SECURE DATA PARSER METHOD AND SYSTEM
The present invention provides a method and system for securing sensitive data from unauthorized access or use. The method and system of the present invention is useful in a wide variety of settings, including commercial settings generally available to the public which may be extremely large or small with respect to the number of users. The method and system of the present invention is also useful in a more private setting, such as with a corporation or governmental agency, as well as between corporation, governmental agencies or any other entity.
1 . A method of securely storing data in a network, the method comprising:
receiving a unit of data from a client device;
splitting the unit of data into a predetermined number of secondary units of data, each of the secondary units of data associated with one of a plurality of shares;
encrypting the plurality of shares with a corresponding number of different keys; and
storing each secondary unit of data and key used to encrypt the secondary unit of data.
2 . The method of claim 1 , wherein the encrypted plurality of shares are associated with a workgroup of a user capable of accessing the data.
3 . The method of claim 2 , further comprising storing a workgroup encryption key on a key management server.
4 . The method of claim 1 , wherein the plurality of shares contain a substantially random distribution of the unit of data.
5 . The method of claim 1 , wherein the unit of data is restorable from at least two shares of the plurality of shares.
6 . The method of claim 1 , wherein storing each secondary unit of data comprises storing the secondary units of data in different physical storage devices.
7 . A method of reading secured data in a network, the method comprising:
receiving a request from a client device to read a unit of data managed by a secure storage appliance;
determining a number of secondary units of data required to reconstitute the unit of data;
transmitting a request for the number of secondary units of data to a plurality of shares located at a plurality of physical storage devices, the plurality of shares corresponding to the number of secondary units of data required to reconstitute the unit of data, each of the secondary units of data representing a portion of the unit of data encrypted by a different key;
receiving at least the number of secondary units of data required to reconstitute the block of data from the plurality of shares;
reconstituting the unit of data from the secondary units of data; and
transmitting the reconstituted unit of data to the client device.
8 . The method of claim 7 , wherein reconstituting the block of data includes decrypting each of the shares received from the physical storage devices using the keys.
9 . The method of claim 8 , further comprising decrypting each of the keys with a workgroup key prior to decrypting the shares.
10 . The method of claim 9 , wherein the workgroup key is stored on a key management server separate from the physical storage devices.
11 . The method of claim 7 , wherein the number of secondary units of data required to reconstitute the unit of data is less than the number of secondary units of data stored on the physical storage devices.
12 . The method of claim 7 , wherein the plurality secondary units contain a substantially random distribution of the unit of data.
13 . A method of securing data in a network, the method comprising:
receiving at a secure storage appliance a unit of data for storage on a volume, the volume associated with a plurality of shares distributed across a plurality of physical storage devices;
cryptographically splitting the unit of data received by the secure storage appliance into a plurality of secondary data units; and
encrypting each of the plurality of secondary data units with a different key, each key associated with at least one of the plurality of shares.
14 . The method of claim 13 , further comprising storing each data unit remote from the secure storage appliance.
15 . The method of claim 14 , further comprising storing each key locally to the secure storage appliance.
16 . The method of claim 13 , further comprising, upon initializing the secure storage appliance, retrieving one or more of the different keys from a physical storage device remote for use by the secure storage appliance.
17 . The method of claim 13 , wherein the unit of data is received from a client device.
18 . The method of claim 13 , wherein the encrypted plurality of secondary data units are associated with a workgroup of a user capable of accessing the data.
19 . The method of claim 13 , wherein the plurality of secondary data units contain a substantially random distribution of the unit of data.
20 . The method of claim 13 , wherein the unit of data is restorable from at least two of the plurality of secondary data units.
21 . A secure storage appliance comprising a programmable circuit configured to execute program instructions which, when executed, configure the secure storage appliance to:
receive from a client device a unit of data for storage on a volume, the volume associated with a plurality of shares distributed across a plurality of physical storage devices;
cryptographically split the unit of data into a plurality of secondary data units; and
encrypt each of the plurality of secondary data units with a different key, each key associated with at least one of the plurality of shares.
22 . The secure storage appliance of claim 21 further configured to transmit each data unit remote from the secure storage appliance.
23 . The secure storage appliance of claim 21 , wherein the encrypted plurality of secondary data units are associated with a workgroup of a user capable of accessing the data.
24 . The secure storage appliance of claim 21 , wherein the plurality of secondary data units contain a substantially random distribution of the unit of data.
25 . The secure storage appliance of claim 21 , wherein the unit of data is restorable from at least two of the plurality of secondary data units.
26 . A secure data storage network comprising:
a client device;
a plurality of physical storage devices;
a secure storage appliance communicatively connected to the client device and the plurality of physical storage devices, the secure storage appliance including a programmable circuit configured to execute program instructions which, when executed, cause the secure storage appliance to:
receive from the client device a unit of data for storage on a volume, the volume associated with a plurality of shares distributed across the plurality of physical storage devices;
cryptographically split the unit of data into a plurality of secondary data units; and
encrypt each of the plurality of secondary data blocks with a different key, each key associated with at least one of the plurality of shares.
27 . The secure data storage network of claim 26 , wherein the secure storage applicant is further configured to transmit each data unit remote from the secure storage appliance.
28 . The secure data storage network of claim 26 , wherein the encrypted plurality of secondary data units are encrypted with a workgroup key.
29 . The secure data storage network of claim 28 , further comprising a key server configured to store the workgroup key.
30 . The secure data storage network of claim 28 , wherein the workgroup key is associated with a group of users, the group of users including a user of the client device.
31 . The secure data storage network of claim 26 , wherein the plurality of secondary data units contain a substantially random distribution of the unit of data.
32 . The secure data storage network of claim 26 , wherein the unit of data is restorable from at least two of the plurality of secondary data units.