IP Library Granted Patent US 10,657,283
Granted Patent B2
US 10,657,283 · App. 15/833,345 · Granted May 19, 2020

Secure high speed data storage, access, recovery, transmission, and retrieval from one or more of a plurality of physical storage locations

Inventors: Linda Eigner (La Jolla, CA); William Eigner (La Jolla, CA); Anthony Iasi (San Diego, CA); Charles Kahle (Escondido, CA); Gary Schneir (Carlsbad, CA); Eric Tobias (La Jolla, CA)
Assignee: Ubiq Security, Inc.
G06F21/6245G06F21/6227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,657,283
App. No.
15/833,345
Granted
May 19, 2020
Kind
B2
Abstract

A method for storing a first data object includes: decomposing the first data object into a first fragment associated with a first original record locator and a second fragment associated with a second original record locator; obfuscating the first original record locator to generate a first obfuscated record locator and the second original record locator to generate a second obfuscated record locator; encrypting the first fragment using a first encryption key and the second fragment using a second encryption key; and storing, to at least a first of a plurality of storage locations, the first encrypted fragment with the corresponding first obfuscated record locator and the second encrypted fragment with the second obfuscated record locator.

Claims (28)

1. A method for retrieving a data object, the method comprising:

retrieving a data map that includes at least a first portion of information required to retrieve and reconstruct the data object from one or more of a plurality of data storage locations;

performing one or more computations to dynamically derive at least a second portion of the information required to retrieve and reconstruct the data object from the one or more of the plurality of physical storage locations, wherein the one or more computations are performed to dynamically derive a portion of the information required to retrieve and reconstruct the data object that is not included in the data map; and

retrieving the data object from the one or more of the plurality of data storage locations and reconstructing the data object based on one or more of the first and second portions of the information included in the data map and the information dynamically derived through the one or more computations.

2. The method of claim 1 , wherein the information required to retrieve and reconstruct the data object includes an index of a sequence of a plurality of fragments of the data object, an encryption key used to encrypt each of the plurality of fragments, an obfuscated record locator associated with each of the plurality of fragments, and at least the first of the plurality of data storage locations at which each of the plurality of fragments are stored.

3. The method of claim 1 , wherein the one or more computations include determining a decomposition function applied to decompose the data object into a plurality of fragments, determining an obfuscated record locator associated with each of the plurality of fragments, calculating an encryption key used to encrypt each of the plurality of fragments, and identifying at least the first of the plurality of data storage locations at which each of the plurality of fragments are stored.

4. The method of claim 1 , wherein varying a content of the data map varies an extent of computations that is required to be performed in order to dynamically derive the second portion of the information required to retrieve and reconstruct the data object, and

wherein the content of the data map is varied based on one or more of a username, a user passphrase, a current security model, a type of the data object, a size of the data object, one or more security requirements, and one or more performance requirements.

5. The method of claim 1 , wherein at least one data storage location of the one or more of the plurality of data storage locations is physically separated from others of the one or more of the plurality of data storage locations.

6. The method of claim 1 , wherein at least one data storage location of the one or more of the plurality of data storage locations is geographically separated from others of the one or more of the plurality of data storage locations.

7. The method of claim 1 , wherein contents of the data map varies based on one or more of a user passphrase, a current security model, a size of the data object, a type of the data object, security requirements, and performance requirements.

8. The method of claim 1 , wherein the data map is encrypted.

9. The method of claim 8 , further comprising decrypting the data map prior to retrieving and reconstructing the data object.

10. A system for storing a data object, the system comprising:

a plurality of data storage locations; and

a secure platform comprising one or more processors coupled to at least one memory, the secure platform configured to:

retrieve a data map that includes at least a first portion of information required to retrieve and reconstruct the data object;

perform one or more computations to dynamically derive at least a second portion of the information required to retrieve and reconstruct the data object, wherein the one or more computations are performed to dynamically derive a portion of the information required to retrieve and reconstruct the data object that is not included in the data map; and

retrieve the data object from at least a first of the plurality of data storage locations and reconstruct the data object based on one or more of the first and second portions of the information included in the data map and the information dynamically derived through the one or more computations.

11. The system of claim 10 , wherein the information required to retrieve and reconstruct the data object includes an index of a sequence of a plurality of fragments of the data object, an encryption key used to encrypt each of the plurality of fragments, an obfuscated record locator associated with each of the plurality of fragments, and at least the first of the plurality of data storage locations at which each of the plurality of fragments are stored.

12. The system of claim 10 , wherein the one or more computations include determining a decomposition function applied to decompose the data object into a plurality of fragments, determining an obfuscated record locator associated with each of the plurality of fragments, calculating an encryption key used to encrypt each of the plurality of fragments, and identifying at least the first of the plurality of data storage locations at which each of the plurality of fragments are stored.

13. The system of claim 10 , wherein varying a content of the data map varies an extent of computations that is required to be performed in order to dynamically derive the second portion of the information required to retrieve and reconstruct the data object, and

wherein the content of the data map is varied based on one or more of a username, a user passphrase, a current security model, a type of the data object, a size of the data object, one or more security requirements, and one or more performance requirements.

14. The system of claim 10 , wherein at least one data storage location of the one or more of the plurality of data storage locations is physically separated from others of the one or more of the plurality of data storage locations.

15. The system of claim 10 , wherein at least one data storage location of the one or more of the plurality of data storage locations is geographically separated from others of the one or more of the plurality of data storage locations.

16. The system of claim 10 , wherein contents of the data map varies based on one or more of a user passphrase, a current security model, a size of the data object, a type of the data object, security requirements, and performance requirements.

17. The system of claim 10 , wherein the data map is encrypted.

18. The system of claim 17 , wherein the one or more processors are configured to decrypt the data map prior to retrieving and reconstructing the data object.

Assignments (2)
CHANGE OF NAME Recorded May 20, 2019
From: FHOOSH, INC.
To: UBIQ SECURITY, INC.
Reel/Frame 049517/0566 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2017
From: EIGNER, LINDA; TOBIAS, ERIC; EIGNER, WILLIAM; SCHNEIR, GARY; KAHLE, CHARLES; IASI, ANTHONY
To: FHOOSH, INC.
Reel/Frame 044315/0672 →
Continuity (6)
Continuation 14863294 · Sep 23, 2015
Provisional Application 62167227 · May 27, 2015
Provisional Application 62119794 · Feb 23, 2015
Provisional Application 62057225 · Sep 29, 2014
Provisional Application 62054310 · Jun 23, 2014
Related Publication 20180107841A1 · Apr 19, 2018
Cited By (5)
US 12,381,857 US 12,517,661 US 12,518,048 US 12,591,698 US 12,671,583