IP Library Granted Patent US 9,819,491
Granted Patent B2
US 9,819,491 · App. 15/149,830 · Granted Nov 14, 2017

System and method for secure release of secret information over a network

Inventors: Dustin C. Kirkland (Austin, TX); Eduardo Garcia (Austin, TX)
Assignee: Cloudera, Inc.
H04L9/321H04L9/083H04L9/0825H04L63/0442H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,819,491
App. No.
15/149,830
Granted
Nov 14, 2017
Kind
B2
Abstract

Embodiments of the present disclosure include systems and methods for secure release of secret information over a network. The server can be configured to receive a request from a client to access the deposit of secret information, send an authorization request to at least one designated trustee in the set of designated trustees for the deposit of secret information, receive responses over the network from one or more of the designated trustees in the set of designated trustees and apply a trustee policy to the responses from the one or more designated trustees in the set of trustees to determine if the request is authorized. If the request is authorized, the server can send the secret information to the client. If the request is not authorized, the server denies access by the client to the secret information.

Claims (39)

1. A method for a computer system to securely manage secret information over a network, the system having a server being communicatively coupled to one or more trustees, the method being performed by the server and comprising:

receiving a secret payload from a depositing client, wherein the secret payload is encrypted by a client public key and can only be decrypted with a client private key, which is not possessed by either the server or the trustees;

receiving, from the depositing client, companion information associated with and specific to the secret payload, wherein the companion information is encrypted by a server public key and can only be decrypted with a server private key, which is possessed by the server, and wherein the companion information includes rules for accessing the secret payload, the rules identifying a list of trustees from the one or more trustees and a trustee policy that specifies a manner necessary for the list of trustees to approve access requests to the secret payload;

storing the secret payload along with the companion information;

receiving, from a requesting client, an access request to access the secret payload, the access request being encrypted by the server public key and including a seed, wherein the seed is randomly generated by the server and assigned to the requesting client in a preceding transaction;

decrypting the access request using the server private key;

verifying a validity of the access request based on the seed;

after the access request is verified, sending an authorization request regarding the access request to each trustee in the list of trustees, wherein each authorization request sent to each trustee from the list of trustees is encrypted with a trustee public key that corresponds to a respective trustee;

receiving responses to the authorization requests from the list of trustees;

applying the trustee policy to the received responses to determine whether to disseminate the secret payload; and

selectively disseminating the secret payload to the requesting client based on a result of applying the trustee policy and causing the requesting client to limit storage of the disseminated secret payload to a volatile memory.

2. The method of claim 1 , wherein the seed is valid for a single transaction only.

3. The method of claim 1 , wherein the companion information further includes a list of authorized requesting clients.

4. The method of claim 1 , wherein the requesting client is the depositing client.

5. The method of claim 1 , further comprising:

causing the depositing client to delete a local copy of the secret payload.

6. The method of claim 1 , wherein the responses from the list of trustees are encrypted with the server public key.

7. The method of claim 1 , wherein the disseminated secret payload is encrypted with the client public key.

8. The method of claim 1 , wherein each secret payload has a unique companion information.

9. A computer system to securely manage secret information over a network, the system comprising:

a server communicatively coupled to one or more trustees, wherein the server comprises one or more processors and memory and is configured to:

receiving a secret payload from a depositing client, wherein the secret payload is encrypted by a client public key and can only be decrypted with a client private key, which is not possessed by either the server or the trustees;

receiving, from the depositing client, companion information associated with and specific to the secret payload, wherein the companion information is encrypted by a server public key and can only be decrypted with a server private key, which is possessed by the server, and wherein the companion information includes rules for accessing the secret payload, the rules identifying a list of trustees from the one or more trustees and a trustee policy that specifies a manner necessary for the list of trustees to approve access requests to the secret payload;

storing the secret payload along with the companion information;

receiving, from a requesting client, an access request to access the secret payload, the access request being encrypted by the server public key and including a seed, wherein the seed is randomly generated by the server and assigned to the requesting client in a preceding transaction;

decrypting the access request using the server private key;

verifying a validity of the access request based on the seed;

after the access request is verified, sending an authorization request regarding the access request to each trustee in the list of trustees, wherein each authorization request sent to each trustee from the list of trustees is encrypted with a trustee public key that corresponds to a respective trustee;

receiving responses to the authorization requests from the list of trustees;

applying the trustee policy to the received responses to determine whether to disseminate the secret payload; and

selectively disseminating the secret payload to the requesting client based on a result of applying the trustee policy and causing the requesting client to limit storage of the disseminated secret payload to a volatile memory.

10. The system of claim 9 , wherein the seed is valid for a single transaction only.

11. The system of claim 9 , wherein the companion information further includes a list of authorized requesting clients.

12. The system of claim 9 , wherein the requesting client is the depositing client.

13. The system of claim 9 , the method performed by the server further comprising:

causing the depositing client to delete a local copy of the secret payload.

14. The system of claim 9 , wherein the responses from the list of trustees are encrypted with the server public key.

15. The system of claim 9 , wherein the disseminated secret payload is encrypted with the client public key.

16. The system of claim 9 , wherein each secret payload has a unique companion information.

Assignments (5)
RELEASE OF SECURITY INTERESTS IN PATENTS Recorded Oct 14, 2021
From: CITIBANK, N.A.
To: CLOUDERA, INC.; HORTONWORKS, INC.
Reel/Frame 057804/0355 →
FIRST LIEN NOTICE AND CONFIRMATION OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Oct 12, 2021
From: CLOUDERA, INC.; HORTONWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 057776/0185 →
SECOND LIEN NOTICE AND CONFIRMATION OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Oct 12, 2021
From: CLOUDERA, INC.; HORTONWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 057776/0284 →
SECURITY INTEREST Recorded Dec 22, 2020
From: CLOUDERA, INC.; HORTONWORKS, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 054832/0559 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2016
From: GAZZANG, INC.
To: CLOUDERA, INC.
Reel/Frame 039850/0910 →
Continuity (3)
Continuation 13854773 · Apr 1, 2013
Provisional Application 61619225 · Apr 2, 2012
Related Publication 20160254913A1 · Sep 1, 2016