IP Library › Granted Patent US 11,683,166
Granted Patent B2
US 11,683,166 · App. 16/943,188 · Granted Jun 20, 2023

Secure file modification with supervision

Inventors: Praveen Raja Dhanabalan (Bangalore, IN); Anudeep Athlur (Bangalore, IN); Anuj Magazine (Bangalore, IN)
H04L9/0861G06F16/116G06F16/176G06F21/602H04L9/0891
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,683,166
App. No.
16/943,188
Filed
Jul 30, 2020
Granted
Jun 20, 2023
Kind
B2
Examiner
YANG, HAN
Art Unit
2493
USPC
713/165
Abstract

In some embodiments, a method may be performed by a computing device that involves displaying an identifier indicative of a file, the display of the identifier being readable by a second device, receiving first data from the second device in response to the identifier being read by the second device, and enabling performance of at least one action with respect to the file with use of the first data. In some embodiments, the method may further involve receiving a first encryption fragment associated with the file, receiving, from the second device, a second encryption fragment associated with the file, reconstructing, using at least the first encryption fragment and the second encryption fragment, an encryption key enabling viewing of the file, and viewing the file using the encryption key.

Claims (80)

1. A method, comprising:

generating, by a computing system, a first key for a file;

determining, by the computing system, a first number of primary users required to take at least one action with respect to the file using the first key;

determining, by the computing system, a second number of total primary users;

generating, by the computing system and using the first key and the first number of primary users, a third number of first fragments of data equal to the second number of total primary users, wherein the third number of the first fragments of data are generated such that a first set of the third number of the first fragments of data can be used to reconstruct the first key, the third number of the first fragments of data including a first data fragment and a second data fragment;

sending, by the computing system, the file and an identifier to a first client device to configure the first client device to display the identifier on the first client device in response to a request received by the first client device to take at least one action with respect to the file;

sending, by the computing system, the second data fragment and the identifier to a second client device to configure the second client device to send the second data fragment to the first client device in response to receipt by the second client device of the identifier displayed by the first client device; and

sending, by the computing system, the first data fragment to the first client device to configure the first client device to reconstruct the first key in response to receipt of the second data fragment from the second client device.

2. The method of claim 1 , further comprising:

receiving, at the computing system from the first client device, data representing the file, the data including a signature;

determining the first key associated with the file;

validating the signature using the first key; and

storing the data.

3. The method of claim 1 , further comprising:

generating, by the computing system, a key; and

determining, by the computing system, a first subkey using the key, wherein the first key comprises the first subkey.

4. The method of claim 3 , further comprising:

determining, by the computing system, a second subkey using the key;

determining, by the computing system, a fourth number of secondary users required to take the at least one action with respect to the file using the second subkey;

determining, by the computing system, a fifth number of total secondary users;

generating, by the computing system and using the second subkey and the fourth number of secondary users, a sixth number of second fragments of data equal to the fifth number of total secondary users, wherein the sixth number of the second fragments of data are generated such that a second set of the sixth number of the second fragments of data can be used to reconstruct the second subkey, the sixth number of second fragments including a third data fragment; and

sending, by the computing system, the third data fragment and the identifier to a third client device to configure the third client device to send the third data fragment to the first client device in response to receipt by the third client device of the identifier displayed by the first client device.

5. The method of claim 4 , wherein, the sixth number of the second fragments of data further include at least a fourth data fragment, and the method further comprises:

sending, by the computing system, the fourth data fragment and the identifier to a fourth client device to configure the fourth client device to send the fourth data fragment to the first client device in response to receipt by the fourth client device of the identifier displayed by the first client device.

6. The method of claim 1 , wherein the third number of the first fragments of data further include at least a third data fragment, and the method further comprises:

sending, by the computing system, the third data fragment and the identifier to a third client device to configure the third client device to send the third data fragment to the first client device in response to receipt by the third client device of the identifier displayed by the first client device.

7. A system, comprising:

at least one processor; and

at least one computer-readable medium encoded with instruction which, when executed by the at least one processor, cause the system to:

generate a first key for a file;

determine a first number of primary users required to take at least one action with respect to the file using the first key;

determine a second number of total primary users;

generate, using the first key and the first number of primary users, a third number of first fragments of data equal to the second number of total primary users, wherein the third number of the first fragments of data are generated such that a first set of the third number of the first fragments of data can be used to reconstruct the first key, the third number of the first fragments of data including a first data fragment and a second data fragment;

send the file and an identifier to a first client device to configure the first client device to display the identifier on the first client device in response to a request received by the first client device to take at least one action with respect to the file;

send the second data fragment and the identifier to a second client device to configure the second client device to send the second data fragment to the first client device in response to receipt by the second client device of the identifier displayed by the first client device; and

send the first data fragment to the first client device to configure the first client device to reconstruct the first key in response to receipt of the second data fragment from the second client device.

8. The system of claim 7 , wherein the at least one computer-readable medium is further encoded with additional instructions which, when executed by the at least one processor, further cause the system to:

receive, from the first client device, data representing the file, the data including a signature;

determine the first key associated with the file;

validate the signature using the first key; and

store the data.

9. The system of claim 7 , wherein the third number of the first fragments of data further include at least a third data fragment, and the at least one computer-readable medium is further encoded with additional instructions which, when executed by the at least one processor, further cause the system to:

send the third data fragment and the identifier to a third client device to configure the third client device to send the third data fragment to the first client device in response to receipt by the third client device of the identifier displayed by the first client device.

10. The system of claim 7 , wherein the at least one computer-readable medium is further encoded with additional instructions which, when executed by the at least one processor, further cause the system to:

generate a key; and

determine a first subkey using the key, wherein the first key comprises the first subkey.

11. The system of claim 10 , wherein the at least one computer-readable medium is further encoded with additional instructions which, when executed by the at least one processor, further cause the system to:

determine a second subkey using the key;

determine a fourth number of secondary users required to take the at least one action with respect to the file using the second subkey;

determine a fifth number of total secondary users;

generate, using the second subkey and the fourth number of secondary users, a sixth number of second fragments of data equal to the fifth number of total secondary users, wherein the sixth number of the second fragments of data are generated such that a second set of the sixth number of the second fragments of data can be used to reconstruct the second subkey, the sixth number of second fragments including a third data fragment; and

send the third data fragment and the identifier to a third client device to configure the third client device to send the third data fragment to the first client device in response to receipt by the third client device of the identifier displayed by the first client device.

12. The system of claim 11 , wherein, the sixth number of the second fragments of data further include at least a fourth data fragment, and the at least one computer-readable medium is further encoded with additional instructions which, when executed by the at least one processor, further cause the system to:

send the fourth data fragment and the identifier to a fourth client device to configure the fourth client device to send the fourth data fragment to the first client device in response to receipt by the fourth client device of the identifier displayed by the first client device.

13. At least one non-transitory computer-readable medium encoded with instruction which, when executed by at least one processor of a system, cause the system to:

generate a first key for a file;

determine a first number of primary users required to take at least one action with respect to the file using the first key;

determine a second number of total primary users;

generate, using the first key and the first number of primary users, a third number of first fragments of data equal to the second number of total primary users, wherein the third number of the first fragments of data are generated such that a first set of the third number of the first fragments of data can be used to reconstruct the first key, the third number of the first fragments of data including a first data fragment and a second data fragment;

send the file and an identifier to a first client device to configure the first client device to display the identifier on the first client device in response to a request received by the first client device to take at least one action with respect to the file;

send the second data fragment and the identifier to a second client device to configure the second client device to send the second data fragment to the first client device in response to receipt by the second client device of the identifier displayed by the first client device; and

send the first data fragment to the first client device to configure the first client device to reconstruct the first key in response to receipt of the second data fragment from the second client device.

14. The at least one non-transitory computer-readable medium of claim 13 , further encoded with additional instructions which, when executed by the at least one processor, further cause the system to:

receive, from the first client device, data representing the file, the data including a signature;

determine the first key associated with the file;

validate the signature using the first key; and

store the data.

15. The at least one non-transitory computer-readable medium of claim 13 , wherein the third number of the first fragments of data further include at least a third data fragment, and the at least one computer-readable medium is further encoded with additional instructions which, when executed by the at least one processor, further cause the system to:

send the third data fragment and the identifier to a third client device to configure the third client device to send the third data fragment to the first client device in response to receipt by the third client device of the identifier displayed by the first client device.

16. The at least one non-transitory computer-readable medium of claim 13 , further encoded with additional instructions which, when executed by the at least one processor, further cause the system to:

generate a key; and

determine a first subkey using the key, wherein the first key comprises the first subkey.

17. The at least one non-transitory computer-readable medium of claim 16 , further encoded with additional instructions which, when executed by the at least one processor, further cause the system to:

determine a second subkey using the key;

determine a fourth number of secondary users required to take the at least one action with respect to the file using the second subkey;

determine a fifth number of total secondary users;

generate, using the second subkey and the fourth number of secondary users, a sixth number of second fragments of data equal to the fifth number of total secondary users, wherein the sixth number of the second fragments of data are generated such that a second set of the sixth number of the second fragments of data can be used to reconstruct the second subkey, the sixth number of second fragments including a third data fragment; and

send the third data fragment and the identifier to a third client device to configure the third client device to send the third data fragment to the first client device in response to receipt by the third client device of the identifier displayed by the first client device.

18. The at least one non-transitory computer-readable medium of claim 17 , wherein, the sixth number of the second fragments of data further include at least a fourth data fragment, and the at least one computer-readable medium is further encoded with additional instructions which, when executed by the at least one processor, further cause the system to:

send the fourth data fragment and the identifier to a fourth client device to configure the fourth client device to send the fourth data fragment to the first client device in response to receipt by the fourth client device of the identifier displayed by the first client device.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2020
From: DHANABALAN, PRAVEEN RAJA; ATHLUR, ANUDEEP; MAGAZINE, ANUJ
To: CITRIX SYSTEMS, INC.
Reel/Frame 053355/0656 →
Priority Claims (1)
IN 202041025496 · Jun 17, 2020 · national
Continuity (1)
Related Publication 20210399886A1 · Dec 23, 2021