IP Library Patent Application 13866345
Patent Application
App. No. 13/866,345

SYSTEMS AND METHODS FOR SECURING DATA IN MOTION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/866,345
Abstract

The systems and methods of the present invention provide a solution that makes data provably secure and accessible—addressing data security at the bit level—thereby eliminating the need for multiple perimeter hardware and software technologies. Data security is incorporated or weaved directly into the data at the bit level. The systems and methods of the present invention enable enterprise communities of interest to leverage a common enterprise infrastructure. Because security is already woven into the data, this common infrastructure can be used without compromising data security and access control. In some applications, data is authenticated, encrypted, and parsed or split into multiple shares prior to being sent to multiple locations, e.g., a private or public cloud. The data is hidden while in transit to the storage location, and is inaccessible to users who do not have the correct credentials for access.

Claims (34)

1 . A coprocessor acceleration device for acceleration of secure data processing, comprising:

a memory for storing data;

a main processor coupled to the memory; and

a first coprocessor coupled to the main processor and the memory, the first coprocessor dedicated to perform at least one of encrypting data, decrypting data, and generating data shares, wherein each of the data shares contains at least a subset of the data.

2 . The device of claim 1 , wherein generating the data shares includes use of an information dispersal algorithm (IDA).

3 . The device of claim 1 , further comprising a field programmable gate array (FPGA) coupled to the first coprocessor.

4 . The device of claim 3 , wherein the FPGA performs the at least one of the encrypting, the decrypting, and the generating.

5 . The device of claim 1 , wherein the memory includes a dedicated memory for the first coprocessor.

6 . The device of claim 1 , wherein the first coprocessor comprises a redundant array of independent disks (RAID) processing unit that implements one or more RAID functions.

7 . The device of claim 1 , wherein the first coprocessor is dedicated to perform the encrypting.

8 . The device of claim 7 , wherein the first coprocessor is further dedicated to perform the generating.

9 . The device of claim 8 , wherein the first coprocessor is further dedicated to perform the decrypting.

10 . The device of claim 1 , further comprising a second coprocessor coupled to the main processor and the memory, the second coprocessor dedicated to perform at least one of encrypting data, decrypting data, and generating data shares, wherein the first coprocessor and the second coprocessor each perform a different one of the encrypting, the decrypting, and the generating.

11 . The device of claim 10 , further comprising a third coprocessor coupled to the main processor and the memory, the third coprocessor dedicated to perform at least one of encrypting data, decrypting data, and generating data shares, wherein the first coprocessor, second coprocessor, and third processor each perform a different one of the encrypting, the decrypting, and the generating.

12 . The device of claim 1 , wherein each data share contains a substantially randomized distribution of the data.

13 . The device of claim 12 , wherein the first coprocessor is further configured to store the data shares in different storage devices.

14 . The device of claim 12 , wherein encrypting data comprises encrypting each of the generated data shares with a different encryption key.

15 . A method for accelerating secure data processing, comprising:

receiving a request at a main processor coupled to a memory to perform at least one of encrypting data, decrypting data, or generating data shares, wherein each of the data shares contains at least a subset of the data;

passing the request from the main processor to a first coprocessor coupled to the main processor and the memory, the first coprocessor dedicated to perform at least the corresponding function; and

performing the function by the first coprocessor.

16 . The method of claim 1 , wherein generating the data shares includes use of an information dispersal algorithm (IDA).

17 . The method of claim 1 , wherein the first coprocessor is further coupled to a field programmable gate array (FPGA).

18 . The method of claim 17 , wherein the FPGA performs the at least one of the encrypting, the decrypting, and the generating.

19 . The method of claim 1 , wherein the memory includes a dedicated memory for the first coprocessor.

20 . The method of claim 1 , wherein the first coprocessor comprises a redundant array of independent disks (RAID) processing unit that implements one or more RAID functions.

21 . The method of claim 1 , wherein the first coprocessor is dedicated to perform the encrypting.

22 . The method of claim 21 , wherein the first coprocessor is further dedicated to perform the generating.

23 . The method of claim 22 , wherein the first coprocessor is further dedicated to perform the decrypting.

24 . The method of claim 1 , further comprising passing the request to a second coprocessor coupled to the main processor and the memory dedicated to perform at least one of encrypting data, decrypting data, and generating data shares, wherein the first coprocessor and the second coprocessor each perform a different one of the encrypting, the decrypting, and the generating.

25 . The method of claim 24 , further comprising passing the request to a third coprocessor coupled to the main processor and the memory dedicated to perform at least one of encrypting data, decrypting data, and generating data shares, wherein the first coprocessor, second coprocessor, and third processor each perform a different one of the encrypting, the decrypting, and the generating.

26 . The method of claim 1 , wherein each of the data shares contains a substantially randomized distribution of the data.

27 . The method of claim 26 , wherein the request further includes storing the data shares in different storage devices.

28 . The method of claim 26 , wherein encrypting data comprises encrypting each of the generated data shares with a different encryption key.

Assignments (2)
PATENT SECURITY AGREEMENT Recorded Jun 24, 2016
From: SECURITY FIRST CORP.
To: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1; O'REILLY, COLIN; COOPER ROAD LLC; COYDOG FOUNDATION; DASA INVESTMENTS LLC; LAKOFF, DAVID E; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JORDAN, GERALD R, JR; GRANDPRIX LIMITED; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M; MERCER, ROBERT; ROLA INVESTMENTS LLC; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC; BARTON, WESLEY W; ZUG VENTURES LLC; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
Reel/Frame 039153/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2013
From: ORSINI, RICK L.; O'HARE, MARK S.
To: SECURITY FIRST CORP.
Reel/Frame 030294/0528 →