IP Library Granted Patent US 10,574,456
Granted Patent B2
US 10,574,456 · App. 16/182,554 · Granted Feb 25, 2020

Encrypted file storage

Inventors: Erich Stuntebeck (Marietta, GA); Ramani Panchapakesan (Bangalore, IN); Akshay Laxminarayan (Atlanta, GA); Kumar Ashish (Bangalore, IN)
Assignee: VMware, Inc.
H04L9/0894G06F16/13G06F16/16G06F16/1727G06F16/182G06F16/185G06F21/602G06F21/6209G06F21/6218H04L9/14H04L63/0428H04L67/1097H04L67/303G06F8/61
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,574,456
App. No.
16/182,554
Granted
Feb 25, 2020
Kind
B2
Abstract

Various systems facilitate encrypted file storage. A client device may generate an encrypted version of a file. The client device may obtain at least one reference to at least one storage location for the encrypted version of the file. The client device may cause the encrypted version of the file to be store at the at least one storage location using the at least one reference to the at least one storage location.

Claims (87)

1. A method of storing files comprising:

sending, to an index server from a client device, a request to store a first file on behalf of a user of the client device, the user associated with access credentials of a user account of a cloud data storage provider;

receiving, by the client device from the index server, a first storage location and a second storage location associated with the user account for the first file at the cloud data storage provider, the first and second storage locations being different than the index server;

partitioning, by a file management application at the client device, the first file into first and second portions;

encrypting the first and second portions based on a first and second encryption keys;

sending an encrypted version of the first portion to the first storage location at the cloud data storage provider, wherein the first encryption key is stored by the index server corresponding to the first storage location; and

sending an encrypted version of the second portion to the second storage location at the cloud data storage provider, wherein the second encryption key is stored by the index server corresponding to the second storage location.

2. The method of claim 1 , further comprising:

sending, to the index server, a request from the client device to access the first file;

receiving, from the index server, the first and second locations for retrieving the first and second encrypted portions, respectively; and

obtaining at least one of the first and second encrypted portions by transmitting access credentials to the cloud storage provider.

3. The method of claim 2 , further comprising:

receiving multiple keys, including a first key, at the client device in response to the request to access the first file; and

decrypting the first and second encrypted portions using the multiple keys.

4. The method of claim 1 , further comprising:

transmitting a first key to the index server from the client device;

requesting, by the client device, access to the file; and

receiving a version of the first key for decrypting the first encrypted portion.

5. The method of claim 1 , further comprising:

deleting, by the file management application, a first key from the client device after the encrypting the first portion using the first key.

6. The method of claim 1 , further comprising:

sending, from the client device to the index server, a request to store a second file;

receiving a third storage location unassociated with the cloud data storage provider, wherein the second storage location is at the index server;

encrypting the second file based on a key associated with the third storage location; and

sending, from the client device, the encrypted second file to the third storage location using access credentials associated with the third storage location.

7. The method of claim 1 , further comprising:

requesting access to the first file;

receiving, from the index server, the first and second storage locations;

receiving, from the index server, a first key for decrypting the first portion and a second key for decrypting the second portion; and

combining the first and second portions, by the file management application, to provide access to the first file.

8. A system for storing files, comprising:

a non-transitory, computer-readable medium containing instructions; and

a hardware processor that executes the instructions for a file management service at a client device to perform stages comprising:

sending, to an index server from the client device, a request to store a first file on behalf of a user of the client device, the user associated with access credentials of a user account of a cloud data storage provider;

receiving, by the client device from the index server, a first storage location and a second storage location associated with the user account for the first file at the cloud data storage provider, the first and second locations being different than the index server;

partitioning, by the file management service at the client device, the first file into first and second portions;

encrypting the first and second portions based on a first and second encryption keys;

sending an encrypted version of the first portion to the first storage location at the cloud data storage provider, wherein the first encryption key is stored by the index server corresponding to the first storage location; and

sending an encrypted version of the second portion to the second storage location at the cloud data storage provider, wherein the second encryption key is stored by the index server corresponding to the second storage location.

9. The system of claim 8 , the stages further comprising:

sending, to the index server, a request from the client device to access the first file;

receiving, from the index server, the first and second locations for retrieving the first and second encrypted portions, respectively; and

obtaining at least one of the first and second encrypted portions by transmitting access credentials to the cloud storage provider.

10. The system of claim 9 , the stages further comprising:

receiving multiple keys, including a first key, at the client device in response to the request to access the first file; and

decrypting the first and second encrypted portions using the multiple keys.

11. The system of claim 8 , the stages further comprising:

transmitting a first key to the index server from the client device;

requesting, by the client device, access to the file; and

receiving a version of the first key for decrypting the first encrypted portion.

12. The system of claim 8 , the stages further comprising:

deleting, by the file management service, a first key from the client device after the encrypting the first portion using the first key.

13. The system of claim 8 , the stages further comprising:

sending, from the client device to the index server, a request to store a second file;

receiving a third storage location unassociated with the cloud data storage provider, wherein the second storage location is at the index server;

encrypting the second file based on a key associated with the third storage location; and

sending, from the client device, the encrypted second file to the third storage location using access credentials associated with the third storage location.

14. The system of claim 8 , the stages further comprising:

requesting access to the first file;

receiving, from the index server, the first and second storage locations;

receiving, from the index server, a first key for decrypting the first portion and a second key for decrypting the second portion; and

combining the first and second portions, by the file management service, to provide access to the first file.

15. A non-transitory, computer-readable medium containing instructions for a file management service of a client device, the instructions being executed by a hardware processor to perform stages comprising:

sending, to an index server from a client device, a request to store a first file on behalf of a user of the client device, the user associated with access credentials of a user account of a cloud data storage provider;

receiving, by the client device from the index server, a first storage location and a second storage location associated with the user account for the first file at the cloud data storage provider, the first and second storage locations being different than the index server;

partitioning, by the file management service of the client device, the first file into first and second portions;

encrypting the first and second portions based on a first and second encryption keys;

sending an encrypted version of the first portion to the first storage location at the cloud data storage provider, wherein the first encryption key is stored by the index server corresponding to the first storage location; and

sending an encrypted version of the second portion to the second storage location at the cloud data storage provider, wherein the second encryption key is stored by the index server corresponding to the second storage location.

16. The non-transitory, computer-readable medium of claim 15 , further comprising:

sending, to the index server, a request from the client device to access the first file;

receiving, from the index server, the first and second locations for retrieving the first and second encrypted portions, respectively; and

obtaining at least one of the first and second encrypted portions by transmitting access credentials to the cloud storage provider.

17. The non-transitory, computer-readable medium of claim 16 , further comprising:

receiving multiple keys, including a first key, at the client device in response to the request to access the first file; and

decrypting the first and second encrypted portions using the multiple keys.

18. The non-transitory, computer-readable medium of claim 15 , further comprising:

transmitting a first key to the index server from the client device;

requesting, by the client device, access to the file; and

receiving a version of the first key for decrypting the first encrypted portion.

19. The non-transitory, computer-readable medium of claim 15 , further comprising:

deleting, by the file management service, a first key from the client device after the encrypting the first portion using the first key.

20. The non-transitory, computer-readable medium of claim 15 , further comprising:

sending, from the client device to the index server, a request to store a second file;

receiving a third storage location unassociated with the cloud data storage provider, wherein the second storage location is at the index server;

encrypting the second file based on a key associated with the third storage location; and

sending, from the client device, the encrypted second file to the third storage location using access credentials associated with the third storage location.

Assignments (5)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2024
From: AIRWATCH LLC
To: VMWARE, INC.
Reel/Frame 067879/0157 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2024
From: STUNTEBECK, ERICH; PANCHAPAKESAN, RAMANI; LAXMINARAYAN, AKSHAY; ASHISH, KUMAR
To: AIRWATCH LLC
Reel/Frame 068063/0528 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
Continuity (5)
Continuation 15804861 · Nov 6, 2017
Continuation 15439375 · Feb 22, 2017
Continuation 15055847 · Feb 29, 2016
Continuation 14727909 · Jun 2, 2015
Related Publication 20190074967A1 · Mar 7, 2019