1 · Murdoch et al. · 2021 [cited by applicant]
US 20210279355A1 · Otte · 2021 [cited by applicant]
US 20210303714A1 · Yaghoobi · 2021 [cited by applicant]
US 20210367778A1 · Hamel · 2021 [cited by applicant]
US 20210377037A1 · Antonopoulos et al. · 2021 [cited by applicant]
US 20220020003A1 · Sarkar · 2022 [cited by applicant]
US 20220021711A1 · Marsh · 2022 [cited by applicant]
US 20220138181A1 · Irazabal · 2022 [cited by applicant]
US 20220188810A1 · Doney · 2022 [cited by applicant]
US 20220269927A1 · Rice · 2022 [cited by applicant]
US 20220271936A1 · Doney · 2022 [cited by applicant]
US 20220292211A1 · Reineke · 2022 [cited by applicant]
US 20220400020A1 · Davies · 2022 [cited by applicant]
US 20220417254A1 · Michaelis · 2022 [cited by applicant]
US 20230015569A1 · Davies · 2023 [cited by applicant]
US 20230035317A1 · Jufer · 2023 [cited by applicant]
US 20230336547A1 · Damour · 2023 [cited by applicant]
US 20230379699A1 · Oerton · 2023 [cited by applicant]
US 20230388348A1 · Authement · 2023 [cited by applicant]
US 20240056424A1 · Venkatesan · 2024 [cited by applicant]
US 20240104229A1 · Venkatesan · 2024 [cited by applicant]
US 20240114012A1 · Venkatesan · 2024 [cited by applicant]
US 20240119168A1 · Venkatesan · 2024 [cited by applicant]
US 20240121081A1 · Venkatesan · 2024 [cited by applicant]
CN 110363528A · 2019 [cited by applicant]
CN 114221764A · 2022 [cited by applicant]
JP 2022020557A · 2022 [cited by applicant]
Alansari., “A Blockchain-Based Approach for Secure, Transparent and Accountable Personal Data Sharing”, A thesis submitted in partial fulfillment for the degree of Doctor of Philosophy, Aug. 2, 2020, 213 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Application No. PCT/US2023/031022, mailed on Dec. 11, 2023, 16 pages. [cited by applicant]
Mounnan, et al., “Efficient Distributed Access Control Using Blockchain for Big Data in Clouds”, International Conference on Wireless and Mobile Communications (ICWMC), Jun. 30, 2019, pp. 53-62. [cited by applicant]
“Application as Filed in U.S. Appl. No. 17/819,030”, Filed Date: Aug. 11, 2022, 57 Pages. [cited by applicant]
Antonopoulos, et al., “SQL Ledger: Cryptographically Verifiable Data in Azure SQL Database”, In Proceedings of the International Conference on Management of Data, Jun. 20, 2021, pp. 2437-2449. [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US23/027303”, Mailed Date: Oct. 13, 2023, 12 Pages. [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US23/030412”, Mailed Date: Oct. 18, 2023, 12 Pages. [cited by applicant]
Singh, et al., “Security for Online Transaction Based on User Location”, In Journal of International Journal For Innovative Research In Multidisciplinary Field, vol. 3, Issue 4, Apr. 1, 2017, pp. 60-64. [cited by applicant]
Yue, et al., “GlassDB: An Efficient Verifiable Ledger Database System Through Transparency”, In repository of arXiv:2207.00944v2, Aug. 8, 2022, 14 Pages. [cited by applicant]
Non-Final Office Action mailed on Sep. 6, 2024, in U.S. Appl. No. 17/937,098, 18 pages. [cited by applicant]
Non-Final Office Action mailed on Oct. 18, 2024, in U.S. Appl. No. 17/934,730, 25 pages. [cited by applicant]
Notice of Allowance mailed on Mar. 14, 2025, in U.S. Appl. No. 17/937,098, 12 pages. [cited by applicant]
International Preliminary Report on Patentability received for PCT Application No. PCT/US23/030412, Mar. 27, 2025, 08 Pages. [cited by applicant]
Final Office Action mailed on Apr. 24, 2025, in U.S. Appl. No. 17/934,730, 27 pages. [cited by applicant]
International Preliminary Report On Patentability received for PCT Application No. PCT/US23/030988, Apr. 3, 2025, 08 pages. [cited by applicant]
International Preliminary Report on Patentability received for PCT Application No. PCT/US23/031022, mailed on Apr. 10, 2025, 09 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Application No. PCT/US23/030988, mailed on Nov. 30, 2023, 13 pages. [cited by applicant]
Jaroucheh, et al., “Secretation: Toward a Decentralised Identity and Verifiable Credentials Based Scalable and Decentralised Secret Management Solution”, IEEE International Conference on Blockchain and Cryptocurrency, 2… [cited by applicant]
Notice of Allowance mailed on May 19, 2025, in U.S. Appl. No. 17/937,098 12 pages. [cited by applicant]
Notice of Allowance mailed on May 20, 2025, in U.S. Appl. No. 17/938,711, 10 pages. [cited by applicant]
Notice of Allowance mailed on May 29, 2025, in U.S. Appl. No. 17/819,030, 06 pages. [cited by applicant]