IP Library Granted Patent US 12,425,381
Granted Patent B2
US 12,425,381 · App. 18/350,451 · Granted Sep 23, 2025

Hybrid content protection architecture for email

Inventor: Nicolas Lidzborski (Belmont, CA)
Assignee: Google LLC
H04L63/0485H04L9/321H04L51/212
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,381
App. No.
18/350,451
Granted
Sep 23, 2025
Kind
B2
Abstract

A computer-implemented method when executed by data processing hardware of a user device causes the data processing hardware to perform operations. The operations include obtaining, from a message server, an encrypted message encrypted by a single-use data encryption key (DEK) and an encrypted DEK including the single-use DEK encrypted by a public key (PK). The operations also include transmitting, to a key access control list server (KACLS), a decryption request requesting the KACLS decrypt the encrypted DEK with a PRK associated with the PK. The decryption request includes the encrypted DEK. The KACLS is independent from the message server. The operations also include receiving, from the KACLS, the single-use DEK and decrypting, using the single-use DEK, the encrypted message.

Claims (54)

1. A computer-implemented method when executed by data processing hardware of a user device causes the data processing hardware to perform operations comprising:

generating a single-use data encryption key (DEK);

signing a message with the single-use DEK;

transmitting, to a key access control list server (KACLS), an encryption request comprising the single-use DEK;

after transmitting the encryption request to the KACLS, receiving, from the KACLS, an encrypted single-use DEK encrypted by a private key associated with a user of the user device; and

transmitting, to a message server independent from the KACLS, the signed message and the encrypted single-use DEK.

2. The computer-implemented method of claim 1 , wherein the single-use DEK has not been used to encrypt any previous messages.

3. The computer-implemented method of claim 1 , wherein the encryption request is configured to cause the KACLS to:

obtain, via the message server, an encrypted private key encrypted by a KACLS encryption key;

decrypt the encrypted private key using the KACLS encryption key;

encrypt the single-use DEK with the private key; and

return the encrypted single-use DEK to the user device.

4. The computer-implemented method of claim 1 , wherein the signed message and the encrypted single-use DEK are configured to cause the message server to send the signed message and the encrypted single-use DEK to a second user device.

5. The computer-implemented method of claim 4 , wherein the signed message and the encrypted single-use DEK are configured to cause the second user device to decrypt the encrypted single-use DEK using a public key associated with the user.

6. The computer-implemented method of claim 4 , wherein the operations further comprise encrypting the message with a public key associated with a second user associated with the second user device.

7. The computer-implemented method of claim 1 , wherein the encryption request is configured to cause the KACLS to:

authenticate the user of the user device with the message server; and

authenticate the user of the user device with a third party identity provider independent from the message server.

8. The computer-implemented method of claim 1 , wherein the encryption request is configured to cause the KACLS to log information associated with the encryption request.

9. The computer-implemented method of claim 8 , wherein the logged information comprises at least one of:

a date and time of the encryption request;

a user identification; or

a purpose of the encryption request.

10. The computer-implemented method of claim 1 , wherein:

the signed message comprises an email; and

the message server comprises an email service.

11. A system comprising:

data processing hardware of a user device; and

memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:

generating a single-use data encryption key (DEK);

signing a message with the single-use DEK;

transmitting, to a key access control list server (KACLS), an encryption request comprising the single-use DEK;

after transmitting the encryption request to the KACLS, receiving, from the KACLS, an encrypted single-use DEK encrypted by a private key associated with a user of the user device; and

transmitting, to a message server independent from the KACLS, the signed message and the encrypted single-use DEK.

12. The system of claim 11 , wherein the single-use DEK has not been used to encrypt any previous messages.

13. The system of claim 11 , wherein the encryption request is configured to cause the KACLS to:

obtain, via the message server, an encrypted private key encrypted by a KACLS encryption key;

decrypt the encrypted private key using the KACLS encryption key;

encrypt the single-use DEK with the private key; and

return the encrypted single-use DEK to the user device.

14. The system of claim 11 , wherein the signed message and the encrypted single-use DEK are configured to cause the message server to send the signed message and the encrypted single-use DEK to a second user device.

15. The system of claim 14 , wherein the signed message and the encrypted single-use DEK are configured to cause the second user device to decrypt the encrypted single-use DEK using a public key associated with the user.

16. The system of claim 14 , wherein the operations further comprise encrypting the message with a public key associated with a second user associated with the second user device.

17. The system of claim 11 , wherein the encryption request is configured to cause the KACLS to:

authenticate the user of the user device with the message server; and

authenticate the user of the user device with a third party identity provider independent from the message server.

18. The system of claim 11 , wherein the encryption request is configured to cause the KACLS to log information associated with the encryption request.

19. The system of claim 18 , wherein the logged information comprises at least one of:

a date and time of the encryption request;

a user identification; or

a purpose of the encryption request.

20. The system of claim 11 , wherein:

the signed message comprises an email; and

the message server comprises an email service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2023
From: LIDZBORSKI, NICOLAS
To: GOOGLE LLC
Reel/Frame 064215/0305 →
Continuity (2)
Continuation 17649675 · Feb 1, 2022
Related Publication 20230353548A1 · Nov 2, 2023
References Cited (13)
US 7178021B1 · Hanna · 2007 [cited by examiner]
US 10033703B1 · Sharifi Mehr · 2018 [cited by applicant]
US 11483305B2 · Ilic et al. · 2022 [cited by applicant]
US 20140369498A1 · Hammersmith · 2014 [cited by applicant]
US 20180091484A1 · Atta · 2018 [cited by examiner]
US 20190130128A1 · Khassanov et al. · 2019 [cited by applicant]
CN 107491296A · 2017 [cited by applicant]
EP 2112625A2 · 2009 [cited by applicant]
JP H1040100A · 1998 [cited by applicant]
Anonymous: “Google Cloud Security Whitepapers Google Cloud Infrastructure Security Design Overview”, Mar. 31, 2018 (Mar. 31, 2018), XP055776854. [cited by applicant]
Barnes Cisco K Bhargavan B Lipp Inria C A Wood Cloudflare R L: “Hybrid Public Key Encryption draft-irtf-cfrg-hpke-12; draft-irtf-cfrg-hpke-12.txt”, Hybrid Public Key Encryption DRAFT-IRTF-CFRG-HPKE-12; DRAFT-IRTF-CFRG-H… [cited by applicant]
Hobson, F., What is an IdP (Identity Provider) and why do you need one?, [online], Aug. 21, 2020, <available at: https://www.ubisecure.com/identity-provider/what-is-anidentity-provider-idp/>. [cited by applicant]
Japanese Office Action for the related JP application No. 2024-544987 dated Jun. 20, 2025. [cited by applicant]