IP Library Granted Patent US 9,602,477
Granted Patent B1
US 9,602,477 · App. 15/190,142 · Granted Mar 21, 2017

Secure file transfer

Inventors: Ernest W. Grzybowski (Edison, NJ); Christopher A. Howell (Freehold, NJ); Thomas Michael Leavy (Hoboken, NJ); David A. Sugar (Cape May, NJ); Dipakkumar R. Kasabwala (Clifton, NJ)
Assignee: Wickr Inc.
H04L63/0435G06F21/6218H04L63/061H04L63/0853
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,602,477
App. No.
15/190,142
Granted
Mar 21, 2017
Kind
B1
Abstract

The present disclosure describes techniques for storing encrypted files in a secure file repository and transferring those encrypted files to one or more recipients. A user selects a file to upload to a secure file repository. A secure collaboration app on the user's device generates a first encryption key that is used to encrypt the file. The encrypted file is then uploaded to the secure file repository, which provides the secure collaboration app with a random file name and a location of the encrypted file. The secure collaboration app updates locally stored metadata of the first encrypted file. To securely transfer the file, the user generates a second encryption key, encrypts the metadata with the second encryption key, and transmits the encrypted metadata to one or more receivers. The one or more receivers decrypt the encrypted metadata and use the decrypted metadata to retrieve the file and decrypt it.

Claims (41)

1. A system, comprising:

a processor configured to:

receive a first encrypted communication from a sender's device, wherein the first encrypted communication includes notification of an encrypted shared file and encrypted file metadata;

decrypt the encrypted file metadata using a second encryption key to obtain file metadata and a first encryption key, wherein the first encryption key was previously generated at least in part by obtaining ephemeral environmental noise from a kernel operation executing on the sender's device;

retrieve the encrypted shared file from a secure file repository using the file metadata obtained from the first encrypted communication;

decrypt the encrypted shared file using the first encryption key; and

provide the decrypted shared file to the receiver;

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the encrypted file metadata includes a first encryption key used to encrypt the encrypted shared file.

3. The system of claim 1 , wherein the second encryption key is a twice-encrypted second encryption key in the first encrypted communication.

4. The system of claim 3 , wherein the processor is further configured to:

decrypt the twice-encrypted second encryption key using a device key unique to a receiver's device to produce an encrypted second encryption key; and

decrypt the encrypted second encryption key with a key-encrypting key unique to the receiver's device to obtain the second encryption key.

5. The system of claim 1 , wherein the encrypted shared filed is decrypted using a symmetric encryption algorithm.

6. The system of claim 1 , wherein the secure file repository is a third-party file repository.

7. A method comprising:

receiving a first encrypted communication from a sender's device, wherein the first encrypted communication includes notification of an encrypted shared file and encrypted file metadata;

decrypting the encrypted file metadata using a second encryption key to obtain file metadata and a first encryption key, wherein the first encryption key was previously generated at least in part by obtaining ephemeral environmental noise from a kernel operation executing on the sender's device;

retrieving the encrypted shared file from a secure file repository using the file metadata obtained from the first encrypted communication;

decrypting the encrypted shared file using the first encryption key; and

providing the decrypted shared file to the receiver.

8. The method of claim 7 , wherein the encrypted file metadata includes a first encryption key used to encrypt the encrypted shared file.

9. The method of claim 7 , wherein the second encryption key is a twice-encrypted second encryption key in the first encrypted communication.

10. The method of claim 9 , further comprising:

decrypting the twice-encrypted second encryption key using a device key unique to a receiver's device to produce an encrypted second encryption key; and

decrypting the encrypted second encryption key with a key-encrypting key unique to the receiver's device to obtain the second encryption key.

11. The method of claim 7 , wherein the encrypted shared filed is decrypted using a symmetric encryption algorithm.

12. The method of claim 7 , wherein the secure file repository is a third-party file repository.

13. A non-transitory computer-readable medium comprising instructions that, when executed by at least one processor, perform the steps of:

receiving a first encrypted communication from a sender's device, wherein the first encrypted communication includes notification of an encrypted shared file and encrypted file metadata;

decrypting the encrypted file metadata using a second encryption key to obtain file metadata and a first encryption key, wherein the first encryption key was previously generated at least in part by obtaining ephemeral environmental noise from a kernel operation executing on the sender's device;

retrieving the encrypted shared file from a secure file repository using the file metadata obtained from the first encrypted communication;

decrypting the encrypted shared file using the first encryption key; and

providing the decrypted shared file to the receiver.

14. The non-transitory computer-readable medium of claim 13 , wherein the encrypted file metadata includes a first encryption key used to encrypt the encrypted shared file.

15. The non-transitory computer-readable medium of claim 13 , wherein the second encryption key is a twice-encrypted second encryption key in the first encrypted communication.

16. The non-transitory computer-readable medium of claim 15 , further comprising instructions for:

decrypting the twice-encrypted second encryption key using a device key unique to a receiver's device to produce an encrypted second encryption key; and

decrypting the encrypted second encryption key with a key-encrypting key unique to the receiver's device to obtain the second encryption key.

17. The non-transitory computer-readable medium of claim 13 , wherein the encrypted shared filed is decrypted using a symmetric encryption algorithm.

18. The non-transitory computer-readable medium of claim 13 , wherein the secure file repository is a third-party file repository.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2021
From: WICKR LLC
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 057366/0573 →
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 25, 2021
From: SILICON VALLEY BANK
To: WICKR INC.
Reel/Frame 056684/0366 →
SECURITY AGREEMENT Recorded Dec 12, 2017
From: WICKR INC.
To: SILICON VALLEY BANK
Reel/Frame 044872/0729 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2016
From: GRZYBOWSKI, ERNEST W.; HOWELL, CHRISTOPHER A.; LEAVY, THOMAS MICHAEL; SUGAR, DAVID A.; KASABWALA, DIPAKKUMAR R.
To: WICKR INC.
Reel/Frame 039343/0975 →
Continuity (1)
Provisional Application 62322664 · Apr 14, 2016