IP Library Granted Patent US 9,454,673
Granted Patent B1
US 9,454,673 · App. 14/536,460 · Granted Sep 27, 2016

Searchable encryption for cloud storage

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,454,673
App. No.
14/536,460
Granted
Sep 27, 2016
Kind
B1
Abstract

A method implements searchable encryption of cloud stored data by appending tokenized keywords to an encrypted file destined for a cloud storage service. In some embodiments, the tokenized keywords are appended to the header of the encrypted file. Searching of cloud-stored encrypted files using the native search capability of the cloud storage service is then possible by performing the search using the tokenized keywords. In alternate embodiments of the present invention, a method enables searching of cloud stored encrypted file using a cloud search appliance.

Claims (23)

1. A method for searchable encryption of cloud stored data, comprising:

receiving a file destined for a cloud storage service;

extracting a plurality of keywords from the content of the file;

tokenizing each keyword of the plurality of keywords using a first algorithm comprising a hash-based message authentication code (HMAC) to generate a plurality of tokenized keywords, a tokenized keyword being generated for each keyword;

appending the plurality of tokenized keywords together into a string with each tokenized keyword being separated by a separator;

encrypting the file using an encryption algorithm, wherein the encryption algorithm used to encrypt the file is different from the first algorithm used to tokenize the one or more keywords;

appending the string of tokenized keywords to a file header or to a tail to the encrypted file;

transmitting the encrypted file with the appended string of tokenized keywords to the cloud storage service for storage, where the tokenized keywords in the string are to be indexed at the cloud storage service by the cloud storage service;

receiving a search request with a search term;

tokenizing the search term in the search request by applying the first algorithm to the search term to generate a tokenized search term;

transmitting the search request with the tokenized search term to the cloud storage service;

receiving a search result, as a result of performing a search on the cloud storage service using the index created by the cloud storage service, the search result containing a first encrypted file from the cloud storage service in response to the tokenized search term matching a tokenized keyword in a string of tokenized keyword appended to the first encrypted file being stored at the cloud storage service;

decrypting the first encrypted file to generate an unencrypted file containing the search term; and

providing the unencrypted file as the search result.

2. The method of claim 1 , wherein extracting a plurality of keywords from the content of the file comprises:

extracting all of the unique words in the content of the file as the plurality of keywords.

3. The method of claim 1 , wherein appending the plurality of tokenized keywords together into a string comprises:

appending the plurality of tokenized keywords together into a string with each tokenized keyword being separated by a space.

4. A system for searchable encryption of cloud stored data, comprising:

a network proxy server configured as a network intermediary to receive a file destined for a cloud storage service, the network proxy server being configured to extract a plurality of keywords from the content of the file, to tokenize each keyword of the plurality of keywords using a first algorithm comprising a hash-based message authentication code (HMAC) to generate a plurality of tokenized keywords, a tokenized keyword being generated for each keyword, to append the plurality of tokenized keywords together into a string with each tokenized keyword being separated by a separator, to encrypt the file using an encryption algorithm, wherein the encryption algorithm used to encrypt the file is different from the first algorithm used to tokenize the one or more keywords, to append the string of tokenized keywords to a file header or to a tail to the encrypted file, and to transmit the encrypted file with the appended string of tokenized keywords to the cloud storage service for storage, where the tokenized keywords in the string are to be indexed at the cloud storage service by the cloud storage service,

wherein the network proxy server is further configured to receive a search request with a search term, to tokenize the search term in the search request by applying the first algorithm to the search term to generate a tokenized search term, to transmit the search request with the tokenized search term to the cloud storage service, to receive a search result, as a result of performing a search on the cloud storage service using the index created by the cloud storage service, the search result containing a first encrypted file from the cloud storage service in response to the tokenized search term matching a tokenized keyword in a string of tokenized keyword appended to the first encrypted file being stored at the cloud storage service, to decrypt the first encrypted file to generate an unencrypted file containing the search term, and to provide the unencrypted file as the search result.

5. The system of claim 4 , wherein the network proxy server is further configured to extract all of the unique words in the content of the file as the plurality of keywords.

6. The system of claim 4 , wherein the network proxy server is further configured to append the plurality of tokenized keywords together into a string with each tokenized keyword being separated by a space.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2021
From: SKYHIGH NETWORKS, LLC
To: MCAFEE, LLC
Reel/Frame 057010/0244 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 046416/0286 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: SKYHIGH NETWORKS, LLC
Reel/Frame 054211/0739 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED AT REEL: 046416 FRAME: 0286. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 19, 2020
From: SKYHIGH NETWORKS, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 054560/0325 →
CHANGE OF NAME Recorded Dec 27, 2018
From: SKYHIGH NETWORKS, INC.
To: SKYHIGH NETWORKS, LLC
Reel/Frame 047985/0829 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0225 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0286 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2015
From: SARUKKAI, SEKHAR; NARAYAN, KAUSHIK; GUPTA, RAJIV; GRUBBS, PAUL
To: SKYHIGH NETWORKS, INC.
Reel/Frame 034685/0476 →