IP Library Granted Patent US 10,452,854
Granted Patent B2
US 10,452,854 · App. 16/127,077 · Granted Oct 22, 2019

Secure data parser method and system

Inventors: Mark S. O'Hare (Coto De Caza, CA); Rick L. Orsini (Flower Mound, TX); Roger S. Davenport (Campbell, TX); Steven Winick (Roslyn Heights, NY)
Assignee: Security First Corp.
G06F21/62H04L9/085H04L9/3231H04L9/3247H04L63/0428H04L2209/56H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,452,854
App. No.
16/127,077
Granted
Oct 22, 2019
Kind
B2
Abstract

A secure data parser is provided that may be integrated into any suitable system for securely storing and communicating data. The secure data parser parses data and then splits the data into multiple portions that are stored or communicated distinctly. Encryption of the original data, the portions of data, or both may be employed for additional security. The secure data parser may be used to protect data in motion by splitting original data into portions of data, that may be communicated using multiple communications paths.

Claims (39)

1. A method for securely storing a data set, the method comprising:

receiving an external key from an external storage system,

generating a plurality of data chunks based on the data set, such that the data set can be reconstructed using at least a minimum number of the plurality of data chunks, wherein generating the data chunks comprises:

distributing the data set into a plurality of shares, wherein each of the shares comprises less than all of the data set,

accessing a plurality of distinct encryption keys,

encrypting each of the shares with a respective one of the plurality of distinct encryption keys,

performing an encryption operation based on the external key to further secure the plurality of data chunks; and

storing with the plurality of data chunks data indicative of at least one of the distinct encryption keys on a plurality of different storage devices.

2. The method of claim 1 , wherein storing with the plurality of data chunks data indicative of at least one of the distinct encryption keys comprises storing each of the plurality of data chunks with at least one of the distinct encryption keys.

3. The method of claim 1 , wherein storing each of the plurality of data chunks with at least one of the distinct encryption keys comprises including with a particular data chunk of the plurality of data chunks data indicative of an encryption key that was used to encrypt a different data chunk of the plurality of data chunks.

4. The method of claim 1 , wherein distributing the data set into a plurality of shares comprises using a random technique or pseudorandom technique.

5. The method of claim 1 , wherein distributing the data set into a plurality of shares comprises using a deterministic technique or pseudorandom technique.

6. The method of claim 1 , wherein each share of the plurality of shares comprises a substantially random distribution of a subset of the data set.

7. The method of claim 1 , wherein performing an encryption operation based on the external key to further secure the plurality of data chunks comprises encrypting primary data with the external key.

8. The method of claim 1 , wherein distributing the data set into a plurality of shares comprises:

generating a split encryption key based on the external key; and

distributing the data set based on the split encryption key.

9. The method of claim 8 , further comprising encrypting each of the shares with the external key.

10. The method of claim 9 , wherein the data set is recoverable using at least a minimum number of the plurality of data chunks and the external key.

11. A computer system for securing a data set, the system comprising:

at least one hardware processor, configured to:

receive an external key from an external storage system,

generate a plurality of data chunks based on the data set, such that the data set can be reconstructed using at least a minimum number of the plurality of data chunks, wherein generating the data chunks comprises:

distributing the data set into a plurality of shares, wherein each of the shares comprises less than all of the data set,

accessing a plurality of distinct encryption keys, and

encrypting each of the shares with a respective one of the plurality of distinct encryption keys,

performing an encryption operation based on the external key to further secure the plurality of data chunks; and

store with the plurality of data chunks data indicative of at least one of the distinct encryption keys on a plurality of different storage devices.

12. The computer system of claim 11 , wherein while storing with the plurality of data chunks data indicative of at least one of the distinct encryption keys, the at least one hardware processor is configured to store each of the plurality of data chunks with at least one of the distinct encryption keys.

13. The computer system of claim 11 , wherein while storing each of the plurality of data chunks with at least one of the distinct encryption keys, the at least one hardware processor is configured to include, with a particular data chunks of the plurality of data chunks, data indicative of an encryption key that was used to encrypt a different data chunk of the plurality of data chunks.

14. The computer system of claim 11 , wherein when distributing the data set into a plurality of shares, the at least one hardware processor is configured to use a random technique or pseudorandom technique.

15. The computer system of claim 11 , wherein when distributing the data set into a plurality of shares, the at least one hardware processor is configured to use a deterministic technique or pseudorandom technique.

16. The computer system of claim 11 , wherein each share of the plurality of shares comprises a substantially random distribution of a subset of the data set.

17. The computer system of claim 11 , wherein, when performing an encryption operation based on the external key to further secure the plurality of data chunks, the at least one hardware processor is configured to encrypt primary data with the external key.

18. The computer system of claim 11 , wherein when distributing the data set into a plurality of shares, the at least one hardware processor is configured to:

generate a split encryption key based on the external key; and

distribute the data set based on the split encryption key.

19. The computer system of claim 18 , wherein the data set is recoverable using at least a minimum number of the plurality of data chunks and the external key.

20. The computer system of claim 19 , wherein the data set can be reconstructed using at least two of the plurality of data chunks and the key received from the external storage system.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1 C/O FAMILY OFFICE SOLUTIONS; O'REILLY, COLIN; COOPER ROAD LLC.; COYDOG FOUNDATION C/O FAMILY OFFICE SOLUTIONS; DASA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; LAKOFF, DAVID E.; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C.; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JOR, GERALD R, JR.; GRANDPRIX LIMITED C/O LOEB BLOCK & PARTNERS L.P.; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC.; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M.; MERCER, ROBERT; ROLA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC.; BARTON, WESLEY W.; ZUG VENTURES LLC C/O KATHY COOK, FUSION GROUP; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
To: SECURITY FIRST CORP.
Reel/Frame 061578/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: SECURITY FIRST CORP
To: SECURITY FIRST INNOVATIONS, LLC
Reel/Frame 061262/0865 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2019
From: O'HARE, MARK; ORSINI, RICK; DAVENPORT, ROGER; WINICK, STEVEN
To: SECURITY FIRST CORP.
Reel/Frame 049184/0302 →
Cited By (4)
US 12,381,857 US 12,406,258 US 12,517,661 US 12,671,583