IP Library Granted Patent US 9,614,684
Granted Patent B2
US 9,614,684 · App. 15/151,864 · Granted Apr 4, 2017

External indexing and search for a secure cloud collaboration system

Inventor: Shaun Cooley (El Segundo, CA)
Assignee: Cisco Technology, Inc.
H04L9/3263G06F17/3048G06F17/30371G06F17/30864G06F17/30867H04L9/14H04L9/30H04L63/0428H04L63/06H04L63/061H04L67/1097
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,614,684
App. No.
15/151,864
Granted
Apr 4, 2017
Kind
B2
Abstract

An end-to-end secure cloud-hosted collaboration service is provided with a hybrid cloud/on-premise index and search capability. This approach includes on-premise indexing and search handling, while relying on the cloud for persistent storage and search of the index. The on-premise indexer receives a copy of an encrypted message from the cloud-hosted collaboration service. The encrypted message has been encrypted with a conversation key. The indexer receives the conversation key from an on-premise key management service, and decrypts the encrypted message with the conversation key. A set of tokens are extracted from the decrypted message, and subsequently encrypted with a secret key, different than the conversation key, to generate a first set of encrypted tokens. The first set of encrypted tokens is transmitted for storage in a search index on the cloud-hosted collaboration service.

Claims (52)

1. A method comprising:

at a collaboration server, facilitating a collaboration session comprising a plurality of encrypted messages without decrypting the plurality of encrypted messages;

storing the plurality of encrypted messages in association with a conversation identifier;

transmitting a copy of the plurality of encrypted messages and the conversation identifier over a network to a search indexer;

receiving, from the search indexer, a first set of encrypted tokens associated with the conversation identifier; and

storing the first set of encrypted tokens in an index in association with the conversation identifier.

2. The method of claim 1 , further comprising:

receiving over the network a second set of encrypted tokens from a search handler;

comparing the second set of encrypted tokens to the index, and

if at least one of the second set of encrypted tokens matches at least one of the first set of encrypted tokens, transmitting the conversation identifier to the search handler.

3. The method of claim 2 , further comprising transmitting the plurality of encrypted messages associated with the conversation identifier to the search handler.

4. The method of claim 1 , wherein the first set of encrypted tokens and the second set of encrypted tokens comprise a plurality of hash-based message authentication codes (HMACs).

5. The method of claim 1 , wherein facilitating the collaboration session comprises:

receiving an initiation message for the collaboration session;

sending a notification of the collaboration session to an on-premise key management service, the notification instructing the on-premise key management service to generate a conversation key for the collaboration session.

6. The method of claim 1 , wherein storing the plurality of encrypted messages comprises locally caching the plurality of encrypted messages.

7. The method of claim 1 , wherein storing the plurality of encrypted messages comprises archiving the plurality of encrypted messages in a cloud-based storage archive.

8. An apparatus comprising:

a network interface unit configured to enable communications over a network between a plurality of clients of a collaboration session, the collaboration session comprising a plurality of encrypted messages; and

a processor configured to:

facilitate the collaboration session without decrypting the plurality of encrypted messages;

store the plurality of encrypted messages in association with a conversation identifier;

transmit, via the network interface unit, a copy of the plurality of encrypted messages and the conversation identifier to a search indexer;

receive from the search indexer, via the network interface unit, a first set of encrypted tokens associated with the conversation identifier; and

store the first set of encrypted tokens in an index in association with the conversation identifier.

9. The apparatus of claim 8 , wherein the processor is further configured to:

receive, via the network interface unit, a second set of encrypted tokens from a search handler;

compare the second set of encrypted tokens to the index, and

if at least one of the second set of encrypted tokens matches at least one of the first set of encrypted tokens, cause the network interface unit to transmit the conversation identifier to the search handler.

10. The apparatus of claim 9 , wherein the processor is further configured to transmit, via the network interface unit, the plurality of encrypted messages associated with the conversation identifier to the search handler.

11. The apparatus of claim 8 , wherein the first set of encrypted tokens and the second set of encrypted tokens comprise a plurality of hash-based message authentication codes (HMACs).

12. The apparatus of claim 8 , wherein the processor is configured to facilitate the collaboration session by:

receiving, via the network interface unit, an initiation message for the collaboration session;

cause the network interface unit to send a notification of the collaboration session to an on-premise key management service, the notification instructing the on-premise key management service to generate a conversation key for the collaboration session.

13. The apparatus of claim 8 , wherein the processor is configured to store the plurality of encrypted messages by locally caching the plurality of encrypted messages.

14. The apparatus of claim 8 , wherein the processor is configured to store the plurality of encrypted messages by archiving the plurality of encrypted messages in a cloud-based storage archive.

15. One or more non-transitory computer readable storage media encoded with software comprising executable instructions and when the software is executed operable to cause a processor to:

facilitate a collaboration session comprising a plurality of encrypted messages without decrypting the plurality of encrypted messages;

store the plurality of encrypted messages in association with a conversation identifier;

transmit a copy of the plurality of encrypted messages and the conversation identifier over a network to a search indexer;

receive, from the search indexer, a first set of encrypted tokens associated with the conversation identifier; and

store the first set of encrypted tokens in an index in association with the conversation identifier.

16. The computer readable media of claim 15 , further comprising instructions operable to cause the processor to:

receive a second set of encrypted tokens from a search handler;

compare the second set of encrypted tokens to the index, and

if at least one of the second set of encrypted tokens matches at least one of the first set of encrypted tokens, transmit the conversation identifier to the search handler.

17. The computer readable media of claim 16 , further comprising instructions operable to cause the processor to transmit the plurality of encrypted messages associated with the conversation identifier to the search handler.

18. The computer readable media of claim 15 , further comprising instructions operable to cause the processor to facilitate the collaboration session by:

receiving an initiation message for the collaboration session;

sending a notification of the collaboration session to an on-premise key management service, the notification instructing the on-premise key management service to generate a conversation key for the collaboration session.

19. The computer readable media of claim 15 , further comprising instructions operable to cause the processor to store the plurality of encrypted messages by locally caching the plurality of encrypted messages.

20. The computer readable media of claim 15 , further comprising instructions operable to cause the processor to store the plurality of encrypted messages by archiving the plurality of encrypted messages in a cloud-based storage archive.

Continuity (2)
Division 14225636 · Mar 26, 2014
Related Publication 20160254917A1 · Sep 1, 2016