IP Library › Granted Patent US 12,580,740
Granted Patent B2
US 12,580,740 · App. 18/045,335 · Granted Mar 17, 2026

Access control using mediated location, attribute, policy, and purpose verification

Inventors: Ramarathnam Venkatesan (Redmond, WA); Nishanth Chandran (Bangalore, IN); Ganesh Ananthanarayanan (Sammamish, WA); Panagiotis Antonopoulos (Redmond, WA); Srinath T. V. Setty (Redmond, WA); Daniel John Carroll, Jr. (Columbia, MD); Kiran Muthabatulla (Sammamish, WA); Yuanchao Shu (Kirkland, WA); Sanjeev Mehrotra (Kirkland, WA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
H04L9/0825H04L9/085H04L9/0866
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,740
App. No.
18/045,335
Granted
Mar 17, 2026
Kind
B2
Abstract

An access control system is disclosed for controlling access to a resource. A request is received by a location attribute policy (LAP) server to access an encrypted resource. The LAP server accesses a resource policy that identifies requirements for granting access to the encrypted resource, such as a list of attributes of the requestor that are required and a dynamic attribute requirement of the requestor. The LAP server receives a cryptographic proof from the computing device that the requestor possesses the attributes and validates the proof based at least on information obtained from a trusted ledger. Once the proof is validated, the LAP server provides a shared secret associated with the dynamic attribute requirement to a decryption algorithm. The decryption algorithm uses the dynamic attribute shared secret in combination with one or more attribute shared secrets from the requestor to generate a decryption key for the encrypted resource.

Claims (51)

1 . An access control system, comprising:

a processor circuit; and

a memory that stores program code configured to be executed by the processor circuit, the program code, when executed by the processor circuit, causes the system to:

receive a request originating from a computing device to access an encrypted resource;

access a resource policy that indicates a set of requirements for accessing the encrypted resource, the set of requirements including a static attribute requirement and a dynamic attribute requirement;

receive a proof of a static attribute from the computing device, the proof indicating that a user of the computing device possesses the static attribute, the static attribute being associated with a first shared secret stored on the computing device;

validate the proof of the static attribute based at least on information in a trusted ledger associated with the user of the device;

determine that the validated proof satisfies the static attribute requirement;

in response to the determination that the validated proof satisfies the static attribute requirement, provide a certificate validating the dynamic attribute requirement to a decryption algorithm, the certificate including a second shared secret corresponding to a dynamic attribute; and

provide the first shared secret to the decryption algorithm, wherein the first shared secret and the second shared secret in the certificate are used by the decryption algorithm to compute a decryption key for the encrypted resource.

2 . The system of claim 1 , wherein the proof indicating that the user of the computing device possesses the static attribute is a cryptographic proof that comprises a value generated based at least on the first shared secret corresponding to the static attribute, a public key corresponding to the static attribute, and an encryption algorithm.

3 . The system of claim 2 , wherein the first shared secret corresponding to the static attribute cannot be reconstructed from the value in the cryptographic proof.

4 . The system of claim 1 , wherein the dynamic attribute requirement is a location requirement that requires that the user device be physically located within a proximity of a predetermined location at a time the request is received.

5 . The system of claim 1 , wherein the resource policy further indicates a purpose requirement that defines a predetermined purpose required to access the encrypted resource, and

wherein the program code further verifies that the purpose requirement is satisfied prior to providing the certificate validating the dynamic attribute requirement.

6 . The system of claim 1 , wherein information contained in the trusted ledger comprises a user identifier, a public key corresponding to the static attribute, and an encrypted version of the first shared secret corresponding to the static attribute.

7 . The system of claim 6 , wherein the program code further validates the proof of the static attribute by comparing a first value determined from the encrypted version of the first shared secret and the public key corresponding to the static attribute with a second value based on the proof of the static attribute received from the computing device.

8 . The system of claim 1 , wherein the decryption algorithm further:

provides, to the computing device, the decryption key for decrypting the encrypted resource.

9 . The system of claim 1 , wherein the program code further:

receives identification information from the computing device; and

identifies the information in the trusted ledger based on the identification information.

10 . An access control method, comprising:

receiving a request originating from a computing device to access an encrypted resource;

accessing a resource policy that indicates a set of requirements for accessing the encrypted resource, the set of requirements including a static attribute requirement and a dynamic attribute requirement;

receiving a proof of a static attribute from the computing device, the proof indicating that a user of the computing device possesses the static attribute, the static attribute being associated with a first shared secret stored on the computing device;

validating the proof of the static attribute based at least on information in a trusted ledger associated with the user of the device;

determining that the validated proof satisfies the static attribute requirement;

in response to the determination that the validated proof satisfies the static attribute requirement, providing a certificate validating the dynamic attribute requirement to a decryption algorithm, the certificate including a second shared secret corresponding to a dynamic attribute; and

providing the first shared secret to the decryption algorithm, wherein the first shared secret and the second shared secret in the certificate are used by the decryption algorithm to compute a decryption key for the encrypted resource.

11 . The method of claim 10 , wherein the proof indicating that the user of the computing device possesses the static attribute is a cryptographic proof that comprises a value generated based at least on the first shared secret corresponding to the static attribute, a public key corresponding to the static attribute, and an encryption algorithm.

12 . The method of claim 11 , wherein the first shared secret corresponding to the static attribute cannot be reconstructed from the value in the cryptographic proof.

13 . The method of claim 10 , wherein the dynamic attribute requirement is a location requirement that requires that the user device be physically located within a proximity of a predetermined location at a time the request is received.

14 . The method of claim 10 , wherein the resource policy further indicates a purpose requirement that defines a predetermined purpose required to access the encrypted resource, and

wherein the method further comprises verifying that the purpose requirement is satisfied prior to providing the certificate validating the dynamic attribute requirement.

15 . The method of claim 10 , wherein information contained in the trusted ledger comprises a user identifier, a public key corresponding to the static attribute, and an encrypted version of the first shared secret corresponding to the static attribute.

16 . The method of claim 15 , wherein the method further comprises validating the proof of the static attribute by comparing a first value determined from the encrypted version of the first shared secret and the public key corresponding to the static attribute with a second value based on the proof of the static attribute received from the computing device.

17 . The method of claim 10 , wherein the decryption algorithm further:

provides, to the computing device, the decryption key for decrypting the encrypted resource.

18 . The method of claim 10 , further comprising:

receiving identification information from the computing device; and

identifying the information in the trusted ledger based on the identification information.

19 . A computer-readable storage medium having computer program code recorded thereon that when executed by at least one processor causes the at least one processor to perform a method comprising:

receiving a request originating from a computing device to access an encrypted resource;

accessing a resource policy that indicates a set of requirements for accessing the encrypted resource, the set of requirements including a static attribute requirement and a dynamic attribute requirement;

receiving a proof of a static attribute from the computing device, the proof indicating that a user of the computing device possesses the static attribute, the static attribute being associated with a first shared secret stored on the computing device;

validating the proof of the static attribute based at least on information in a trusted ledger associated with the user of the device;

determining that the validated proof satisfies the static attribute requirement;

in response to the determination that the validated proof satisfies the static attribute requirement, providing a certificate validating the dynamic attribute requirement to a decryption algorithm, the certificate including a second shared secret corresponding to a dynamic attribute; and

providing the first shared secret to the decryption algorithm, wherein the first shared secret and the second shared secret in the certificate are used by the decryption algorithm to compute a decryption key for the encrypted resource.

20 . The computer-readable storage medium of claim 19 , wherein the proof indicating that the user of the computing device possesses the static attribute is a cryptographic proof that comprises a value generated based at least on the first shared secret corresponding to the static attribute, a public key corresponding to the static attribute, and an encryption algorithm.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2022
From: VENKATESAN, RAMARATHNAM; CHANDRAN, NISHANTH; ANANTHANARAYANAN, GANESH; ANTONOPOULOS, PANAGIOTIS; SETTY, SRINATH T.V.; CARROLL, DANIEL JOHN, JR.; MUTHABATULLA, KIRAN; SHU, YUANCHAO; MEHROTRA, SANJEEV
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 061422/0796 →
Continuity (1)
Related Publication 20240121081A1 · Apr 11, 2024
References Cited (87)
US 8601549B2 · Dickerson · 2013 [cited by applicant]
US 9547771B2 · Roth · 2017 [cited by applicant]
US 10211977B1 · Roth · 2019 [cited by applicant]
US 10637855B2 · Mikulski · 2020 [cited by applicant]
US 10990689B1 · Reiner · 2021 [cited by applicant]
US 11036869B2 · Roth · 2021 [cited by applicant]
US 11139954B2 · Mercuri · 2021 [cited by applicant]
US 11424920B2 · Bursell et al. · 2022 [cited by applicant]
US 11544409B2 · Brannon · 2023 [cited by applicant]
US 11593316B2 · Haldar · 2023 [cited by applicant]
US 11695555B2 · Roth · 2023 [cited by applicant]
US 11799630B2 · Zhang · 2023 [cited by applicant]
US 11886574B2 · Bursell et al. · 2024 [cited by applicant]
US 12058265B2 · Khoury · 2024 [cited by applicant]
US 12107900B2 · Gargaro · 2024 [cited by applicant]
US 20020023213A1 · Walker · 2002 [cited by applicant]
US 20020138738A1 · Sames · 2002 [cited by applicant]
US 20070055867A1 · Kanungo et al. · 2007 [cited by applicant]
US 20120060207A1 · Mardikar et al. · 2012 [cited by applicant]
US 20130145151A1 · Brown · 2013 [cited by applicant]
US 20150089575A1 · Vepa · 2015 [cited by applicant]
US 20150288669A1 · Litoiu · 2015 [cited by applicant]
US 20150381575A1 · Bhargav-spantzel et al. · 2015 [cited by applicant]
US 20170041148A1 · Pearce · 2017 [cited by applicant]
US 20170111175A1 · Oberhauser · 2017 [cited by examiner]
US 20190020485A1 · Uhr · 2019 [cited by applicant]
US 20190163912A1 · Kumar · 2019 [cited by applicant]
US 20190258811A1 · Ferraiolo · 2019 [cited by applicant]
US 20190370358A1 · Nation · 2019 [cited by applicant]
US 20190394175A1 · Zhang · 2019 [cited by applicant]
US 20200014537A1 · Ortiz · 2020 [cited by applicant]
US 20200082401A1 · Arora · 2020 [cited by examiner]
US 20200322342A1 · Gokhale · 2020 [cited by applicant]
US 20200374105A1 · Padmanabhan · 2020 [cited by applicant]
US 20200396222A1 · Gargaro et al. · 2020 [cited by applicant]
US 20200404023A1 · Zhu · 2020 [cited by examiner]
US 20210089676A1 · Ford · 2021 [cited by applicant]
US 20210092607A1 · Klinkner · 2021 [cited by applicant]
US 20210218742A1 · Cook · 2021 [cited by applicant]
US 20210232707A1 · Wilson · 2021 [cited by applicant]
US 20210233673A1 · Zhang · 2021 [cited by applicant]
US 20210273931A1 · Murdoch · 2021 [cited by examiner]
US 20210279355A1 · Otte · 2021 [cited by examiner]
US 20210303714A1 · Yaghoobi · 2021 [cited by applicant]
US 20210367778A1 · Hamel · 2021 [cited by applicant]
US 20210377037A1 · Antonopoulos et al. · 2021 [cited by applicant]
US 20220020003A1 · Sarkar · 2022 [cited by applicant]
US 20220021711A1 · Marsh · 2022 [cited by applicant]
US 20220138181A1 · Irazabal · 2022 [cited by applicant]
US 20220188810A1 · Doney · 2022 [cited by applicant]
US 20220269927A1 · Rice · 2022 [cited by applicant]
US 20220271936A1 · Doney · 2022 [cited by applicant]
US 20220292211A1 · Reineke · 2022 [cited by applicant]
US 20220400020A1 · Davies · 2022 [cited by applicant]
US 20220417254A1 · Michaelis · 2022 [cited by applicant]
US 20230015569A1 · Davies · 2023 [cited by applicant]
US 20230035317A1 · Jufer · 2023 [cited by applicant]
US 20230336547A1 · Damour · 2023 [cited by applicant]
US 20230379699A1 · Oerton · 2023 [cited by applicant]
US 20230388348A1 · Authement · 2023 [cited by applicant]
US 20240056424A1 · Venkatesan · 2024 [cited by applicant]
US 20240089098A1 · Venkatesan · 2024 [cited by applicant]
US 20240104229A1 · Venkatesan · 2024 [cited by applicant]
US 20240114012A1 · Venkatesan · 2024 [cited by applicant]
US 20240119168A1 · Venkatesan · 2024 [cited by applicant]
CN 110363528A · 2019 [cited by applicant]
CN 114221764A · 2022 [cited by applicant]
JP 2022020557A · 2022 [cited by applicant]
Non-Final Office Action mailed on Sep. 6, 2024, in U.S. Appl. No. 17/937,098, 18 pages. [cited by applicant]
Alansari., “A Blockchain-Based Approach for Secure, Transparent and Accountable Personal Data Sharing”, A thesis submitted in partial fulfillment for the degree of Doctor of Philosophy, Aug. 2, 2020, 213 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Application No. PCT/US2023/031022, mailed on Dec. 11, 2023, 16 pages. [cited by applicant]
Mounnan, et al., “Efficient Distributed Access Control Using Blockchain for Big Data in Clouds”, International Conference on Wireless and Mobile Communications (ICWMC), Jun. 30, 2019, pp. 53-62. [cited by applicant]
International Search Report and Written Opinion received for PCT Application No. PCT/US23/030988, mailed on Nov. 30, 2023, 13 pages. [cited by applicant]
“Application as Filed in U.S. Appl. No. 17/819,030”, filed Aug. 11, 2022, 57 Pages. [cited by applicant]
Non-Final Office Action mailed on Oct. 18, 2024, in U.S. Appl. No. 17/934,730, 25 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Application No. PCT/US23/031471, Nov. 14, 2023, 18 pages. [cited by applicant]
Jaroucheh, et al., “Secretation: Toward a Decentralised Identity and Verifiable Credentials Based Scalable and Decentralised Secret Management Solution”, IEEE International Conference on Blockchain and Cryptocurrency, 2… [cited by applicant]
Notice of Allowance mailed on Mar. 14, 2025, in U.S. Appl. No. 17/937,098, 12 pages. [cited by applicant]
International Preliminary Report On Patentability received for PCT Application No. PCT/US23/030988, Apr. 3, 2025, 08 pages. [cited by applicant]
Antonopoulos, et al., “SQL Ledger: Cryptographically Verifiable Data in Azure SQL Database”, In Proceedings of the International Conference on Management of Data, Jun. 20, 2021, pp. 2437-2449. [cited by applicant]
Final Office Action mailed on Apr. 24, 2025, in U.S. Appl. No. 17/934,730, 27 pages. [cited by applicant]
International Preliminary Report on Patentability received for PCT Application No. PCT/US23/031022, mailed on Apr. 10, 2025, 09 pages. [cited by applicant]
International Preliminary Report on Patentability received for PCT Application No. PCT/US23/031471, mailed on Apr. 24, 2025, 14 pages. [cited by applicant]
Notice of Allowance mailed on May 19, 2025, in U.S. Appl. No. 17/937,098 12 pages. [cited by applicant]
Notice of Allowance mailed on May 29, 2025, in U.S. Appl. No. 17/819,030, 06 pages. [cited by applicant]
Singh, et al. , “Security for Online Transaction Based on User Location”, In Journal of International Journal For Innovative Research In Multidisciplinary Field, vol. 3, Issue 4, Apr. 1, 2017, pp. 60-64. [cited by applicant]
Yue, et al. , “GlassDB: An Efficient Verifiable Ledger Database System Through Transparency”, In repository of arXiv:2207.00944v2, Aug. 8, 2022, 14 Pages. [cited by applicant]
Cited By (1)
US 12,701,008