IP Library › Granted Patent US 11,677,567
Granted Patent B2
US 11,677,567 · App. 17/141,602 · Granted Jun 13, 2023

Validating shared files

Inventors: Praveen Raja Dhanabalan (Karnataka, IN); Aayush Bhala (Karnataka, IN); Shubham Choudhary (Karnataka, IN)
H04L9/3263H04L9/088
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,677,567
App. No.
17/141,602
Filed
Jan 5, 2021
Granted
Jun 13, 2023
Kind
B2
Examiner
TRAN, VU V
Art Unit
2491
USPC
713/175
Abstract

A computing device may receive a file previously uploaded by another device, and may validate the received file using data including a first value encrypted based on a document (e.g., a digital certificate or identification certificate) of the uploading device. The computing device may determine the validity of the certificate based on a certificate of a remote computing device to which the file was uploaded, and may decrypt the first value using a key of the certificate of the uploading device. The computing device may determine a second value for the received file and may determine validity of the received file based on a match of the first value and the second value.

Claims (80)

1. A method, comprising:

receiving, by a first client device, a file and data, the file having been previously uploaded by a second client device to a remote computing system and the data including a first hash value based on contents of the file previously uploaded by the second client device, the first hash value encrypted based on a document of the second client device;

determining, by the first client device, validity of the document of the second client device based on another document of the remote computing system;

decrypting, by the first client device, the first hash value with use of a key of the document of the second client device in response to validation of the document of the second client device;

determining, by the first client device, a second hash value for the received file, the second hash value based on contents of the file received by the first client device;

determining, by the first client device, validity of the received file based on a match of the first hash value and the second hash value;

receiving, at the first client device, an additional file and additional data, the additional file having been previously uploaded by the second client device to the remote computing system and the additional data including a third hash value encrypted based on the document of the second client device;

decrypting, by the first client device, the third hash value with use of the key of the document of the second client device in response to validation of the document of the second client device;

determining, by the first client device, a fourth hash value for the received additional file;

determining, by the first client device, that the received additional file is invalid based on a mismatch of the third hash value and the fourth hash value; and

denying access to the received additional file at the first client device.

2. The method of claim 1 , wherein:

the data further includes a document of a certificate authority (CA) of the remote computing system, and

determining the validity of the document of the second client device includes determining that the document has been signed by the CA.

3. The method of claim 1 , wherein the data further includes an identifier of the second client device, and the method further comprises:

determining, by the first client device and using the identifier, that the key of the document of the second client device is available at the first client device; and

using the available key to decrypt the first hash value.

4. The method of claim 1 , wherein the data further includes an identifier of the second client device, and the method further comprises:

determining, by the first client device and using the identifier, that the key of the document of the second client device is not available at the first client device;

sending, from the first client device to the remote computing system, a request for the key of the document of the second client device;

receiving, by the first client device and from the remote computing system, the key of the document of the second client device; and

using the received key to decrypt the first hash value.

5. The method of claim 1 , further comprising:

receiving, from the first client device, input data representing a request to download the file,

wherein receiving the file and the data is in response to receiving the input data.

6. The method of claim 1 , further comprising:

determining that the first client device is to download the file in response to uploading of the file to the remote computing system,

wherein receiving the file and the data is in response to detecting that the file is uploaded to the remote computing system.

7. The method of claim 1 , wherein the data further includes a document for the remote computing system and an identifier of the second client device.

8. A system, comprising:

a first client device;

a second client device; and

a remote computing system, wherein the remote computing system includes at least a first processor, and at least a first non-transitory computer-readable medium encoded with instruction which, when executed by the first processor, cause the remote computing system to:

receive a file to be uploaded and a first hash value based on contents of the file and encrypted based on a document of the second client device;

generate a second hash value based on contents of the received file; decrypt the first hash value using a public key of the second client device to determine a decrypted hash value,

determine validity of the received file based on a match of the second hash value and the decrypted hash value;

based at least in part on the second hash value matching the decrypted hash value, generate data to include at least the first hash value; and

store the received file and the data so that the file is available for download by at least the first client device;

wherein the first client device includes at least a second processor, and at least a second computer-readable medium encoded with instruction which, when executed by the second processor, cause the first client device to:

receive the file and the data, the file having been previously uploaded by the second client device to the remote computing system and the data including the first hash value;

determine validity of the document of the second client device based on another document of the remote computing system;

decrypt the first hash value with use of public key of the document of the second client device in response to validation of the document;

determine a third hash value for the received file, the third hash value based on contents of the file received by the first client device; and

determine validity of the received file based on a match of the first hash value and the third hash value.

9. The system of claim 8 , wherein the second client device includes at least a third processor, and at least a third computer-readable medium encoded with instruction which, when executed by the third processor, cause the second client device to:

receive a request to upload the file to the remote computing system;

in response to the request to upload the file, generate the first hash value based on contents of the file to be uploaded, the first hash value encrypted using a private key of the second client device; and

send, to the remote computing system, the first hash value and the file to be uploaded.

10. The system of claim 8 , wherein the second client device includes at least a third processor, and at least a third computer-readable medium encoded with instruction which, when executed by the third processor, cause the second client device to:

receive a request to register for file sharing using the remote computing system; and

in response to the request to register for file sharing, initiate a document authorization process with a certificate authority (CA) for the remote computing system by causing the second client device to:

generate a key pair including a private key and the public key for the second client device,

generate a document including the public key and information identifying the second client device,

send the document to the CA for signature, and

receive a signed document from the CA, the signed document indicative of the private key being authorized to encrypt data sent by the second client device to the remote computing system.

11. The system of claim 8 , wherein the data further includes an identifier associated with the second client device, and the second computer-readable medium is further encoded with additional instructions which, when executed by the second processor, further cause the first client device to:

determine, using the identifier, that the public key of the document of the second client device is available at the first client device; and

use the available public key to decrypt the first hash value.

12. The system of claim 8 , wherein the data further includes an identifier for the second client device, and the second computer-readable medium is further encoded with additional instructions which, when executed by the second processor, further cause the first client device to:

determine, using the identifier, that the public key of the document of the second client device is not available at the first client device;

send, to the remote computing system, a request for the public key of the document of the second client device; and

use the received public key to decrypt the first hash value.

13. The system of claim 8 , wherein the first second computer-readable medium is further encoded with additional instructions which, when executed by the second processor, further cause the first client device to:

receive input data representing a request to download the file,

wherein the file and the data are received in response to receiving the input data.

14. The system of claim 8 , wherein the second computer-readable medium is further encoded with additional instructions which, when executed by the second processor, further cause the first client device to:

determine that the first client device is to automatically download the file after upload of the file to the remote computing system,

wherein the file and the data are received in response to detecting that the file is uploaded to the remote computing system.

15. A method, comprising:

receiving, at a computing system and from a first client device, a request to register for file sharing using the computing system;

receiving, at a certificate authority (CA) of the computing system, a document including a public key of the first client device and information identifying the first client device;

validating, by the CA and using the document, an identity of the first client device;

signing, by the CA, the document with a key of the CA;

sending, to the first client device, the signed document indicative of the first client device being authorized to encrypt data, using a private key corresponding to the public key of the first client device, sent to the computing system;

receiving, by the computing system, a file and a first value from the first client device, the first value being encrypted based on contents of the file;

decrypting, by the computing system, the first value with use of the public key of the document of the first client device;

generating, by the computing system, a second value for the file;

determining, by the computing system, a match of the first value and the second value; and

generating, by the computing system, data in response to the match of the first value and the second value, so as to enable download of the file by a second client device.

16. The method of claim 15 , wherein the data further includes a CA signature of a document of the computing system, and an identifier of the first client device.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2021
From: DHANABALAN, PRAVEEN RAJA; BHALA, AAYUSH; CHOUDHARY, SHUBHAM
To: CITRIX SYSTEMS, INC.
Reel/Frame 054814/0174 →
Continuity (1)
Related Publication 20220217001A1 · Jul 7, 2022