IP Library Granted Patent US 9,015,483
Granted Patent B2
US 9,015,483 · App. 13/732,258 · Granted Apr 21, 2015

Method and system for secured data storage and sharing over cloud based network

Inventor: Prakash Baskaran (Ashburn, VA)
H04L63/0428H04L67/06H04L67/1097G06F9/00G06F17/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,015,483
App. No.
13/732,258
Granted
Apr 21, 2015
Kind
B2
Abstract

The various embodiments herein provide a method and system for secure data storage and sharing over a cloud based network. The method comprises installing a client application on a user device, authenticating a client application user, extracting content from a data source, obtaining content sharing information from a content storage provider, sending a content distribution list and a content usage policy to an application server, encrypting the content by the client application, creating and sharing a secure content file, decrypting the content file, finding the content usage policy and sharing information from the content file, obtaining an updated content usage policy from the application server, authenticating the content recipient using an authentication mechanism, verifying the identity of the content recipient using an identity resolution mechanism, rendering the secure content file to the recipient, enforcing the content usage policy and sending content usage logs to the application server.

Claims (28)

1. A method for content sharing over a cloud based storage network, said method comprising the following steps:

authenticating a content sender using an authentication mechanism provided by the cloud based storage network, thereby obviating the need for an identity management scheme at the content sender end;

selecting, from a content storage, the content to be transmitted to at least one content recipient;

encrypting the selected content and creating a wrapper file that encapsulates the selected content and the content usage policy corresponding to the selected content;

querying the cloud based storage network for a distribution list corresponding to the selected content, wherein the distribution list comprises the information corresponding to content recipient(s);

analyzing the content usage policy embedded in the wrapper file;

uploading the wrapper file onto the cloud storage based network and initiating the transfer of the wrapper file to the intended contended recipient(s);

authenticating the content recipient(s) using the authentication mechanism provided by the cloud based storage network, thereby obviating the need for an identity management scheme at the content recipient end, wherein the identity of the content recipient is verified using an identity resolution mechanism;

decrypting the wrapper file, subsequent to successful authentication of the content recipient(s), and enforcing the content usage policy on the decrypted wrapper file; and

providing the content recipient(s) with access to the decrypted wrapper hie, based on the content usage policy.

2. The method of claim 1 , further comprising the following steps:

enforcing the content usage policy after the decrypted wrapper file is retrieved from the cloud based storage network; and

selectively enforcing a modified content usage policy on the decrypted wrapper file after the decrypted wrapper file is retrieved from the cloud based storage network, in the event that the content usage policy has been modified.

3. The method as claimed in claim 1 , wherein the selected content is encrypted using at least one of an AES 256 encryption algorithm and an NSA Standard encryption algorithm.

4. The method as claimed in claim 1 , wherein the secure content file wraps digital content of any MIME type with layered encryption and with embedded policies controlling time, location and usage of the content.

5. A system for providing secured content sharing, said system comprising:

a cloud based storage network accessible via an application server;

a first communication device accessible to a content sender and a second communication device accessible to a content recipient, said first communication device and said second communication device in communication with the application server, said application server configured to authenticate the content sender using an authentication mechanism provided by the cloud based storage network, thereby obviating the need for a key management scheme at the content sender end;

wherein, said first communication device is adapted to:

select data from the content storage, for transmission and sharing;

query the cloud based storage network for a distribution list comprising the information corresponding to content recipient(s);

encrypt the content, and create a wrapper file that encapsulates the selected content and at least the content usage policy corresponding to the selected content;

wherein, the second communication device is adapted to:

authenticate the content recipient using the authentication mechanism provided, by the cloud based storage network, thereby obviating the need for a key management scheme at the content recipient end, said second communication device further adapted to verify the identity of the content recipient, using an identity resolution mechanism;

decrypt the secure content file, post successful authentication of the content recipient;

analyze the content usage policy embedded in the wrapper file;

render the decrypted wrapper file onto the second communication device, based on the content usage policy.

6. The system as claimed in claim 5 , wherein said second communication device is further configured to query said cloud based storage network to selectively obtain a modified content usage policy, said second communication device still further configured to selectively implement said modified content usage policy prior to rendering said secure content file.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Sep 27, 2023
From: TECHNOLOGY DEVELOPMENT BOARD
To: SECURELYSHARE SOFTWARE PRIVATE LIMITED
Reel/Frame 066040/0682 →
MORTGAGE Recorded Apr 25, 2019
From: SECURELYSHARE SOFTWARE PRIVATE LIMITED
To: TECHNOLOGY DEVELOPMENT BOARD
Reel/Frame 048988/0336 →
CHANGE OF NAME Recorded Jan 2, 2017
From: VARISTHA STRATEGIC SOURCING PVT. LTD.
To: SECURELYSHARE SOFTWARE PVT. LTD.
Reel/Frame 040813/0125 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2016
From: CISCO TECHNOLOGY, INC.
To: VARISTHA STRATEGIC SOURCING PVT. LTD.
Reel/Frame 040531/0630 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2016
From: PAWAA SOFTWARE PRIVATE LIMITED
To: CISCO TECHNOLOGY, INC.
Reel/Frame 040045/0961 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2015
From: BASKARAN, PRAKASH, MR
To: PAWAA SOFTWARE PRIVATE LIMITED
Reel/Frame 035771/0290 →
Continuity (1)
Related Publication 20140189352A1 · Jul 3, 2014