IP Library Granted Patent US 9,047,475
Granted Patent B2
US 9,047,475 · App. 13/468,450 · Granted Jun 2, 2015

Secure data parser method and system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,047,475
App. No.
13/468,450
Granted
Jun 2, 2015
Kind
B2
Abstract

A secure data parser is provided that may be integrated into any suitable system for securely storing and communicating data. The secure data parser parses data and then splits the data into multiple portions that are stored or communicated distinctly. Encryption of the original data, the portions of data, or both may be employed for additional security. The secure data parser may be used to protect data in motion by splitting original data into portions of data that may be communicated using multiple communications paths.

Claims (46)

1. A method of presenting data in a secure data storage network, the method comprising:

defining a plurality of user groups capable of accessing data stored in a secure data storage network, each user group including a plurality of users desiring access to a common set of data, and each user group having a set of security rights;

associating each of the plurality of user groups with a different workgroup key; and

upon determining that a client device is associated with a user from a user group, presenting, using a hardware processor, a virtual disk to the client device in accordance with the set of security rights, wherein:

the common set of data is secured using the workgroup key associated with the user group;

the virtual disk comprises a directory mapped to a plurality of physical storage devices such that physical locations of a plurality of shares are hidden from the client device, and

each of the plurality of shares comprises data units from the common set of data that have been shuffled.

2. The method of claim 1 , wherein each of the users within one of the plurality of user groups has a common set of security rights.

3. The method of claim 1 , wherein presenting the virtual disk to the client device is performed by a secure storage system connected to the client device.

4. The method of claim 1 , wherein the workgroup key is managed at a key server remote from the secure storage system.

5. The method of claim 1 , wherein the plurality of user groups are members of a plurality of security groups, each security group defining security rights common among the user groups that are members of the security group.

6. The method claim 1 , further comprising:

generating the plurality of shares by performing a cryptographic operation on data stored on the virtual disk and distributing the data in the shares; and

storing the plurality of shares on the plurality of physical storage devices.

7. The method of claim 1 , wherein each of the plurality of user groups has a different set of security rights.

8. A secure data storage network comprising:

a plurality of storage systems arranged to manage a plurality of physical storage devices; and

a secure storage system connected to the plurality of storage systems, the secure storage system configured to:

determine that a user of a client device is associated with a user group from a plurality of user groups capable of accessing data stored in the secure data storage network, each user group including a plurality of users desiring access to a common set of data, and each user group having a set of security rights; and

upon determining that the user is associated with the user group, presenting a virtual disk to the client device in accordance with the set of security rights, wherein:

the common set of data is secured using a workgroup key associated with the user group;

the virtual disk comprises a directory mapped to the plurality of physical storage devices such that physical locations of the plurality of shares are hidden from the client device, and

each of the plurality of shares comprises data units from the common set of data that have been shuffled.

9. The secure data storage network of claim 8 , further comprising a key server communicatively connected to the secure storage system, the key server configured to associate each of the plurality of user groups with a different workgroup key.

10. The secure data storage network of claim 8 , wherein the secure storage system is further configured to associate each of the plurality of user groups with a different workgroup key.

11. The secure data storage network of claim 8 , wherein the secure storage system is further configured to:

generate the plurality of shares by performing a cryptographic operation on data stored on the virtual disk and distributing the data in the shares; and

store the plurality of shares on the plurality of physical storage devices.

12. The secure data storage network of claim 8 , wherein each of the plurality of user groups has a different set of security rights.

13. The secure data storage network of claim 12 , wherein each of the users within one of the plurality of user groups has a common set of security rights.

14. A secure storage system comprising a programmable circuit configured to:

determine that a user of a client device is associated with a user group from a plurality of user groups capable of accessing data stored in the secure data storage network, each user group including a plurality of users desiring access to a common set of data, and each user group having a set of security rights; and

upon determining that the user is associated with the user group, presenting a virtual disk to the client device in accordance with the set of security rights, wherein:

the common set of data is secured using a workgroup key associated with the user group;

the virtual disk comprises a directory mapped to a plurality of physical storage devices such that physical locations of a plurality of shares are hidden from the client device, and

each of the plurality of shares comprises data units from the common set of data that have been shuffled.

15. The secure storage system of claim 14 , wherein the programmable circuit is further configured to:

generate the plurality of shares by performing a cryptographic operation on data stored on the virtual disk and distributing the data in the shares; and

store the plurality of shares on the plurality of physical storage devices.

16. The secure storage system of claim 14 , wherein each of the plurality of user groups has a different set of security rights.

17. The secure data storage system of claim 14 , wherein each of the users within one of the plurality of user groups has a common set of security rights.

18. The secure data storage system of claim 14 , further comprising a key server communicatively connected to the secure storage system, the key server configured to associate each of the plurality of user groups with a different workgroup key.

19. The secure data storage system of claim 14 , wherein the secure storage system is further configured to associate each of the plurality of user groups with a different workgroup key.

20. The method of claim 1 , wherein the plurality of shares contain a substantially random distribution of the common set of data.

21. The secure data storage network of claim 8 , wherein the plurality of shares contain a substantially random distribution of the common set of data.

22. The secure storage system of claim 14 , wherein the plurality of shares contain a substantially random distribution of the common set of data.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1 C/O FAMILY OFFICE SOLUTIONS; O'REILLY, COLIN; COOPER ROAD LLC.; COYDOG FOUNDATION C/O FAMILY OFFICE SOLUTIONS; DASA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; LAKOFF, DAVID E.; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C.; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JOR, GERALD R, JR.; GRANDPRIX LIMITED C/O LOEB BLOCK & PARTNERS L.P.; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC.; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M.; MERCER, ROBERT; ROLA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC.; BARTON, WESLEY W.; ZUG VENTURES LLC C/O KATHY COOK, FUSION GROUP; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
To: SECURITY FIRST CORP.
Reel/Frame 061578/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: SECURITY FIRST CORP
To: SECURITY FIRST INNOVATIONS, LLC
Reel/Frame 061262/0865 →
PATENT SECURITY AGREEMENT Recorded Jun 24, 2016
From: SECURITY FIRST CORP.
To: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1; O'REILLY, COLIN; COOPER ROAD LLC; COYDOG FOUNDATION; DASA INVESTMENTS LLC; LAKOFF, DAVID E; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JORDAN, GERALD R, JR; GRANDPRIX LIMITED; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M; MERCER, ROBERT; ROLA INVESTMENTS LLC; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC; BARTON, WESLEY W; ZUG VENTURES LLC; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
Reel/Frame 039153/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2012
From: ORSINI, RICK L.; O'HARE, MARK S.; DAVENPORT, ROGER; WINICK, STEVEN
To: SECURITY FIRST CORP.
Reel/Frame 028190/0217 →