IP Library Granted Patent US 10,083,307
Granted Patent B2
US 10,083,307 · App. 15/147,277 · Granted Sep 25, 2018

Distributed encryption and access control scheme in a cloud environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,083,307
App. No.
15/147,277
Granted
Sep 25, 2018
Kind
B2
Abstract

An approach is proposed that contemplates systems, methods, and computer-readable storage mediums to support receiving, from a computerized system, a first encrypted file entity key and signed access metadata, wherein the first encrypted file entity key is created by encrypting a file entity key using a first encryption key, the signed access metadata is signed by the file entity key and the encrypted file entity is created by encrypting a file entity using the file entity key. The approach then determines whether to facilitate the decryption of the encrypted file entity by the computerized system and sends a second encrypted file entity key to the computerized system if it is determined to facilitate the decryption. The approach prevents the computerized system to decrypt the encrypted file entity if it is determined not to facilitate the decryption of the encrypted file entity by the computerized system.

Claims (70)

1. A method for selectively assisting a decryption process of an encrypted file entity, the method comprises:

receiving, from a computerized system, a first encrypted file entity key and signed access metadata,

wherein the first encrypted file entity key is created by encrypting a file entity key using a first encryption key;

wherein the signed access metadata is signed by the file entity key;

wherein the encrypted file entity is created by encrypting a file entity using the file entity key;

determining whether to facilitate the decryption of the encrypted file entity by the computerized system;

sending a second encrypted file entity key to the computerized system if it is determined to facilitate the decryption, wherein the second encrypted file entity key is created by (a) decrypting the first encrypted file entity key to provide the file entity key, and (b) encrypting the file entity key with an encryption key of the computerized system; and

preventing the computerized system to decrypt the encrypted file entity if it is determined not to facilitate the decryption of the encrypted file entity by the computerized system.

2. The method according to claim 1 wherein the file entity is a file.

3. The method according to claim 1 wherein the file entity is a first portion of a file.

4. The method according to claim 3 , wherein the file further comprises a second file portion that is not encrypted by the file entity key.

5. The method according to claim 1 wherein the first encrypted file entity key and the signed access metadata are received from the computerized system via another computerized system.

6. The method according to claim 1 wherein the first encrypted file entity key, the signed access metadata, and the encrypted file entity are created, signed, and encrypted by one or more computerized systems other than the computerized system.

7. The method according to claim 1 comprising determining not to facilitate the decryption of the encrypted file entity by the computerized system if the signed access data is invalid.

8. The method according to claim 1 comprising determining whether to facilitate the decryption of the encrypted file entity by the computerized system based a content of the signed access data if the signed access data is valid.

9. The method according to claim 1 wherein the signed access metadata comprises information about one or more computerized systems that are entitled to decrypt the encrypted file entity.

10. A method for selectively assisting a decryption process of an encrypted file entity, the method comprises:

receiving, from a computerized system, a double encrypted file entity key and signed access metadata;

wherein the first encrypted file entity key is created by encrypting a file entity key using a first encryption key;

wherein the double encrypted file entity key is created by encrypting a first encrypted file entity key using a second encryption key;

wherein the signed access metadata is signed by the file entity key;

wherein the encrypted file entity is created by encrypting a file entity using the file entity key;

determining whether the computerized system is entitled to decrypt the file entity;

preventing from assisting the computerized system to decrypt the encrypted file entity if it is determined that the computerized system is not entitled to decrypt the file entity;

decrypting the double encrypted file entity key to provide the first encrypted file entity key if it is determined that the computerized system is entitled to decrypt the file entity;

sending a second encrypted file entity key to the computerized system, wherein the second encrypted file entity key is created by (a) decrypting the first encrypted file entity key to provide the file entity key, and (b) encrypting the file entity key with an encryption key of the computerized system.

11. The method according to claim 10 wherein the file entity is a file.

12. The method according to claim 10 wherein the file entity is a first portion of a file.

13. The method according to claim 12 , wherein the file further comprises a second file portion that is not encrypted by the file entity key.

14. The method according to claim 10 wherein one or more of the first encrypted file entity key, the double encrypted file entity key, the second encrypted file entity key, the signed access metadata, and the encrypted file entity are created, signed, and encrypted by one or more computerized systems other than the computerized system.

15. The method according to claim 10 wherein the signed access metadata comprises information about one or more computerized systems that are entitled to decrypt the encrypted file entity.

16. The method according to claim 10 comprising determining not to facilitate the decryption of the encrypted file entity by the computerized system if the signed access data is invalid.

17. At least one computer-readable storage medium having computer-executable instructions embodied thereon, wherein, when executed by at least one processor, the computer-executable instructions cause the at least one processor to:

receive, from a computerized system, a first encrypted file entity key and signed access metadata,

wherein the first encrypted file entity key is created by encrypting a file entity key using a first encryption key;

wherein the signed access metadata is signed by the file entity key;

wherein the encrypted file entity is created by encrypting a file entity using the file entity key;

determine whether to facilitate the decryption of the encrypted file entity by the computerized system;

send a second encrypted file entity key to the computerized system if it is determined to facilitate the decryption, wherein the second encrypted file entity key is created by (a) decrypting the first encrypted file entity key to provide the file entity key, and (b) encrypting the file entity key with an encryption key of the computerized system; and

prevent the computerized system to decrypt the encrypted file entity if it is determined not to facilitate the decryption of the encrypted file entity by the computerized system.

18. At least one computer-readable storage medium having computer-executable instructions embodied thereon, wherein, when executed by at least one processor, the computer-executable instructions cause the at least one processor to:

receive a double encrypted file entity key and signed access metadata;

wherein the double encrypted file entity key is created by encrypting a first encrypted file entity key using a second encryption key;

wherein the first encrypted file entity key is created by encrypting a file entity key using a first encryption key;

wherein the signed access metadata is signed by the file entity key;

wherein the encrypted file entity is created by encrypting a file entity using the file entity key;

determine whether the computerized system is entitled to decrypt the file entity;

prevent from assisting the computerized system to decrypt the encrypted file entity if it is determined that the computerized system is not entitled to decrypt the file entity;

decrypt the double encrypted file entity key to provide the first encrypted file entity key if it is determined that the computerized system is entitled to decrypt the file entity;

send a second encrypted file entity key to the computerized system, wherein the second encrypted file entity key is created by (a) decrypting the first encrypted file entity key to provide the file entity key, and (b) encrypting the file entity key with an encryption key of the computerized system.

19. A computer, comprising:

a processor configured to

receive, from a computerized system, a first encrypted file entity key and signed access metadata;

wherein the first encrypted file entity key is created by encrypting a file entity key using a first encryption key;

wherein the signed access metadata is signed by the file entity key;

wherein the encrypted file entity is created by encrypting a file entity using the file entity key;

determine whether to facilitate the decryption of the encrypted file entity by the computerized system;

send a second encrypted file entity key to the computerized system if it is determined to facilitate the decryption, wherein the second encrypted file entity key is created by (a) decrypting the first encrypted file entity key to provide the file entity key, and (b) encrypting the file entity key with an encryption key of the computerized system; and

prevent the computerized system to decrypt the encrypted file entity if it is determined not to facilitate the decryption of the encrypted file entity by the computerized system.

20. A computer, comprising:

a processor configured to

receive, from a computerized system, a double encrypted file entity key and signed access metadata;

wherein the double encrypted file entity key is created by encrypting a first encrypted file entity key using a second encryption key;

wherein the first encrypted file entity key is created by encrypting a file entity key using a first encryption key;

wherein the signed access metadata is signed by the file entity key;

wherein the encrypted file entity is created by encrypting a file entity using the file entity key;

determine whether the computerized system is entitled to decrypt the file entity;

prevent from assisting the computerized system to decrypt the encrypted file entity if it is determined that the computerized system is not entitled to decrypt the file entity;

decrypt the double encrypted file entity key to provide the first encrypted file entity key if it is determined that the computerized system is entitled to decrypt the file entity;

send a second encrypted file entity key to the computerized system, wherein the second encrypted file entity key is created by (a) decrypting the first encrypted file entity key to provide the file entity key, and (b) encrypting the file entity key with an encryption key of the computerized system.

Assignments (10)
SECURITY INTEREST Recorded Mar 17, 2025
From: BARRACUDA NETWORKS, INC.
To: OAKTREE FUND ADMINISTRATION, LLC, AS COLLATERAL AGENT
Reel/Frame 070529/0123 →
SECURITY INTEREST Recorded Sep 3, 2022
From: BARRACUDA NETWORKS, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 061377/0208 →
SECURITY INTEREST Recorded Sep 3, 2022
From: BARRACUDA NETWORKS, INC.
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 061377/0231 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN IP RECORDED AT R/F 045327/0877 Recorded Aug 16, 2022
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 061179/0602 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN IP RECORDED AT R/F 054260/0746 Recorded Aug 16, 2022
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 061521/0086 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 30, 2020
From: BARRAUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 054260/0746 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 045327/0934 Recorded Apr 15, 2019
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 048895/0841 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 14, 2018
From: BARRACUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045327/0877 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 14, 2018
From: BARRACUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045327/0934 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2016
From: SOOKASA INC
To: BARRACUDA NETWORKS, INC
Reel/Frame 039034/0587 →