IP Library › Granted Patent US 11,281,790
Granted Patent B2
US 11,281,790 · App. 15/931,673 · Granted Mar 22, 2022

Method and system for distributed data storage with enhanced security, resilience, and control

Inventor: Jaeyoon Chung (Chesterbrook, PA)
Assignee: Myota, Inc.
G06F21/6218G06F9/544G06F16/164G06F16/168G06F16/178G06F16/1734G06F16/1748G06F16/1824G06F21/602H04L9/0631G06F2221/0755
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,281,790
App. No.
15/931,673
Granted
Mar 22, 2022
Kind
B2
Abstract

A method and system for encrypting and reconstructing data files, including related metadata, is disclosed. The method involves separately encrypting data and metadata as chaining processes and integrating a plurality of encryption/encoding techniques together with strategic storage distribution techniques and parsing techniques which results in the integrated benefits of the collection of techniques. As disclosed, the content data is separated from its metadata, encryption keys may be embedded in the metadata, and in a content data encryption chaining process, the method chunks, encrypts, shards, and stores content data and separately shards and stores metadata, and stored in a flexible, distributed, and efficient manner, at least in part to assure improved resiliency In addition, the processes are preferably implemented locally, including at the site of the content data or a proxy server.

Claims (25)

1. A method for a processor to encrypt at least one computer file based on a combination of computational and theoretical cryptography, said computer file accessible at least on a local device, said computer file including a content data portion and an associated metadata portion, comprising the steps of:

generating a plurality of randomly generated encryption keys;

selecting at least one computer file for encryption;

parsing said content data portion of said computer file into a chain of content chunks, each said chunk assigned a chunk ID;

using computational cryptography, said computational cryptography includes use of one or more encryption algorithms and erasure coding, using said at least one encryption key per chunk, encrypting each of said content chunks;

using computational cryptography encoding and parsing each of said content chunks into a plurality of content shards;

using theoretical cryptography, said theoretical cryptography includes secret sharing methods and storing a secret in multiple shards, n, without use of an encryption key, encrypting said chunk IDs;

augmenting said metadata portion with said encrypted chunk IDs thereby forming an augmented metadata portion;

parsing said plurality of randomly generated encryption keys into a plurality of key shards;

using theoretical cryptography, encrypting said plurality of key shards;

adding said encrypted plurality of key shards into said augmented metadata portion;

parsing a subset of said metadata portion into a plurality of metadata shards;

encrypting said metadata shards;

delivering said plurality of content shards to at least a first storage location; and

delivering said plurality of metadata shards to at least a second storage location;

wherein said at least a first storage location differs from said at least a second storage location, said method is configured to protect stored data from brute force attacks, and said method is configured such that decryption requires knowledge of t out of n content shards, t out of n key shards, and t out of n metadata shards, where t and n are integers.

2. The method of claim 1 , where the encrypted key shards and said chunk IDs are separately stored.

3. The method of claim 1 , where the steps of parsing said at least one key into a plurality of key shards and encrypting said plurality of key shards is at least partially performed using Shamir's Secret Sharing Scheme (SSSS).

4. The method of claim 1 , where the computational cryptography portion of the method includes use of Reed-Solomon encoding.

5. The method of claim 1 , where the step of encrypting each of said content chunks includes use of AES-256.

6. The method of claim 1 , where said content data portion is fully encrypted before encoding.

7. The method of claim 1 , where at least one file attribute in said metadata portion is not encrypted.

8. The method of claim 1 , where at least some of said metadata portion is stored in a vault on said local device.

9. The method of claim 1 , where a number, n, of each of metadata storage, key storage, and data storage is configurable and each is greater than 2.

10. The method of claim 1 , where t is a number of required shards to reconstruct and n is a number of shards stored, parameters t and n of metadata shards, key shards, and data shards are each independently configurable, individually selectable by a user, and where t is an integer greater than 1 and n is n integer greater than t.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2022
From: CHUNG, JAEYOON
To: MYOTA, INC.
Reel/Frame 060230/0822 →
CHANGE OF ASSIGNEE'S ADDRESS Recorded Apr 20, 2022
From: MYOTA, INC.
To: MYOTA, INC.
Reel/Frame 060615/0638 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2020
From: CHUNG, JAEYOON
To: MYOTA, INC.
Reel/Frame 052658/0775 →
Continuity (2)
Provisional Application 62851146 · May 22, 2019
Related Publication 20200372163A1 · Nov 26, 2020
Cited By (2)
US 12,627,480 US 12,712,724