IP Library Granted Patent US 9,785,785
Granted Patent B2
US 9,785,785 · App. 14/984,087 · Granted Oct 10, 2017

Systems and methods for secure data sharing

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,785,785
App. No.
14/984,087
Granted
Oct 10, 2017
Kind
B2
Abstract

Systems and methods are provided for creating and using a sharable file-level key to secure data files. The file-level key is generated based on a workgroup key associated with the data file and unique information associated with the data file. The file-level key may be used to encrypt and split data. Systems and methods are also provided for sharing data without replicating the data on an end user machine. Data is encrypted and split across an external/consumer network and an enterprise/producer network. Access to the data is provided using a computing image generated by a server in the enterprise/producer network and then distributed to end users of the external/consumer network. This computing image may include preloaded files that provide pointers to the data. No access or replication of the data on the enterprise/producer network is needed in order for a user of the external/consumer network to access the data.

Claims (39)

1. A method for securely sharing a data set, comprising:

distributing, using a hardware processor, the data set into two or more shares;

distributing the two or more shares across at least one consumer storage location and at least one enterprise storage location;

generating permissions associated with the data set;

in response to receiving a request for the data set, generating a computing image that provides one or more pointers to the two or more shares, wherein generating the computing image comprises:

generating a virtual machine that includes a pointer to a storage location of the two or more shares;

retrieving updated stub file information; and

recreating, using the retrieved stub file information, a stub file associated with the computing image;

distributing the computing image to a user associated with the at least one consumer storage location;

executing the virtual machine on the at least one consumer storage location;

using the virtual machine, providing access to the one or more pointers to the two or more shares based on the permissions without replicating the data set at the at least one consumer storage location.

2. The method of claim 1 , wherein the permissions designate the data set as read and write access enabled for users associated with the at least one enterprise storage location and as read access enabled for users associated with the at least one consumer storage location.

3. The method of claim 1 , further comprising receiving, from the at least one consumer storage location, a request for the data set.

4. The method of claim 1 , wherein the computing image comprises a stub file that provides attributes of the two or more shares.

5. The method of claim 1 , wherein the computing image comprises a virtual machine file, stub files, and configuration data that allows the user the access to the data set.

6. The method of claim 1 , wherein distributing the computing image further comprises distributing the computing image, across a network, as a virtual machine that may be installed on hardware associated with the user.

7. The method of claim 1 , wherein distributing the computing image further comprises distributing a physical device.

8. The method of claim 1 , wherein providing access to the one or more pointers to the two or more shares comprises providing access to a subset of the data set.

9. The method of claim 1 , further comprising generating stub files independently of generating the computing image.

10. A system for securely sharing a data set, comprising:

a hardware processor configured to:

distribute, using a hardware processor, the data set into two or more shares;

distribute the two or more shares across at least one consumer storage location and at least one enterprise storage location;

generate permissions associated with the data set;

in response to receiving a request for the data set, generate a computing image that provides one or more pointers to the two or more shares, wherein the generated computing image comprises:

generating a virtual machine that includes a pointer to a storage location of the two or more shares;

retrieving updated stub file information; and

recreating, using the retrieved stub file information, a stub file associated with the computing image;

distribute the computing image to a user associated with the at least one consumer storage location;

execute the virtual machine on the at least one consumer storage location;

use the virtual machine to provide access to the one or more pointers to the two or more shares based on the permissions without replicating the data set at the at least one consumer storage location.

11. The system of claim 10 , wherein the permissions designate the data set as read and write access enabled for users associated with the at least one enterprise storage location and as read access enabled for users associated with the at least one consumer storage location.

12. The system of claim 10 , wherein the hardware processor is further configured to receive, from the at least one consumer storage location, a request for the data set.

13. The system of claim 10 , wherein the computing image comprises a stub file that provides attributes of the two or more shares.

14. The system of claim 10 , wherein the computing image comprises a virtual machine file, stub files, and configuration data that allows the user the access to the data set.

15. The system of claim 10 , wherein the hardware processor is configured to distribute the computing image by distributing the computing image, across a network, as a virtual machine that may be installed on hardware associated with the user.

16. The system of claim 10 , wherein the computing image is distributed on a physical device.

17. The system of claim 10 , wherein the hardware processor is configured to provide access to the one or more pointers to the two or more shares by providing access to a subset of the data set.

18. The system of claim 10 , wherein the hardware processor is further configured to generate stub files independently of generating the computing image.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1 C/O FAMILY OFFICE SOLUTIONS; O'REILLY, COLIN; COOPER ROAD LLC.; COYDOG FOUNDATION C/O FAMILY OFFICE SOLUTIONS; DASA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; LAKOFF, DAVID E.; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C.; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JOR, GERALD R, JR.; GRANDPRIX LIMITED C/O LOEB BLOCK & PARTNERS L.P.; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC.; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M.; MERCER, ROBERT; ROLA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC.; BARTON, WESLEY W.; ZUG VENTURES LLC C/O KATHY COOK, FUSION GROUP; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
To: SECURITY FIRST CORP.
Reel/Frame 061578/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: SECURITY FIRST CORP
To: SECURITY FIRST INNOVATIONS, LLC
Reel/Frame 061262/0865 →
PATENT SECURITY AGREEMENT Recorded Jun 24, 2016
From: SECURITY FIRST CORP.
To: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1; O'REILLY, COLIN; COOPER ROAD LLC; COYDOG FOUNDATION; DASA INVESTMENTS LLC; LAKOFF, DAVID E; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JORDAN, GERALD R, JR; GRANDPRIX LIMITED; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M; MERCER, ROBERT; ROLA INVESTMENTS LLC; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC; BARTON, WESLEY W; ZUG VENTURES LLC; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
Reel/Frame 039153/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2016
From: O'HARE, MARK S.; LANDAU, GABRIEL D.; STAKER, MATTHEW; YAKAMOVICH, WILLIAM; ORSINI, RICK L.
To: SECURITY FIRST CORP.
Reel/Frame 037744/0151 →