IP Library Granted Patent US 9,015,480
Granted Patent B2
US 9,015,480 · App. 13/973,637 · Granted Apr 21, 2015

Systems and methods for secure multi-tenant data storage

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,015,480
App. No.
13/973,637
Granted
Apr 21, 2015
Kind
B2
Abstract

Systems and methods are provided for transmitting data for secure storage. For each of two or more data sets, a plurality of shares are generated containing a distribution of data from an encrypted version of the data set. The shares are then stored in a shared memory device, wherein a data set may be reconstructed from a threshold number of the associated plurality of shares using an associated key. Also provided are systems and methods for providing access to secured data. A plurality of shares containing a distribution of data from an encrypted version of a data set are stored in a memory device. A client is provided with a virtual machine that indicates the plurality of shares, and the capability to reconstruct the data set from the plurality of shares using an associated key.

Claims (48)

1. A method of providing access to secured data, comprising:

encrypting a first data set using a first key;

generating a first plurality of shares, wherein each of the first plurality of shares contains a distribution of data from the encrypted first data set;

transmitting the first plurality of shares to at least one memory device for storage;

providing, to a first client, access to a second key;

providing, to the first client, a virtual machine that indicates the first plurality of shares stored on the at least one memory device, wherein the first client is provided with the capability to retrieve the first plurality of shares from the at least one memory device and reconstruct the first data set using the second key; and

revoking, from the first client, access to the second key a predetermined period of time after providing to the first client access to the second key.

2. The method of claim 1 , wherein the first key contains identical data to the second key.

3. The method of claim 2 , wherein each of the first plurality of shares comprises a distribution of data from the encrypted first data set and the first key.

4. The method of claim 1 , wherein the first key contains different data than the second key.

5. The method of claim 1 , wherein the first and second keys are an asymmetric key pair.

6. The method of claim 1 , further comprising:

storing the second key in a network-attached memory device;

wherein providing, to the first client, access to the second key comprises providing, to the first client, access to the network-attached memory device.

7. The method of claim 1 , further comprising:

encrypting a second data set using a third key different from the first key;

generating a second plurality of shares, wherein each of the second plurality of shares contains a distribution of data from the encrypted second data set;

transmitting the second plurality of shares to the at least one memory device for storage;

providing, to a second client different from the first client, access to a fourth key;

providing, to the second client, a virtual machine that indicates the second plurality of shares stored on the at least one memory device, wherein the second client is provided with the capability to retrieve the second plurality of shares from the at least one memory device and reconstruct the second data set using the fourth key.

8. The method of claim 7 , wherein the at least one memory device is part of a multi-tenant data storage system.

9. A system for providing access to secured data, comprising:

at least one processing device;

a first client; and

at least one memory device;

wherein the at least one processing device is configured to:

encrypt a first data set using a first key;

generate a first plurality of shares, wherein each of the first plurality of shares contains a distribution of data from the encrypted first data set;

transmit the first plurality of shares to the at least one memory device for storage;

provide, to the first client, access to a second key;

provide, to the first client, a virtual machine that indicates the first plurality of shares stored on the at least one memory device, wherein the first client is provided with the capability to retrieve the first plurality of shares from the at least one memory device and reconstruct the first data set using the second key; and

revoke, from the first client, access to the second key a predetermined period of time after providing to the first client access to the second key.

10. The system of claim 9 , wherein the first key contains identical data to the second key.

11. The system of claim 10 , wherein each of the first plurality of shares comprises a distribution of data from the encrypted first data set and the first key.

12. The system of claim 9 , wherein the first key contains different data than the second key.

13. The system of claim 9 , wherein the first and second keys are an asymmetric key pair.

14. The system of claim 9 , further comprising:

a network-attached memory device;

wherein the at least one processing device is further configured to:

store the second key in a network-attached memory device;

wherein providing, to the first client, access to the second key comprises providing, to the first client, access to the network-attached memory device.

15. The system of claim 9 , wherein the at least one processing device is further configured to:

encrypt a second data set using a third key different from the first key;

generate a second plurality of shares, wherein each of the second plurality of shares contains a distribution of data from the encrypted second data set;

transmit the second plurality of shares to the at least one memory device for storage;

provide, to a second client different from the first client, access to a fourth key;

provide, to the second client, a virtual machine that indicates the second plurality of shares stored on the at least one memory device, wherein the second client is provided with the capability to retrieve the second plurality of shares from the at least one memory device and reconstruct the second data set using the fourth key.

16. The system of claim 9 , wherein the at least one memory device is part of a multi-tenant data storage system.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1 C/O FAMILY OFFICE SOLUTIONS; O'REILLY, COLIN; COOPER ROAD LLC.; COYDOG FOUNDATION C/O FAMILY OFFICE SOLUTIONS; DASA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; LAKOFF, DAVID E.; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C.; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JOR, GERALD R, JR.; GRANDPRIX LIMITED C/O LOEB BLOCK & PARTNERS L.P.; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC.; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M.; MERCER, ROBERT; ROLA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC.; BARTON, WESLEY W.; ZUG VENTURES LLC C/O KATHY COOK, FUSION GROUP; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
To: SECURITY FIRST CORP.
Reel/Frame 061578/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: SECURITY FIRST CORP
To: SECURITY FIRST INNOVATIONS, LLC
Reel/Frame 061262/0865 →
PATENT SECURITY AGREEMENT Recorded Jun 24, 2016
From: SECURITY FIRST CORP.
To: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1; O'REILLY, COLIN; COOPER ROAD LLC; COYDOG FOUNDATION; DASA INVESTMENTS LLC; LAKOFF, DAVID E; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JORDAN, GERALD R, JR; GRANDPRIX LIMITED; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M; MERCER, ROBERT; ROLA INVESTMENTS LLC; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC; BARTON, WESLEY W; ZUG VENTURES LLC; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
Reel/Frame 039153/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 4, 2013
From: ORSINI, RICK L.; O'HARE, MARK S.; STAKER, MATT
To: SECURITY FIRST CORP.
Reel/Frame 031134/0858 →