IP Library Granted Patent US 9,027,092
Granted Patent B2
US 9,027,092 · App. 12/604,805 · Granted May 5, 2015

Techniques for securing data access

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,027,092
App. No.
12/604,805
Granted
May 5, 2015
Kind
B2
Abstract

Techniques for securing data access are presented. A user's data is encrypted on multiple servers throughout a network. Each portion of the encrypted data resides on a different server, and each portion represents a non-contiguous data selection from the user's original unencrypted data. Each portion encrypted using a master credential that is different from the user's logon credential. Also, each portion encrypted using a server identity for the server on which that portion resides. An order, which is used for assembling decrypted versions of the encrypted portions back into the user's data, is acquired via another and different principal-supplied credential.

Claims (30)

1. A processor-implemented method to execute on a processor, the method comprising:

segmenting server-controlled data for a principal into a first portion for a first server and a second portion for a second server, each of the first and second portions represents non-contiguous data selections from the server-controlled data, the first portion and the second portion each represents scrambled portions of the server-controlled data that is mixed up from a normal created order for the server-controlled data, both the first portion and the second portion have a random ordering of the server-controlled data;

encrypting the first portion using a master credential and a first server identity for the first server to produce an encrypted first portion and then housing the first portion on the first server;

encrypting the second portion using the master credential and a second server identity for the second server to produce an encrypted second portion and then housing the second portion on the second server; and

creating a second credential that is distributed to the principal, the second credential identifying an order for assembling a decrypted version of the encrypted first portion from the first server with a decrypted version of the encrypted second portion from the second server for purposes of recreating the server-controlled data, and recreating the server-controlled data when the principal provides the second credential having the order.

2. The method of claim 1 , wherein segmenting further includes authenticating the principal for initial access via a principal-supplied credential that is different from the master credential.

3. The method of claim 2 , wherein authenticating further includes generating the master credential in response to principal-supplied credential.

4. The method of claim 1 , wherein segmenting further includes resolving the non-contiguous data selections from the server-controlled data to produce the first and second portions in response to a policy.

5. The method of claim 1 , wherein segmenting further includes resolving the non-contiguous data selections from the server-controlled data to produce the first and second portions in response to a random order generation algorithm.

6. The method of claim 1 , wherein creating further includes producing the order in response to the non-contiguous data selections used to create the first portion and the second portion.

7. The method of claim 6 , wherein producing the order further includes encrypting the order using the second credential, the second credential different than the master credential and different from a principal-supplied credential used to initially authenticate the principal for access.

8. A processor-implemented method to execute on a processor, the method comprising:

receiving a request from a principal to access server-controlled data;

authenticating the principal via a principal-supplied credential that is provided by the principal and obtaining an order from the principal-supplied credential;

reproducing the order for assembling encrypted portions of the server-controlled data located on a first server and a second server, each encrypted portion representing non-contiguous data selections from the server-controlled data wherein each encrypted portion is scrambled in a different order from a normal created order, and each encrypted portion includes a random ordering;

decrypting the encrypted portions using a master credential and a first server identity for the first server and a second server identity for the second server to produce decrypted portions of the server-controlled data;

assembling the decrypted portions in the order to reproduce the server-controlled data; and

providing the principal access to the reproduced server-controlled data.

9. The method of claim 8 , wherein receiving further includes authenticating the principal for initial access via a logon credential, the logon credential, the principal-supplied credential, and the master credential are all different from one another.

10. The method of claim 8 , wherein authenticating further includes acquiring the principal-supplied credential from the principal as a security phrase previously provided to the principal when the encrypted portions were initially encrypted.

11. A data access security system implemented on a processing device, comprising:

a master credential service implemented in a computer-readable medium and to execute on the processing device; and

a encryption service implemented in a computer-readable medium and to execute on the processing device; and

a decryption service implemented in a computer-readable medium and to execute on the processing device;

the master credential service configured to generate a master credential, the encryption service configured to encrypted multiple portions of server-controlled data, each portion representing non-contiguous data selections from the server-controlled data, and each portion stored on a different server of a network, wherein each portion is scrambled in a different order from a normal created order, and each different order is a random order, and each portion also encrypted using the master credential and a specific server identity for a particular server that the portion being encrypted is to be stored on, the decryption service configured to authenticate a principal-supplied credential received from a principal, the principal-supplied credential used to produce an order for assembling decrypted versions of the encrypted portions acquired from the different servers of the network, and the decryption service configured to assemble the decrypted versions into the order to reproduce the server-controlled data for the principal to access when the principal-supplied credential is provided by the principal.

12. The system of claim 11 , wherein the master credential service is configured to generate the master credential in response to a logon credential supplied to authenticate the principal for initial access, the master credential and the logon credential different from one another.

13. The system of claim 12 , wherein the principal-supplied credential is different from the master credential and the logon credential.

14. The system of claim 11 , wherein the order is a rule that is specific to the server-controlled data.

15. The system of claim 14 , wherein the rule is principal-supplied when the principal initially requests that the server-controlled data be encrypted.

16. The system of claim 14 , wherein the rule is randomly generated for the server-controlled data.

Assignments (16)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2009
From: PRABHUSWAMY, KIRAN PRABHU DOORA
To: NOVELL, INC.
Reel/Frame 023544/0974 →