IP Library Granted Patent US 8,656,189
Granted Patent B2
US 8,656,189 · App. 13/208,132 · Granted Feb 18, 2014

Systems and methods for secure multi-tenant data storage

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,656,189
App. No.
13/208,132
Granted
Feb 18, 2014
Kind
B2
Abstract

Systems and methods are provided for transmitting data for secure storage. For each of two or more data sets, a plurality of shares are generated containing a distribution of data from an encrypted version of the data set. The shares are then stored in a shared memory device, wherein a data set may be reconstructed from a threshold number of the associated plurality of shares using an associated key. Also provided are systems and methods for providing access to secured data. A plurality of shares containing a distribution of data from an encrypted version of a data set are stored in a memory device. A client is provided with a virtual machine that indicates the plurality of shares, and the capability to reconstruct the data set from the plurality of shares using an associated key.

Claims (35)

1. A method of securely storing data in a multi-tenant data storage system, comprising:

receiving a first data set from a first data source;

receiving a second data set from a second data source;

encrypting the first data set with a first key;

encrypting the second data set with a second key, the second key different from the first key;

generating a first plurality of shares, wherein each of the first plurality of shares contains a distribution of data from the encrypted first data set;

generating a second plurality of shares, wherein each of the second plurality of shares contains a distribution of data from the encrypted second data set; and

storing at least one share of the first plurality of shares and at least one share of the second plurality of shares in a first shared memory device of the multi-tenant data storage system without a physical partitioning or a virtual partitioning of the first shared memory device between the stored at least one share of the first plurality of shares and the stored at least one share of the second plurality of shares,

wherein access to the first key and a threshold number of the first plurality of shares are necessary to restore the first data set.

2. The method of claim 1 , wherein the first and second data sources are unrelated.

3. The method of claim 1 , wherein the first data set is encrypted with the first key at a first server and the second data set is encrypted with the second key at a second server different from the first server.

4. The method of claim 3 , wherein the first and second servers are blades.

5. The method of claim 3 , wherein the first and second servers are virtual machines.

6. The method of claim 1 , wherein the at least one share of the first plurality of shares and the at least one share of the second plurality of shares are stored contiguously in the first shared memory device.

7. The method of claim 1 , further comprising:

storing some of the first plurality of shares and some of the second plurality of shares in a second shared memory device different from the first shared memory device.

8. The method of claim 7 , wherein at least one of the first plurality of shares is stored on both the first shared memory device and the second shared memory device.

9. The method of claim 1 , further comprising:

storing at least two of the first plurality of shares and at least two of the second plurality of shares in the first shared memory device.

10. The method of claim 1 , wherein access to the second key and a threshold number of the second plurality of shares are necessary to restore the second data set.

11. A system for securely storing data in a multi-tenant data storage system, comprising:

at least one processing device configured to receive a first data set from a first data source and a second data set from a second data source; and

a first shared memory device;

the at least one processing device further configured to:

encrypt the first data set with a first key;

encrypt the second data set with a second key, the second key different from the first key;

generate a first plurality of shares, wherein each of the first plurality of shares contains a distribution of data from the encrypted first data set;

generate a second plurality of shares, wherein each of the second plurality of shares contains a distribution of data from the encrypted second data set; and

store at least one share of the first plurality of shares and at least one share of the second plurality of shares in a first shared memory device of the multi-tenant data storage system without a physical partitioning or a virtual partitioning of the first shared memory device between the stored at least one share of the first plurality of shares and the stored at least one share of the second plurality of shares,

wherein access to the first key and a threshold number of the first plurality of shares are necessary to restore the first data set.

12. The system of claim 11 , wherein the first and second data sources are unrelated.

13. The system of claim 12 , wherein the at least one processing device comprises a first server and a second server, and wherein the first data set is encrypted with the first key at a first server and the second data set is encrypted with the second key at a second server different from the first server.

14. The system of claim 13 , wherein the first and second servers are blades.

15. The system of claim 13 , wherein the first and second servers are virtual machines.

16. The system of claim 11 , wherein the at least one share of the first plurality of shares and the at least one share of the second plurality of shares are stored contiguously in the first shared memory device.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1 C/O FAMILY OFFICE SOLUTIONS; O'REILLY, COLIN; COOPER ROAD LLC.; COYDOG FOUNDATION C/O FAMILY OFFICE SOLUTIONS; DASA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; LAKOFF, DAVID E.; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C.; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JOR, GERALD R, JR.; GRANDPRIX LIMITED C/O LOEB BLOCK & PARTNERS L.P.; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC.; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M.; MERCER, ROBERT; ROLA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC.; BARTON, WESLEY W.; ZUG VENTURES LLC C/O KATHY COOK, FUSION GROUP; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
To: SECURITY FIRST CORP.
Reel/Frame 061578/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: SECURITY FIRST CORP
To: SECURITY FIRST INNOVATIONS, LLC
Reel/Frame 061262/0865 →
PATENT SECURITY AGREEMENT Recorded Jun 24, 2016
From: SECURITY FIRST CORP.
To: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1; O'REILLY, COLIN; COOPER ROAD LLC; COYDOG FOUNDATION; DASA INVESTMENTS LLC; LAKOFF, DAVID E; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JORDAN, GERALD R, JR; GRANDPRIX LIMITED; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M; MERCER, ROBERT; ROLA INVESTMENTS LLC; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC; BARTON, WESLEY W; ZUG VENTURES LLC; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
Reel/Frame 039153/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 12, 2012
From: ORSINI, RICK L.; O'HARE, MARK S.; STAKER, MATT
To: SECURITY FIRST CORP.
Reel/Frame 027842/0370 →