Peer-to-peer network information storage
Abstract
In a typical peer-to-peer network, any user of the peer-to-peer network may request a lookup of a key and its associated value. To limit access to a stored key-value pair, a user node may register a key-value pair in a peer-to-peer network associated with an access list listing those user nodes which are authorized to access the key-value pair. The access list may include one or more retrieval identifiers. To further secure the information, the retrieval identifiers and/or the payload may be encrypted. To allow the retrieving user to decrypt an encrypted payload, the payload may be encrypted using a group key associated with the stored key-value pair. The group key may be encrypted using a key known to the retrieving user.
Claims
exact text as granted — not AI-modified1 . A system configured to form and protect a key-value pair, the system comprising:
a computer; a crypto service module implemented by the computer and configured to encrypt a payload using a group key, and to encrypt the group key using a public key of a device authorized to retrieve the key-value pair; and a registration process implemented by the computer and configured to generate the group key, and a registration key that uniquely identifies the computer, and an access list that includes a pair comprising the encrypted group key and a unique identifier of the authorized device, and to form the key-value pair by pairing the registration key and data that includes the access list and the encrypted payload.
2 . The system of claim 1 further comprising the registration process further configured for constructing a registration message comprising the key-value pair, and for registering the key-value pair with a network by sending the registration message to nodes of the network.
3 . The system of claim 2 wherein the registered key-value pair is stored in at least one of the nodes of the network.
4 . The system of claim 1 wherein the registration key corresponds to a user of the computer.
5 . The system of claim 1 wherein the unique identifier indicates that the authorized device is authorized by the computer to retrieve the key-value pair.
6 . The system of claim 1 wherein the unique identifier is derived from a key corresponding to the authorized device.
7 . The system of claim 1 wherein the network is a peer-to-peer network.
8 . A method of forming and protecting a key-value pair, the method comprising:
generating, by a computer, a group key; encrypting a payload using the group key; encrypting the group key using a public key of a device authorized to retrieve the key-value pair; and generating, by a computer, a registration key that uniquely identifies the computer; generating an access list that includes a pair comprising the encrypted group key and a unique identifier of the authorized device; and forming the key-value pair by pairing the registration key and data that includes the access list and the encrypted payload.
9 . The method of claim 8 further comprising:
constructing a registration message comprising the key-value pair; and
registering the key-value pair of the registration message with a network.
10 . The method of claim 9 wherein the registered key-value pair is stored in a distributed hash table of at least one node of the network.
11 . The method of claim 8 wherein the registration key corresponds to a user of the computer.
12 . The method of claim 8 wherein the unique identifier indicates that the authorized device is authorized by the computer to retrieve the key-value pair.
13 . The method of claim 8 wherein the unique identifier is derived from a key corresponding to the authorized device.
14 . The method of claim 8 wherein the network is a peer-to-peer network.
15 . At least one computer storage medium that includes instructions that, when executed by a computer, cause the computer to perform a method of forming and protecting a key-value pair, the method comprising:
generating a group key; encrypting a payload using the group key; encrypting the group key using a public key of a device authorized to retrieve the key-value pair; and generating a registration key that uniquely identifies the computer; generating an access list that includes a pair comprising the encrypted group key and a unique identifier of the authorized device; and forming the key-value pair by pairing the registration key and data that includes the access list and the encrypted payload.
16 . The at least one computer storage medium of claim 8 , the method further comprising:
constructing a registration message comprising the key-value pair; and registering the key-value pair of the registration message with a network.
17 . The at least one computer storage medium of claim 16 wherein the registered key-value pair is stored in a distributed hash table of at least one node of the network.
18 . The at least one computer storage medium of claim 15 wherein the registration key corresponds to a user of the computer.
19 . The at least one computer storage medium of claim 15 wherein the unique identifier indicates that the authorized device is authorized by the computer to retrieve the key-value pair.
20 . The at least one computer storage medium of claim 15 wherein the unique identifier is derived from a key corresponding to the authorized device.Join the waitlist — get patent alerts
Track US2011047380A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.