IP Library Granted Patent US 8,656,167
Granted Patent B2
US 8,656,167 · App. 12/391,025 · Granted Feb 18, 2014

Systems and methods for secure workgroup management and communication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,656,167
App. No.
12/391,025
Granted
Feb 18, 2014
Kind
B2
Abstract

A secure data parser is provided that may be integrated into any suitable system for securely storing and communicating data. The secure data parser may split or share a data set into multiple portions that are stored or communicated distinctly. Encryption of the original data, the portions of data, or both may be employed for additional security. The secure data parser may be used to protect data in motion by splitting an original data set into portions of data that may be communicated using one or more communications paths. Secure workgroup communication is supported through the secure distribution and management of a workgroup key for use with the secure data parser.

Claims (39)

1. A method for secure workgroup communication, the method comprising:

recording, at a key server, a plurality of public keys associated with a plurality of clients in a workgroup;

generating a time-to-live (TTL) value for a workgroup key, wherein the workgroup key is generated by the key server and used to encrypt workgroup communications, and the TTL value indicates a period of time until the workgroup key expires;

generating a workgroup key update message, wherein the workgroup key update message includes the workgroup key, a workgroup key version number, and the TTL value for the workgroup key;

encrypting the workgroup key update message using at least a subset of the public keys;

wherein encrypting the workgroup key update message comprises generating separate ciphertexts for each of the at least a subset of public keys, wherein each ciphertext comprises the workgroup key update message encrypted using a respective public key; and

broadcasting the encrypted workgroup key update message to the workgroup.

2. The method of claim 1 wherein encrypting the workgroup key update message comprising encrypting the workgroup key update message using a public-key broadcast encryption scheme.

3. The method of claim 2 wherein encrypting the workgroup key update message using a public-key broadcast encryption scheme comprises:

generating a binary tree of span M, wherein M is the maximum size of the workgroup;

associating the public key of each client of the workgroup with a unique leaf of the binary tree;

identifying all nodes of the binary tree that are coexistent to or parents of leaves associated with non-revoked clients of the workgroup; and

encrypting the workgroup key update message under each of the public keys associated with the identified nodes.

4. The method of claim 1 wherein the generating the workgroup key update message and broadcasting are performed periodically on a predefined schedule.

5. The method of claim 1 wherein the generating the workgroup key update message and broadcasting are performed automatically in response to the communication privileges of a client of the workgroup being revoked.

6. The method of claim 1 wherein broadcasting the encrypted workgroup key update message to the workgroup comprises posting the key update message to a website.

7. The method of claim 1 , wherein the workgroup key update message further includes a timestamp which indicates when the workgroup key was generated.

8. The method of claim 1 , wherein the workgroup key comprises a session key used by the clients in the workgroup to encrypt the workgroup communications.

9. The method of claim 1 , wherein the workgroup communications comprise one or more key exchange messages for communicating a cryptographic key within the workgroup, and the workgroup key is used to encrypt the cryptographic key.

10. A system for secure workgroup communication, the system comprising:

a workgroup key server configured to:

record a plurality of public keys associated with a plurality of clients in a workgroup;

generate a time-to-live (TTL) value for a workgroup key, wherein the workgroup key is generated by the workgroup key server and used to encrypt workgroup communications, and the TTL value indicates a period of time until the workgroup key expires;

generate a workgroup key update message, wherein the workgroup key update message includes the workgroup key, a workgroup key version number, and the TTL value for the workgroup key;

encrypt the workgroup key update message using at least a subset of the public keys;

wherein the workgroup key server is configured to encrypt the workgroup key update message by generating separate ciphertexts for each of the at least a subset of public keys, wherein each ciphertext comprises the workgroup key update message encrypted using a respective public key; and

broadcast the encrypted workgroup key update message to the workgroup.

11. The system of claim 10 wherein the workgroup key server is configured to encrypt the workgroup key update message using a public-key broadcast encryption scheme.

12. The system of claim 10 wherein the workgroup key server is configured to encrypt the workgroup key update message using a public-key broadcast encryption scheme by:

generating a binary tree of span M, wherein M is the maximum size of the workgroup;

associating the public key of each client of the workgroup with a unique leaf of the binary tree;

identifying all nodes of the binary tree that are coexistent to or parents of leaves associated with non-revoked clients of the workgroup; and

encrypting the workgroup key update message under each of the public keys associated with the identified nodes.

13. The system of claim 10 wherein the workgroup key server is configured to generate the workgroup key update message and broadcast the encrypted workgroup key update message periodically on a predefined schedule.

14. The system of claim 10 wherein the workgroup key server is configured to generate the workgroup key update message and broadcast the encrypted workgroup key update message automatically in response to the communication privileges of a client of the workgroup being revoked.

15. The system of claim 10 wherein the workgroup key server is configured to broadcast the encrypted workgroup key update message to the workgroup by posting the key update message to a website.

16. The system of claim 10 wherein the workgroup key update message further includes a timestamp which indicates when the workgroup key was generated.

17. The system of claim 10 , wherein the workgroup key comprises a session key used by the clients in the workgroup to encrypt the workgroup communications.

18. The system of claim 10 , wherein the workgroup communications comprise one or more key exchange messages for communicating a cryptographic key within the workgroup, and the workgroup key is used to encrypt the cryptographic key.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1 C/O FAMILY OFFICE SOLUTIONS; O'REILLY, COLIN; COOPER ROAD LLC.; COYDOG FOUNDATION C/O FAMILY OFFICE SOLUTIONS; DASA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; LAKOFF, DAVID E.; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C.; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JOR, GERALD R, JR.; GRANDPRIX LIMITED C/O LOEB BLOCK & PARTNERS L.P.; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC.; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M.; MERCER, ROBERT; ROLA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC.; BARTON, WESLEY W.; ZUG VENTURES LLC C/O KATHY COOK, FUSION GROUP; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
To: SECURITY FIRST CORP.
Reel/Frame 061578/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: SECURITY FIRST CORP
To: SECURITY FIRST INNOVATIONS, LLC
Reel/Frame 061262/0865 →
PATENT SECURITY AGREEMENT Recorded Jun 24, 2016
From: SECURITY FIRST CORP.
To: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1; O'REILLY, COLIN; COOPER ROAD LLC; COYDOG FOUNDATION; DASA INVESTMENTS LLC; LAKOFF, DAVID E; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JORDAN, GERALD R, JR; GRANDPRIX LIMITED; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M; MERCER, ROBERT; ROLA INVESTMENTS LLC; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC; BARTON, WESLEY W; ZUG VENTURES LLC; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
Reel/Frame 039153/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2009
From: BONO, STEPHEN C.; GREEN, MATTHEW D.; LANDAU, GABRIEL D.; ORSINI, RICK L.; O'HARE, MARK S.; DAVENPORT, ROGER S.
To: SECURITY FIRST CORP.
Reel/Frame 022869/0362 →