IP Library › Granted Patent US 11,646,874
Granted Patent B2
US 11,646,874 · App. 17/483,754 · Granted May 9, 2023

Organized data storage system

Inventor: Mindaugas Valkaitis (Vilnius, LT)
Assignee: UAB 360 IT
H04L9/088G06F3/0622G06F3/0655G06F3/0679H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,646,874
App. No.
17/483,754
Filed
Sep 23, 2021
Granted
May 9, 2023
Kind
B2
Art Unit
2494
USPC
713/171
Abstract

A method including determining, by a device, an assigned key pair including an assigned public key and an assigned private key; determining, by the device for a folder including encrypted content, a folder access key pair including a folder access public key and a folder access private key; encrypting, by the device, the folder access private key by utilizing the assigned public key; and accessing, by the device, the encrypted content based at least in part on decrypting the folder access private key. Various other aspects are contemplated.

Claims (76)

1. A method, comprising:

determining, by a user device in communication with a server associated with providing data storage services to the user device, an assigned key pair including an assigned public key and an assigned private key;

determining, by the user device for a folder, a folder access key pair including a folder access public key and a folder access private key;

determining, by the user device for content to be stored in the folder, a content access key pair including a content access public key and a content access private key;

determining, by the user device for the content, a symmetric content key;

encrypting, by the user device, the folder access private key by utilizing the assigned public key;

encrypting, by the user device, the content access private key by utilizing the folder access public key;

encrypting, by the user device, the symmetric content key by utilizing the content access public key;

encrypting, by the user device, the content by utilizing the symmetric content key;

transmitting, by the user device, the encrypted content, the encrypted folder access private key, the encrypted content access private key, and the encrypted symmetric content key to the server for storage; and

decrypting, by the user device, the encrypted content based at least in part on decrypting the folder access private key, the content access private key, and the symmetric content key.

2. The method of claim 1 , further comprising:

receiving a master string of alphanumeric characters uniquely associated with the user device;

determining a master key based at least in part on the master string of alphanumeric characters and a derivation function;

encrypting the assigned private key by utilizing the master key, wherein decrypting the encrypted content includes decrypting the assigned private key by utilizing the master key; and

transmitting the encrypted assigned private key to the server for storage.

3. The method of claim 1 , further comprising:

decrypting the assigned private key, encrypted by utilizing a master key; and

decrypting the folder access private key by utilizing the assigned private key.

4. The method of claim 1 , wherein the assigned public key and the assigned private key are specific to a registered account associated with the device.

5. The method of claim 1 , wherein the folder is a virtual folder.

6. The method of claim 1 , further comprising:

transmitting, by the user device to the server, the encrypted folder access private key, the encrypted symmetric content key, and the encrypted content access private key;

transmitting, by the user device to the server, a request to access the encrypted content; and

receiving, by the user device from the server based at least in part on transmitting the request, the encrypted content access private key, the encrypted symmetric content key, and the encrypted folder access private key.

7. A user device in communication with a server associated with providing data storage services to the user device, the user device comprising:

a memory; and

a processor communicatively coupled to the memory, the memory and the processor being configured to:

determine an assigned key pair including an assigned public key and an assigned private key;

determine, for a folder, a folder access key pair including a folder access public key and a folder access private key;

determine, for content to be stored in the folder, a content access key pair including a content access public key and a content access private key;

determine, for the content, a symmetric content key;

encrypt the folder access private key by utilizing the assigned public key;

encrypt the content access private key by utilizing the folder access public key;

encrypt the symmetric content key by utilizing the content access public key;

encrypt the content by utilizing the symmetric content key;

transmit the encrypted content, the encrypted folder access private key, the encrypted content access private key, and the encrypted symmetric content key to the server for storage; and

decrypt the encrypted content based at least in part on decrypting the folder access private key, the content access private key, and the symmetric content key.

8. The user device of claim 7 , wherein the memory and the processor are configured to:

receive a master string of alphanumeric characters uniquely associated with the user device;

determine a master key based at least in part on the master string of alphanumeric characters and a derivation function;

encrypt the assigned private key by utilizing the master key, wherein the encrypted content is decrypted by the user device based at least in part on decrypting the assigned private key by utilizing the master key; and

transmit the encrypted assigned private key to the server for storage.

9. The user device of claim 7 , wherein the memory and the processor are configured to:

decrypt the assigned private key, encrypted by utilizing a master key; and

decrypt the folder access private key by utilizing the assigned private key.

10. The user device of claim 7 , wherein the assigned public key and the assigned private key are specific to a registered account associated with the device.

11. The user device of claim 7 , wherein the folder is a virtual folder.

12. The user device of claim 8 , wherein the memory and the processor are configured to:

transmit, to the server, the encrypted folder access private key, the encrypted symmetric content key, and the encrypted content access private key;

transmit, to the server, a request to access the encrypted content; and

receive, from the server based at least in part on transmitting the request, the encrypted content access private key, the encrypted symmetric content key, and the encrypted folder access private key.

13. A non-transitory computer-readable medium configured to store instructions, which when executed by a processor associated with a user device in communication with a server associated with providing data storage services to the user device, configure the processor to:

determine an assigned key pair including an assigned public key and an assigned private key;

determine, for a folder, a folder access key pair including a folder access public key and a folder access private key;

determine, for content to be stored in the folder, a content access key pair including a content access public key and a content access private key;

determine, for the content, a symmetric content key;

encrypt the folder access private key by utilizing the assigned public key;

encrypt the content access private key by utilizing the folder access public key;

encrypt the symmetric content key by utilizing the content access public key;

encrypt the content by utilizing the symmetric content key;

transmit the encrypted content, the encrypted folder access private key, the encrypted content access private key, and the encrypted symmetric content key to the server for storage; and

decrypt the encrypted content based at least in part on decrypting the folder access private key, the content access private key, and the symmetric content key.

14. The non-transitory computer-readable medium of claim 13 , wherein the processor is configured to:

receive a master string of alphanumeric characters uniquely associated with the user device;

determine a master key based at least in part on the master string of alphanumeric characters and a derivation function;

encrypt the assigned private key by utilizing the master key, wherein the encrypted content is decrypted by the user device based at least in part on decrypting the assigned private key by utilizing the master key; and

transmit the encrypted assigned private key to the server for storage.

15. The non-transitory computer-readable medium of claim 13 , wherein the processor is configured to:

decrypt the assigned private key, encrypted by utilizing a master key; and

decrypt the folder access private key by utilizing the assigned private key.

16. The non-transitory computer-readable medium of claim 13 , wherein the assigned public key and the assigned private key are specific to a registered account associated with the device.

17. The non-transitory computer-readable medium of claim 13 , wherein the processor is configured to:

transmit, to the server, the encrypted folder access private key, the encrypted symmetric content key, and the encrypted content access private key;

transmit, to the server, a request to access the encrypted content; and

receive, from the server based at least in part on transmitting the request, the encrypted content access private key, the encrypted symmetric content key, and the encrypted folder access private key.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2026
From: UAB 360 IT
To: 720 IT, UAB
Reel/Frame 074330/0675 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2021
From: VALKAITIS, MINDAUGAS
To: UAB 360 IT
Reel/Frame 057602/0037 →
Continuity (1)
Related Publication 20230086968A1 · Mar 23, 2023