AI News AI资讯 1h ago Updated 48m ago 更新于 48分钟前 43

Ring says its new encryption limits what it can give police Ring称其新加密技术限制了可向警方提供的内容

Ring introduced TAKE (Throw Away the Key Encryption), a new encryption method that limits cloud access to video footage without full end-to-end encryption (E2EE) Encryption keys rotate every five minutes and are automatically destroyed after 24 hours using AWS Nitro Enclaves with cryptographic attestation and irreversible deletion TAKE is built on Messaging Layer Security (MLS), an open IETF standard, and will become the default encryption for all Ring customers starting in September Unlike E2EE Ring推出新型加密方案TAKE(Throw Away the Key Encryption),在保留云端AI功能的同时限制公司对视频数据的访问权限 采用5分钟轮换加密密钥机制,密钥在24小时后自动永久删除,用户保留最终控制权 基于IETF开源标准Messaging Layer Security构建,密钥存储于AWS Nitro Enclave硬件隔离环境中 与端到端加密(E2EE)形成差异化定位,平衡隐私保护与智能功能体验 9月起逐步 rollout,将成为所有Ring用户的默认加密方式

68
Hot 热度
62
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • Ring introduced TAKE (Throw Away the Key Encryption), a new encryption method that limits cloud access to video footage without full end-to-end encryption (E2EE)
  • Encryption keys rotate every five minutes and are automatically destroyed after 24 hours using AWS Nitro Enclaves with cryptographic attestation and irreversible deletion
  • TAKE is built on Messaging Layer Security (MLS), an open IETF standard, and will become the default encryption for all Ring customers starting in September
  • Unlike E2EE, TAKE allows Ring to process videos for smart features (alerts, search, descriptions) while still restricting what can be handed to law enforcement to encrypted files and non-video metadata
  • The system requires customer-initiated key retrieval for older footage, with no persistent storage or backups, though users must still trust Ring/Amazon's implementation

Why It Matters

Ring's TAKE represents a significant shift in how consumer smart home companies balance privacy and functionality, offering a middle ground between full E2EE (which sacrifices cloud features) and traditional cloud encryption (which offers weaker privacy guarantees). For AI practitioners and security researchers, it demonstrates a practical application of MLS and hardware-isolated key management at consumer scale, while raising important questions about trust assumptions in cloud-based AI processing pipelines.

Technical Details

  • Key Rotation & Deletion: Encryption keys rotate every five minutes per footage segment; each key copy is permanently deleted within 24 hours using a Cloud Member Management Service (CMMS) that ratchets forward intermediary secrets via one-way key derivation functions, making reconstruction cryptographically infeasible
  • Hardware Isolation: Key storage and management occur within AWS Nitro Enclaves, protected by access controls, cryptography, and hardware isolation; Ring employees have no direct access, and key release requires cryptographic attestation proving the enclave runs approved software
  • MLS Foundation: TAKE is built on Messaging Layer Security (IETF open standard), adapted by Ring for video encryption with custom key-throwaway logic not present in the base standard
  • Key Retrieval Model: Key delivery is push-only from user devices—Amazon servers cannot remotely force key handover; users must actively request keys via the Ring app on authorized devices, with recovery options including cloud backup, passphrase, passkey, secondary devices, or camera-based recovery
  • Feature Compatibility: Cloud-dependent AI features (Unusual Event Alert, Video Descriptions, Smart Alerts, Video Search) continue to function under TAKE, whereas E2EE disables these entirely; older Ring cameras support only TAKE, while newer models offer both TAKE and E2EE

Industry Insight

  • TAKE sets a precedent for "privacy-preserving cloud AI" in consumer hardware, suggesting that full E2EE may not be the only viable path to stronger privacy—time-bounded key access with hardware isolation could become a standard pattern for devices that need cloud processing
  • The approach highlights an ongoing tension in the smart home industry: companies will likely continue offering tiered encryption options (TAKE vs. E2EE) rather than mandating the strongest privacy by default, placing the burden of privacy choices on consumers
  • Law enforcement compliance remains a gray area—while TAKE prevents Ring from producing decryptable video without user cooperation, the existence of Community Requests and partnerships like Axon means privacy-conscious users should carefully evaluate what features they enable and understand the full scope of data sharing beyond legal process

TL;DR

  • Ring推出新型加密方案TAKE(Throw Away the Key Encryption),在保留云端AI功能的同时限制公司对视频数据的访问权限
  • 采用5分钟轮换加密密钥机制,密钥在24小时后自动永久删除,用户保留最终控制权
  • 基于IETF开源标准Messaging Layer Security构建,密钥存储于AWS Nitro Enclave硬件隔离环境中
  • 与端到端加密(E2EE)形成差异化定位,平衡隐私保护与智能功能体验
  • 9月起逐步 rollout,将成为所有Ring用户的默认加密方式

为什么值得看

本文揭示了智能家居安防领域在隐私保护与功能体验之间的技术平衡方案,为行业提供了除E2EE之外的第三条路径。对于关注物联网安全、云存储隐私及AI功能集成的从业者具有重要参考价值。

技术解析

  • 密钥管理机制:TAKE采用动态密钥轮换策略,每5分钟生成新的内容加密密钥(CEK),密钥副本存储在AWS Nitro Enclave中,24小时后通过单向密钥派生函数永久删除,无备份保留
  • 硬件隔离架构:密钥管理依赖AWS Nitro Enclave的密码学证明机制,通过访问控制、加密和硬件隔离三重保障,确保Ring员工无法直接访问密钥
  • 开源标准基础:基于IETF标准化的Messaging Layer Security协议开发,Ring仅实现"密钥丢弃"核心逻辑,公开技术白皮书供审查
  • 功能兼容性设计:保留云端AI处理能力(智能警报、视频搜索、描述生成),通过密钥按需推送机制实现用户主动请求解密,而非服务器主动获取

行业启示

  • 隐私-功能平衡新范式:TAKE证明了无需完全端到端加密即可实现有意义的隐私保护,为需要云端AI功能的物联网设备提供了可行架构
  • 硬件安全 enclave 成为标配:AWS Nitro Enclave等硬件隔离技术正从云服务商基础设施转变为消费者产品隐私保护的关键组件
  • 信任模型重构:从"公司可控"转向"用户主导"的密钥管理模式,要求企业建立透明的密钥生命周期管理机制以重建用户信任

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Product Launch 产品发布 Ethics 伦理 Regulation 监管