IP Library › Granted Patent US 9,912,645
Granted Patent B2
US 9,912,645 · App. 15/198,508 · Granted Mar 6, 2018

Methods and apparatus to securely share data

Inventors: Ned M. Smith (Beaverton, OR); Omer Ben-Shalom (Rishon Le-Zion, IL); Alex Nayshtut (Gan Yavne, IL)
Assignee: Intel Corporation
H04L63/0428G06F21/6218H04L9/30H04L63/083H04L63/10H04L67/10H04L67/12H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,912,645
App. No.
15/198,508
Granted
Mar 6, 2018
Kind
B2
Abstract

Methods and apparatus to securely share data are disclosed. An example includes retrieving, by executing an instruction with a processor at a first computing device associated with a first user of a cloud service, an encrypted archive file and a wrapped encryption key from a second computing device associated with a second user of the cloud service, the wrapped encryption key wrapped with key data associated with the first user of the cloud service at the second computing device, unwrapping the wrapped encryption key with the key data to obtain an unwrapped encryption key, and decrypting the encrypted archive file with the unwrapped encryption key to obtain a decrypted archive file.

Claims (49)

1. A first computing device associated with a first user of a cloud service, comprising:

a processor;

a trusted execution environment to:

retrieve an encrypted archive file and a wrapped encryption key from a second computing device associated with a second user of the cloud service, the wrapped encryption key wrapped with key data associated with the first user of the cloud service at the second computing device, the encrypted archive file provisioned with the wrapped encryption key; and

unwrap the wrapped encryption key with the key data to obtain an unwrapped encryption key; and

an encryption engine to decrypt the encrypted archive file with the unwrapped encryption key to obtain a first archive file representative of first data from the second computing device, the first archive file to be mounted to an operating system (OS) of the first computing device thereby exposing the first data of the first archive file to an OS file system of the first computing device as a virtual drive, at least one of the encryption engine, and the trusted execution environment implemented using the processor.

2. The first computing device as defined in claim 1 , wherein the key data associated with the first user of the cloud service is at least one of a private key generated based on a password associated with the first user of the cloud service or a public key associated with the first user.

3. The first computing device as defined in claim 1 , further including a mount point to mount the first archive file to the operating system of the first computing device.

4. The first computing device as defined in claim 3 , wherein the operating system of the first computing device is different from an operating system of the second computing device.

5. A method, comprising:

retrieving, by executing an instruction with a processor at a first computing device associated with a first user of a cloud service, an encrypted archive file and a wrapped encryption key from a second computing device associated with a second user of the cloud service, the wrapped encryption key wrapped with key data associated with the first user of the cloud service at the second computing device, the encrypted archive file provisioned with the wrapped encryption key;

unwrapping, by executing an instruction with the processor, the wrapped encryption key with the key data to obtain an unwrapped encryption key; and

decrypting, by executing an instruction with the processor, the encrypted archive file with the unwrapped encryption key to obtain a decrypted archive file, the decrypted archive file to be mounted, by executing an instruction with the processor, to an operating system (OS) of the first computing device thereby exposing data of the decrypted archive file to an OS file system of the first computing device as a virtual drive.

6. A first computing device associated with a first user of a cloud service, comprising:

a processor;

a trusted execution environment to:

retrieve an encrypted archive file and a wrapped encryption key from a second computing device associated with a second user of the cloud service, the wrapped encryption key wrapped with first key data associated with the first user of the cloud service at the second computing device; and

unwrap the wrapped encryption key with the first key data to obtain an unwrapped encryption key; and

an encryption engine to decrypt the encrypted archive file with the unwrapped encryption key to obtain a first archive file representative of first data from the second computing device;

wherein the encrypted archive file is a first encrypted archive file, the wrapped encryption key is a first wrapped encryption key, and further including an archive generator to generate a second archive file representative of second data from the first computing device, the encryption engine to encrypt the second archive file with a second encryption key to form a second encrypted archive file, and the trusted execution environment to wrap the second encryption key with second key data associated with the second user of the cloud service to form a second wrapped encryption key, and the trusted execution environment is to provision the second encrypted archive file with the second wrapped encryption key; and

a communicator to convey the provisioned, second encrypted archive file to the second computing device, the second encrypted archive file to be decrypted by the second computing device based on the second wrapped encryption key to obtain the second archive file, the second archive file to be mounted to an operating system of the second computing device, at least one of the encryption engine, the trusted execution environment and the communicator implemented using the processor.

7. The method as defined in claim 5 , wherein the operating system of the first computing device is different from a second operating system of the second computing device.

8. The method as defined in claim 7 , wherein the key data associated with the first user of the cloud service is at least one of a private key generated based on a password associated with the first user of the cloud service or a public key associated with the first user.

9. A method, comprising:

retrieving, by executing an instruction with a processor at a first computing device associated with a first user of a cloud service, an encrypted archive file and a wrapped encryption key from a second computing device associated with a second user of the cloud service, the wrapped encryption key wrapped with first key data associated with the first user of the cloud service at the second computing device;

unwrapping, by executing an instruction with the processor, the wrapped encryption key with the first key data to obtain an unwrapped encryption key; and

decrypting, by executing an instruction with the processor, the encrypted archive file with the unwrapped encryption key to obtain a decrypted archive file;

wherein the encrypted archive file is a first encrypted archive file, the wrapped encryption key is a first wrapped encryption key, and further including:

generating a second archive file representative of data from the first computing device;

encrypting the second archive file with an encryption key to form a second encrypted archive file; and

wrapping the encryption key with second key data associated with the second user of the cloud service to form a second wrapped encryption key;

provisioning the second encrypted archive file with the second wrapped encryption key; and

conveying the provisioned, second encrypted archive file to the second computing device, the second encrypted archive file to be decrypted by the second computing device based on the second wrapped encryption key to obtain the second archive file, the second archive file to be mounted to an operating system of the second computing device.

10. At least one tangible computer readable storage medium comprising instructions that, when executed, cause a first computing device associated with a first user of a cloud service to at least:

retrieve a first encrypted archive file and a first wrapped encryption key from a second computing device associated with a second user of the cloud service, the first wrapped encryption key wrapped with key data associated with the first user of the cloud service at the second computing device, the first encrypted archive file provisioned with the first wrapped encryption key;

unwrap the first wrapped encryption key with the key data to obtain an unwrapped encryption key; and

decrypt the first encrypted archive file with the unwrapped encryption key to obtain a first archive file representative of first data from the second computing device, the first archive file to be mounted to an operating system (OS) of the first computing device thereby exposing the first data of the first archive file to an OS file system of the first computing device as a virtual drive.

11. The at least one storage medium as defined in claim 10 , wherein the key data associated with the first user of the cloud service is at least one of a private key generated based on a password associated with the first user of the cloud service or a public key associated with the first user.

12. The at least one storage medium as defined in claim 10 , wherein the operating system of the first computing device is different from an operating system of the second computing device.

13. At least one tangible computer readable storage medium comprising instructions that, when executed, cause a first computing device associated with a first user of a cloud service to at least:

retrieve an encrypted archive file and a wrapped encryption key from a second computing device associated with a second user of the cloud service, the wrapped encryption key wrapped with first key data associated with the first user of the cloud service at the second computing device;

unwrap the wrapped encryption key with the first key data to obtain an unwrapped encryption key; and

decrypt the encrypted archive file with the unwrapped encryption key to obtain a first archive file representative of first data from the second computing device;

wherein the encrypted archive file is a first encrypted archive file, the wrapped encryption key is a first wrapped encryption key, and where the instructions, when executed, cause the first computing device to:

generate a second archive file representative of second data from the first computing device;

encrypt the second archive file with an encryption key to form a second encrypted archive file; and

wrap the encryption key with second key data associated with the second user of the cloud service to form a second wrapped encryption key;

provision the second encrypted archive file with the second wrapped encryption key; and

convey the provisioned, second encrypted archive file to the second computing device, the provisioned second encrypted archive file to be decrypted by the second computing device based on the second wrapped encryption key to obtain the second archive file, the second archive file to be mounted to an operating system of the second computing device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2016
From: SMITH, NED M.; BEN-SHALOM, OMER; NAYSHTUT, ALEX
To: INTEL CORPORATION
Reel/Frame 040221/0961 →
Continuity (2)
Continuation 14230618 · Mar 31, 2014
Related Publication 20160315917A1 · Oct 27, 2016