IP Library › Granted Patent US 12,273,444
Granted Patent B2
US 12,273,444 · App. 17/496,610 · Granted Apr 8, 2025

Grouping data in an organized storage system

Inventor: Mindaugas Valkaitis (Vilnius, LT)
Assignee: UAB 360 IT
H04L9/0833G06F21/602H04L9/0825H04L9/14H04L9/3073H04L67/1097
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,444
App. No.
17/496,610
Granted
Apr 8, 2025
Kind
B2
Abstract

A method including determining, by a first device, an assigned key pair including an assigned public key and an assigned private key; determining, by the first device for a folder associated with encrypted content, a folder access public key and a folder access private key; determining, by the first device for a group, a group access public key and a group access private key; encrypting, by the first device, the folder access private key by utilizing the assigned public key; encrypting, by the first device, the folder access private key by utilizing the group access public key; and accessing, by a second device, the folder based on decrypting the folder access private key by utilizing the group access private key or based on decrypting the folder access private key by utilizing the assigned private key, the first device being different than the second device. Other aspects are contemplated.

Claims (87)

1. A method, comprising:

determining, by a first device, an assigned key pair associated with an account related to the first device and a second device, the assigned key pair including an assigned public key and an assigned private key;

determining, by the first device for a folder associated with encrypted content, a folder access key pair including a folder access public key and a folder access private key;

determining, by the first device for a group, a group access key pair including a group access public key and a group access private key;

determining, by the first device for respective content, a respective symmetric key and a respective content access key pair associated with encrypting content to determine the encrypted content, the respective content access key pair including a content access public key and a content access private key;

encrypting, by the first device based at least in part on utilizing the respective symmetric key, the respective content to determine the encrypted content;

encrypting, by the first device, the respective symmetric key for the respective content based at least in part on utilizing the content access public key to determine an encrypted symmetric key;

first encrypting, by the first device, the content access private key for the respective content by utilizing the assigned public key to determine a first encrypted content access private key;

second encrypting, by the first device, the content access private key by utilizing the folder access public key to determine a second encrypted content access private key;

encrypting, by the first device, the folder access private key by utilizing the assigned public key to determine a first encrypted folder access private key;

encrypting, by the first device, the folder access private key by utilizing the group access public key to determine a second encrypted folder access private key;

transmitting, by the first device for storage in correlation with the folder, the encrypted symmetric key, the first encrypted content access private key, the second encrypted content access private key, the first encrypted folder access private key, and the second encrypted folder access private key; and

accessing, by the second device, the folder based at least in part on decrypting the first encrypted folder access private key by utilizing the assigned group access-private key or based at least in part on decrypting the second encrypted folder access private key by utilizing the group access private key.

2. The method of claim 1 , further comprising:

encrypting, by the first device, the group access private key by utilizing the assigned public key to determine an encrypted group access private key.

3. The method of claim 1 , further comprising:

decrypting, by the second device, an encrypted group access private key by utilizing the assigned private key.

4. The method of claim 1 , further comprising:

determining, by the first device, a master key based at least in part on a master string of alphanumeric characters;

encrypting, by the first device, the assigned private key by utilizing the master key to determine an encrypted assigned private key; and

encrypting, by the first device, the group access private key by utilizing the assigned public key to determine an encrypted group access private key.

5. The method of claim 1 , further comprising:

determining, by the second device, a master key based at least in part on a master string of alphanumeric characters;

decrypting, by the second device, an encrypted assigned private key by utilizing the master key; and

decrypting, by the second device, an encrypted group access private key by utilizing the assigned private key.

6. The method of claim 1 , further comprising:

decrypting, by the second device, the encrypted content based at least in part on the second device accessing the folder.

7. The method of claim 1 , wherein the group is a virtual group.

8. A system, comprising:

a first device configured to:

determine an assigned key pair associated with an account related to the first device and a second device, the assigned key pair including an assigned public key and an assigned private key;

determine, for a folder associated with encrypted content, a folder access key pair including a folder access public key and a folder access private key;

determine, for a group, a group access key pair including a group access public key and a group access private key;

determine, for respective content, a respective symmetric key and a respective content access key pair associated with encrypting content to determine the encrypted content, the respective content access key pair including a content access public key and a content access private key;

encrypt, based at least in part on utilizing the respective symmetric key, the respective content to determine the encrypted content;

encrypt the respective symmetric key for the respective content based at least in part on utilizing the content access public key to determine an encrypted symmetric key;

first encrypt the content access private key for the respective content by utilizing the assigned public key to determine a first encrypted content access private key;

second encrypt the content access private key by utilizing the folder access public key to determine a second encrypted content access private key;

encrypt the folder access private key by utilizing the assigned public key to determine a first encrypted folder access private key;

encrypt the folder access private key by utilizing the group access public key to determine a second encrypted folder access private key; and

transmit, for storage in correlation with the folder, the encrypted symmetric key, the first encrypted content access private key, the second encrypted content access private key, the first encrypted folder access private key, and the second encrypted folder access private key; and

the second device, different than the first device, configured to:

access the folder based at least in part on decrypting the first encrypted folder access private key by utilizing the assigned private key or based at least in part on decrypting the second encrypted folder access private key by utilizing the group access private key.

9. The system of claim 8 , wherein the first device is configured to:

encrypt the group access private key by utilizing the assigned public key to determine an encrypted group access private key.

10. The system of claim 8 , wherein the second device is configured to:

decrypt an encrypted group access private key by utilizing the assigned private key.

11. The system of claim 8 , wherein the first device is configured to:

determine a master key based at least in part on a master string of alphanumeric characters;

encrypt the assigned private key by utilizing the master key to determine an encrypted assigned private key; and

encrypt the group access private key by utilizing the assigned public key to determine an encrypted group access private key.

12. The system of claim 8 , wherein the second device is configured to:

determine a master key based at least in part on a master string of alphanumeric characters;

decrypt an encrypted assigned private key by utilizing the master key; and

decrypt an encrypted group access private key by utilizing the assigned private key.

13. The system of claim 8 , wherein the second device is configured to:

decrypt the encrypted content based at least in part on the second device accessing the folder.

14. The user system of claim 8 , wherein the group is a virtual group.

15. A non-transitory computer-readable medium configured to store instructions, which

when executed by a first processor associated with a first device, configure the first processor to:

determine an assigned key pair associated with an account related to the first device and a second device, the assigned key pair including an assigned public key and an assigned private key;

determine, for a folder associated with encrypted content, a folder access key pair including a folder access public key and a folder access private key;

determine, for a group, a group access key pair including a group access public key and a group access private key;

determine, for respective content, a respective symmetric key and a respective content access key pair associated with encrypting content to determine the encrypted content, the respective content access key pair including a content access public key and a content access private key;

encrypt, based at least in part on utilizing the respective symmetric key, the respective content to determine the encrypted content;

encrypt the respective symmetric key for the respective content based at least in part on utilizing the content access public key to determine an encrypted symmetric key;

first encrypt the content access private key for the respective content by utilizing the assigned public key to determine a first encrypted content access private key;

second encrypt the content access private key by utilizing the folder access public key to determine a second encrypted content access private key;

encrypt the folder access private key by utilizing the assigned public key to determine a first encrypted folder access private key;

encrypt the folder access private key by utilizing the group access public key to determine a second encrypted folder access private key; and

transmit, for storage in correlation with the folder, the encrypted symmetric key, the first encrypted content access private key, the second encrypted content access private key, the first encrypted folder access private key, and the second encrypted folder access private key; and

when executed by a second processor associated with the second device, different than the first device, configure the second processor to:

access the folder based at least in part on decrypting the first encrypted folder access private key by utilizing the assigned private key or based at least in part on decrypting the second encrypted folder access private key by utilizing the group access private key.

16. The non-transitory computer-readable medium of claim 15 , wherein the first processor is configured to:

encrypt the group access private key by utilizing the assigned public key to determine an encrypted group access private key.

17. The non-transitory computer-readable medium of claim 15 , wherein the second processor is configured to:

decrypt an encrypted group access private key by utilizing the assigned private key.

18. The non-transitory computer-readable medium of claim 15 , wherein the first processor is configured to:

determine a master key based at least in part on a master string of alphanumeric characters;

encrypt the assigned private key by utilizing the master key to determine an encrypted assigned private key; and

encrypt the group access private key by utilizing the assigned public key to determine an encrypted group access private key.

19. The non-transitory computer-readable medium of claim 15 , wherein the second processor is configured to:

determine a master key based at least in part on a master string of alphanumeric characters;

decrypt an encrypted assigned private key by utilizing the master key; and

decrypt an encrypted group access private key by utilizing the assigned private key.

20. The non-transitory computer-readable medium of claim 15 , wherein the second processor is configured to:

decrypt the encrypted content based at least in part on the second device accessing the folder.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2021
From: VALKAITIS, MINDAUGAS
To: UAB 360 IT
Reel/Frame 057908/0955 →
Continuity (2)
Continuation 17485403 · Sep 25, 2021
Related Publication 20230096914A1 · Mar 30, 2023
References Cited (11)
US 5652795A · Dillon · 1997 [cited by examiner]
US 6789195B1 · Prihoda · 2004 [cited by examiner]
US 9397984B1 · Hu · 2016 [cited by applicant]
US 20130254536A1 · Glover · 2013 [cited by examiner]
US 20140115327A1 · Gorbach et al. · 2014 [cited by applicant]
US 20150143107A1 · Kale · 2015 [cited by examiner]
US 20160080149A1 · Mehta · 2016 [cited by examiner]
US 20180183777A1 · Guillory · 2018 [cited by examiner]
US 20230098739A1 · Valkaitis · 2023 [cited by examiner]
US 20230101213A1 · Trivedi · 2023 [cited by examiner]
WO WO2001052473A1 · 2004 [cited by examiner]