IP Library Granted Patent US 8,788,843
Granted Patent B2
US 8,788,843 · App. 13/284,223 · Granted Jul 22, 2014

Storing user data in a service provider cloud without exposing user-specific secrets to the service provider

Inventors: Krisztian Kopasz (Budapest, HU); Marton B. Anka (Windham, NH)
Assignee: LogMeln, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,788,843
App. No.
13/284,223
Granted
Jul 22, 2014
Kind
B2
Abstract

Subscriber (user) data is encrypted and stored in a service provider cloud in a manner such that the service provider is unable to decrypt and, as a consequence, to view, access or copy the data. Only the user knows a user-specific secret (e.g., a password) that is the basis of the encryption. The techniques herein enable the user to share his or her data, privately or publicly, without exposing the user-specific secret with anyone or any entity (such as the service provider).

Claims (32)

1. A method of storing and protecting user data in a service provider cloud, comprising:

associating a key pair with an account of an authorized user, the key pair comprising an account public key, and an associated account secret key;

storing a value that has been generated by encrypting the account secret key with a user-specific secret, the value being distinct from the account public key and the associated account secret key of the key pair;

storing in the service provider cloud a file that has been generated by encrypting data associated with the authorized user with a data key that is distinct from the value, and from the account public key and the associated account secret key of the key pair;

encrypting the data key with the account public key to generate an account encrypted data key that is distinct from the value, from the data key, and from the account public key and the associated account secret key of the key pair;

storing the account encrypted data key; and

providing access to the data associated with the authorized user upon receipt at the service provider cloud of the user-specific secret by the following ordered operations: (i) decrypting the value to obtain the account secret key, then (ii) decrypting, using the account secret key so obtained, the account encrypted data key to obtain the data key, then (iii) decrypting, using the data key so obtained, the file stored in the service provider cloud with the data key.

2. The method as described in claim 1 wherein the user-specific secret is not shared with the service provider.

3. The method as described in claim 1 wherein the data key is not stored persistently by the service provider.

4. The method as described in claim 1 wherein the data key is a symmetric key.

5. The method as described in claim 1 wherein the key pair is an RSA public/private key pair.

6. The method as described in claim 1 wherein access to the data associated with the authorized user is provided to an invitee associated with the user without exposing the user-specific secret to the invitee.

7. The method as described in claim 1 wherein access to the data associated with the authorized user is provided publicly without exposing the user-specific secret to any entity accessing the data publicly.

8. The method as described in claim 1 wherein the key pair is associated with the account of an authorized user upon registration of the authorized user to use the service provider cloud.

9. The method as described in claim 1 wherein each authorized user of the service provider cloud obtains a distinct key pair.

10. The method as described in claim 1 wherein the file is received in association with a synchronization operation initiated at a user machine.

11. An article comprising a tangible non-transitory machine-readable medium that stores a program, the program being executable by a machine to store and protect user data in a service provider cloud, the program comprising:

program code to associate a key pair with an account of an authorized user, the key pair comprising an account public key, and an associated account secret key;

program code to store a value that has been generated by encrypting the account secret key with a user-specific secret, the value being distinct from the account public key and the associated account secret key of the key pair;

program code to store in the service provider cloud a file that has been generated by encrypting data associated with the authorized user with a data key that is distinct from the value, and from the account public key and the associated account secret key of the key pair;

program code to encrypt the data key with the account public key to generate an account encrypted data key that is distinct from the value, from the data key, and from the account public key and the associated account secret key of the key pair;

program code to store the account encrypted data key; and

program code to provide access to the data associated with the authorized user upon receipt at the service provider cloud of the user-specific secret by the following ordered operations: (i) decrypting the value to obtain the account secret key, then (ii) decrypting, using the account secret key so obtained, the account encrypted data key to obtain the data key, then (iii) decrypting, using the data key so obtained, the file stored in the service provider cloud with the data key.

12. Apparatus, comprising:

one or more processors;

computer memory holding computer program instructions executed by the one or more processors to provide a method of storing and protecting user data in a service provider cloud, the method comprising:

associating a key pair with an account of an authorized user, the key pair comprising an account public key, and an associated account secret key;

storing a value that has been generated by encrypting the account secret key with a user-specific secret, the value being distinct from the account public key and the associated account secret key of the key pair;

storing in the service provider cloud a file that has been generated by encrypting data associated with the authorized user with a data key that is distinct from the value, and from the account public key and the associated account secret key of the key pair;

encrypting the data key with the account public key to generate an account encrypted data key that is distinct from the value, from the data key, and from the account public key and the associated account secret key of the key pair;

storing the account encrypted data key; and

providing access to the data associated with the authorized user upon receipt at the service provider cloud of the user-specific secret by the following ordered operations: (i) decrypting the value to obtain the account secret key, then (ii) decrypting, using the account secret key so obtained, the account encrypted data key to obtain the data key, then (iii) decrypting, using the data key so obtained, the file stored in the service provider cloud with the data key.

Assignments (14)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 053667/0169, REEL/FRAME 060450/0171, REEL/FRAME 063341/0051) Recorded Mar 15, 2024
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: GOTO GROUP, INC. (F/K/A LOGMEIN, INC.)
Reel/Frame 066800/0145 →
SECURITY INTEREST Recorded Feb 16, 2024
From: GOTO COMMUNICATIONS, INC.; GOTO GROUP, INC.; LASTPASS US LP
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS THE NOTES COLLATERAL AGENT
Reel/Frame 066614/0355 →
SECURITY INTEREST Recorded Feb 16, 2024
From: GOTO COMMUNICATIONS, INC.,; GOTO GROUP, INC., A; LASTPASS US LP,
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS THE NOTES COLLATERAL AGENT
Reel/Frame 066614/0402 →
SECURITY INTEREST Recorded Feb 7, 2024
From: GOTO GROUP, INC.,; GOTO COMMUNICATIONS, INC.; LASTPASS US LP
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 066508/0443 →
CHANGE OF NAME Recorded Apr 8, 2022
From: LOGMEIN, INC.
To: GOTO GROUP, INC.
Reel/Frame 059644/0090 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (SECOND LIEN) Recorded Feb 16, 2021
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: LOGMEIN, INC.
Reel/Frame 055306/0200 →
NOTES LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: LOGMEIN, INC.
To: U.S. BANK NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 053667/0032 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: LOGMEIN, INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 053667/0079 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: LOGMEIN, INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 053667/0169 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 35624/0662 Recorded Aug 31, 2020
From: JPMORGAN CHASE BANK, N.A.
To: LOGMEIN, INC.
Reel/Frame 053650/0902 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 041588/0143 Recorded Aug 31, 2020
From: JPMORGAN CHASE BANK, N.A.
To: LOGMEIN, INC.; GETGO, INC.
Reel/Frame 053650/0978 →
SECURITY INTEREST Recorded Feb 1, 2017
From: GETGO, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 041588/0143 →
SECURITY INTEREST Recorded May 13, 2015
From: LOGMEIN, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 035624/0662 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 12, 2014
From: KOPASZ, KRISZTIAN; ANKA, MARTON B.
To: LOGMEIN, INC.
Reel/Frame 033084/0366 →
Continuity (1)
Related Publication 20130111217A1 · May 2, 2013