IP Library › Granted Patent US 10,721,062
Granted Patent B2
US 10,721,062 · App. 15/329,997 · Granted Jul 21, 2020

Utilizing error correction for secure secret sharing

Inventors: Liqun Chen (Long Down Avenue, GB); Peter Thomas Camble (Stoke Gifford Bristol Avon, GB); Mark Robert Watkins (Stoke Gifford Bristol Avon, GB); Ieuan James Henry (Stoke Gifford Bristol Avon, GB)
Assignee: Hewlett Packard Enterprise Development LP
H04L9/085H04L9/0869H04L9/0894H04L9/304G06F7/588H04L2209/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,721,062
App. No.
15/329,997
Granted
Jul 21, 2020
Kind
B2
Abstract

Utilizing error correction (ECC) for secure secret sharing includes computing an encrypted key using a key and a number of random values, computing, based on a first ECC scheme, a key ECC for the encrypted key and the random values, and storing a number of key fragments on a number of storage servers, the number of key fragments includes the encrypted key, the random values, and the key ECC.

Claims (76)

1. A method comprising:

computing an encrypted key from a key and from a plurality of random values;

calculating encrypted key reconstruction data for the encrypted key and random value reconstruction data for the random values;

splitting the encrypted key, the encrypted key reconstruction data, the plurality of random values, and the random value reconstruction data into a plurality of key fragments;

storing the plurality of key fragments on a plurality of storage servers, the encrypted key reconstruction data enabling the encrypted key to be reconstructed from a threshold number of the storage servers, and the random value reconstruction data enabling the random values to be reconstructed from the threshold number of the storage servers; and

reconstructing an encrypted object, the encrypted key, and the random values from the threshold number of the storage servers.

2. The method of claim 1 , further comprising:

computing an encrypted object with the key;

calculating object reconstruction data for the encrypted object; and

storing a plurality of object fragments on the number of storage servers, the plurality of object fragments comprising the encrypted object and the object reconstruction data.

3. The method of claim 2 , comprising:

receiving an object;

wherein computing the encrypted object comprises encrypting the object with the key, the key randomly chosen using a high entropy random number generator; and

the object reconstruction data enabling the encrypted object to be reconstructed from the threshold number of the storage servers.

4. The method of claim 1 , comprising:

selecting the number of random values using a high entropy random number generator, the number of random values being the same length as the key;

computing, based on the random values and the key, an exclusive or (XOR) cipher to create the encrypted key; and

concatenating the encrypted key reconstruction data to the encrypted key.

5. The method of claim 1 in which reconstructing the encrypted object, the encrypted key, and the random values from the threshold number of the storage servers comprises:

reconstructing the encrypted object from a number of object fragments from the threshold number of the storage servers;

reconstructing the encrypted key from a number of the key fragments from the threshold number of the storage servers;

reconstructing the random values from a number of the key fragments from the threshold number of the storage servers;

decrypting, based on the encrypted key and the random values, the encrypted key to obtain the key; and

decrypting the encrypted object using the key to obtain an object.

6. A system comprising:

a processor; and

a non-transitory computer readable storage medium comprising instructions executable by the processor to:

compute an encrypted key from a key and from a number of random values;

calculate encrypted key reconstruction data for the encrypted key and random value reconstruction data for the random values;

split the encrypted key, the encrypted key reconstruction data, the number of random values, and the random value reconstruction data into a plurality of key fragments;

store the plurality of key fragments on a plurality of storage servers, the encrypted key reconstruction data enabling the encrypted key to be reconstructed from a threshold number of the storage servers, and the random value reconstruction data enabling the random values to be reconstructed from the threshold number of the storage servers; and

reconstruct an encrypted object, the encrypted key, and the random values from the threshold number of the storage servers.

7. The system of claim 6 , wherein the instructions are executable by the processor to:

compute an encrypted object with the key;

calculate object reconstruction data for the encrypted object;

store a plurality of object fragments on the number of storage servers, the plurality of object fragments comprising the encrypted object and the object reconstruction data; and

reconstruct the encrypted object, the encrypted key, and the random values from the threshold number of the storage servers.

8. The system of claim 7 , wherein the instructions are executable by the processor to:

receive an object;

encrypt the object with the key to compute the encrypted object, the key randomly chosen using a high entropy random number generator; and

the object reconstruction data enabling the encrypted object to be reconstructed from the threshold number of the storage servers.

9. The system of claim 6 , wherein the instructions are executable by the processor to:

select the number of random values using a high entropy random number generator, the number of random values being the same length as the key;

compute, based on the random values and the key, an exclusive or (XOR) cipher to create the encrypted key; and

concatenate the encrypted key reconstruction data to the encrypted key.

10. The system of claim 6 , wherein the instructions are executable by the processor to:

reconstruct an encrypted object from a number of object fragments from the threshold number of the storage servers;

reconstruct the encrypted key from a number of key fragments from the threshold number of the storage servers;

reconstruct the random values from a number of the key fragments from the threshold number of the storage servers;

decrypt, based on the encrypted key and the random values, the encrypted key to obtain the key; and

decrypt the encrypted object using the key to obtain an object.

11. A non-transitory computer readable storage medium comprising instructions executable by a processor to:

compute an encrypted key from a key and from a number of random values;

calculate encrypted key reconstruction data for the encrypted key and random value reconstruction data for the random values;

split the encrypted key, the encrypted key reconstruction data, the number of random values, and the random value reconstruction data into a plurality of key fragments;

store the plurality of key fragments on a plurality of storage servers, the encrypted key reconstruction data enabling the encrypted key to be reconstructed from a threshold number of the storage servers, and the random value reconstruction data enabling the random values to be reconstructed from the threshold number of the storage servers; and

reconstruct an encrypted object, the encrypted key, and the random values from the threshold number of the storage servers.

12. The non-transitory computer readable storage medium of claim 11 , wherein the instructions are executable by the processor to:

compute an encrypted object with the key;

calculate object reconstruction data for the encrypted object; and

store a plurality of object fragments on the number of storage servers, the plurality of object fragments comprising the encrypted object and the object reconstruction data.

13. The non-transitory computer readable storage medium of claim 12 , wherein the instructions are executable by the processor to reconstruct the encrypted object, the encrypted key, and the random values from the threshold number of the storage servers.

14. The non-transitory computer readable storage medium of claim 12 , wherein the instructions are executable by the processor to:

receive an object;

encrypt the object with the key to compute the encrypted object, the key randomly chosen using a high entropy random number generator; and

the object reconstruction data enabling the encrypted object to be reconstructed from the threshold number of the storage servers.

15. The non-transitory computer readable storage medium of claim 11 , wherein the instructions are executable by the processor to:

select the number of random values using a high entropy random number generator, the number of random values being the same length as the key;

compute, based on the random values and the key, an exclusive or (XOR) cipher to create the encrypted key;

concatenate the encrypted key reconstruction data to the encrypted key.

16. The non-transitory computer readable storage medium of claim 13 , wherein the instructions are executable by the processor to:

reconstruct the encrypted object from a number of object fragments from the threshold number of the storage servers;

reconstruct the encrypted key from a number of key fragments from the threshold number of the storage servers;

reconstruct the random values from a number of the key fragments from the threshold number of the storage servers;

decrypt, based on the encrypted key and the random values, the encrypted key to obtain the key; and

decrypt the encrypted object using the key to obtain an object.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 11, 2020
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 052905/0253 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 041113 FRAME: 0034. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded May 4, 2017
From: CHEN, LIQUN; CAMBLE, PETER THOMAS; WATKINS, MARK ROBERT; HENRY, IEUAN JAMES
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 042399/0871 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2017
From: CHEN, LIQUN; CAMBLE, PETER THOMAS; WATKINS, MARK ROBERT; HENRY, IEUAN JAMES
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 041113/0034 →
Continuity (1)
Related Publication 20170250801A1 · Aug 31, 2017
Cited By (6)
US 12,278,893 US 12,335,387 US 12,381,857 US 12,517,661 US 12,591,698 US 12,671,583