IP Library › Granted Patent US 11,489,660
Granted Patent B2
US 11,489,660 · App. 16/865,889 · Granted Nov 1, 2022

Re-encrypting data on a hash chain

Inventors: Ian R. Pentland (Mountain View, CA); Glenn Scott (Mountain View, CA); Roger Meike (Redwood City, CA); Michael R. Gabriel (Mountain View, CA)
Assignee: INTUIT, INC.
H04L9/06H04L9/0643H04L9/3239H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,489,660
App. No.
16/865,889
Granted
Nov 1, 2022
Kind
B2
Abstract

Techniques are disclosed for managing encrypted data stored in one or more blocks of a first data structure. One embodiment presented herein includes a computer-implemented method, which includes retrieving the encrypted data from the one or more blocks. The method further includes placing the encrypted data in a container object. The method further includes applying an encryption technique to the container object to generate an encrypted container object and a key. The method further includes generating a second data structure. A first block of the second data structure may include either the encrypted container object or information related to the encrypted container object.

Claims (35)

1. A computer-implemented method for managing encrypted data, comprising:

retrieving, by a data retriever, encrypted data from one or more blocks of a first data structure;

applying, by an encryption engine, an encryption technique to the encrypted data to generate further encrypted data, wherein the encryption technique is different than an encryption technique used to generate the encrypted data;

generating a second data structure, wherein the first data structure and the second data structure comprise hash chains, and wherein a first block of the second data structure comprises either:

the further encrypted data; or

information related to the further encrypted data.

2. The computer-implemented method of claim 1 , wherein the encrypted data was encrypted with an outdated or compromised cryptographic hash function.

3. The computer-implemented method of claim 1 , wherein the first block of the second data structure comprises information related to the further encrypted data, and wherein the method further comprises storing the further encrypted data separately from both the first data structure and the second data structure.

4. The computer-implemented method of claim 3 , wherein the information related to the further encrypted data comprises a hash and a storage location of the further encrypted data.

5. The computer-implemented method of claim 1 , further comprising: either erasing or prohibiting access to the first data structure.

6. The computer-implemented method of claim 1 , wherein the hash chains are blockchains.

7. A system, comprising:

a processor; and

a memory comprising instructions that, when executed by the processor, cause the system to perform a method for managing encrypted data, the method comprising:

retrieving, by a data retriever, encrypted data from one or more blocks of a first data structure;

applying, by an encryption engine, an encryption technique to the encrypted data to generate further encrypted data, wherein the encryption technique is different than an encryption technique used to generate the encrypted data;

generating a second data structure, wherein the first data structure and the second data structure comprise hash chains, and wherein a first block of the second data structure comprises either:

the further encrypted data; or

information related to the further encrypted data.

8. The system of claim 7 , wherein the encrypted data was encrypted with an outdated or compromised cryptographic hash function.

9. The system of claim 7 , wherein the first block of the second data structure comprises information related to the further encrypted data, and wherein the method further comprises storing the further encrypted data separately from both the first data structure and the second data structure.

10. The system of claim 9 , wherein the information related to the further encrypted data comprises a hash and a storage location of the further encrypted data.

11. The system of claim 7 , wherein the method further comprises either erasing or prohibiting access to the first data structure.

12. The system of claim 7 , wherein the hash chains are blockchains.

13. A computer-implemented method for managing encrypted data, comprising:

retrieving, by a data retriever, encrypted data from one or more blocks of a first data structure;

applying, by an encryption engine, an encryption technique to the encrypted data to generate further encrypted data, wherein the encryption technique is different than an encryption technique used to generate the encrypted data;

generating a second data structure, wherein the first data structure and the second data structure comprise hash chains, and wherein a first block of the second data structure comprises either:

the further encrypted data; or

an encryption key for the further encrypted data.

14. The computer-implemented method of claim 13 , wherein the encrypted was encrypted with an outdated or compromised cryptographic hash function.

15. The computer-implemented method of claim 13 , wherein the first block of the second data structure comprises the encryption key for the further encrypted data, and wherein the method further comprises storing the further encrypted data separately from both the first data structure and the second data structure.

16. The computer-implemented method of claim 15 , wherein the first block of the second data structure comprises the encryption key for the further encrypted data, and wherein the first block of the second data structure further comprises a storage location of the further encrypted data.

17. The computer-implemented method of claim 15 , further comprising: either erasing or prohibiting access to the first data structure.

18. The computer-implemented method of claim 13 , wherein the hash chains are blockchains.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2020
From: PENDTLAND, IAN R.; SCOTT, GLENN; MEIKE, ROGER; GABRIEL, MICHAEL R.
To: INTUIT, INC.
Reel/Frame 052562/0450 →
Continuity (2)
Continuation 15852345 · Dec 22, 2017
Related Publication 20200266971A1 · Aug 20, 2020
Cited By (1)
US 12,457,099