IP Library Granted Patent US 11,128,452
Granted Patent B2
US 11,128,452 · App. 15/933,290 · Granted Sep 21, 2021

Encrypted data sharing with a hierarchical key structure

Inventors: Petr Van{hacek over (e)}k (Velké N{hacek over (e)}m{hacek over (c)}ice, CZ); Jan Schwarz (Letovice, CZ); Pavel Studený (Praha 5, CZ)
Assignee: Avast Software s.r.o.
H04L9/085H04L9/0822H04L9/0861H04L9/0869H04L9/14H04L9/3066
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,128,452
App. No.
15/933,290
Granted
Sep 21, 2021
Kind
B2
Abstract

A data set shared by multiple nodes is encrypted. The data set can be split into independent records. The records can be encrypted and shared independently, without the need to modify and transmit the full data set. Although the records are encrypted with their own encryption key, they are all accessible by a single authentication method.

Claims (56)

1. A method for encrypting data in a data set shared between a plurality of nodes, the method comprising:

creating a first identity secret key by processing a first shared secret maintained by a first two of the plurality of nodes;

generating a first record key;

encrypting a first record in the data set using the first record key;

generating a first record key encryption key based, at least in part, on the first identity secret key and a first salt value;

encrypting the first record key using the first record key encryption key to create a first encrypted record key;

storing the first encrypted record in association with the first encrypted record key and the first salt value; and

creating a second identity secret key by processing a second shared secret maintained by a second two of the plurality of nodes;

generating a second record key;

encrypting a second record in the data set using the second record key;

generating a second record key encryption key based, at least in part, on the second identity secret key and a second salt value;

encrypting the second record key using the second record key encryption key to create a second encrypted record key; and

storing the second encrypted record in association with the second encrypted record key and the second salt value.

2. The method of claim 1 , wherein generating the first record key comprises providing the first identity secret key and the first salt value to a key derivation function, and wherein generating the first record key comprises providing the second identity secret key and the second salt value to a key derivation function.

3. The method of claim 1 , further comprising determining records for the data set.

4. The method of claim 3 , wherein determining records for the data set comprises determining one of fixed size records for a file comprising the data set or determining rows in tables of the data set.

5. The method of claim 1 , further comprising generating the first shared secret and the second shared secret using an elliptic curve key pair.

6. The method of claim 1 , wherein creating the first identity secret key using a first shared secret comprises processing the first shared secret using a key derivation function, and wherein creating the second identity secret key using a second shared secret comprises processing the second shared secret using a key derivation function.

7. A non-transitory machine-readable medium having stored thereon instructions for encrypting data in a data set shared between a plurality of nodes, the instructions comprising computer executable instructions to cause one or more processors to:

create first identity secret key by processing a first shared secret maintained by a first two of the plurality of nodes;

generate a first record key;

encrypt a first record in the data set using the first record key;

generate a first record key encryption key based, at least in part, on the first identity secret key and a first salt value;

encrypt the first record key using the first record key encryption key to create a first encrypted record key;

store the first encrypted record in association with the first encrypted record key and the first salt value;

create a second identity secret key by processing a second shared secret maintained by a second two of the plurality of nodes;

generate a second record key;

encrypt a second record in the data set using the second record key;

generate a second record key encryption key based, at least in part, on the second identity secret key and a second salt value;

encrypt the second record key using the second record key encryption key to create a second encrypted record key; and

store the encrypted record in association with the second encrypted record key and the second salt value.

8. The non-transitory machine-readable medium of claim 7 , wherein the computer executable instructions to generate the first record key include computer executable instructions to provide the first identity secret key and the first salt value to a key derivation function and wherein the computer executable instructions to generate the second record key include computer executable instructions to provide the second identity secret key and the second salt value to a key derivation function.

9. The non-transitory machine-readable medium of claim 7 , wherein the computer executable instructions further comprise computer executable instructions to determine records for the data set.

10. The non-transitory machine-readable medium of claim 9 , wherein the computer executable instructions to determine records for the data set comprise computer executable instructions to determine one of fixed size records for a file comprising the data set or determining rows in tables of the data set.

11. The non-transitory machine-readable medium of claim 7 , wherein the computer executable instructions further comprise computer executable instructions to generate the first shared secret and the second shared secret using an elliptic curve key pair.

12. The non-transitory machine-readable medium of claim 7 , wherein the computer executable instructions to create the identity secret key using a shared secret comprises computer executable instructions to process the first shared secret and the second shared secret using a key derivation function.

13. An apparatus for encrypting data in a data set shared between a plurality of nodes, the apparatus comprising:

one or more processors; and

a non-transitory machine-readable medium having stored thereon computer executable instructions to cause the one or more processors to:

create a first identity secret key by processing a first shared secret maintained by a first two of the plurality of nodes;

generate a first record key;

encrypt a first record in the data set using the first record key;

generate a first record key encryption key based, at least in part, on the first identity secret key and a first salt value;

encrypt the first record key using the first record key encryption key to create a first encrypted record key;

store the first encrypted record in association with the first encrypted record key and the first salt value;

create a second identity secret key by processing a second shared secret maintained by a second two of the plurality of nodes;

generate a second record key;

encrypt a second record in the data set using the second record key;

generate a second record key encryption key based, at least in part, on the second identity secret key and a second salt value;

encrypt the second record key using the second record key encryption key to create a second encrypted record key; and

store the second encrypted record in association with the second encrypted record key and the second salt value.

14. The apparatus of claim 13 , wherein the computer executable instructions to generate the first record key include computer executable instructions to provide the first identity secret key and the first salt value to a key derivation function and wherein the computer executable instructions to generate the second record key include computer executable instructions to provide the second identity key and the second salt value to a key derivation function.

15. The apparatus of claim 13 , wherein the computer executable instructions further comprise computer executable instructions to determine records for the data set.

16. The system of claim 15 , wherein the computer executable instructions to determine records for the data set comprise computer executable instructions to determine one of fixed size records for a file comprising the data set or determining rows in tables of the data set.

17. The apparatus of claim 13 , wherein the computer executable instructions further comprise computer executable instructions to generate the first and second shared secrets using an elliptic curve key pair.

18. The apparatus of claim 13 , wherein the computer executable instructions to create the first identity secret key using a first shared secret comprise computer executable instructions to process the first shared secret using a key derivation function, and wherein the computer executable instructions to create the second identity secret key using a second shared secret comprise computer executable instructions to process the second shared secret using a key derivation function.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: GEN DIGITAL AMERICAS S.R.O.
To: GEN DIGITAL INC.
Reel/Frame 071771/0767 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: AVAST SOFTWARE S.R.O.
To: GEN DIGITAL AMERICAS S.R.O.
Reel/Frame 071777/0341 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2018
From: VANEK, PETR; SCHWARZ, JAN; STUDENÝ, PAVEL
To: AVAST SOFTWARE S.R.O.
Reel/Frame 045322/0016 →
Cited By (1)
US 12,547,749