IP Library Granted Patent US 10,250,385
Granted Patent B2
US 10,250,385 · App. 15/179,727 · Granted Apr 2, 2019

Customer call logging data privacy in cloud infrastructure

Inventors: Leonidas P Papadopoulos (Ridgefield, CT); Roger Norman Dunn (Stratham, NH); Anil Mathai Varghese (Jersey City, NJ)
Assignee: Cloud9 Technologies, LLC
H04L9/0861H04L9/088H04L9/0894H04L63/0442H04L63/061H04L2463/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,250,385
App. No.
15/179,727
Granted
Apr 2, 2019
Kind
B2
Abstract

Systems and methods are provided for encrypting data at a customer for storage at a hosted service provider. In addition to the data being encrypted by the client, the secret encryption key used to encrypt the data is also encrypted. Both the encrypted data and the encrypted secret encryption key are transmitted to the service provider who may further encrypt the data with another encryption key and who stores the further encrypted data, the encrypted secret encryption key and the another encryption key.

Claims (35)

1. A system for secure storage of customer data by a remote service provider equipment (SPE), said system comprising:

a processor based customer premise equipment (CPE); said CPE having an application programming interface (API) and a key manager;

said CPE configured to generate a secret encryption key;

said key manager is configured to provide a master encryption key to said API for encrypting said secret encryption key;

said CPE is also configured to generate a data, and encrypt said data with said secret encryption key, to encrypt said secret encryption key with said master encryption key and to transmit said encrypted data and said encrypted secret encryption key for receipt and storage by said service provider.

2. The system according to claim 1 wherein said data includes a voice recording.

3. The system according to claim 1 further comprising a download tool configured to recall said data from said service provider and decrypt said recalled data for playback.

4. The system according to claim 3 wherein said download tool is further configured to receive said secret encryption key and decrypt said secret encryption key with said master key.

5. The system according to claim 1 wherein said CPE is further configured to receive a service provider public encryption key (PK) and to encrypt said encrypted data and said encrypted secret encryption key with said PK prior to said transmission of said encrypted data and said encrypted secret encryption key.

6. A method for storing customer data at a remote service provider, said method comprising:

a customer accessing via a processor based device a service provided by said service provider;

said customer generating data as a result of said access;

said processor based device generating a secret encryption key;

said processor based device encrypting said data with said secret encryption key and transmitting said encrypted data for receipt by said service provider;

said processor based device encrypting said secret encryption key with a master encryption key; and,

said processor based device transmitting said encrypted secret encryption key for receipt by said service provider.

7. The method according to claim 6 wherein said CPE generates said master encryption key.

8. The method according to claim 6 wherein said CPE receives said master key from the service provider.

9. The method according to claim 6 wherein said CPE receives said master key from a third party.

10. The method according to claim 6 further comprising said SPE receiving said encrypted data and said encrypted secret encryption key and further encrypting said encrypted data with a tenant encryption key; and,

said service provider storing said further encrypted data and said tenant key in a storage.

11. The method according to claim 10 further including said SPE further encrypting said encrypted secret encryption key and storing said encrypted secret encryption key in another storage which is separate from said storage.

12. The method according to claim 10 further including said SPE further encrypting said encrypted secret encryption key and transmitting said further encrypted secret encryption key for receipt by said CPE.

13. The method according to claim 6 further comprising said SPE receiving said encrypted data and said encrypted secret encryption key, further encrypting said encrypted secret encryption key with a tenant encryption key and further encrypting said encrypted data with a CPE public key; and,

said SPE storing said further encrypted data and said further encrypted secret encryption key in physically separate storage devices.

14. A method for storing at a service provider customer data, said method comprising:

said service provider receiving an encrypted secret encryption key and an encrypted data from a processor based customer equipment running an application provided by said service provider, said data being encrypted with said secret encryption key;

said service provider further encrypting said encrypted data and storing said further encrypted data in a storage device; and,

said service provider further encrypting said encrypted secret encryption key.

15. The method according to claim 14 wherein said further encryption of said data is with a customer provider public encryption key and said further encryption of said encrypted secret encryption key is with a tenant encryption key.

16. The method according to claim 14 wherein said further encryption of said data is with a tenant encryption key and said further encryption of said encrypted secret encryption key is with a customer provided public encryption key.

17. The method according to claim 14 further including said service provider storing said further encrypted secret encryption key in a storage which is separate from said storage containing said further encrypted data.

18. The method according to claim 16 further including said service provider transmitting said further encrypted secret encryption key for receipt by said customer.

19. The method according to claim 16 wherein said data is a voice recording.

20. The method according to claim 15 wherein said tenant encryption key is stored separate from said further encrypted secret encryption key.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Dec 18, 2025
From: HPS INVESTMENT PARTNERS, LLC, AS GRANTEE
To: SYMPHONY COMMUNICATION SERVICES, LLC; CLOUD9 TECHNOLOGIES LLC
Reel/Frame 073264/0835 →
SECURITY INTEREST Recorded Sep 29, 2025
From: SYMPHONY COMMUNICATION SERVICES HOLDINGS, LLC; SYMPHONY COMMUNICATION SERVICES, LLC; CLOUD9 TECHNOLOGIES LLC; PERZO INC.; STREETLINX INC.; AMENITY ANALYTICS, INC.
To: MUFG BANK, LTD.
Reel/Frame 072408/0921 →
SECURITY INTEREST Recorded Jun 24, 2021
From: CLOUD9 TECHNOLOGIES LLC; SYMPHONY COMMUNICATION SERVICES HOLDINGS, LLC
To: HPS INVESTMENT PARTNERS, LLC
Reel/Frame 056652/0359 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2016
From: PAPADOPOULOS, LEONIDAS P; DUNN, ROGER NORMAN; MATHAI VARGHESE, ANIL
To: CLOUD9 TECHNOLOGIES, LLC
Reel/Frame 038882/0538 →
Continuity (2)
Provisional Application 62297105 · Feb 18, 2016
Related Publication 20170244693A1 · Aug 24, 2017