IP Library › Granted Patent US 12,547,758
Granted Patent B1
US 12,547,758 · App. 18/210,591 · Granted Feb 10, 2026

System, method, and computer program for transmitting data between a backup system and an external application using an encryption proxy within a customer-controlled data perimeter

Inventors: Sovane Bin (San Francisco, CA); Francois Lopitaux (San Carlos, CA); Arnaud Treps (Paris, FR); Remi Poujeaux (Rueil-Malmaison, FR); Saddek Dekoum (Ris-Orangis, FR); Arnaud Deronne (Castelnau le Iez, FR); Maxime Aubanel (Toulouse, FR); Julien Carmigani (Sèvres, FR)
Assignee: Odaseva Technologies SAS
G06F21/6236G06F11/1469G06F21/602H04L9/0618G06F2201/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,547,758
App. No.
18/210,591
Granted
Feb 10, 2026
Kind
B1
Abstract

The present disclosure describes a system, method, and computer program for transmitting data between a backup system and an external application using an encryption proxy that is within a customer-controlled data perimeter. The encryption proxy virtually resides within a customer-controlled data perimeter and acts as an intermediary between the external application and backup system. The backup system is outside the customer-controlled data perimeter. Data is transferred between the external application and the backup system to perform backup and recovery operations. The encryption proxy encrypts and decrypts data messages between the external application and the backup application in accordance with configurable data transfer rules. The encryption proxy enables a customer to control which data items are transferred to the backup system in clear text and which data items are encrypted before being forwarded to the backup system. When performing a restore operation, encrypted data items transmitted from the backup application enroute to the external application are converted back to cleartext by the encryption proxy so that they are received as cleartext by the external application.

Claims (68)

1 . A method, performed by a computer system, for transmitting customer data between a backup system and an external application while preventing the backup system from viewing sensitive data at any stage of a backup or restore process, the method comprising:

providing an encryption proxy between a backup system and an external application, wherein the encryption proxy is within a customer-controlled data perimeter and wherein the backup system is outside the customer-controlled data perimeter;

enabling a customer to configure data transfer rules that specify 1) which types of messages transmitted between the backup system and the external application require encryption or decryption and 2) a set of data items in the customer data corresponding to the messages that are permitted in cleartext beyond the customer-controlled data perimeter;

transmitting messages between the external application and the backup system via the encryption proxy, wherein:

when the encryption proxy receives a message with a data payload having data items from the external application for transmission to the backup system, the encryption proxy converts the data items to ciphertext, except for those data items permitted in cleartext beyond the customer-controlled data perimeter per the configurable data transfer rules, before forwarding the message to the backup system; and

when the encryption proxy receives a message from the backup system to the external application having a data payload with one or more data items in ciphertext, the encryption proxy converts said data items from ciphertext to cleartext before forwarding the message to the external application.

2 . The method of claim 1 , wherein transmitting a message from the backup system to the external application via the encryption proxy comprises the following steps:

receiving a message at the encryption proxy from the backup system and intended for the external application;

determining whether the message requires any decryption based on the configurable data transfer rules;

if the configurable data transfer rules indicate that the message does not require decryption, forwarding the message from the encryption proxy to the external application without performing any decryption on the message;

if the configurable data transfer rules indicate that the message requires decryption, performing the following:

identifying a plurality of ciphertext data items in the message that require decryption based on the configurable data transfer rules;

decrypting the identified data items to transform the plurality of ciphertext data items to cleartext; and

transmitting the message to the external application with the cleartext data items.

3 . The method of claim 1 , wherein transmitting a message from the external application to the backup system via the encryption proxy comprises the following steps:

receiving a message at the encryption proxy that is transmitted from the external application and intended for the backup system;

determining whether the message requires any encryption based on configurable data transfer rules;

if the configurable data transfer rules indicate that the message does not require encryption, forwarding the message from the encryption proxy to the backup system without performing any encryption on the message; and

if the configurable data transfer rules indicate that the message requires encryption, performing the following:

identifying a plurality of data items in the message that are permitted in cleartext beyond the customer-controlled data perimeter;

encrypting all the data items in the message except for the identified plurality of data items; and

transmitting the message to the backup system.

4 . A non-transitory computer-readable medium comprising a computer program, that, when executed by a computer system, enables the computer system to perform the following steps for transmitting customer data between a backup system and an external application while preventing the backup system from viewing sensitive data at any stage of a backup or restore process, the steps comprising:

providing an encryption proxy between a backup system and an external application, wherein the encryption proxy is within a customer-controlled data perimeter and wherein the backup system is outside the customer-controlled data perimeter;

enabling a customer to configure data transfer rules that specify 1) which types of messages transmitted between the backup system and the external application require encryption or decryption and 2) a set of data items in the customer data corresponding to the messages that are permitted in cleartext beyond the customer-controlled data perimeter;

transmitting messages between the external application and the backup system via the encryption proxy, wherein:

when the encryption proxy receives a message with a data payload having data items from the external application for transmission to the backup system, the encryption proxy converts the data items to ciphertext, except for those data items permitted in cleartext beyond the customer-controlled data perimeter per the configurable data transfer rules, before forwarding the message to the backup system; and

when the encryption proxy receives a message from the backup system to the external application having a data payload with one or more data items in ciphertext, the encryption proxy converts said data items from ciphertext to cleartext before forwarding the message to the external application.

5 . The non-transitory computer-readable medium of claim 4 , wherein transmitting a message from the backup system to the external application via the encryption proxy comprises the following steps:

receiving a message at the encryption proxy from the backup system and intended for the external application;

determining whether the message requires any decryption based on the configurable data transfer rules;

if the configurable data transfer rules indicate that the message does not require decryption, forwarding the message from the encryption proxy to the external application without performing any decryption on the message;

if the configurable data transfer rules indicate that the message requires decryption, performing the following:

identifying a plurality of ciphertext data items in the message that require decryption based on the configurable data transfer rules;

decrypting the identified data items to transform the plurality of ciphertext data items to cleartext; and

transmitting the message to the external application with the cleartext data items.

6 . The non-transitory computer-readable medium of claim 4 , wherein transmitting a message from the external application to the backup system via the encryption proxy comprises the following steps:

receiving a message at the encryption proxy that is transmitted from the external application and intended for the backup system;

determining whether the message requires any encryption based on configurable data transfer rules;

if the configurable data transfer rules indicate that the message does not require encryption, forwarding the message from the encryption proxy to the backup system without performing any encryption on the message; and

if the configurable data transfer rules indicate that the message requires encryption, performing the following:

identifying a plurality of data items in the message that are permitted in cleartext beyond the customer-controlled data perimeter;

encrypting all the data items in the message except for the identified plurality of data items; and

transmitting the message to the backup system.

7 . A computer system for transmitting customer data between a backup system and an external application while preventing the backup system from viewing sensitive data at any stage of a backup or restore process, the system comprising:

one or more processors;

one or more memory units coupled to the one or more processors, wherein the one or more memory units store instructions that, when executed by the one or more processors, cause the system to perform the operations of:

providing an encryption proxy between a backup system and an external application, wherein the encryption proxy is within a customer-controlled data perimeter and wherein the backup system is outside the customer-controlled data perimeter;

enabling a customer to configure data transfer rules that specify 1) which types of messages transmitted between the backup system and the external application require encryption or decryption and 2) a set of data items in the customer data corresponding to the messages that are permitted in cleartext beyond the customer-controlled data perimeter;

transmitting messages between the external application and the backup system via the encryption proxy, wherein:

when the encryption proxy receives a message with a data payload having data items from the external application for transmission to the backup system, the encryption proxy converts the data items to ciphertext, except for those data items permitted in cleartext beyond the customer-controlled data perimeter per the configurable data transfer rules, before forwarding the message to the backup system; and

when the encryption proxy receives a message from the backup system to the external application having a data payload with one or more data items in ciphertext, the encryption proxy converts said data items from ciphertext to cleartext before forwarding the message to the external application.

8 . The system of claim 7 , wherein transmitting a message from the backup system to the external application via the encryption proxy comprises the following steps:

receiving a message at the encryption proxy from the backup system and intended for the external application;

determining whether the message requires any decryption based on the configurable data transfer rules;

if the configurable data transfer rules indicate that the message does not require decryption, forwarding the message from the encryption proxy to the external application without performing any decryption on the message;

if the configurable data transfer rules indicate that the message requires decryption, performing the following:

identifying a plurality of ciphertext data items in the message that require decryption based on the configurable data transfer rules;

decrypting the identified data items to transform the plurality of ciphertext data items to cleartext; and

transmitting the message to the external application with the cleartext data items.

9 . The system of claim 7 , wherein transmitting a message from the external application to the backup system via the encryption proxy comprises the following steps:

receiving a message at the encryption proxy that is transmitted from the external application and intended for the backup system;

determining whether the message requires any encryption based on configurable data transfer rules;

if the configurable data transfer rules indicate that the message does not require encryption, forwarding the message from the encryption proxy to the backup system without performing any encryption on the message; and

if the configurable data transfer rules indicate that the message requires encryption, performing the following:

identifying a plurality of data items in the message that are permitted in cleartext beyond the customer-controlled data perimeter;

encrypting all the data items in the message except for the identified plurality of data items; and

transmitting the message to the backup system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2023
From: BIN, SOVANE; LOPITAUX, FRANCOIS; TREPS, ARNAUD; POUJEAUX, REMI; DEKOUM, SADDEK; DERONNE, ARNAUD; AUBANEL, MAXIME; CARMIGANI, JULIEN
To: ODASEVA TECHNOLOGIES SAS
Reel/Frame 065375/0241 →
References Cited (111)
US 6642946B1 · Janes et al. · 2003 [cited by applicant]
US 8078645B2 · Singh · 2011 [cited by applicant]
US 8255320B1 · Seal et al. · 2012 [cited by applicant]
US 8667273B1 · Billstrom et al. · 2014 [cited by applicant]
US 8775328B1 · Abhyanker · 2014 [cited by applicant]
US 9268587B2 · Kruglick · 2016 [cited by applicant]
US 9288184B1 · Kvamme et al. · 2016 [cited by applicant]
US 9330301B1 · Ozog · 2016 [cited by applicant]
US 9769131B1 · Hartley et al. · 2017 [cited by applicant]
US 9794064B2 · Anderson · 2017 [cited by examiner]
US 9990511B1 · Dreyfus · 2018 [cited by applicant]
US 10664494B2 · Ding et al. · 2020 [cited by applicant]
US 11055123B1 · Bin et al. · 2021 [cited by applicant]
US 11609774B2 · Bin et al. · 2023 [cited by applicant]
US 12032718B1 · Bin et al. · 2024 [cited by applicant]
US 12056723B1 · Bin et al. · 2024 [cited by applicant]
US 12210640B1 · Bin et al. · 2025 [cited by applicant]
US 12229099B1 · Bin et al. · 2025 [cited by applicant]
US 12235737B1 · Bin et al. · 2025 [cited by applicant]
US 20060150169A1 · Cook et al. · 2006 [cited by applicant]
US 20080016127A1 · Field · 2008 [cited by applicant]
US 20080049942A1 · Sprunk et al. · 2008 [cited by applicant]
US 20080162532A1 · Daga · 2008 [cited by applicant]
US 20080270444A1 · Brodie et al. · 2008 [cited by applicant]
US 20080310633A1 · Brown et al. · 2008 [cited by applicant]
US 20090031230A1 · Kesler · 2009 [cited by applicant]
US 20100079460A1 · Breeds et al. · 2010 [cited by applicant]
US 20120059857A1 · Jackson, Jr. · 2012 [cited by applicant]
US 20120110566A1 · Park · 2012 [cited by applicant]
US 20120117558A1 · Futty et al. · 2012 [cited by applicant]
US 20120246472A1 · Berengoltz et al. · 2012 [cited by applicant]
US 20120254197A1 · Kuzmin · 2012 [cited by applicant]
US 20120324242A1 · Kirsch · 2012 [cited by applicant]
US 20130191780A1 · Holmes et al. · 2013 [cited by applicant]
US 20130227703A1 · Sotos et al. · 2013 [cited by applicant]
US 20130246451A1 · Kaiser · 2013 [cited by applicant]
US 20130283060A1 · Kulkarni et al. · 2013 [cited by applicant]
US 20130297769A1 · Chang et al. · 2013 [cited by applicant]
US 20140040182A1 · Gilder et al. · 2014 [cited by applicant]
US 20140040196A1 · Wijayaratne et al. · 2014 [cited by applicant]
US 20140040197A1 · Wijayaratne et al. · 2014 [cited by applicant]
US 20140101438A1 · Elovici et al. · 2014 [cited by applicant]
US 20140143661A1 · Carreno-Fuentes et al. · 2014 [cited by applicant]
US 20140278534A1 · Romeo · 2014 [cited by applicant]
US 20140344778A1 · Lau et al. · 2014 [cited by applicant]
US 20150019858A1 · Roth · 2015 [cited by examiner]
US 20160019233A1 · Wijayaratne et al. · 2016 [cited by applicant]
US 20160147999A1 · Fontanetta et al. · 2016 [cited by applicant]
US 20160156671A1 · Cabrera · 2016 [cited by examiner]
US 20160277374A1 · Reid et al. · 2016 [cited by applicant]
US 20160308855A1 · Lacey et al. · 2016 [cited by applicant]
US 20170025040A1 · Maturana et al. · 2017 [cited by applicant]
US 20170048252A1 · Straub et al. · 2017 [cited by applicant]
US 20170091293A1 · Cummings et al. · 2017 [cited by applicant]
US 20170249656A1 · Gantner et al. · 2017 [cited by applicant]
US 20180081905A1 · Kamath et al. · 2018 [cited by applicant]
US 20180089270A1 · Qiu et al. · 2018 [cited by applicant]
US 20180150476A1 · Koos et al. · 2018 [cited by applicant]
US 20180176117A1 · Gudetee et al. · 2018 [cited by applicant]
US 20180181613A1 · Acharya et al. · 2018 [cited by applicant]
US 20180232402A1 · Bhatti et al. · 2018 [cited by applicant]
US 20180336209A1 · Burshteyn · 2018 [cited by applicant]
US 20190007206A1 · Surla et al. · 2019 [cited by applicant]
US 20190034509A1 · Ding et al. · 2019 [cited by applicant]
US 20190042988A1 · Brown et al. · 2019 [cited by applicant]
US 20190050925A1 · Hodge et al. · 2019 [cited by applicant]
US 20190303270A1 · Hoermann · 2019 [cited by applicant]
US 20200026532A1 · Bill et al. · 2020 [cited by applicant]
US 20200067772A1 · Tomkins et al. · 2020 [cited by applicant]
US 20200073854A1 · Wijayaratne et al. · 2020 [cited by applicant]
US 20200082890A1 · Karr et al. · 2020 [cited by applicant]
US 20200127937A1 · Busick et al. · 2020 [cited by applicant]
US 20200159700A1 · Wijayaratne et al. · 2020 [cited by applicant]
US 20200183906A1 · Spillane et al. · 2020 [cited by applicant]
US 20200226953A1 · Anand et al. · 2020 [cited by applicant]
US 20200336481A1 · Fan et al. · 2020 [cited by applicant]
US 20200342117A1 · Richards et al. · 2020 [cited by applicant]
US 20200387625A1 · Saad · 2020 [cited by applicant]
US 20210026982A1 · Amarendran et al. · 2021 [cited by applicant]
US 20210049029A1 · Kumble et al. · 2021 [cited by applicant]
US 20210067324A1 · Valente et al. · 2021 [cited by applicant]
US 20210191629A1 · Vibhor et al. · 2021 [cited by applicant]
US 20210255991A1 · Koos et al. · 2021 [cited by applicant]
US 20210255992A1 · Wijayaratne et al. · 2021 [cited by applicant]
US 20210349580A1 · Dentzer · 2021 [cited by applicant]
US 20210365414A1 · Lu et al. · 2021 [cited by applicant]
US 20210365587A1 · Lu et al. · 2021 [cited by applicant]
US 20220067115A1 · Zheng et al. · 2022 [cited by applicant]
US 20220107826A1 · Bin et al. · 2022 [cited by applicant]
US 20220129804A1 · Dooley et al. · 2022 [cited by applicant]
US 20220148084A1 · Baker · 2022 [cited by applicant]
US 20220188334A1 · Chen · 2022 [cited by applicant]
US 20220207489A1 · Gupta et al. · 2022 [cited by applicant]
US 20220263657A1 · Chang et al. · 2022 [cited by applicant]
US 20220269809A1 · Chopra et al. · 2022 [cited by applicant]
US 20220317831A1 · Karis et al. · 2022 [cited by applicant]
US 20230010219A1 · Howley et al. · 2023 [cited by applicant]
US 20230082010A1 · Clifford et al. · 2023 [cited by applicant]
US 20230145349A1 · Watari · 2023 [cited by applicant]
US 20230237034A1 · Garg et al. · 2023 [cited by applicant]
US 20230281305A1 · Savry et al. · 2023 [cited by applicant]
US 20230315694A1 · Koos et al. · 2023 [cited by applicant]
US 20230325360A1 · Wijayaratne et al. · 2023 [cited by applicant]
US 20240012921A1 · Yannuzzi · 2024 [cited by examiner]
US 20240020414A1 · Burns · 2024 [cited by applicant]
US 20240045811A1 · Gurin · 2024 [cited by applicant]
US 20240064020A1 · Kiraz et al. · 2024 [cited by applicant]
US 20240220656A1 · Nozawa et al. · 2024 [cited by applicant]
US 20250165357A1 · Bin et al. · 2025 [cited by applicant]
CA 2634576 · 2008 [cited by applicant]
WO 2022081408 · 2022 [cited by applicant]