IP Library Granted Patent US 9,847,981
Granted Patent B1
US 9,847,981 · App. 15/431,414 · Granted Dec 19, 2017

Encrypted augmentation storage

Inventor: John Millikin (Mountain View, CA)
Assignee: Google Inc.
H04L63/061H04L63/0435H04L63/0442
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,847,981
App. No.
15/431,414
Granted
Dec 19, 2017
Kind
B1
Abstract

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for storing and retrieving encrypted data. In one aspect, a method includes receiving, at a server computer separate from a user device, a first encrypted resource encrypted by use of a public encryption key, wherein the public encryption key is paired with a private encryption key according to an asymmetric encryption key scheme; retrieving, by the server computer, a second encrypted resource encrypted by use of the public key; augmenting, by the server computer, the first encrypted resource with the second encrypted resource to form an encrypted data tuple; encrypting, by the server computer, the encrypted data tuple; and storing, by the server computer, the encrypted data tuple as the second encrypted resource.

Claims (62)

1. A method performed by a user device, the method comprising:

sending, by a user device to a server that is separate from the user device, a request for a current version of a first encrypted resource, the current version of the first encrypted resource being an encrypted set of respective index entries, wherein:

each respective index entry includes a combination of a respective first encryption key encrypted as a respective first encrypted key by use of a second encryption key, and a respective storage location of a respective first encrypted data file encrypted by use of the respective first encryption key, the respective storage location generated by the server;

each respective index entry has been previously appended to a respective prior version of the first encrypted resource that did not include the respective index entry to form a respective encrypted data tuple;

the respective encrypted data tuple so formed has been encrypted by the server by to form another prior version of the first encrypted resource; and

a most recent prior version of the first encrypted resource is the current version of the first encrypted resource;

receiving, by the user device and from the server, the first encrypted resource;

decrypting the first encrypted resource to decrypt the encrypted index entries;

selecting one of the respective storage locations that has been decrypted;

sending to the server a request the respective first encrypted data file stored at the respective storage location; and

receiving, from the server, the respective first encrypted data file.

2. The method of claim 1 , wherein:

the second encryption key is a public key;

each respective data tuple has been encrypted by use of the public key by the server; and

the first encrypted resource is decrypted by use of a private key that is paired to the public key.

3. The method of claim 2 , wherein each first encryption key is a respective first symmetric encryption key generated according to a symmetric encryption scheme.

4. The method of claim 3 , further comprising:

decrypting the first encryption key used to encrypt the respective first encrypted data file received from the server by use of the public key; and

decrypting the respective first encrypted data file using the first encryption key.

5. The method of claim 4 , wherein each respective encrypted first encryption key is different from each other respective encrypted first encryption key.

6. A user device, comprising:

a processing system; and

a non-transitory computer readable medium storing instructions executable by the processing system and that upon such execution cause the user device to perform operations comprising:

sending, by the user device to a server that is separate from the user device, a request for a current version of a first encrypted resource, the current version of the first encrypted resource being an encrypted set of respective index entries, wherein:

each respective index entry includes a combination of a respective first encryption key encrypted as a respective first encrypted key by use of a second encryption key, and a respective storage location of a respective first encrypted data file encrypted by use of the respective first encryption key, the respective storage location generated by the server;

each respective index entry has been previously appended to a respective prior version of the first encrypted resource that did not include the respective index entry to form a respective encrypted data tuple;

the respective encrypted data tuple so formed has been encrypted by the server by to form another prior version of the first encrypted resource; and

a most recent prior version of the first encrypted resource is the current version of the first encrypted resource;

receiving, by the user device and from the server, the first encrypted resource;

decrypting the first encrypted resource to decrypt the encrypted index entries;

selecting one of the respective storage locations that has been decrypted;

sending to the server a request the respective first encrypted data file stored at the respective storage location; and

receiving, from the server, the respective first encrypted data file.

7. The system of claim 6 , wherein:

the second encryption key is a public key;

each respective data tuple has been encrypted by use of the public key by the server; and

the first encrypted resource is decrypted by use of a private key that is paired to the public key.

8. The system of claim 7 , wherein each first encryption key is a respective first symmetric encryption key generated according to a symmetric encryption scheme.

9. The system of claim 8 , further comprising:

decrypting the first encryption key used to encrypt the respective first encrypted data file received from the server by use of the public key; and

decrypting the respective first encrypted data file using the first encryption key.

10. The system of claim 9 , wherein each respective encrypted first encryption key is different from each other respective encrypted first encryption key.

11. A non-transitory computer readable medium storing instructions executable by a user device and that upon such execution cause the user device to perform operations comprising:

sending, by the user device to a server that is separate from the user device, a request for a current version of a first encrypted resource, the current version of the first encrypted resource being an encrypted set of respective index entries, wherein:

each respective index entry includes a combination of a respective first encryption key encrypted as a respective first encrypted key by use of a second encryption key, and a respective storage location of a respective first encrypted data file encrypted by use of the respective first encryption key, the respective storage location generated by the server;

each respective index entry has been previously appended to a respective prior version of the first encrypted resource that did not include the respective index entry to form a respective encrypted data tuple;

the respective encrypted data tuple so formed has been encrypted by the server by to form another prior version of the first encrypted resource; and

a most recent prior version of the first encrypted resource is the current version of the first encrypted resource;

receiving, by the user device and from the server, the first encrypted resource;

decrypting the first encrypted resource to decrypt the encrypted index entries;

selecting one of the respective storage locations that has been decrypted;

sending to the server a request the respective first encrypted data file stored at the respective storage location; and

receiving, from the server, the respective first encrypted data file.

12. The non-transitory computer readable medium of claim 11 , wherein:

the second encryption key is a public key;

each respective data tuple has been encrypted by use of the public key by the server; and

the first encrypted resource is decrypted by use of a private key that is paired to the public key.

13. The non-transitory computer readable medium of claim 12 , wherein each first encryption key is a respective first symmetric encryption key generated according to a symmetric encryption scheme.

14. The non-transitory computer readable medium of claim 13 , further comprising:

decrypting the first encryption key used to encrypt the respective first encrypted data file received from the server by use of the public key; and

decrypting the respective first encrypted data file using the first encryption key.

15. The non-transitory computer readable medium of claim 14 , wherein each respective encrypted first encryption key is different from each other respective encrypted first encryption key.

Assignments (2)
CHANGE OF NAME Recorded Dec 5, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044695/0115 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2017
From: MILLIKIN, JOHN
To: GOOGLE INC.
Reel/Frame 041437/0076 →
Continuity (2)
Continuation 15053665 · Feb 25, 2016
Continuation 14145174 · Dec 31, 2013