IP Library Granted Patent US 10,068,103
Granted Patent B2
US 10,068,103 · App. 13/866,452 · Granted Sep 4, 2018

Systems and methods for securing data in motion

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,068,103
App. No.
13/866,452
Granted
Sep 4, 2018
Kind
B2
Abstract

The systems and methods of the present invention provide a solution that makes data provably secure and accessible—addressing data security at the bit level—thereby eliminating the need for multiple perimeter hardware and software technologies. Data security is incorporated or weaved directly into the data at the bit level. The systems and methods of the present invention enable enterprise communities of interest to leverage a common enterprise infrastructure. Because security is already woven into the data, this common infrastructure can be used without compromising data security and access control. In some applications, data is authenticated, encrypted, and parsed or split into multiple shares prior to being sent to multiple locations, e.g., a private or public cloud. The data is hidden while in transit to the storage location, and is inaccessible to users who do not have the correct credentials for access.

Claims (30)

1. A method for securing the filename of a file to be split and stored on a storage network, the method comprising:

encrypting, by processing circuitry communicatively coupled to the storage network, the filename of the file using an encryption algorithm;

generating one or more data shares from the file using an information dispersal algorithm, at least one of the one or more data shares having a share name that is associated with the encrypted filename;

storing the generated data shares on one or more data share locations in the storage network; and

regenerating the filename of the file by decrypting the share name of one of the generated data shares.

2. The method of claim 1 , wherein the storage network includes one of a private cloud, a public cloud, a hybrid cloud, a removable storage device, and a mass storage device.

3. The method of claim 1 , wherein the encryption algorithm is an AES algorithm.

4. The method of claim 1 , further comprising appending additional information to the filename of the file prior to the encrypting.

5. The method of claim 4 , wherein the additional information includes a number associated with a data share location.

6. The method of claim 1 , wherein each of the one or more data shares has a share name which contains at least a portion of the filename of the file.

7. The method of claim 1 , further comprising processing the encrypted filename using an authentication algorithm to generate an authentication value.

8. The method of claim 7 , wherein the authentication algorithm is an HMAC-SHA256 algorithm.

9. The method of claim 7 , further comprising generating share names for the one or more data shares based on the authentication value.

10. The method of claim 9 , wherein the authentication value and the generated share names for the one or more data shares are substantially equal.

11. A system for securing the filename of a file to be split and stored on a storage network, the system comprising:

at least one non-transitory computer readable medium storing computer executable instructions; and

processing circuitry communicatively coupled to the at least one non-transitory computer readable medium and operable to execute the computer-readable instructions stored thereon, the processing circuitry configured to:

encrypt the filename of the file using an encryption algorithm;

generate one or more data shares from the file using an information dispersal algorithm, at least one of the one or more data shares having a share name that is associated with the encrypted filename;

store the generated data shares on one or more data share locations in the storage network; and

regenerate the filename of the file by decrypting the share name of one of the generated data shares.

12. The system of claim 11 , wherein the storage network includes one of a private cloud, a public cloud, a hybrid cloud, a removable storage device, and a mass storage device.

13. The system of claim 11 , wherein the encryption algorithm is an AES algorithm.

14. The system of claim 11 , wherein the processing circuitry is further configured to append additional information to the filename of the file prior to the encrypting.

15. The system of claim 14 , wherein the additional information includes a number associated with a data share location.

16. The system of claim 11 , wherein each of the one or more data shares has a share name which contains at least a portion of the filename of the file.

17. The system of claim 11 , wherein the processing circuitry is further configured to process the encrypted filename using an authentication algorithm to generate an authentication value.

18. The system of claim 17 , wherein the authentication algorithm is an HMAC-SHA256 algorithm.

19. The system of claim 17 , wherein the processing circuitry is further configured to generate share names for the one or more data shares based on the authentication value.

20. The system of claim 19 , wherein the authentication value and the generated share names for the one or more data shares are substantially equal.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1 C/O FAMILY OFFICE SOLUTIONS; O'REILLY, COLIN; COOPER ROAD LLC.; COYDOG FOUNDATION C/O FAMILY OFFICE SOLUTIONS; DASA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; LAKOFF, DAVID E.; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C.; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JOR, GERALD R, JR.; GRANDPRIX LIMITED C/O LOEB BLOCK & PARTNERS L.P.; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC.; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M.; MERCER, ROBERT; ROLA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC.; BARTON, WESLEY W.; ZUG VENTURES LLC C/O KATHY COOK, FUSION GROUP; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
To: SECURITY FIRST CORP.
Reel/Frame 061578/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: SECURITY FIRST CORP
To: SECURITY FIRST INNOVATIONS, LLC
Reel/Frame 061262/0865 →
PATENT SECURITY AGREEMENT Recorded Jun 24, 2016
From: SECURITY FIRST CORP.
To: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1; O'REILLY, COLIN; COOPER ROAD LLC; COYDOG FOUNDATION; DASA INVESTMENTS LLC; LAKOFF, DAVID E; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JORDAN, GERALD R, JR; GRANDPRIX LIMITED; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M; MERCER, ROBERT; ROLA INVESTMENTS LLC; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC; BARTON, WESLEY W; ZUG VENTURES LLC; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
Reel/Frame 039153/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2013
From: ORSINI, RICK L.; O'HARE, MARK S.
To: SECURITY FIRST CORP.
Reel/Frame 030294/0528 →
Cited By (2)
US 12,712,723 US 12,719,670