CLIENT-SIDE ENCRYPTION
Methods and systems of encrypting files at a client in a cloud-based file system are provided. A first key corresponding to an organization to which the client belongs is obtained. Then a first file is encrypted using the first key. Then the encrypted first file is transmitted to a server via a secure channel, for storage in a storage device shared among multiple organizations, the storage device containing one or more files encrypted using keys different than the first key.
1 . A method of encrypting files at a client in a cloud-based file system, comprising:
obtaining a first key corresponding to an organization to which the client belongs;
encrypting a first file using the first key; and
transmitting the encrypted first file to a server via a secure channel, for storage in a storage device shared among multiple organizations, the storage device containing one or more files encrypted using keys different than the first key.
2 . The method of claim 1 , further comprising:
downloading an encrypted second file from the storage device via the secure channel;
obtaining a second key related to the first key and corresponding to the organization to which the client belongs; and
decrypting the encrypted second file using the second key.
3 . The method of claim 1 , wherein the first key is obtaining from a key management system used to assign keys to a plurality of different organizations.
4 . The method of claim 2 , further comprising:
obtaining access to the storage device and locating one or more encrypted files belonging to organizations other than the organization to which the client belongs;
attempting to decrypt the one or more encrypted files belonging to organizations other than the organization to which the client belongs, using the first key; and
receiving an indication that the attempt to decrypt the one or more encrypted files belonging to organizations other than the organization to which the client belongs, using the first key, has failed.
5 . The method of claim 1 , wherein no other keys than the first key correspond to the organization.
6 . The method of claim 1 , wherein the organization is a company.
7 . The method of claim 1 , wherein the organization is a division of a company.
8 . A system comprising:
a client device comprising:
one or more processors;
a memory;
a client application executable by the one or more processors and configured to:
obtain a first key corresponding to an organization to which the client belongs;
encrypt a first file using the first key; and
transmit the encrypted first file to a server via a secure channel, for storage in a storage device shared among multiple organizations, the storage device containing one or more files encrypted using keys different than the first key.
9 . The system of claim 8 , wherein the client application is further configured to:
download an encrypted second file from the storage device via the secure channel;
obtain a second key related to the first key and corresponding to the organization to which the client belongs; and
decrypt the encrypted second file using the second key.
10 . The system of claim 8 , wherein the first key is obtaining from a key management system used to assign keys to a plurality of different organizations.
11 . The system of claim 9 , wherein the client application is further configured to:
obtain access to the storage device and locating one or more encrypted files belonging to organizations other than the organization to which the client belongs;
attempt to decrypt the one or more encrypted files belonging to organizations other than the organization to which the client belongs, using the first key; and
receive an indication that the attempt to decrypt the one or more encrypted files belonging to organizations other than the organization to which the client belongs, using the first key, has failed.
12 . The system of claim 8 , wherein no other keys than the first key correspond to the organization.
13 . The system of claim 8 , wherein the organization is a company.
14 . The system of claim 8 , wherein the organization is a division of a company.
15 . A non-transitory machine-readable storage medium comprising instructions, which when implemented by one or more machines, cause the one or more machines to perform operations comprising:
obtaining a first key corresponding to an organization to which the client belongs;
encrypting a first file using the first key; and
transmitting the encrypted first file to a server via a secure channel, for storage in a storage device shared among multiple organizations, the storage device containing one or more files encrypted using keys different than the first key.
16 . The non-transitory machine-readable storage medium of claim 15 , further comprising:
downloading an encrypted second file from the storage device via the secure channel;
obtaining a second key related to the first key and corresponding to the organization to which the client belongs; and
decrypting the encrypted second file using the second key.
17 . The non-transitory machine-readable storage medium of claim 15 , wherein the first key is obtaining from a key management system used to assign keys to a plurality of different organizations.
18 . The non-transitory machine-readable storage medium of claim 16 , further comprising:
obtaining access to the storage device and locating one or more encrypted files belonging to organizations other than the organization to which the client belongs;
attempting to decrypt the one or more encrypted files belonging to organizations other than the organization to which the client belongs, using the first key; and
receiving an indication that the attempt to decrypt the one or more encrypted files belonging to organizations other than the organization to which the client belongs, using the first key, has failed.
19 . The non-transitory machine-readable storage medium of claim 15 , wherein no other keys than the first key correspond to the organization.
20 . The non-transitory machine-readable storage medium of claim 15 , wherein the organization is a company.