IP Library › Granted Patent US 12,524,563
Granted Patent B2
US 12,524,563 · App. 18/173,111 · Granted Jan 13, 2026

System and method for efficient cryptographically-assured data access management for advanced data access policies

Inventor: Vivek Chinar Nair (Santa Clara, CA)
Assignee: Multifactor, Inc.
G06F21/6227G06F21/602G06F21/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,524,563
App. No.
18/173,111
Granted
Jan 13, 2026
Kind
B2
Abstract

A system and method for efficient cryptographically-assured data access management for advanced data access policies includes: a user having a cryptographic key; a client device; and a graph database; whereby the user makes requests to the graph database using the client device; and whereby the graph database cryptographically enforces a data access policy.

Claims (26)

1 . A system for efficient cryptographically-assured data access management for advanced data access policies comprising:

a graph database including one or more encrypted objects;

whereby a user makes requests to the graph database using a client device;

whereby each user holds at least one key from a set of user keys, and each of the one or more encrypted objects is encrypted with at least one key from a set of object keys;

whereby cryptographic material is stored as properties of edges in the graph database;

whereby the process of accessing the one or more encrypted objects involves combining the encrypted object and the cryptographic material; and

whereby the graph database cryptographically enforces a data access policy.

2 . The system for efficient cryptographically-assured data access management of claim 1 , whereby proxy re-encryption is further used for objects stored by the graph database.

3 . The system for efficient cryptographically-assured data access management of claim 2 , whereby the graph database applies proxy re-encryption to transform data objects requested by the client.

4 . The system for efficient cryptographically-assured data access management of claim 2 , whereby users can delegate their access by creating an edge in the graph database.

5 . The system for efficient cryptographically-assured data access management of claim 1 , whereby at least one of attribute-based encryption, homomorphic encryption, property-preserving encryption, and threshold encryption is further used for objects stored by the graph database.

6 . The system for efficient cryptographically-assured data access management of claim 1 , whereby the graph database is further capable of automatically optimizing a provided data access policy using one or more available cryptosystems.

7 . The system for efficient cryptographically-assured data access management of claim 1 , whereby edges are used to provide hierarchical organization.

8 . The system for efficient cryptographically-assured data access management of claim 1 , whereby a shortest path algorithm is used to determine the most efficient way to access an object.

9 . The system for efficient cryptographically-assured data access management of claim 1 , whereby a graph algorithm is used to generate a list of objects or collections accessible to a user or group.

10 . The system for efficient cryptographically-assured data access management of claim 1 , whereby a graph algorithm is used to generate a list of users or groups with access to an object or collection.

11 . The system for efficient cryptographically-assured data access management of claim 1 , whereby separate read and write permissions are used.

12 . The system for efficient cryptographically-assured data access management of claim 1 , whereby at least one server is granted access to an object or collection.

13 . The system for efficient cryptographically-assured data access management of claim 1 , whereby separate administrative permissions are used.

14 . The system for efficient cryptographically-assured data access management of claim 1 , further comprising an audit log which stores data access requests.

15 . The system for efficient cryptographically-assured data access management of claim 1 , whereby users can generate a proof of access permission using at least one of a signature chain and zero-knowledge proofs.

16 . The system for efficient cryptographically-assured data access management of claim 1 , whereby at least one of the graph database and a function associated with the graph database is serverless.

17 . The system for efficient cryptographically-assured data access management of claim 1 , further comprising a trusted computing chip associated with at least one of the graph database and a server communicating with the graph database.

18 . The system for efficient cryptographically-assured data access management of claim 1 , further comprising a database for storing data objects, whereby the graph database stores cryptographic keys used to encrypt objects in the database.

19 . The system for efficient cryptographically-assured data access management of claim 1 , whereby access control models are enforced by the graph database.

20 . The system for efficient cryptographically-assured data access management of claim 1 , whereby a cryptographic key of the user is at least one of a derived key and a hardware-based key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2025
From: NAIR, VIVEK
To: MULTIFACTOR, INC.
Reel/Frame 072298/0781 →
Continuity (2)
Provisional Application 63269336 · Mar 14, 2022
Related Publication 20240070309A1 · Feb 29, 2024
References Cited (5)
US 9203815B1 · Bogorad · 2015 [cited by examiner]
US 11785114B1 · Fregly · 2023 [cited by examiner]
US 20200051127A1 · Johnson · 2020 [cited by examiner]
US 20200067907A1 · Avetisov · 2020 [cited by examiner]
US 20240193255A1 · Quinlan · 2024 [cited by examiner]