IP Library Granted Patent US 11,218,312
Granted Patent B2
US 11,218,312 · App. 16/587,847 · Granted Jan 4, 2022

Secure file sharing method and system

Inventors: Mark S. O'Hare (Coto De Caza, CA); Rick L. Orsini (Flower Mound, TX); Don Martin (Chesterfield, VA)
Assignee: Security First Corp.
H04L9/321G06F21/31G06F21/32G06F21/33G06F21/606G06F21/6209G06F21/6218G06F21/645G06Q40/08H04L9/085H04L9/0822H04L9/0825H04L9/0894H04L9/3231H04L9/3247H04L63/0428H04L67/1097G06F2221/2107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,218,312
App. No.
16/587,847
Granted
Jan 4, 2022
Kind
B2
Abstract

Systems and methods are provided for securely sharing data. A processor forms two or more shares of a data set encrypted with a symmetric key, the data set associated with a first user device, and causes the encrypted data set shares to be stored separately from each other in at least one remote storage location. The processor generates first and second encrypted keys by encrypting data indicative of the symmetric key with a first asymmetric key of first and second asymmetric key pairs associated with the first user device and a second user device, respectively, and causes the encrypted key to be stored in the at least one storage location. To restore the data set, a predetermined number of the two or more encrypted data set shares and at least one of the second asymmetric keys of the first and second asymmetric key pairs are needed.

Claims (31)

1. A method for secure storage, the method comprising:

accessing, using at least one hardware processor, data that is encrypted by a cryptographic key;

generating first encrypted key data by encrypting data indicative of the cryptographic key with a first key-encryption key;

generating second encrypted key data by encrypting data indicative of the cryptographic key with a second key-encryption key,

generating a plurality of shares, where a least one of the plurality of shares comprises a portion of the first encrypted key data and a portion of the second encrypted key data, wherein the data indicative of the cryptographic key is restorable from a minimum number of the two or more plurality of shares; and

storing the plurality of shares of the plurality of shares separately in at least one storage location.

2. The method of claim 1 , wherein the cryptographic key is selected from a group consisting of a split key, an encryption key, a session key, a workgroup key, a symmetric key, and an asymmetric key.

3. The method of claim 1 , wherein the minimum number is all of shares of the plurality of shares.

4. The method of claim 1 , wherein the minimum number is fewer than all of the shares of the plurality of shares.

5. The method of claim 1 , wherein the first key-encryption key is associated with a first user device, the second key-encryption key is associated with a second user device, and the data is associated with the first user device.

6. The method of claim 1 , wherein storing the plurality of shares comprises storing at least one share in a cloud computing storage location.

7. The method of claim 1 , wherein storing the plurality of shares comprises storing at least one share on a user device.

8. The method of claim 1 , wherein generating the plurality of shares comprises generating at least one share using a substantially random technique.

9. The method of claim 1 , wherein generating the plurality of shares comprises generating at least one share using a deterministic technique.

10. The method of claim 1 , wherein generating the plurality of shares comprises shuffling the data from an original order.

11. A computer system for securely a data set, comprising:

at least one hardware processor, configured to:

access, using at least one hardware processor, data that is encrypted by a cryptographic key;

generate first encrypted key data by encrypting data indicative of the cryptographic key with a first key-encryption key;

generate second encrypted key data by encrypting data indicative of the cryptographic key with a second key-encryption key;

generate a plurality of shares, where a least one of the plurality of shares comprises: a portion of the first encrypted key data and a portion of the second encrypted key data, wherein the data indicative of the cryptographic key is restorable from a minimum number of the two or more plurality of shares; and

store the plurality of shares of the plurality of shares separately in at least one storage location.

12. The computer system of claim 11 , wherein the at least one hardware processor is configured to select the cryptographic key is from a group consisting of a split key, an encryption key, a session key, a workgroup key, a symmetric key, and an asymmetric key.

13. The computer system of claim 11 , wherein the minimum number is all of the shares of the plurality of shares.

14. The system of claim 11 , wherein the minimum number is fewer than all of the shares of the plurality of shares.

15. The computer system of claim 11 , wherein the first key-encryption key is associated with a first user device, the second key-encryption key is associated with a second user device, and the dataset is associated with the first user device.

16. The computer system of claim 11 , wherein, when storing the plurality of shares, the at least one hardware processor is configured to store at least one share in a cloud computing storage location.

17. The computer system of claim 11 , wherein, when storing the plurality of shares, the at least one hardware processor is configured to store at least one share on a user device.

18. The computer system of claim 11 , wherein, when generating the plurality of shares, the at least one hardware processor is configured to generate at least one share using a substantially random technique.

19. The computer system of claim 11 , wherein, when generating the plurality of shares, the at least one hardware processor is configured to shuffle the dataset from an original order.

20. The computer system of claim 11 , wherein, when generating the plurality of shares, the at least one hardware processor is configured to shuffle the dataset from an original order.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1 C/O FAMILY OFFICE SOLUTIONS; O'REILLY, COLIN; COOPER ROAD LLC.; COYDOG FOUNDATION C/O FAMILY OFFICE SOLUTIONS; DASA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; LAKOFF, DAVID E.; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C.; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JOR, GERALD R, JR.; GRANDPRIX LIMITED C/O LOEB BLOCK & PARTNERS L.P.; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC.; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M.; MERCER, ROBERT; ROLA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC.; BARTON, WESLEY W.; ZUG VENTURES LLC C/O KATHY COOK, FUSION GROUP; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
To: SECURITY FIRST CORP.
Reel/Frame 061578/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: SECURITY FIRST CORP
To: SECURITY FIRST INNOVATIONS, LLC
Reel/Frame 061262/0865 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2020
From: O'HARE, MARK S.; ORSINI, RICK L.; MARTIN, DON
To: SECURITY FIRST CORP.
Reel/Frame 052697/0601 →
Continuity (5)
Continuation 16036749 · Jul 16, 2018
Continuation 14749172 · Jun 24, 2015
Continuation 13413195 · Mar 6, 2012
Provisional Application 61450110 · Mar 7, 2011
Related Publication 20200274711A1 · Aug 27, 2020