IP Library › Granted Patent US 12,189,823
Granted Patent B1
US 12,189,823 · App. 18/120,992 · Granted Jan 7, 2025

Secure online collaboration

Inventor: Luke Ernest Camery (New York, NY)
Assignee: Google LLC
G06F21/6272H04L9/0822H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,189,823
App. No.
18/120,992
Granted
Jan 7, 2025
Kind
B1
Abstract

A method for secure online collaboration is provided. The method includes receiving, at a server of a cloud-based storage system, an encrypted edit from a first client device. The cloud-based storage system stores a plurality of documents in an encrypted form. The method also includes determining a document of the plurality of documents that is associated with the encrypted edit. The server is unable to decrypt both the document in the encrypted form and the encrypted edit. The method further includes determining a plurality of user accounts of collaborators of the document. The plurality of user accounts includes a first user account associated with the first client device. The method further includes providing the encrypted edit to one or more other client devices that are each associated with one of the plurality of user accounts.

Claims (68)

1. A method comprising:

receiving, at a first server of a cloud-based storage system that stores a plurality of documents in an encrypted form, an edit encrypted using a data encryption key associated with a second server that is independent from the first server;

determining, at the first server, which document of the plurality of documents stored in the encrypted form is associated with the encrypted edit, wherein the first server is unable to decrypt both the document in the encrypted form and the encrypted edit encrypted using the data encryption key;

determining, at the first server, a plurality of user accounts of collaborators of the document, the plurality of user accounts comprising a first user account associated with a first client device; and

providing, by the first server, the encrypted edit to one or more other client devices that are each associated with one of the plurality of user accounts.

2. The method of claim 1 , further comprising:

receiving, from the first client device, the data encryption key encrypted based on a key encryption key, wherein the key encryption key is not accessible to the first server; and

providing the encrypted data encryption key to the one or more other client devices.

3. The method of claim 2 , wherein the key encryption key is provided by the second server that is not in communication with the first server and is in communication with the first client device and the one or more other client devices.

4. The method of claim 2 , further comprising:

configuring a second user account from the plurality of user accounts of collaborators to coordinate with the first server for collaborative editing of the document, wherein a second client device associated with the second user account is to combine edits to the document made by the collaborators in a chronological order and generate encrypted data based on the combined edits.

5. The method of claim 4 , wherein:

the determining of the plurality of user accounts of collaborators of the document comprises determining that the first user account corresponds to a user account other than the second user account; and

the providing of the encrypted data encryption key comprises providing the encrypted edit to the second client device that is associated with the second user account, the second client device being one of the one or more other client devices.

6. The method of claim 4 , wherein:

the determining of the plurality of user accounts of collaborators of the document comprises determining that the first user account corresponds to the second user account; and

the providing of the encrypted data encryption key comprises providing the encrypted edit to the one or more other client devices that are each associated with one of the plurality of user accounts other than the second user account, wherein the encrypted edit corresponds to the encrypted data.

7. The method of claim 3 , wherein the first client device is to perform operations comprising:

generating the data encryption key;

encrypting the edit based on the data encryption key;

obtaining the encrypted data encryption key based on encryption of the data encryption key using the key encryption key provided by the second server; and

providing the encrypted edit with the encrypted data encryption key to the first server.

8. A non-transitory computer readable storage medium comprising instructions for a server that, when executed by a processing device, cause the processing device to perform operations comprising:

receiving, at a first server of a cloud-based storage system that stores a plurality of documents in an encrypted form, an edit encrypted using a data encryption key associated with a second server that is independent from the first server;

determining, at the first server, which document of the plurality of documents stored in the encrypted form is associated with the encrypted edit, wherein the first server is unable to decrypt both the document in the encrypted form and the encrypted edit encrypted using the data encryption key;

determining, at the first server, a plurality of user accounts of collaborators of the document, the plurality of user accounts comprising a first user account associated with a first client device; and

providing, by the first server, the encrypted edit to one or more other client devices that are each associated with one of the plurality of user accounts.

9. The non-transitory computer readable storage medium of claim 8 , the operations further comprising:

receiving, from the first client device, the data encryption key encrypted based on a key encryption key, wherein the key encryption key is not accessible to the first server; and

providing the encrypted data encryption key to the one or more other client devices.

10. The non-transitory computer readable storage medium of claim 9 , wherein the key encryption key is provided by the second server that is not in communication with the first server and is in communication with the first client device and the one or more other client devices.

11. The non-transitory computer readable storage medium of claim 9 , the operations further comprising:

configuring a second user account from the plurality of user accounts of collaborators to coordinate with the first server for collaborative editing of the document, wherein a second client device associated with the second user account is to combine edits to the document made by the collaborators in a chronological order and generate encrypted data based on the combined edits.

12. The non-transitory computer readable storage medium of claim 11 , wherein:

the determining of the plurality of user accounts of collaborators of the document comprises determining that the first user account corresponds to a user account other than the second user account; and

the providing of the encrypted data encryption key comprises providing the encrypted edit to the second client device that is associated with the second user account, the second client device being one of the one or more other client devices.

13. The non-transitory computer readable storage medium of claim 11 , wherein:

the determining of the plurality of user accounts of collaborators of the document comprises determining that the first user account corresponds to the second user account; and

the providing of the encrypted data encryption key comprises providing the encrypted edit to the one or more other client devices that are each associated with one of the plurality of user accounts other than the second user account, wherein the encrypted edit corresponds to the encrypted data.

14. The non-transitory computer readable storage medium of claim 10 , wherein the first client device is to perform operations comprising:

generating the data encryption key;

encrypting the edit based on the data encryption key;

obtaining the encrypted data encryption key based on encryption of the data encryption key using the key encryption key provided by the second server; and

providing the encrypted edit with the encrypted data encryption key to the first server.

15. A system comprising:

a memory; and

a processing device, coupled to the memory, to perform operations comprising:

receiving, at a first server of a cloud-based storage system that stores a plurality of documents in an encrypted form, an edit encrypted using a data encryption key associated with a second server that is independent from the first server;

determining, at the first server, which document of the plurality of documents stored in the encrypted form is associated with the encrypted edit, wherein the first server is unable to decrypt both the document in the encrypted form and the encrypted edit encrypted using the data encryption key;

determining, at the first server, a plurality of user accounts of collaborators of the document, the plurality of user accounts comprising a first user account associated with a first client device; and

providing, by the first server, the encrypted edit to one or more other client devices that are each associated with one of the plurality of user accounts.

16. The system of claim 15 , the operations further comprising:

receiving, from the first client device, the data encryption key encrypted based on a key encryption key, wherein the key encryption key is not accessible to the first server; and

providing the encrypted data encryption key to the one or more other client devices.

17. The system of claim 15 , wherein the key encryption key is provided by the second server that is not in communication with the first server and is in communication with the first client device and the one or more other client devices.

18. The system of claim 16 , the operations further comprising:

configuring a second user account from the plurality of user accounts of collaborators to coordinate with the first server for collaborative editing of the document, wherein a second client device associated with the second user account is to combine edits to the document made by the collaborators in a chronological order and generate encrypted data based on the combined edits.

19. The system of claim 18 , wherein:

the determining of the plurality of user accounts of collaborators of the document comprises determining that the first user account corresponds to a user account other than the second user account; and

the providing of the encrypted data encryption key comprises providing the encrypted edit to the second client device that is associated with the second user account, the second client device being one of the one or more other client devices.

20. The system of claim 18 , wherein:

the determining of the plurality of user accounts of collaborators of the document comprises determining that the first user account corresponds to the second user account; and

the providing of the encrypted data encryption key comprises providing the encrypted edit to the one or more other client devices that are each associated with one of the plurality of user accounts other than the second user account, wherein the encrypted edit corresponds to the encrypted data.

21. The system of claim 17 , wherein the first client device is to perform operations comprising:

generating the data encryption key;

encrypting the edit based on the data encryption key;

obtaining the encrypted data encryption key based on encryption of the data encryption key using the key encryption key provided by the second server; and

providing the encrypted edit with the encrypted data encryption key to the first server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2023
From: CAMERY, LUKE ERNEST
To: GOOGLE LLC
Reel/Frame 063320/0242 →
Continuity (1)
Continuation 16546017 · Aug 20, 2019
References Cited (24)
US 8321688B2 · Auradkar · 2012 [cited by applicant]
US 9590958B1 · Howell · 2017 [cited by applicant]
US 10007809B1 · Douglis · 2018 [cited by applicant]
US 11604898B2 · Camery · 2023 [cited by examiner]
US 20060133617A1 · Minamizawa · 2006 [cited by applicant]
US 20120185759A1 · Balinsky · 2012 [cited by applicant]
US 20130007464A1 · Madden · 2013 [cited by applicant]
US 20130159695A1 · Chiueh et al. · 2013 [cited by applicant]
US 20140115332A1 · Crosbie · 2014 [cited by applicant]
US 20150312227A1 · Follis et al. · 2015 [cited by applicant]
US 20170070506A1 · Reddy · 2017 [cited by applicant]
US 20180048464A1 · Lim · 2018 [cited by applicant]
US 20180062852A1 · Schmahmann · 2018 [cited by applicant]
CN 102318262A · 2012 [cited by applicant]
CN 104303157A · 2015 [cited by applicant]
CN 107040577A · 2017 [cited by applicant]
CN 109462644A · 2019 [cited by applicant]
CN 109714155A · 2019 [cited by applicant]
WO 2018213871A1 · 2018 [cited by applicant]
Wikipedia, ““Key Wrap”” Oct. 24, 2016 {Oct. 24, 2016). XP055733906, Retrieved from the Internet: URL: https:J/en.wikipedia.org/w/index.phptitle=Key_Wrap oldid=745981622, [retrieved on Sep. 25, 2020], 2 pages. [cited by applicant]
Wikipedia, “Collaborative real-time editor” Aug. 7, 2019 {Aug. 7, 2019), XP055733909, Retrieved from the Internet: URL: https:J/en.wikipedia.org/w/index.phptitle=Collaborative_real-time_editor oldid=909827932, [retrieve… [cited by applicant]
PCT International Search Report and Written Opinion for International Application No. PCT/US2020/047108, mailed Oct. 6, 2020 16 pages. [cited by applicant]
Zimmerman, Jonathan, “End-to-End Encryption (E2EE) for Dropbox, Google Drive and Co.,” https://www.boxcryptor.com/en/blog/post/end-to-end-encryption-e2ee-for-dropbox-google-drive-and-co/, Jun. 13, 2019, 2 pages. [cited by applicant]
Office Action for Chinese Patent Application No. 202080007799.0, mailed Apr. 2, 2024, 36 Pages. [cited by applicant]
Cited By (3)
US 12,493,705 US 12,505,239 US 12,608,087