IP Library Granted Patent US 12,596,487
Granted Patent B2
US 12,596,487 · App. 18/701,726 · Granted Apr 7, 2026

Device and system for the secure storage of data in a distributed manner

Inventor: Hector Elbaum (Murrumbeena, AU)
Assignee: New Cloud Dynamics Pty Ltd.
G06F3/0622G06F3/0655G06F3/067
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,596,487
App. No.
18/701,726
Granted
Apr 7, 2026
Kind
B2
Abstract

A network of storage devices for encrypting and storing data is provided. A first storage device of the network comprises: a mechanism or system for authenticating a user via user interaction directly with the first storage device, a mechanism for connecting over a local connection with one or more user devices, and computer-readable memory for storing electronic data on the first storage device. The first storage device is configured to receive, over the local connection and from a first of the one or more user devices, first data for storage at the first storage device, to encrypt the first data and store the encrypted first data locally in the computer-readable memory of the first storage device; to split the encrypted first data into multiple portions; to apply a cryptographic signature to each of plural groups of one or more of the portions, the cryptographic signature enabling the first storage device to be identified and authenticated by other storage devices of a network of storage devices, to send each of the cryptographically signed groups to a respective other storage device of the network of storage devices, and to create a first record which associates the first data with the other storage devices of the network to which the cryptographically signed groups of were sent. The first storage device is further configured to, responsive to a request to access the first data, the request to access the first data resulting from a user request to access the first data provided to a user device and received at the first storage device via a local connection with the user device, retrieve the encrypted first data from the computer-readable memory, decrypt the encrypted first data, and send, over the local connection with the user device to which the user request to access the first data was provided, the decrypted first data. The first storage device is further is configured to: receive a request for transmission of previously-received, cryptographically signed second data, authenticate the request for the transmission of the previously-received, cryptographically signed second data as having originated from another storage device of the network of storage devices, and having authenticated the request for the transmission of the previously-received, cryptographically signed second data as having originated from another storage device of the network of storage devices, send the previously-received, cryptographically signed second data to the other storage device of the network of storage devices.

Claims (50)

1 . A first storage device for encrypting and storing data, comprising:

a mechanism or system for authenticating a user via user interaction directly with the first storage device;

a mechanism for connecting over a local connection with one or more user devices; and

computer-readable memory for storing electronic data on the first storage device;

wherein the first storage device is configured to:

receive, over the local connection and from a first of the one or more user devices, first data for storage at the first storage device;

encrypt the first data and store the encrypted first data locally in the computer-readable memory of the first storage device;

split the encrypted first data into multiple portions;

apply a cryptographic signature to each of plural groups of one or more of the portions, the cryptographic signature enabling the first storage device to be identified and authenticated by other storage devices of a network of storage devices;

send each of the cryptographically signed groups to a respective other storage device of the network of storage devices; and

create a first record which associates the first data with the other storage devices of the network to which the cryptographically signed groups of were sent;

wherein the first storage device is further configured to, responsive to a request to access the first data, the request to access the first data resulting from a user request to access the first data provided to a user device and received at the first storage device via a local connection with the user device:

retrieve the encrypted first data from the computer-readable memory,

decrypt the encrypted first data, and

send, over the local connection with the user device to which the user request to access the first data was provided, the decrypted first data; and

wherein the first storage device is further is configured to:

receive a request for transmission of previously-received, cryptographically signed second data,

authenticate the request for the transmission of the previously-received, cryptographically signed second data as having originated from another storage device of the network of storage devices, and

having authenticated the request for the transmission of the previously-received, cryptographically signed second data as having originated from another storage device of the network of storage devices, send the previously-received, cryptographically signed second data to the other storage device of the network of storage devices.

2 . The first storage device of claim 1 , wherein the storage device is further configured to:

responsive to receipt of a request to access third data, the request to access the third data resulting from a user request to access the third data provided to a user device and received at the first storage device via a local connection with the user device:

determine that the third data is not retrievable from the first storage device;

access a second record which associates the third data with other storage devices of the network to which one or more portions of the third data were previously sent;

generate a respective request to be sent to plural ones of the other storage devices identified in the second record, each of the requests being for requesting that the one or more portions of the third data, that were previously sent to the storage device for which the request is intended, be transmitted to the first storage device,

sign each request with the cryptographic signature of the first storage device to identify the first storage device and verify the authenticity of the request

send the cryptographically signed requests to the plural ones of the other storage devices.

3 . The first storage device of claim 2 , wherein the first storage device is further configured to:

receive plural groups of one or more portions of the third data from the plural ones of the other storage devices;

arrange the data of the plural groups of one or more portions of the third data and decrypt the arranged data to reproduce the third data, and

transfer, to the user device to which the user request to access the third data was provided and via the local connection with the user device to which the user request to access the third data was provided, the reproduced third data.

4 . The first storage device of claim 2 , wherein determining that the third data is not retrievable from the first storage device comprises determining that a copy of the third data previously-stored locally on the first storage device is corrupted.

5 . The first storage device of claim 2 , wherein the third data was never locally stored on the first storage device.

6 . The first storage device of claim 1 , wherein the request for transmission of previously-received, cryptographically signed second data is authenticated using a cryptographic signature received with the request for the transmission of a previously-received, cryptographically signed second data.

7 . The first storage device of claim 1 , wherein the first storage device is configured to communicate with the other storage devices of the network via a combination of a local connection with a currently connected user device and a connection of the currently connected user device with a communications network.

8 . The first storage device of claim 1 , wherein the first storage device is a portable storage device.

9 . The first storage device of claim 1 , wherein the mechanism for authenticating a user via user interaction directly with the first storage device comprises a group of buttons or other mechanical, electronic or electromagnetic switches permitting user input.

10 . The first storage device of claim 1 , wherein the mechanism for authenticating a user via user interaction directly with the first storage device comprises a biometric reader.

11 . The first storage device of claim 1 , wherein the first storage device is configured to encrypt the first data and store the encrypted first data locally in the computer-readable memory of the first storage device responsive to a successful authentication of the user via user interaction directly with the first storage device.

12 . The first storage device of claim 1 , wherein the first storage device is configured to retrieve the encrypted first data from the computer-readable memory, decrypt the encrypted first data, and send the decrypted first data over the local connection responsive to a successful authentication of the user via user interaction directly with the first storage device.

13 . The first storage device of claim 1 , wherein the first storage device is configured to send the cryptographically signed requests to the plural ones of the other storage devices responsive to a successful authentication of the user via user interaction directly with the first storage device.

14 . The first storage device of claim 1 , wherein the first storage device is configured so as not to respond to any user-derived requests unless the user has been successful authenticated via user interaction directly with the first storage device.

15 . The first storage device of claim 1 , further comprising an anti-tamper system to detect physical or electrical tampering with the device and to respond by rendering cryptographic keys, which are stored at the first storage device and are for use in decrypting data also stored on the first storage device, unusable.

16 . The first storage device of claim 1 , wherein each of the storage devices of the network of storage devices is of a same type as the first storage device.

17 . The first storage device of claim 1 , wherein each of the storage devices of the network of storage devices is a portable storage device.

18 . The first storage device of claim 1 , wherein each of the storage devices of the network of storage devices comprises:

a mechanism or system for authenticating a user via user interaction directly with the storage device;

a mechanism for connecting over a local connection with one or more user devices;

computer-readable memory for storing electronic data on the storage device; and

at least one processor configured to encrypt data prior to storage and/or transmission.

19 . The first storage device of claim 1 , further comprising a display for presenting information to the user.

Assignments (2)
CHANGE OF NAME Recorded May 5, 2025
From: NEO NEBULA PTY LTD.
To: NEW CLOUD DYNAMICS PTY LTD.
Reel/Frame 071021/0040 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2024
From: ELBAUM, HECTOR DANIEL
To: NEO NEBULA PTY LTD.
Reel/Frame 067356/0202 →
Priority Claims (2)
AU 2021254561 · Oct 19, 2021 · national
WO PCT/AU2021/051222 · Oct 20, 2021 · international
Continuity (1)
Related Publication 20250231695A1 · Jul 17, 2025
References Cited (14)
US 20100162003A1 · Dodgson · 2010 [cited by examiner]
US 20160156469A1 · Takahashi · 2016 [cited by applicant]
US 20160180102A1 · Kim · 2016 [cited by examiner]
US 20160323103A1 · Baptist et al. · 2016 [cited by applicant]
US 20170005788A1 · Irvine · 2017 [cited by examiner]
US 20170272209A1 · Yanovsky · 2017 [cited by examiner]
US 20180315044A1 · Schukai et al. · 2018 [cited by applicant]
US 20200363994A1 · Jing · 2020 [cited by applicant]
US 20200401718A1 · Hennig et al. · 2020 [cited by applicant]
CN 103959302A · 2014 [cited by examiner]
WO WO2010057194A2 · 2010 [cited by examiner]
Search Report & Written Opinion issued in PCT/AU2022/051258. (Jan. 26, 2023). [cited by applicant]
Examination Report dated Jun. 5, 2025, related Australian Application No. 2022370371, 3 pages. [cited by applicant]
Communication dated Aug. 6, 2025, related European Application No. 22882105.4, 10 pages. [cited by applicant]