IP Library Granted Patent US 11,283,595
Granted Patent B1
US 11,283,595 · App. 16/555,382 · Granted Mar 22, 2022

Systems and methods for securing cached data stored off-chain in a blockchain-based network

Inventors: Yukan Liao (Toronto, CA); Matthew Little (New York, NY); Jude Nelson (New Brunswick, NJ); Aaron Blankstein (Chicago, IL)
Assignee: Hiro Systems PBC
H04L9/0637G06F9/451G06F16/166G06F16/172G06F21/602H04L67/1097H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,283,595
App. No.
16/555,382
Granted
Mar 22, 2022
Kind
B1
Abstract

A storage server communicating with a backend storage provider, such as a cloud-based provider, performs processes for backing up encrypted data in the backend storage in a data cache shared by multiple decentralized applications, to allow a user of a frontend client to revert to a prior version of an encrypted file if that encrypted file has been compromised by one of the decentralized applications, where the storage server performs no encryption of the data and is not exposed to encryption keys.

Claims (43)

1. In a blockchain-based network, a storage server configured to communicate with a storage provider configured to store encrypted data for a plurality of decentralized applications outside of the blockchain of the blockchain-based network, the storage server comprising:

one or more network interfaces configured to couple the storage server to the storage provider and to an application client authorized to write data on behalf of a user client;

a hardware processor;

a first non-transitory computer readable storage medium configured to store resource identifiers corresponding to resources on the storage provider, the resources comprising a data cache configured to store shared data having a common data type off-chain from the blockchain, the data cache configured to store the shared data for authorized decentralized applications of the plurality of decentralized applications; and

a second non-transitory computer readable storage medium configured to store program instructions for execution by the hardware processor in order to cause the storage server to:

receive, from the application client, an access token and a first request to write a working file in the data cache by a first requesting decentralized application of the authorized decentralized applications,

read from an index file stored in a file format to determine a first indicator previously associated with the working file,

rename the working file to a renamed file based on a second indicator that is different from the first indicator, such that the renamed file is stored on the storage provider,

update the index file with the second indicator,

deny a second request to write to the renamed file on the storage provider by a second decentralized application of the authorized decentralized applications, and

write the working file in the data cache.

2. The storage server of claim 1 , wherein the renamed filed comprises an alphanumeric indicator that indicates the renamed file is a historical file.

3. The storage server of claim 1 , wherein the first indicator is a numeric indicator.

4. The storage server of claim 1 , wherein the second indicator is a numeric indicator.

5. The storage server of claim 4 , wherein the first indicator and the second indictor are sequential.

6. The storage server of claim 1 , wherein the access token is a JavaScript Object Notation (JSON) web token.

7. The storage device of claim 1 , wherein the index file retains the first indicator.

8. The storage device of claim 1 , wherein the index file is stored in the data cache.

9. A computer-implemented method comprising:

under the control of a storage server that is configured to store resource identifiers corresponding to resources on a storage provider that stores encrypted data outside of the blockchain of the blockchain-based network, the resources comprising a data cache configured to store shared data off-chain from the blockchain, the data cache configured to store the shared data for authorized decentralized applications of the plurality of decentralized applications,

receiving, from an application client, a request to write a working file in the data cache by a requesting decentralized application of the authorized decentralized applications;

reading from an index file stored in a file format to determine a first indicator previously associated with the working file;

storing, on the storage provider, a renamed file based on the working file, with a file name comprising a second indicator that is different from the first indicator;

updating the index file with the second indicator; and

writing the working file in the data cache.

10. The method of claim 9 , wherein the renamed file is stored in the data cache.

11. The method of claim 9 , wherein the renamed filed comprises an alphanumeric indicator that indicates the renamed file is a historical file.

12. The method of claim 9 , wherein the first indicator and the second indictor are sequential.

13. The method of claim 9 , wherein contents of the working file are encrypted with an encryption key known to the requesting decentralized application and not known to the storage server, and a file name of the working file is not encrypted.

14. A non-transitory, computer-readable storage medium comprising computer-executable instructions for managing encrypted data in a data cache off-chain from a blockchain on a storage provider with a storage server that locally stores no encryption keys for encrypting the encrypted data, wherein the computer-executable instructions, when executed by a computer system, cause the storage server to:

receive, from an application client, an access token, an encryption key identifier, and a first request to write a working file in the data cache by a first requesting decentralized application of the authorized decentralized applications, wherein contents of the working file are previously encrypted with the unencrypted encryption key, which is known to the requesting decentralized application and not known to the storage server, and a file name of the working file is not encrypted;

read from an index file, stored in a file format, to determine a first indicator previously associated with the working file;

rename the working file to a renamed file based on a second indicator that is different from the first indicator;

cause the renamed file to be stored on the storage provider;

update the index file with the second indicator;

cause the working file, previously encrypted with the encryption key, to be written to the data cache; and

deny a second request to write to the renamed file on the storage provider by a second decentralized application of the authorized decentralized applications.

15. The non-transitory, computer readable storage medium of claim 14 , wherein the renamed file comprises an alphanumeric indicator that indicates the renamed file is a historical file.

16. The non-transitory, computer readable storage medium of claim 14 , wherein the second indicator is a numeric indicator.

17. The non-transitory, computer readable storage medium of claim 16 , wherein the first indicator and the second indictor are sequential.

18. The non-transitory, computer readable storage medium of claim 14 , wherein the access token is a JavaScript Object Notation (JSON) web token.

19. The non-transitory, computer readable storage medium of claim 14 , wherein the index file retains the first indicator.

20. The non-transitory, computer readable storage medium of claim 14 , wherein the renamed file is stored in the data cache.

Assignments (2)
CHANGE OF NAME Recorded Jun 24, 2021
From: BLOCKSTACK PBC
To: HIRO SYSTEMS PBC
Reel/Frame 056679/0402 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2019
From: LIAO, KEN; LITTLE, MATTHEW; NELSON, JUDE; BLANKSTEIN, AARON
To: BLOCKSTACK PBC
Reel/Frame 050283/0965 →
Cited By (3)
US 12,362,918 US 12,406,019 US 12,585,736