Method and apparatus for querying content protected by identity-based encryption
Abstract
An approach is provided for reducing communication traffic/cost and protecting content by applying recipient criteria in identity-based encryption. A criterion application of a querier causes, at least in part, transmission of a query associated with a first user described according to a first set of criteria. Based on the query, the criterion application of the querier receives one or more second sets of criteria associated with respective second users, wherein the second sets of criteria are matched, at least in part, to the first set of criteria, and wherein at least one of the second sets of criteria is used as a public key for encrypting data according to an identity-based encryption scheme. A criterion application of an information store receives the query associated with the first user, and matches one or more second sets of criteria with all or part of the first set of criteria.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
receiving at a first device a query from a second device for encrypted data, the query being associated with a first user, the first user being described according to a first set of criteria; based, at least in part, on the query and one or more second sets of criteria associated with a second user, determining by the first device whether at least one of the second sets of criteria are matched, at least in part, to the first set of criteria; and associating by the first device the query with the matched at least one of the second sets of criteria used as a public key for encrypting the encrypted data according to an identity-based encryption scheme, wherein the first set of criteria and the second set of criteria include one or more user physical features, one or more user interests, one or more service providing qualifications, one or more product providing qualifications, service providing experience, product providing experience, or a combination thereof, of the first user, the second user, or a combination thereof, or the first set of criteria and the second set of criteria include one or more technical capabilities, one or more usage patterns, one or more environmental conditions, or a combination thereof, associated with the first device, the second device, or a combination thereof.
2 . A method of claim 1 , further comprising:
causing, at least in part, presentation of the matched at least one of the second sets of criteria to the second user, receiving an input, from the second user, for selecting one of the matched at least one of the second sets of criteria; causing, at least in part, reception by the second device of the encrypted data, wherein the encrypted data was encrypted by the first user to share with others before the query is transmitted; and causing, at least in part, decryption by the second device the encrypted data based, at least in part, on the selected second set of criteria.
3 . A method of claim 2 , wherein the decryption further comprises:
causing, at least in part, transmission by the second device a request for a decryption key for the selected second set of criteria; verifying that the second user satisfies the selected one of the second sets of criteria by determining one or more access rights of the second user; and causing, at least in part, transmission of the decryption key to the second device in response to the request upon verifying that the second user satisfies the selected one of the second sets of criteria, wherein the decryption is based, at least in part, on the decryption key.
4 . A method of claim 1 , wherein an information store maintains the set of criteria associated with the first user, the method further comprising:
negotiating with the information store to keep confidential all or some of the first set of criteria.
5 . A method of claim 1 , further comprising:
formatting by the first device the public key into a predetermined information representation structure; constructing by the first device a reduced ordered binary decision diagram from the information representation structure of the public key; and causing, at last in part by the first device, storage of the decision diagram of the public key.
6 . A method of claim 1 , wherein the first user includes at least one pharmaceutical company,
and the second user includes one or more clinical trial participants.
7 . An apparatus comprising:
at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus embedded in a first user device to perform at least the following, receive a query from a second device for encrypted data, the query being associated with a first user, the first user being described according to a first set of criteria; based, at least in part, on the query and one or more second sets of criteria associated with a second user, determine whether at least one of the second sets of criteria are matched, at least in part, to the first set of criteria; and associating the query with the matched at least one of the second sets of criteria used as a public key for encrypting the encrypted data according to an identity-based encryption scheme, wherein the first set of criteria and the second set of criteria include one or more user physical features, one or more user interests, one or more service providing qualifications, one or more product providing qualifications, service providing experience, product providing experience, or a combination thereof, of the first user, the second user, or a combination thereof, or the first set of criteria and the second set of criteria include one or more technical capabilities, one or more usage patterns, one or more environmental conditions, or a combination thereof, associated with the first device, the second device, or a combination thereof.
8 . An apparatus of claim 7 , wherein the apparatus is further caused to:
cause, at least in part, presentation of the matched at least one of the second sets of criteria to the second user, receive an input, from the second user, for selecting one of the matched at least one of the second sets of criteria; cause, at least in part, reception by the second device of the encrypted data, wherein the encrypted data was encrypted by the first user to share with others before the query is transmitted; and cause, at least in part, decryption by the second device the encrypted data based, at least in part, on the selected second set of criteria.
9 . An apparatus of claim 8 , wherein the decryption further comprises:
causing, at least in part, transmission by the second device a request for a decryption key for the selected second set of criteria; verifying that the second user satisfies the selected one of the second sets of criteria by determining one or more access rights of the second user; and causing, at least in part, transmission of the decryption key to the second device in response to the request upon verifying that the second user satisfies the selected one of the second sets of criteria, wherein the decryption is based, at least in part, on the decryption key.
10 . An apparatus of claim 7 , wherein an information store maintains the set of criteria associated with the first user, and the apparatus is further caused to:
negotiate with the information store to keep confidential all or some of the first set of criteria.
11 . An apparatus of claim 7 , wherein the apparatus is further caused to:
formatting by the first device the public key into a predetermined information representation structure; constructing by the first device a reduced ordered binary decision diagram from the information representation structure of the public key; and causing, at last in part by the first device, storage of the decision diagram of the public key.
12 . An apparatus of claim 7 , wherein the first user includes at least one pharmaceutical company, and the second user includes one or more clinical trial participants.
13 . A method comprising:
receiving at one or more second devices a query sent from a first device as made by a first user for encrypted data, the first user being described according to a first set of criteria; matching, by the one or more second devices, one or more second sets of criteria with all or part of the first set of criteria, wherein the matching defines respective second users who are qualified to receive the query, and wherein at least one of the second sets of criteria is matched with all or part of the first set of criteria and was used by a respective second user as a public key for encrypting data to be shared with others, the encrypted data is associated with the respective second user and was encrypted according to an identity-based encryption scheme; and causing, at least in part, transmission of the at least one of the second sets of criteria to the first device, wherein the first set of criteria and the second set of criteria include one or more user physical features, one or more user interests, one or more service providing qualifications, one or more product providing qualifications, service providing experience, product providing experience, or a combination thereof, of the first user, the second user, or a combination thereof, or the first set of criteria and the second set of criteria include one or more technical capabilities, one or more usage patterns, one or more environmental conditions, or a combination thereof, associated with the first device, the second device, or a combination thereof.
14 . A method of claim 13 , further comprising:
receiving a request, from the first device, for a decryption key for the matched at least one of the second sets of criteria; causing, at least in part, verification of whether the first set of criteria substantially describe the first user; and causing, at least in part, transmission of the decryption key based, at least in part, on the verification.
15 . A method of claim 14 , wherein the verification comprises at least one of:
determining one or more access rights associated with the first user; and causing, at least in part, comparison of all or part of the first set of criteria against information associated with the first user that is available locally or externally, the information including an online or offline public record, a transaction history, an activity history, a history of visited locations, an interaction history, associated communication content items, associated memberships, or a combination thereof.
16 . A method of claim 14 , wherein the verification and the transmission are performed by a private key generator, the information store, or a combination thereof.
17 . An apparatus comprising:
at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus embedded in a second user device to perform at least the following, receive a query sent from a first device as made by a first user for encrypted data, the first user being described according to a first set of criteria; matching one or more second sets of criteria with all or part of the first set of criteria, wherein the matching defines a second user who is qualified to receive the query, and wherein at least one of the second sets of criteria is matched with all or part of the first set of criteria and was used by the second user as a public key for encrypting data to be shared with others, the encrypted data is associated with the second user and was encrypted according to an identity-based encryption scheme; and causing, at least in part, transmission of the at least one of the second sets of criteria to the first device, wherein the first set of criteria and the second set of criteria include one or more user physical features, one or more user interests, one or more service providing qualifications, one or more product providing qualifications, service providing experience, product providing experience, or a combination thereof, of the first user, the second user, or a combination thereof, or the first set of criteria and the second set of criteria include one or more technical capabilities, one or more usage patterns, one or more environmental conditions, or a combination thereof, associated with the first device, the second device, or a combination thereof.
18 . An apparatus of claim 17 , wherein the apparatus is further caused to:
receive a request, from the first device, for a decryption key for the matched at least one of the second sets of criteria; cause, at least in part, verification of whether the first set of criteria substantially describe the first user; and cause, at least in part, transmission of the decryption key based, at least in part, on the verification.
19 . An apparatus of claim 18 , wherein the verification comprises at least one of:
determining one or more access rights associated with the first user; and causing, at least in part, comparison of all or part of the first set of criteria against information associated with the first user that is available locally or externally, the information including an online or offline public record, a transaction history, an activity history, a history of visited locations, an interaction history, associated communication content items, associated memberships, or a combination thereof.
20 . An apparatus of claim 18 , wherein the verification and the transmission are performed by a private key generator, the information store, or a combination thereof.Join the waitlist — get patent alerts
Track US2015237021A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.