IP Library › Granted Patent US 9,639,708
Granted Patent B2
US 9,639,708 · App. 14/829,095 · Granted May 2, 2017

Methods and systems of encrypting file system directories

Inventors: Uday Ramesh Savagaonkar (Mountain View, CA); Michael Halcrow (Mountain View, CA); Theodore Yue Tak Ts'o (Mountain View, CA); Ildar Muslukhov (Vancouver, CA)
Assignee: GOOGLE INC.
G06F21/6209G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,639,708
App. No.
14/829,095
Granted
May 2, 2017
Kind
B2
Abstract

An electronic device implements a method of encrypting directories of a file system. A processor receives a request to access a directory entry of a file system, and identifies a user who is logged into the electronic device. The processor determines whether the user has access to a directory encryption key associated with the directory entry and, if not, identifies an encrypted file name stored in the directory entry, and determines whether the encrypted file name complies with one or more naming rules. If the encrypted file name does not comply with one or more naming rules, the processor applies one or more functions to a file name associated with the encrypted file name to generate an encoded encrypted file name that complies with the one or more naming rules, and causes the encoded encrypted file name to be displayed as a representation of the directory entry.

Claims (53)

1. A method of encrypting directories of a file system on an electronic device, the method comprising:

by a processor:

receiving, from a process running on an electronic device, a request to access a directory entry of a file system;

identifying a user who is logged into the electronic device;

determining whether the user has access to a directory encryption key associated with the directory entry, and

in response to determining that the user does not have access to the directory encryption key:

identifying an encrypted file name stored in the directory entry, wherein the encrypted file name comprises an encrypted user-domain file name,

determining whether the encrypted file name complies with one or more naming rules,

in response to determining that the encrypted file name does not comply with one or more naming rules, applying one or more functions to a file name associated with the encrypted file name to generate an encoded encrypted file name that complies with the one or more naming rules and an access hash value for the directory entry,

storing the access hash value in a directory indexing structure such that it is associated with the directory entry, and

causing the encoded encrypted file name to be displayed via a user interface of the electronic device as a representation of the directory entry.

2. The method of claim 1 , wherein determining whether the encrypted file name complies with one or more naming rules comprises determining whether a length of the encrypted file name exceeds a threshold value.

3. The method of claim 1 , wherein the file system comprises an EXT4 file system.

4. The method of claim 1 , wherein identifying a user who is logged into the electronic device comprises accessing an electronic record of a user who is logged into the electronic device that is stored on the electronic device.

5. The method of claim 1 , wherein determining whether the user has access to a directory encryption key associated with the directory entry comprises accessing an electronic record to determine whether the directory entry was created by the user.

6. The method of claim 1 , wherein applying one or more functions to a file name associated with the encrypted file name to generate an encoded encrypted file name comprises:

applying a cryptographic hash to the file name to generate a first value; and

encoding the first value.

7. The method of claim 1 , wherein applying one or more functions to a file name associated with the encrypted file name to generate an encoded encrypted file name comprises:

applying a hash function to the file name to generate a first value;

concatenating the first value and at least a portion of the file name.

8. A system of encrypting directories of a file system on an electronic device, the system comprising:

an electronic device; and

a non-transitory computer-readable storage medium comprising one or more programming instructions that are configured to instruct the electronic device to:

receive, from a process running on an electronic device, a request to access a directory entry of a file system,

identify a user who is logged into the electronic device,

determine whether the user has access to a directory encryption key associated with the directory entry, and

in response to determining that the user does not have access to the directory encryption key:

identify an encrypted file name stored in the directory entry, wherein the encrypted file name comprises an encrypted user-domain file name,

determine whether the encrypted file name complies with one or more naming rules,

in response to determining that the encrypted file name does not comply with one or more naming rules, apply one or more functions to a file name associated with the encrypted file name to generate an encoded encrypted file name that complies with the one or more naming rules and an access hash value for the directory entry,

storing the access hash value in a directory indexing structure such that it is associated with the directory entry, and

cause the encoded encrypted file name to be displayed via a user interface of the electronic device as a representation of the directory entry.

9. The system of claim 8 , wherein the one or more programming instructions that are configured to instruct the electronic device to determine whether the encrypted file name complies with one or more naming rules comprise one or more programming instructions that are configured to instruct the electronic device to determine whether a length of the encrypted file name exceeds a threshold value.

10. The system of claim 8 , wherein the one or more programming instructions that are configured to instruct the electronic device to determine whether the user has access to a directory encryption key associated with the directory entry comprise one or more programming instructions that are configured to instruct the electronic device to access an electronic record to determine whether the directory entry was created by the user.

11. The system of claim 8 , wherein the one or more programming instructions that are configured to instruct the electronic device to apply one or more functions to a file name associated with the encrypted file name to generate an encoded encrypted file name comprise one or more programming instructions that are configured to instruct the electronic device to:

apply a cryptographic hash to the file name to generate a first value; and

encode the first value.

12. The system of claim 8 , wherein the one or more programming instructions that are configured to instruct the electronic device to apply one or more functions to a file name associated with the encrypted file name to generate an encoded encrypted file name comprise one or more programming instructions that are configured to instruct the electronic device to:

apply a hash function to the file name to generate a first value;

concatenate the first value and at least a portion of the file name.

13. The method of claim 1 , wherein:

receiving a request to access a directory entry of a file system comprises receiving an argument representing a file name,

applying one or more functions to a file name associated with the encrypted file name to generate an encoded encrypted file name that complies with the one or more naming rules and an access hash value for the directory entry comprises:

generating the access hash value using the argument,

using the access hash value to identify the file from the directory indexing structure, and

causing an operation to be performed on the identified file.

14. The system of claim 8 , wherein:

the one or more programming instructions that are configured to instruct the electronic device to receive a request to access a directory entry of a file system comprise one or more programming instructions that are configured to instruct the electronic device to receive an argument representing a file name of a file,

the one or more programming instructions that are configured to instruct the electronic device to apply one or more functions to a file name associated with the encrypted file name to generate an encoded encrypted file name that complies with the one or more naming rules and an access hash value for the directory entry comprise one or more programming instructions that are configured to instruct the electronic device to:

generate the access hash value using the argument,

use the access hash value to identify the file from the directory indexing structure, and

cause an operation to be performed on the identified file.

Assignments (2)
CHANGE OF NAME Recorded Oct 2, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044097/0658 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2015
From: SAVAGAONKAR, UDAY RAMESH; HALCROW, MICHAEL; TS'O, THEODORE YUE TAK; MUSLUKHOV, ILDAR
To: GOOGLE INC.
Reel/Frame 036350/0756 →
Continuity (1)
Related Publication 20170053125A1 · Feb 23, 2017