IP Library Granted Patent US 11,100,107
Granted Patent B2
US 11,100,107 · App. 15/156,014 · Granted Aug 24, 2021

Systems and methods for secure file management via an aggregation of cloud storage services

Inventors: Teo Winton Crofton (Sudbury, MA); David Raissipour (Westborough, MA)
Assignee: Carbonite, Inc.
G06F16/2455G06F16/178G06F21/6227H04L67/1095G06F11/1446G06F2201/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,100,107
App. No.
15/156,014
Granted
Aug 24, 2021
Kind
B2
Abstract

The present disclosure describes systems and methods for aggregation and management of cloud storage among a plurality of providers via file fragmenting to provide increased reliability and security. In one implementation, fragments or blocks may be distributed among a plurality of cloud storage providers, such that no provider retains a complete copy of a file. Accordingly, even if an individual service is compromised, a malicious actor cannot access the data. In another implementation, fragments may be duplicated and distributed to multiple providers, such that loss of communications to any one provider does not result in inability to access the data. This implementation may be combined with error correction techniques to allow recovery, even with loss of multiple providers. File synchronization may also be faster in these implementations by dividing reading and writing operations among multiple providers.

Claims (54)

1. A method for secure file management in an aggregation of cloud storage services for a client device in communication with a storage manager through a network, compromising:

displaying at the client device a folder that includes subfolders of stored items that are synchronized with corresponding stored items in respective storage locations of a plurality of cloud storage providers in communication with the client device through the network, wherein interaction with the folder on the client device designates files for synchronization;

receiving, by a storage manager from a client device, metadata of a file stored at the client device and designated for synchronization;

identifying, by the storage manager, a plurality of fragments of the file;

selecting, by the storage manager, a first account associated with the client device at a first cloud storage provider of a plurality of cloud storage providers and a second account associated with the client device at a second cloud storage provider of the plurality of cloud storage providers based on the metadata of the file;

selecting, by the storage manager, a first subset of the plurality of fragments of the file and a second subset of the plurality of fragments of the file;

storing, by the storage manager, the metadata of the file, an identification of the first subset and second subset, and an identification of the first account and second account in a storage device associated with the storage manager;

transmitting, by the storage manager to the client device, the identification of the first account and first subset of the plurality of fragments, receipt of the identification causing the client device to transmit the first subset of the plurality of fragments to the first cloud storage provider;

transmitting, by the storage manager to the client device, the identification of the second account and second subset of the plurality of fragments, receipt of the identification causing the client device to transmit the second subset of the plurality of fragments to the second cloud storage provider;

subsequently receiving, by the storage manager from the client device, a request for the file;

retrieving, by the storage manager, the metadata of the file, the identification of the first subset and second subset, and the identification of the first account and second account stored in the storage device, responsive to receipt of the request;

transmitting, by the storage manager to the client device, the identification of the first account and first subset of the plurality of fragments, receipt of the identification causing the client device to transmit a request for the first subset of the plurality of fragments to the first cloud storage provider; and

transmitting, by the storage manager to the client device, the identification of the second account and second subset of the plurality of fragments, receipt of the identification causing the client device to transmit a request for the second subset of the plurality of fragments to the second cloud storage provider.

2. The method of claim 1 , wherein identifying the plurality of fragments of the file further comprises dividing the file into a plurality of fragments of a predetermined size.

3. The method of claim 2 , wherein dividing the file into a plurality of fragments of the predetermined size further comprises dividing the file into the plurality of fragments of the predetermined size and an additional fragment including a remainder of the file.

4. The method of claim 2 , wherein the predetermined size is smaller than a header of the file.

5. The method of claim 1 , wherein selecting the first subset of the plurality of fragments of the file and selecting the second subset of the plurality of fragments of the file further comprises distributing alternating fragments of the file to the first subset and second subset.

6. The method of claim 5 , wherein receipt of the identification of the first account and first subset of the plurality of fragments further causes the client device to concatenate the first subset of the plurality of fragments of the file into a first contiguous block.

7. A system for secure file management in an aggregation of cloud storage services for a client device in communication with a storage manager through a network,

compromising:

a server comprising a network interface in communication with a client device and a plurality of cloud storage providers; and

a processor executing a storage manager,

wherein the client device is configured to display a folder that includes subfolders of stored items that are synchronized with corresponding stored items in respective storage locations of a plurality of cloud storage providers in communication with the client device through the network, wherein interaction with the folder on the client device designates files for synchronization, and

wherein the storage manager is configured to:

receive, from the client device, metadata of a file stored at the client device and designated for synchronization;

identify a plurality of fragments of the file;

select a first account associated with the client device at a first cloud storage provider of the plurality of cloud storage providers and a second account associated with the client device at a second cloud storage provider of the plurality of cloud storage providers based on the metadata of the file;

select a first subset of the plurality of fragments of the file and a second subset of the plurality of fragments of the file;

store the metadata of the file, an identification of the first subset and second subset, and an identification of the first account and second account in a storage device associated with the storage manager;

transmit, to the client device, the identification of the first account and first subset of the plurality of fragments, receipt of the identification causing the client device to transmit the first subset of the plurality of fragments to the first cloud storage provider;

transmit, to the client device, the identification of the second account and second subset of the plurality of fragments, receipt of the identification causing the client device to transmit the second subset of the plurality of fragments to the second cloud storage providers;

subsequently receive, from the client device, a request for the file,

retrieve the metadata of the file, the identification of the first subset and second subset, and the identification of the first account and second account stored in the storage device, responsive to receipt of the request,

transmit, to the client device, the identification of the first account and first subset of the plurality of fragments, receipt of the identification causing the client device to transmit a request for the first subset of the plurality of fragments to the first cloud storage provider, and

transmit, to the client device, the identification of the second account and second subset of the plurality of fragments, receipt of the identification causing the client device to transmit a request for the second subset of the plurality of fragments to the second cloud storage provider.

8. The system of claim 7 , wherein the storage manager is further configured to divide the file into a plurality of fragments of a predetermined size.

9. The system of claim 8 , wherein the storage manager is further configured to divide the file into the plurality of fragments of the predetermined size and an additional fragment including a remainder of the file.

10. The system of claim 8 , wherein the predetermined size is smaller than a header of the file.

11. The system of claim 7 , wherein the storage manager is further configured to distribute alternating fragments of the file to the first subset and second subset.

12. The system of claim 11 , wherein receipt of the identification of the first account and first subset of the plurality of fragments further causes the client device to concatenate the first subset of the plurality of fragments of the file into a first contiguous block, concatenate the second subset of the plurality of fragments of the file into a second contiguous block, and concatenate the first contiguous block and the second contiguous block.

13. A method for secure file management in an aggregation of cloud storage services for a client device in communication with a storage manager through a network, compromising:

displaying at the client device a folder that includes subfolders of stored items that are synchronized with corresponding stored items in respective storage locations of a plurality of cloud storage providers in communication with the client device through the network, wherein interaction with the folder on the client device designates files for synchronization; receiving, by a storage manager from a client device, metadata of a file stored at the client device and designated for synchronization;

selecting, by the storage manager, a first account at a first cloud storage provider of a plurality of cloud storage providers and a second account at a second cloud storage provider of the plurality of cloud storage providers based on the metadata of the file;

storing, by the storage manager, the metadata of the file and an identification of the first account and second account;

transmitting, by the storage manager to the client device, the identification of the first account, receipt of the identification causing the client device to transmit a first subset of a plurality of fragments of the file to the first cloud storage provider;

transmitting, by the storage manager to the client device, the identification of the second account, receipt of the identification causing the client device to transmit a second subset of the plurality of fragments of the file to the second cloud storage provider;

subsequently receiving, by the storage manager from the client device, a request for the file;

retrieving, by the storage manager, the metadata of the file, an identification of the first subset and second subset, and the identification of the first account and second account stored in the storage manager, responsive to receipt of the request;

transmitting, by the storage manager to the client device, the identification of the first account and first subset of the plurality of fragments, receipt of the identification causing the client device to transmit a request for the first subset of the plurality of fragments to the first cloud storage provider; and

transmitting, by the storage manager to the client device, the identification of the second account and second subset of the plurality of fragments, receipt of the identification causing the client device to transmit a request for the second subset of the plurality of fragments to the second cloud storage provider.

14. The method of claim 13 , further comprising dividing the file into a plurality of fragments of a predetermined size.

15. The method of claim 14 , wherein dividing the file into a plurality of fragments of the predetermined size further comprises dividing the file into the plurality of fragments of the predetermined size and an additional fragment including a remainder of the file.

16. The method of claim 14 , wherein the predetermined size is smaller than a header of the file.

17. The method of claim 13 , further comprising distributing alternating fragments of the file to the first subset and second subset.

Assignments (7)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Oct 12, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 065222/0310 →
CERTIFICATE OF CONVERSION Recorded Oct 12, 2023
From: CARBONITE, INC.
To: CARBONITE, LLC
Reel/Frame 065222/0303 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS RECORDED AT R/F 048723/0374 Recorded Dec 26, 2019
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: CARBONITE, INC.
Reel/Frame 051418/0807 →
SECURITY INTEREST Recorded Mar 28, 2019
From: CARBONITE, INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 048723/0374 →
TERMINATION OF PATENT SECURITY AGREEMENT FILED AT R/F 045640/0335 Recorded Mar 26, 2019
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: CARBONITE, INC.
Reel/Frame 048702/0929 →
SECURITY INTEREST Recorded Mar 19, 2018
From: CARBONITE, INC.
To: SILICON VALLEY BANK
Reel/Frame 045640/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2016
From: CROFTON, TEO WINTON; RAISSIPOUR, DAVID
To: CARBONITE, INC.
Reel/Frame 038632/0015 →