IP Library › Granted Patent US 10,637,833
Granted Patent B2
US 10,637,833 · App. 15/025,815 · Granted Apr 28, 2020

Method and system for secure data sharing

Inventors: Chen Li Tien (Richmond Hill, CA); Joseph Mari Villamor Ocol (Milton, CA); Deepu Filji (Toronto, CA); Cristian Sebastian Niculescu (Toronto, CA); Ivan Canute Serrao (Toronto, CA); Christian George Batty (Scarborough, CA); Nandini Jolly (Toronto, CA)
Assignee: CRYPTOMILL INC.
H04L63/0428G06F21/6218H04L9/0822H04L63/061H04L63/062G06F2221/2127
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,637,833
App. No.
15/025,815
Granted
Apr 28, 2020
Kind
B2
Abstract

A method of protecting data is disclosed herein. The method comprises: encrypting a data in a protected data item using a first encryption key; and encrypting the first encryption key in the protected data item using a second encryption key that is unique to the protected data item, wherein the unique second encryption key is derived from a third encryption key in the protected data item and to a plurality of protected data items comprising a common characteristic shared with the protected data item.

Claims (22)

1. A method of protecting data, the method comprising:

encrypting a data in a protected data item using a first encryption key, the protected data item being associated with a trust boundary, where one or more other protection data items may also be associated with the trust boundary, the data encrypted in the protected data item being accessible to a defined set of users associated with the trust boundary by using a third encryption key and being inaccessible to users not associated with the trust boundary, the third encryption key being uniquely associated with the trust boundary; and

encrypting the first encryption key in the protected data item using a second encryption key that is unique to the protected data item,

wherein the unique second encryption key is derived from the third encryption key, and prior to encrypting the first encryption key, receiving the third encryption key at a computing device, associated with a user in the defined set of users associated with the trust boundary, from another computing device.

2. The method of claim 1 , wherein the unique second encryption key is derived from both the third encryption key and a cryptographic salt that is randomly generated from the protected data item.

3. The method of claim 1 , wherein the data is encrypted to a payload portion of the protected data item.

4. The method of claim 1 , wherein the first encryption key is encrypted to a header portion of the protected data item.

5. The method of claim 1 , wherein the data comprises a file.

6. The method of claim 1 , wherein the data comprises a document.

7. The method of claim 1 , wherein the data comprises a folder.

8. The method of claim 7 , wherein the data further comprises the contents of the folder.

9. The method of claim 1 , wherein the data comprises files, documents, or folders.

10. A system for protecting data, the system comprising:

a computer processor in combination with an encryption component for encrypting a data in a protected data item using a first encryption key, the protected data item being associated with a trust boundary, where one or more other protection data items may also be associated with the trust boundary, the data encrypted in the protected data item being accessible to a defined set of users associated with the trust boundary by using a third encryption key and being inaccessible to users not associated with the trust boundary, the third encryption key being uniquely associated with the trust boundary, and the processor and encryption component for encrypting the first encryption key in the protected data item using a second encryption key that is unique to the protected data item,

wherein the unique second encryption key is derived from the third encryption key, and a computing device, associated with a user in the defined set of users associated with the trust boundary, comprises the computer processor, and the computer processor is configured to receive from another computing device, prior to encrypting the first encryption key, the third encryption key.

11. The system of claim 10 , wherein the unique second encryption key is derived from both the third encryption key and a cryptographic salt that is randomly generated from the protected data item.

12. The system of claim 10 , wherein the data is encrypted to a payload portion of the protected data item.

13. The system of claim 10 , wherein the data comprises a file.

14. The system of claim 10 , wherein the data comprises a document.

15. The system of claim 10 , wherein the data comprises a folder.

16. The system of claim 13 , wherein the data further comprises the contents of the folder.

17. The system of claim 10 , wherein the data comprises files, documents, or folders.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2020
From: TIEN, CHEN LI; OCOL, JOSEPH MARI VILLAMOR; FILJI, DEEPU; NICULESCU, CRISTIAN SEBASTIAN; SERRAO, CANUTE IVAN; BATTY, CHRISTIAN GEORGE; JOLLY, NANDINI
To: CRYPTOMILL INC.
Reel/Frame 052282/0549 →
Continuity (2)
Provisional Application 61884359 · Sep 30, 2013
Related Publication 20160241522A1 · Aug 18, 2016