IP Library Granted Patent US 11,636,217
Granted Patent B2
US 11,636,217 · App. 17/211,919 · Granted Apr 25, 2023

Systems and methods for breach-proof, resilient, compliant data in a multi-vendor cloud environment and automatically self heals in the event of a ransomware attack

Inventor: Paul Lewis (Asbury, NJ)
Assignee: CALAMU TECHNOLOGIES CORPORATION
G06F21/602G06F3/062G06F3/064G06F3/067G06F21/6218H04L9/0819H04L9/0861H04L9/14H04L9/3226H04L63/0428H04L63/08G06F2221/2107H04L67/1097
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,636,217
App. No.
17/211,919
Granted
Apr 25, 2023
Kind
B2
Abstract

A cloud-based system for securely storing data, the system having a processor which obtains a source data file; splits it into at least three fragments; and uses an encryption key associated with the fragments to encrypt the fragments and distributes the encrypted fragments among at least three cloud storage providers, creates a pointer file containing information for retrieving the encrypted fragments. When a system user requests access to the data, the system uses the information stored in the pointer file to retrieve the stored encrypted fragments from the plurality of clouds; decrypts the fragments and reconstructs the data, and provides data access to the system user.

Claims (43)

1. A cloud-based system for securely storing data, comprising:

a processor coupled to memory configured to:

obtain original data from a client storage device;

split the original data into at least three data blocks;

encrypt the data blocks using an encryption key associated with the data blocks; and

write the encrypted data blocks across at least three cloud storage providers, each cloud storage provider located in a different physical location, each of the encrypted data blocks written to at least two but less than all of the cloud storage providers, whereby there is no single cloud storage provider to which all of the encrypted data blocks are written; such that if any one cloud storage provider is unavailable, the encrypted data blocks stored thereon may be retrieved from at least one other cloud storage provider; and in the case any one of the cloud storage providers is compromised, the original data cannot be recovered from the encrypted data blocks stored in that cloud storage provider alone;

create a pointer file containing locations of each of the encrypted data blocks in every cloud storage provider in which they were written;

store the pointer file in the client storage device; and

delete the original data from the client storage device;

the processor further configured to thereafter:

detect a condition in one of the clouds that renders it abnormal and unusable;

abandon the abnormal cloud;

establish a new cloud to replace the abnormal cloud;

use the pointer file to:

identify encrypted block fragments that were stored in the abnormal cloud; and

locate at least one normal cloud in which each of the identified encrypted block fragments is stored;

copy the identified encrypted block fragments from the located normal clouds to the established new cloud; and

update the pointer file by replacing information contained therein of encrypted block fragments that were stored in the abnormal cloud, with information of corresponding encrypted block fragments stored in the established new cloud.

2. The system as recited in claim 1 , wherein the processor is further configured to thereafter:

obtain encrypted block storage information from the pointer file;

retrieve the encrypted blocks using the storage information; and

decrypt and reassemble the retrieved encrypted blocks as the original data.

3. A computer implemented method for secure storage of data, comprising causing a processor to complete steps including:

obtaining original data from a client storage device;

splitting the original data into at least three data blocks;

encrypting the data blocks using an encryption key associated with the data blocks;

writing the encrypted data blocks across at least three cloud storage providers, each cloud storage provider located in a different physical location, each of the encrypted data blocks written to at least two but less than all of the cloud storage providers, whereby there is no single cloud storage provider to which all of the encrypted data blocks are written; such that if any one cloud storage provider is unavailable, the encrypted data blocks stored thereon may be retrieved from at least one other cloud storage provider; and in the case any one of the cloud storage providers is compromised, the original data cannot be recovered from the encrypted data blocks stored in that cloud storage provider alone;

creating a pointer file containing locations of the encrypted data blocks in every cloud storage provider to which each of the encrypted data blocks was written;

storing the pointer file in the client storage device;

deleting the original data from the client storage device;

and-thereafter:

detecting a condition in one of the clouds that renders it abnormal and unusable;

abandoning the abnormal cloud;

establishing a new cloud to replace the abnormal cloud;

using the pointer file to:

identify the encrypted block fragments that were stored in the abnormal cloud; and

locate at least one normal cloud in which each of the identified encrypted block fragments is stored;

copying the identified encrypted block fragments from the located normal clouds to the established new cloud; and

updating the pointer file by replacing information contained therein of encrypted block fragments that were stored in the abnormal cloud, with information of corresponding encrypted block fragments stored in the established new cloud.

4. The method as recited in claim 3 , further comprising:

obtaining encrypted block storage information from the pointer file;

retrieving the encrypted blocks using the storage information; and

decrypting and reassembling the retrieved encrypted blocks as the original data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2021
From: LEWIS, PAUL
To: CALAMU TECHNOLOGIES CORPORATION
Reel/Frame 055710/0527 →
Continuity (5)
Continuation In Part 16261720 · Jan 30, 2019
Continuation In Part 16055587 · Aug 6, 2018
Continuation 15226237 · Aug 2, 2016
Continuation In Part 14251612 · Jun 30, 2014
Related Publication 20210286884A1 · Sep 16, 2021
Cited By (1)
US 12,499,248