IP Library Granted Patent US 11,178,116
Granted Patent B2
US 11,178,116 · App. 15/977,748 · Granted Nov 16, 2021

Secure data parser method and system

Inventors: Mark S. O'Hare (Coto de Caza, CA); Rick L. Orsini (Flower Mound, TX); Roger S. Davenport (Campbell, TX); Steven Winick (Roslyn Heights, NY)
Assignee: Security First Corp.
H04L63/0428G06F16/22G06F21/602G06F21/606G06F21/62G06F21/6218H04L9/085H04L9/3226H04L9/3263H04L63/04H04L63/08H04L63/0823H04L63/0876H04L67/108H04L69/14G06F11/1092H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,178,116
App. No.
15/977,748
Granted
Nov 16, 2021
Kind
B2
Abstract

A secure data parser is provided that may be integrated into any suitable system for securely storing and communicating data. The secure data parser parses data and then splits the data into multiple portions that are stored or communicated distinctly. Encryption of the original data, the portions of data, or both may be employed for additional security. The secure data parser may be used to protect data in motion by splitting original data into portions of data that may be communicated using multiple communications paths.

Claims (46)

1. A method for securing a data set, the method comprising:

distributing the data set into a plurality of data chunks, wherein none of the data chunks are, by themselves, sufficient to reconstruct the data set;

encrypting each of the data chunks with a respective one of a plurality of encryption keys;

obfuscating each of the plurality of different encryption keys; and

separately storing each data chunk of the plurality of data chunks together with one of the plurality of obfuscated different encryption keys on a plurality of different storage devices.

2. The method of claim 1 , wherein obfuscating each of the plurality of different encryption keys comprises performing a transform on data indicative of at least one of the plurality of different encryption keys.

3. The method of claim 2 , wherein performing a transform on data indicative of at least one of the plurality of different encryption keys comprises performing an all-or-nothing transform on the data indicative of at least one of the plurality of different encryption keys.

4. The method of claim 1 , wherein obfuscating each of the plurality of different encryption keys comprises applying Shamir's Secret Sharing algorithm to data indicative of at least one of the plurality of different encryption keys.

5. The method of claim 1 , wherein storing the plurality of data chunks together with the plurality of obfuscated different encryption keys comprises storing each of the plurality of data chunks together with a respective one of the plurality of obfuscated different encryption keys.

6. The method of claim 1 , wherein storing the plurality of data chunks together with the plurality of obfuscated different encryption keys comprises including, with a data chunk of the plurality of data chunks, data indicative of an encryption key that was used to encrypt a different data chunk of the plurality of data chunks.

7. The method of claim 1 , wherein distributing the data set into a plurality of data chunks comprises using a random technique or pseudorandom technique.

8. The method of claim 1 , further comprising generating the data set by encrypting primary data.

9. A method for securing a data set, the method comprising:

distributing the data set into a plurality of data chunks, wherein none of the data chunks are, by themselves, sufficient to reconstruct the data set;

encrypting each of the data chunks with a respective one of a plurality of encryption keys;

transforming each of the plurality of different encryption keys; and

separately storing each data chunk of the plurality of data chunks together with one of the plurality of transformed different encryption keys on a plurality of different storage devices.

10. The method of claim 9 , wherein transforming each of the plurality of different encryption keys comprises performing an all-or-nothing transform on data indicative of at least one of the plurality of different encryption keys.

11. The method of claim 9 , wherein storing the plurality of data chunks with the plurality of transformed different encryption keys comprises storing each of the plurality of data chunks with a respective one of the plurality of transformed different encryption keys.

12. The method of claim 9 , wherein storing the plurality of data chunks with the plurality of transformed different encryption keys comprises including, with a data chunk of the plurality of data chunks, data indicative of an encryption key of the plurality of encryption keys that was used to encrypt a different data chunk of the plurality of data chunks.

13. The method of claim 9 , wherein distributing the data set into a plurality of data chunks comprises using a random technique or pseudorandom technique.

14. The method of claim 9 , further comprising generating the data by encrypting primary data.

15. A computer system for securing a data set, the system comprising:

at least one hardware processor, configured to:

access the data set;

distribute the data set into a plurality of data chunks, wherein none of the data chunks are, by themselves, sufficient to reconstruct the data set;

encrypt each of the data chunks with a respective one of a plurality of encryption keys;

obfuscate each of the plurality of different encryption keys; and

storing the plurality of data chunks together with the plurality of obfuscated different encryption keys;

separately store each data chunk of the plurality of data chunks together with one of the plurality of obfuscated different encryption keys, wherein the plurality of data chunks is stored on a plurality of different storage devices.

16. The computer system of claim 15 , wherein, when obfuscating each of the plurality of different encryption keys, the at least one hardware processor is configured to perform a transform on data indicative of at least one of the plurality of different encryption keys.

17. The computer system of claim 16 , wherein, when performing a transform on data indicative of at least one of the plurality of different encryption keys, the at least one hardware processor is configured to perform an all-or-nothing transform on the data indicative of at least one of the plurality of different encryption keys.

18. The computer system of claim 15 , wherein, when obfuscating each of the plurality of different encryption keys, the at least one hardware processor is configured to apply Shamir's Secret Sharing algorithm to data indicative of at least one of the plurality of different encryption keys.

19. The computer system of claim 15 , wherein, when storing the plurality of data chunks together with the plurality of obfuscated different encryption keys, the at least one hardware processor is configured to store each of the plurality of data chunks together with a respective one of the plurality of obfuscated different encryption keys.

20. The computer system of claim 15 , wherein, when storing the plurality of data chunks together with the plurality of obfuscated different encryption keys, the at least one hardware processor is configured to include, with a data chunk of the plurality of data chunks, data indicative of an encryption key that was used to encrypt a different data chunk of the plurality of data chunks.

21. A computer system for securing a data set, the system comprising:

at least one hardware processor, configured to:

access the data set;

distribute the data set into a plurality of data chunks, wherein none of the data chunks are, by themselves, sufficient to reconstruct the data set;

encrypt each of the data chunks with a respective one of a plurality of encryption keys;

transform each of the plurality of different encryption keys; and

storing the plurality of data chunks together with the plurality of transformed different encryption keys;

separately store each data chunk of the plurality of data chunks together with one of the plurality of transformed different encryption keys, wherein the plurality of data chunks is stored on a plurality of different storage devices.

22. The computer system of claim 21 , wherein, when transforming each of the plurality of different encryption keys, the at least one hardware processor is configured to perform an all-or-nothing transform on data indicative of at least one of the plurality of different encryption keys.

23. The computer system of claim 21 , wherein, when storing the plurality of data chunks with the plurality of transformed different encryption keys, the at least one hardware processor is configured to store each of the plurality of data chunks with a respective one of the plurality of transformed different encryption keys.

24. The computer system of claim 21 , wherein, when storing the plurality of data chunks with the plurality of transformed different encryption keys, the at least one hardware processor is configured to include, with a data chunk of the plurality of data chunks, data indicative of an encryption key of the plurality of encryption keys that was used to encrypt a different data chunk of the plurality of data chunks.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1 C/O FAMILY OFFICE SOLUTIONS; O'REILLY, COLIN; COOPER ROAD LLC.; COYDOG FOUNDATION C/O FAMILY OFFICE SOLUTIONS; DASA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; LAKOFF, DAVID E.; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C.; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JOR, GERALD R, JR.; GRANDPRIX LIMITED C/O LOEB BLOCK & PARTNERS L.P.; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC.; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M.; MERCER, ROBERT; ROLA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC.; BARTON, WESLEY W.; ZUG VENTURES LLC C/O KATHY COOK, FUSION GROUP; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
To: SECURITY FIRST CORP.
Reel/Frame 061578/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: SECURITY FIRST CORP
To: SECURITY FIRST INNOVATIONS, LLC
Reel/Frame 061262/0865 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 11, 2018
From: ORSINI, RICK L.; O'HARE, MARK S.; DAVENPORT, ROGER; WINICK, STEVEN
To: SECURITY FIRST CORP.
Reel/Frame 045783/0985 →
Continuity (6)
Continuation 13915081 · Jun 11, 2013
Division 13468383 · May 10, 2012
Continuation 11258839 · Oct 25, 2005
Provisional Application 60718185 · Sep 16, 2005
Provisional Application 60622146 · Oct 25, 2004
Related Publication 20180367509A1 · Dec 20, 2018
Cited By (1)
US 12,476,946