IP Library Granted Patent US 9,762,548
Granted Patent B2
US 9,762,548 · App. 14/658,129 · Granted Sep 12, 2017

Controlling encrypted data stored on a remote storage device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,762,548
App. No.
14/658,129
Granted
Sep 12, 2017
Kind
B2
Abstract

A method, system, and apparatus are provided for controlling encrypted data stored on a remote device. In particular, a remote device includes a storage controller device that can receive a “secure hide” command from an administrator device via a cloud server. If the storage controller device determines the “secure hide” command is validly signed, then the storage controller device executes the secure command by erasing the end user's public decryption key from the storage controller device. At that point, end user access to the encrypted data on the remote device is highly improbable.

Claims (54)

1. A storage controller device for controlling encrypted data stored on a storage device, the controller device comprising:

a processor to execute instructions; and

a memory device coupled to the processor, the memory device storing instructions for execution by the processor to cause the processor to perform:

receiving a data packet from a cloud server over a network, wherein the data packet includes a signed secure hide command;

validating the signed secure hide command by using a public administrator decryption key to confirm the signed secure hide command has been signed by using a private administrator encryption key;

if the signed secure hide command is validated, then executing the signed secure hide command by erasing a public user decryption key to revoke end user access to the encrypted data stored on the storage device;

receiving a signed secure unhide command;

validating the signed secure unhide command by using a public administrator decryption key to confirm the signed secure unhide command has been signed by using a private administrator encryption key; and

if the signed secure unhide command is validated, then executing the signed secure unhide command by generating a new user encryption/decryption key pair to grant new end user access to the encrypted data stored on the storage device, wherein the instructions further cause the processor to perform, before receiving the data packet:

executing a heartbeat application by sending a periodic token to the cloud server over the Internet, wherein receiving the data packet further comprises:

receiving the data packet from the cloud server, wherein the data packet further includes the periodic token that has been sent to the cloud server.

2. The storage controller device of claim 1 , further comprising:

an application specific integrated circuit (ASIC), wherein the processor and the memory device are included on the application specific integrated circuit (ASIC).

3. The storage controller device of claim 1 , wherein the periodic token identifies the controller device.

4. The storage controller device of claim 1 , wherein:

an administrator device has signed the signed secure hide command by using the private administrator encryption key;

the administrator device is configured to send the signed secure hide command to a cloud server; and

the cloud server is configured to send the signed secure hide command to the storage controller device.

5. The storage controller device of claim 1 , wherein the instructions further cause the processor to perform, before receiving the data packet:

connecting to a network; and

in less than five seconds after connecting to the network, sending a periodic token to a cloud server over the network.

6. The storage controller device of claim 1 wherein executing the signed secure unhide command further comprises:

storing the new user encryption/decryption key pair on the memory device.

7. A method for controlling encrypted data stored on a storage device, the method comprising:

receiving a data packet from a cloud server over a network, wherein the data packet includes a signed secure hide command;

validating the signed secure hide command by using a public administrator decryption key to confirm the signed secure hide command has been signed by using a private administrator encryption key;

if the signed secure hide command is validated, then executing the signed secure hide command by erasing a public user decryption key to revoke end user access to the encrypted data stored on the storage device;

receiving a signed secure unhide command;

validating the signed secure unhide command by using a public administrator decryption key to confirm the signed secure unhide command has been signed by using a private administrator encryption key; and

if the signed secure unhide command is validated, then executing the signed secure unhide command by generating a new user encryption/decryption key pair to grant new end user access to the encrypted data stored on the storage device,

wherein one or more of the receiving, validating, and executing are performed with a processor, further comprising, before receiving the data packet:

executing a heartbeat application by sending a periodic token to the cloud server over the Internet, wherein receiving the data packet further comprises:

receiving the data packet from the cloud server, wherein the data packet further includes the periodic token that has been sent to the cloud server.

8. The storage controller device of claim 2 , wherein:

the public administrator decryption key is stored on the memory device, and wherein the public administrator decryption key is configured to be substantially inaccessible if the storage controller device undergoes tampering.

9. The method of claim 7 , wherein executing the signed secure unhide command further comprises:

storing the new user encryption/decryption key pair on the memory device.

10. The method of claim 7 , wherein the periodic token identifies the storage controller device.

11. The method of claim 7 , wherein:

an administrator device has signed the signed secure hide command by using the private administrator encryption key;

the administrator device is configured to send the signed secure hide command to a cloud server; and

the cloud server is configured to send the signed secure hide command to a storage controller device that is configured to receive the data packet.

12. The method of claim 7 , further comprising, before receiving the data packet:

connecting to a network; and

in less than five seconds after connecting to the network, sending a periodic token to a cloud server over the network.

13. A computer-readable product for controlling encrypted data stored on a storage device, the computer-readable product including a non-transitory computer-readable storage medium storing instructions that when executed perform the functions comprising:

receiving a data packet from a cloud server over a network, wherein the data packet includes a signed secure hide command;

validating the signed secure hide command by using a public administrator decryption key to confirm the signed secure hide command has been signed by using a private administrator encryption key;

if the signed secure hide command is validated, then executing the signed secure hide command by erasing a public user decryption key to revoke end user access to the encrypted data stored on the storage device;

receiving a signed secure unhide command;

validating the signed secure unhide command by using a public administrator decryption key to confirm the signed secure unhide command has been signed by using a private administrator encryption key; and

if the signed secure unhide command is validated, then executing the signed secure unhide command by generating a new user encryption/decryption key pair to grant new end user access to the encrypted data stored on the storage device, wherein the instructions further cause the processor to perform, before receiving the data packet:

executing a heartbeat application by sending a periodic token to the cloud server over the Internet, wherein receiving the data packet further comprises:

receiving the data packet from the cloud server, wherein the data packet further includes the periodic token that has been sent to the cloud server.

Assignments (13)
SECURITY AGREEMENT (SUPPLEMENTAL) Recorded Nov 14, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 069411/0208 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2024
From: SANDISK TECHNOLOGIES, INC.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 069168/0273 →
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT - DDTL LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 067045/0156 →
PATENT COLLATERAL AGREEMENT - A&R LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064715/0001 →
RELEASE OF SECURITY INTEREST AT REEL 052915 FRAME 0566 Recorded Feb 8, 2022
From: JPMORGAN CHASE BANK, N.A.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 059127/0001 →
SECURITY INTEREST Recorded Feb 6, 2020
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS AGENT
Reel/Frame 052915/0566 →
CORRECTIVE ASSIGNMENT TO CORRECT THE INCORRECT SERIAL NO 15/025,946 PREVIOUSLY RECORDED AT REEL: 040831 FRAME: 0265. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 15, 2017
From: HGST NETHERLANDS B.V.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 043973/0762 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 19, 2017
From: HGST NETHERLANDS B.V.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 042895/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 19, 2017
From: BANDIC, ZVONIMIR; COCOTIS, THOMAS
To: HGST NETHERLANDS B.V.
Reel/Frame 042749/0473 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2016
From: HGST NETHERLANDS B.V.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 040831/0265 →