IP Library Granted Patent US 8,904,194
Granted Patent B2
US 8,904,194 · App. 13/468,562 · Granted Dec 2, 2014

Secure data parser method and system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,904,194
App. No.
13/468,562
Granted
Dec 2, 2014
Kind
B2
Abstract

A secure data parser is provided that may be integrated into any suitable system for securely storing and communicating data. The secure data parser parses data and then splits the data into multiple portions that are stored or communicated distinctly. Encryption of the original data, the portions of data, or both may be employed for additional security. The secure data parser may be used to protect data in motion by splitting original data into portions of data that may be communicated using multiple communications paths.

Claims (46)

1. A method for securely storing and retrieving data, the method comprising:

generating, using an electronic computing system that includes processing circuitry, a plurality of shares by performing a cryptographic operation on a data set and distributing the data set in the plurality of shares such that the data set can be reconstructed using any subset of the shares that includes at least a minimum number less than all of shares;

storing the plurality of shares at a plurality of storage devices;

receiving, at the electronic computing system, request to retrieve the data set;

identifying from the plurality of storage devices a set of fastest-responding storage devices necessary to retrieve the minimum number of shares, wherein the set of fastest-responding storage devices are identified based at least in part on the response time of the storage devices;

retrieving from the set of fastest-responding storage devices, the minimum number of shares;

reconstructing the data set using the minimum number of shares; and

sending the data set responsive to the request.

2. The method of claim 1 , wherein storing the shares comprises:

storing a first subset of the shares at a first subset of the plurality of storage devices that is physically located at a first data center; and

storing a second subset of the shares at a second subset of the plurality of storage devices that is physically located at a second data center, the first data center being geographically separated from the second data center.

3. The method of claim 1 , further comprising establishing secure connections between the electronic computing system and the plurality of storage devices.

4. The method of claim 1 , wherein the plurality of data blocks shares contain a substantially random distribution of the data set.

5. The method of claim 1 , wherein the data set can be reconstructed from shares received from at least two storage devices.

6. The method of claim 1 , wherein the shares are encrypted with a corresponding number of different keys.

7. An electronic computing system for securely storing and retrieving data, the electronic computing system comprising:

a processing unit; and

a system memory comprising instructions that, when executed by the processing unit, cause the processing unit to:

generate a plurality of shares by performing a cryptographic operation on a data set and distributing the data set in the plurality of shares such that the data set can be reconstructed using any subset of the shares that includes at least a minimum number less than all of the shares and such that the data set cannot be reconstructed using any subset of the shares that includes fewer than the minimum number of the shares;

store the plurality of shares at a plurality of storage devices;

receive, via the primary interface, a request to retrieve the data set;

identify, from the plurality of storage devices, a set of fastest-responding storage devices necessary to retrieve the minimum number of shares, wherein the set of fastest-responding storage devices are identified based at least in part on the response time of the storage devices,

retrieve from the set of fastest-responding storage devices the minimum number of shares;

reconstruct the data set using exclusively the minimum number of shares; and

send the data set responsive to the request.

8. The electronic computing system of claim 7 , wherein the instructions cause the processing unit to store a first subset of the shares at a first subset of the plurality of storage devices that is physically located at a first data center and to store a second subset of the shares at a second subset of the plurality of storage devices that is physically located at a second data center, the first data center being geographically separated from the second data center.

9. The electronic computing system of claim 7 , wherein the instructions further cause the processing unit to generate the plurality of shares in response to receiving a request to store the data set.

10. The electronic computing system of claim 7 , wherein the instructions further cause the processing unit to establish secure connections between the electronic computing system and the plurality of storage devices.

11. The electronic computing system of claim 7 , wherein the plurality of shares contain a substantially random distribution of the data set.

12. The electronic computing system of claim 7 , wherein the data set can be reconstructed from shares received from at least two storage devices.

13. The electronic computing system of claim 7 , wherein the shares are encrypted with a corresponding number of different keys.

14. A non-transitory computer-readable storage medium comprising instructions that, when executed at an electronic computing device, cause the electronic computing device to:

receive a request to write a data set to a storage location;

generate a plurality of shares by performing a cryptographic operation on the data set and distributing the data set in the plurality of shares such that the data set can be reconstructed using any subset of the shares that includes at least a minimum number less than all of the shares and such that the data set cannot be reconstructed using any subset of the shares that includes fewer than the minimum number of the shares;

store the plurality of shares at a plurality of storage devices;

receive a request to retrieve the data set;

identify, from the plurality of storage devices, a set of fastest-responding storage devices necessary to retrieve the minimum number of shares, wherein the set of fastest-responding storage devices are identified based at least in part on the response time of the storage devices;

retrieve from the set of fastest-responding storage devices, the minimum number of shares;

reconstruct the data set using exclusively the minimum number of shares; and

send the data set responsive to the request.

15. The non-transitory computer-readable storage medium of claim 14 , wherein the instructions cause the processing unit to store a first subset of the shares at a first subset of the plurality of storage devices that is physically located at a first data center and to store a second subset of the shares at a second subset of the plurality of storage devices that is physically located at a second data center, the first data center being geographically separated from the second data center.

16. The non-transitory computer-readable storage medium of claim 14 , wherein the instructions further cause the processing unit to generate the plurality of shares in response to receiving the request to write the data set to the storage location.

17. The non-transitory computer-readable storage medium of claim 14 , wherein the instructions further cause the processing unit to establish secure connections between the electronic computing device and the plurality of storage devices.

18. The non-transitory computer-readable storage medium of claim 14 , wherein the plurality of shares contain a substantially random distribution of the data set.

19. The non-transitory computer-readable storage medium of claim 14 , wherein the data set can be reconstructed from shares received from at least two storage devices.

20. The non-transitory computer-readable storage medium of claim 14 , wherein the shares are encrypted with a corresponding number of different keys.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1 C/O FAMILY OFFICE SOLUTIONS; O'REILLY, COLIN; COOPER ROAD LLC.; COYDOG FOUNDATION C/O FAMILY OFFICE SOLUTIONS; DASA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; LAKOFF, DAVID E.; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C.; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JOR, GERALD R, JR.; GRANDPRIX LIMITED C/O LOEB BLOCK & PARTNERS L.P.; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC.; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M.; MERCER, ROBERT; ROLA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC.; BARTON, WESLEY W.; ZUG VENTURES LLC C/O KATHY COOK, FUSION GROUP; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
To: SECURITY FIRST CORP.
Reel/Frame 061578/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: SECURITY FIRST CORP
To: SECURITY FIRST INNOVATIONS, LLC
Reel/Frame 061262/0865 →
PATENT SECURITY AGREEMENT Recorded Jun 24, 2016
From: SECURITY FIRST CORP.
To: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1; O'REILLY, COLIN; COOPER ROAD LLC; COYDOG FOUNDATION; DASA INVESTMENTS LLC; LAKOFF, DAVID E; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JORDAN, GERALD R, JR; GRANDPRIX LIMITED; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M; MERCER, ROBERT; ROLA INVESTMENTS LLC; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC; BARTON, WESLEY W; ZUG VENTURES LLC; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
Reel/Frame 039153/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2012
From: ORSINI, RICK L.; O'HARE, MARK S.; DAVENPORT, ROGER; WINICK, STEVEN
To: SECURITY FIRST CORP.
Reel/Frame 028190/0308 →