IP Library › Granted Patent US 10,798,064
Granted Patent B1
US 10,798,064 · App. 15/853,618 · Granted Oct 6, 2020

Proxy computer system to provide encryption as a service

Inventor: Anthony Scotney (Hobart, AU)
Assignee: StratoKey Pty Ltd.
H04L63/0281G06F16/955H04L67/2833H04L2209/76
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,798,064
App. No.
15/853,618
Granted
Oct 6, 2020
Kind
B1
Abstract

A server system implements an encryption service, in connection with a proxy service that enables a client computer to utilize the third-party network service.

Claims (44)

1. A server system comprising:

a memory resource to store:

a set of instructions;

one or more processors to access the set of instructions from the memory resource to:

provide a proxy service for a client computer to utilize when accessing a third-party network service;

wherein in providing the proxy service, the one or more processors:

receive a content submission from the client computer intended for the third-party network service;

analyze the content submission to identify one or more sensitive data elements within the content submission, wherein a remainder of the content submission is not recognized as being sensitive;

perform an encryption operation on the sensitive data elements;

store a decryption key associated with the sensitive data elements with the server system;

transmit the content submission to the third-party network service to store the content submission with the sensitive data elements in an encrypted form;

receive a request, independent of the client computer, identifying the sensitive data elements in the encrypted form; and

provide a response to the request using the decryption key, the response enabling the sensitive data elements to be used in a decrypted form.

2. The server system of claim 1 , wherein the one or more processors provide the response to the request by receiving the sensitive data elements in the encrypted form from a requester independent of the client computer, decrypting the sensitive data elements from the encrypted form into the decrypted form, and then sending the sensitive data elements in the decrypted form to the requester.

3. The server system of claim 2 , wherein the requester is a workflow, program, routine, or process implemented by the third-party network service.

4. The server system of claim 2 , wherein the requester is separate from the third-party network service, and the one or more processors provide the response to the request by (i) retrieving the sensitive data elements specified by the request from the third-party network service, the sensitive data elements being in the encrypted form, (ii) decrypting the sensitive data elements from the encrypted form into the decrypted form, and (iii) sending the sensitive data elements in the decrypted form to the requester.

5. The server system of claim 1 , wherein in providing the proxy service, the one or more processors analyze content communicated from the client computer to the third-party network service to determine one or more data elements to encrypt before the one or more data elements are stored in the encrypted form with the third-party network service.

6. The server system of claim 1 , wherein the decryption key is used for decrypting the sensitive data elements in the encrypted form.

7. The server system of claim 1 , wherein the one or more processors store a set of interoperability parameters associated with the sensitive data elements with the server system.

8. The server system of claim 7 , wherein the set of interoperability parameters specify configurations, settings, and/or workflows to enable the sensitive data elements to be used between distinct systems or services.

9. The server system of claim 7 , wherein the set of interoperability parameters specify a format, configuration, or setting for use of the sensitive data elements in the decrypted form.

10. The server system of claim 7 , wherein the set of interoperability parameters enable the sensitive data elements to be used in the decrypted form for a particular purpose.

11. A method for providing a proxy service between a client computer and a third-party network service, the method being implemented by one or more processors of a network computer system and comprising:

receiving a content submission from the client computer intended for the third-party network service;

analyzing the content submission to identify one or more sensitive data elements within the content submission, wherein a remainder of the content submission is not recognized as being sensitive;

performing an encryption operation on the sensitive data elements;

storing a decryption key associated with the sensitive data elements with the network computer system;

transmitting the content submission to the third-party network service to store the content submission with the sensitive data elements in an encrypted form;

receiving a request, independent of the client computer, identifying the sensitive data elements in the encrypted form; and

providing a response to the request using the decryption, the response enabling the sensitive data elements to be used in a decrypted form.

12. The method of claim 11 , wherein providing the response to the request includes receiving the sensitive data elements in the encrypted form from a requester independent of the client computer, decrypting the sensitive data elements from the encrypted form into the decrypted form, and then sending the sensitive data elements in the decrypted form to the requester.

13. The method of claim 12 , wherein the requester is a workflow, program, routine, or process implemented by the third-party network service.

14. The method of claim 12 , wherein the requester is separate from the third-party network service, and the one or more processors provide the response to the request by (i) retrieving sensitive data elements specified by the request from the third-party network service, the sensitive data elements being in the encrypted form, (ii) decrypting the sensitive data elements from the encrypted form into the decrypted form, and (iii) sending the sensitive data elements in the decrypted form to the requester.

15. A non-transitory computer-readable medium that stores instructions, which when executed by one or more processors of a computer system, cause the computer system to perform operations that include:

receiving a content submission from a client computer intended for a third-party network service;

analyzing the content submission to identify one or more sensitive data elements within the content submission, wherein a remainder of the content submission is not recognized as being sensitive;

performing an encryption operation on the sensitive data elements;

storing a decryption key associated with the sensitive data elements with the computer system;

transmitting the content submission to the third-party network service to store the content submission with the sensitive data elements in an encrypted form;

receiving a request, independent of the client computer, identifying the sensitive data elements in the encrypted form; and

providing a response to the request using the decryption, the response enabling the sensitive data elements to be used in a decrypted form.

16. The non-transitory computer-readable medium of claim 15 , wherein the one or more processors provide the response to the request by receiving the sensitive data elements in the encrypted form from a requester independent of the client computer, decrypting the sensitive data elements from the encrypted form into the decrypted form, and then sending the sensitive data elements in the decrypted form to the requester.

17. The non-transitory computer-readable medium of claim 16 , wherein the requester is a workflow, program, routine, or process implemented by the third-party network service.

18. The non-transitory computer-readable medium of claim 16 , wherein the requester is separate from the third-party network service, and the one or more processors provide the response to the request by (i) retrieving the sensitive data elements specified by the request from the third-party network service, the sensitive data elements being in the encrypted form, (ii) decrypting the sensitive data elements from the encrypted form into the decrypted form, and (iii) sending the sensitive data elements in the decrypted form to the requester.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2018
From: SCOTNEY, ANTHONY
To: STRATOKEY PTY LTD.
Reel/Frame 044991/0954 →
Continuity (2)
Continuation In Part 15808690 · Nov 9, 2017
Provisional Application 62419960 · Nov 9, 2016
Cited By (4)
US 12,189,815 US 12,236,440 US 12,321,156 US 12,432,047