IP Library Granted Patent US 9,715,595
Granted Patent B2
US 9,715,595 · App. 14/730,135 · Granted Jul 25, 2017

Methods, systems, and devices for securing distributed storage

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,715,595
App. No.
14/730,135
Granted
Jul 25, 2017
Kind
B2
Abstract

A method of secure distributed storage on N servers and a secure access method to confidential data stored in a secure and distributed manner on N servers are provided. Additionally, distributed storage, devices, systems, computer programs and storage medium are provided for the implementation of such methods.

Claims (46)

1. A method for secure distributed storage, on N servers, where N is an integer greater than 1, of confidential data, the method comprising, at a recording device:

obtaining confidential data,

obtaining an approximated short representation of the confidential data,

obtaining N shares of the confidential data such that at least t shares among the N shares are required in order to reconstitute the confidential data, where t is an integer threshold of at least 2 and at most N, and obtaining N short shares of the approximated short representation such that at least t short shares among the N short shares are required to reconstitute the approximated short representation,

transmitting the N shares to the N servers, respectively, and the N short shares to the N servers, respectively, in order to store the N shares and the N short shares in the N servers.

2. A method of secure access to confidential data stored in a secure and distributed manner on N servers, where N is an integer greater than 1, wherein a number K greater than 1 of confidential data and a number K of approximated short representations of the K confidential data are stored in a secure and distributed manner on the N servers, the method comprising, at an access device:

obtaining N first short shares of a first approximated short representation of first confidential data such that at least t first short shares among the N first short shares are required in order to reconstitute the first approximated short representation, where t is an integer threshold of at least 2 and at most N,

transmitting the N first short shares,

receiving shares of at least one selected confidential data among the K confidential data, wherein the at least one confidential data is selected among the K confidential data based on K distances, each of the K distances being calculated, through distributed calculation, between the first approximated short representation and a respective approximated short representation among the K approximated short representations stored in a distributed manner on the N servers,

obtaining the at least one selected confidential data using the received shares.

3. The method of secure access according to claim 2 , wherein the distributed calculation comprises:

determining, by each of the N servers, K shares of distances measured between:

a first short share of the first approximated short representation transmitted by the access device to the server, and

K short shares of the K approximated short representations, stored on the server, and

measuring the distance between the first approximated short representation and an approximated short representation among the K approximated short representations, by combining, among said N*K shares of distances, the N shares of distances measured respectively by each server between:

a short share of the approximated short representation stored on the server and

a first short share of the first approximated short representation transmitted by the access device to the server.

4. The method of secure access according to claim 2 , wherein the distributed calculation comprises:

determining by each of the N servers, K shares of distances measured between:

a first short share of the first approximated short representation, transmitted by the access device to the server, and

K short shares of K approximated short representations, stored on the server,

and wherein the method comprises:

securely comparing a threshold to the distance measured between the first approximated short representation and an approximated short representation among the K approximated short representations by applying a secure distance calculating protocol at N shares of distances, among said N*K shares of distances, said N shares of distances being the shares of distances measured respectively by each of the N servers between:

a short share of the approximated short representation stored on the server and

a first short share of the first approximated short representation transmitted by the access device to the server.

5. The method of secure access according to claim 2 , wherein the K distances measured are K Hamming distances.

6. The method of secure access according to claim 2 , wherein the first confidential data is biometric data.

7. A secure access system, comprising:

an access device; and

N servers,

the secure access system being arranged to provide access to confidential data stored in a secure and distributed manner on the N servers, where N is an integer greater than 1, wherein a number K greater than 1 of confidential data and a number K of approximated short representations of the K confidential data are stored in a secure and distributed manner on the N servers,

wherein the access device comprises

a sharing electronic circuit configured to share a first approximated short representation of a first confidential data in N first short shares, such that at least t first short shares among the N first short shares are required in order to reconstitute the first approximated short representation, where t is an integer threshold of at least 2 and at most N, and

an emitter arranged to transmit the N first short shares;

and the N servers comprise processing circuits arranged to implement a distributed calculation of K distances, each of the K distances being calculated, through distributed calculation, between the first approximated short representation and a respective approximated short representation among the K approximated short representations, stored in a distributed manner on the N servers,

each server comprising an emitter arranged to transmit, to a receiver of the access device, the shares of at least one selected confidential data among the K confidential data, wherein the at least one confidential data is selected among the K confidential data based on K distances, each one distance calculated through distributed calculation, between the first approximated short representation and an approximated short representations among K approximated short representations, stored in a distributed manner on the N servers,

wherein the access device further comprises an obtaining electronic circuit arranged to obtain, from the shares received by the access device, the corresponding confidential data.

8. The secure access system according to claim 7 , wherein the K distances measured are K Hamming distances.

9. The secure access system according to claim 7 , wherein the confidential data is biometric data.

10. A non-transitory computer readable storage medium storing a computer program comprising a series of instructions, which, when they are executed by a processor, cause the processor to carry out a method according to claim 1 .

11. The method of secure access according to claim 2 , wherein the at least one confidential data is selected among the K confidential data if the distance, between the at least one confidential data and the first approximated short representation is less than a non-negative threshold d.

12. A recording device for secure distributed storage, on N servers, where N is an integer greater than 1 of confidential data, the recording device comprising:

a first circuit configured to obtain a piece of confidential data,

a second circuit configured to extract an approximated short representation of the confidential data,

a third circuit configured to share the confidential data in N shares such that at least t shares among the N shares are required in order to reconstitute the confidential data, where t is an integer threshold of at least 2 and at most N, and for sharing the approximated short representation in N short shares such that at least t short shares are required to reconstitute the approximated short representation,

an emitter arranged to transmit the N shares to the N servers, respectively, and the N short shares to the N servers, respectively, in order to store the N shares and the N short share in the N servers.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENT NUMBER REPLACING 10158873 WITH 10185873 PREVIOUSLY RECORDED ON REEL 71930 FRAME 625. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Apr 1, 2026
From: IDEMIA IDENTITY & SECURITY FRANCE
To: IDEMIA PUBLIC SECURITY FRANCE
Reel/Frame 075530/0067 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2025
From: IDEMIA IDENTITY & SECURITY FRANCE
To: IDEMIA PUBLIC SECURITY FRANCE
Reel/Frame 071930/0625 →
CHANGE OF NAME Recorded Mar 1, 2023
From: MORPHO
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 062895/0357 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2015
From: PATEY, ALAIN; CHABANNE, HERVÉ; BRINGER, JULIEN
To: MORPHO
Reel/Frame 037229/0179 →