IP Library › Granted Patent US 11,201,857
Granted Patent B2
US 11,201,857 · App. 16/708,080 · Granted Dec 14, 2021

Domain transcendent file cryptology network

Inventors: Thomas C. Scott (Simi Valley, CA); Matthew D. Estes (Celebration, FL); Douglas A. Hill (Winter Garden, FL)
Assignee: Disney Enterprises, Inc.
H04L63/0471H04L9/3228H04L9/3239
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,201,857
App. No.
16/708,080
Granted
Dec 14, 2021
Kind
B2
Abstract

A domain transcendent file cryptology network includes a first data cryptology node in a first data domain having a first security protocol. A hardware processor of the first data cryptology node executes a first instantiation of a software code to receive a request to transfer a data file from the first data domain to a second data domain having a second, different, security protocol, obtain one or more characteristics of the data file, and generate an authentication tag for the data file based on the characteristic(s). The first instantiation of the software code also encrypts the data file and transmits the encrypted data file, the authentication tag, and a decryption key to a second data cryptology node in the second data domain. The decryption key and the authentication tag enable decryption of the encrypted data file by a second instantiation of the software code on the second data cryptology node.

Claims (40)

1. A method for use by a domain transcendent file cryptology network including a first data cryptology node in a first data domain governed by a first security protocol, the first data cryptology node having a hardware processor and a memory storing a first instantiation of a software code, the method comprising:

receiving, by the first instantiation of the software code executed by the hardware processor of the first data cryptology node, a request to transfer a data file stored in the first data domain to a second data domain governed by a second security protocol different from the first security protocol;

obtaining, by the first instantiation of the software code executed by the hardware processor of the first data cryptology node, one or more characteristics of the data file;

generating, by the first instantiation of the software code executed by the hardware processor of the first data cryptology node, an authentication tag for the data file based on the one or more characteristics of the data file;

encrypting, by the first instantiation of the software code executed by the hardware processor of the first data cryptology node, the data file to generate an encrypted data file; and

transmitting, in response to the request, by the first instantiation of the software code executed by the hardware processor of the first data cryptology node, the encrypted data file, the authentication tag, and a decryption key for decrypting the encrypted data file to a second data cryptology node in the second data domain;

wherein the decryption key and the authentication tag enable decryption of the encrypted data file and authentication of the decrypted data file, respectively, by a second instantiation of the software code resident on the second data cryptology node.

2. The method of claim 1 , wherein generating the authentication tag comprises generating a Secure Hash Algorithm 2 (SHA-2) sum of the data file.

3. The method of claim 1 , wherein generating the authentication tag comprises generating a SHA-256 sum of the data file.

4. The method of claim 1 , wherein the authentication tag comprises a Universally Unique Identifier (UUID) of the first data cryptology node.

5. The method of claim 1 , wherein the authentication tag comprises a UUID of the second data cryptology node.

6. The method of claim 1 , further comprising:

generating, by the first instantiation of the software code executed by the hardware processor of the first data cryptology node, a container file for the encrypted data file; and

encrypting, by the first instantiation of the software code executed by the hardware processor of the first data cryptology node, the container file to generate an encrypted container file including the encrypted data file;

wherein the decryption key and the authentication tag generated in the first data domain also enable decryption of the encrypted container file by the second instantiation of the software code resident on the second data cryptology node.

7. The method of claim 6 , wherein the authentication tag comprises a SHA-2 corresponding to a container image of the container file.

8. The method of claim 1 , wherein the authentication tag comprises one or more expiration criteria the data file.

9. The method of claim 1 , wherein the data file comprises a graphical image.

10. The method of claim 1 , wherein the data file comprises an audio-video file.

11. A domain transcendent file cryptology network comprising:

a first data cryptology node in a first data domain governed by a first security protocol, the first data cryptology node having a hardware processor and a memory storing a first instantiation of a software code;

the hardware processor being configured to execute the first instantiation of the software code to:

receive a request to transfer a data file stored in the first data domain to a second data domain governed by a second security protocol different from the first security protocol;

obtain one or more characteristics of the data file;

generate an authentication tag for the data file based on the one or more characteristics of the data file;

encrypt the data file to generate an encrypted data file; and

transmit, in response to the request, the encrypted data file, the authentication tag, and a decryption key for decrypting the encrypted data file to a second data cryptology node in the second data domain;

wherein the decryption key and the authentication tag enable decryption of the encrypted data file and authentication of the decrypted data file, respectively, by a second instantiation of the software code resident on the second data cryptology node.

12. The domain transcendent file cryptology network of claim 11 , wherein the authentication tag comprises a Secure Hash Algorithm 2 (SHA-2) sum of the data file.

13. The domain transcendent file cryptology network of claim 11 , wherein the authentication tag comprises a SHA-256 sum of the data file.

14. The domain transcendent file cryptology network of claim 11 , wherein the authentication tag comprises a Universally Unique Identifier (UUID) of the first data cryptology node.

15. The domain transcendent file cryptology network of claim 11 , wherein the authentication tag comprises a UUID of the second data cryptology node.

16. The domain transcendent file cryptology network of claim 11 , wherein the hardware processor is further configured to execute the first instantiation of the software code to:

generate a container file for the encrypted data file; and

encrypt the container file to generate an encrypted container file including the encrypted data file;

wherein the decryption key and the authentication tag generated in the first data domain also enable decryption of the encrypted container file by the second instantiation of the software code resident on the second data cryptology node.

17. The domain transcendent file cryptology network of claim 16 , wherein the authentication tag comprises a SHA-2 corresponding to a container image of the container file.

18. The domain transcendent file cryptology network of claim 11 , wherein the authentication tag comprises one or more expiration criteria for the data file.

19. The domain transcendent file cryptology network of claim 11 , wherein the data file comprises a graphical image.

20. The domain transcendent file cryptology network of claim 11 , wherein the data file comprises an audio-video file.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2019
From: SCOTT, THOMAS C.; ESTES, MATTHEW D.; HILL, DOUGLAS A.
To: DISNEY ENTERPRISES, INC.
Reel/Frame 051264/0860 →
Continuity (1)
Related Publication 20210176222A1 · Jun 10, 2021