IP Library Granted Patent US 8,332,638
Granted Patent B2
US 8,332,638 · App. 13/399,923 · Granted Dec 11, 2012

Secure data parser method and system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,332,638
App. No.
13/399,923
Granted
Dec 11, 2012
Kind
B2
Abstract

The present invention provides a method and system for securing sensitive data from unauthorized access or use. The method and system of the present invention is useful in a wide variety of settings, including commercial settings generally available to the public which may be extremely large or small with respect to the number of users. The method and system of the present invention is also useful in a more private setting, such as with a corporation or governmental agency, as well as between corporation, governmental agencies or any other entity.

Claims (47)

1. A method for securing a data set, the method steps implemented by a programmed computer system, the method steps comprising:

encrypting, using a computer, the data set based on a first key to produce an encrypted data set;

generating, using a computer, data splitting information, wherein the data splitting information is usable to determine into which of a plurality of shares of data a unit of data of the encrypted data set will be placed;

separating, using a computer, the encrypted data set into the plurality of shares based on the data splitting information;

including, using a computer, in the plurality of shares data indicative of the first key;

encrypting, using a computer, the plurality of shares;

causing, using a computer, each of the plurality of shares to be stored in respective separate storage locations; and

causing, using a computer, information required to decrypt the plurality of shares to be stored elsewhere than the storage locations of the plurality of shares;

wherein the data set is restorable by accessing less than all, but at least a threshold number of, the plurality of shares and the information.

2. The method of claim 1 , wherein the step of separating the encrypted data set comprises using a deterministic technique.

3. The method of claim 1 , wherein the step of separating the encrypted data set comprises using a substantially random technique.

4. The method of claim 1 , further comprising causing a plurality of data units in each of the shares to be rearranged relative to one another after the separating step.

5. The method of claim 1 , wherein the step of separating the encrypted data into the plurality of shares comprises causing the plurality of shares to have a substantially randomly distribution of the encrypted data set.

6. The method of claim 1 , wherein the step of storing the shares in respective separate storage locations comprises storing the shares on at least two separate storage devices.

7. The method of claim 1 , wherein encrypting the plurality of shares comprises encrypting each of the plurality of shares with a different key other than the first key, the information required to decrypt the plurality of shares comprises the different keys, and causing the information required to decrypt the plurality of shares to be stored comprises storing each of the different keys with a share other than the share encrypted by the respective different key.

8. A non-transitory computer readable medium storing computer executable instructions that, when executed by at least one processor, cause a computer system to carry out a method for securing a data set, the method comprising the steps of:

encrypting the data set based on a first key to produce an encrypted data set;

generating data splitting information, wherein the data splitting information is usable to determine into which of a plurality of shares of data a unit of data of the encrypted data set will be placed;

separating the encrypted data set into the plurality of shares based on the data splitting information;

including in the plurality of shares data indicative of the first key;

encrypting the plurality of shares;

causing each of the plurality of shares to be stored in respective separate storage locations; and

causing information required to decrypt the plurality of shares to be stored elsewhere than the storage locations of the plurality of shares;

wherein the data set is restorable by accessing less than all, but at least a threshold number of, the plurality of shares and the information.

9. The non-transitory computer readable medium of claim 8 , wherein the step of separating the encrypted data set comprises using a deterministic technique.

10. The non-transitory computer readable medium of claim 8 , wherein the step of separating the encrypted data set comprises using a substantially random technique.

11. The non-transitory computer readable medium of claim 8 , wherein the method further comprises causing a plurality of data units of the encrypted data set to be rearranged relative to one another after the separating step.

12. The non-transitory computer readable medium of claim 8 , wherein the step of separating the encrypted data into the plurality of shares comprises causing the plurality of shares to have a substantially randomly distribution of the encrypted data set.

13. The non-transitory computer readable medium of claim 8 , wherein the step of storing the shares in respective separate storage locations comprises storing the shares on at least two separate storage devices.

14. The non-transitory computer readable medium of claim 8 , wherein encrypting the plurality of shares comprises encrypting each of the plurality of shares with a different key other than the first key, the information required to decrypt the plurality of shares comprises the different keys, and causing the information required to decrypt the plurality of shares to be stored comprises storing each of the different keys with a share other than the share encrypted by the respective different key.

15. A computer system for securing a data set, the system comprising:

at least one processor;

a non-transitory computer readable medium storing computer executable instructions that, when executed by the at least one processor, cause the computer system to carry out a method for securing a data set, the method comprising the steps of:

encrypting the data set based on a first key to produce an encrypted data set;

generating data splitting information, wherein the data splitting information is usable to determine into which of a plurality of shares of data a unit of data of the encrypted data set will be placed;

separating the encrypted data set into the plurality of shares based on the data splitting information;

including in the plurality of shares data indicative of the first key;

encrypting the plurality of shares;

causing each of the plurality of shares to be stored in respective separate storage locations; and

causing information required to decrypt the plurality of shares to be stored elsewhere than the storage locations of the plurality of shares;

wherein the data set is restorable by accessing less than all, but at least a threshold number of, the plurality of shares and the information.

16. The system of claim 15 , wherein the step of separating the encrypted data set comprises using a deterministic technique.

17. The system of claim 15 , wherein the step of separating the encrypted data set comprises using a substantially random technique.

18. The system of claim 15 , wherein the method further comprises causing a plurality of data units of the encrypted data set to be rearranged relative to one another after the separating step.

19. The system of claim 15 , wherein the step of separating the encrypted data into the plurality of shares comprises causing the plurality of shares to have a substantially randomly distribution of the encrypted data set.

20. The system of claim 15 , wherein the separate storage locations are located on at least two separate storage devices.

21. The system of claim 15 , wherein encrypting the plurality of shares comprises encrypting each of the plurality of shares with a different key other than the first key, the information required to decrypt the plurality of shares comprises the different keys, and causing the information required to decrypt the plurality of shares to be stored comprises storing each of the different keys with a share other than the share encrypted by the respective different key.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1 C/O FAMILY OFFICE SOLUTIONS; O'REILLY, COLIN; COOPER ROAD LLC.; COYDOG FOUNDATION C/O FAMILY OFFICE SOLUTIONS; DASA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; LAKOFF, DAVID E.; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C.; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JOR, GERALD R, JR.; GRANDPRIX LIMITED C/O LOEB BLOCK & PARTNERS L.P.; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC.; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M.; MERCER, ROBERT; ROLA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC.; BARTON, WESLEY W.; ZUG VENTURES LLC C/O KATHY COOK, FUSION GROUP; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
To: SECURITY FIRST CORP.
Reel/Frame 061578/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: SECURITY FIRST CORP
To: SECURITY FIRST INNOVATIONS, LLC
Reel/Frame 061262/0865 →
PATENT SECURITY AGREEMENT Recorded Jun 24, 2016
From: SECURITY FIRST CORP.
To: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1; O'REILLY, COLIN; COOPER ROAD LLC; COYDOG FOUNDATION; DASA INVESTMENTS LLC; LAKOFF, DAVID E; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JORDAN, GERALD R, JR; GRANDPRIX LIMITED; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M; MERCER, ROBERT; ROLA INVESTMENTS LLC; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC; BARTON, WESLEY W; ZUG VENTURES LLC; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
Reel/Frame 039153/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2012
From: ORSINI, RICK L.; VANZANDT, JOHN; O'HARE, MARK S.; DAVENPORT, ROGER S.
To: SECURITY FIRST CORP.
Reel/Frame 028087/0030 →