US2011047380A1PendingUtilityA1

Peer-to-peer network information storage

Assignee: MICROSOFT CORPPriority: Feb 22, 2005Filed: Nov 1, 2010Published: Feb 24, 2011
Est. expiryFeb 22, 2025(expired)· nominal 20-yr term from priority
Inventors:John Miller
H04L 9/0833H04L 67/104H04L 67/1065H04L 9/0825H04L 63/0428H04L 67/1097H04L 63/102H04L 67/1093
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In a typical peer-to-peer network, any user of the peer-to-peer network may request a lookup of a key and its associated value. To limit access to a stored key-value pair, a user node may register a key-value pair in a peer-to-peer network associated with an access list listing those user nodes which are authorized to access the key-value pair. The access list may include one or more retrieval identifiers. To further secure the information, the retrieval identifiers and/or the payload may be encrypted. To allow the retrieving user to decrypt an encrypted payload, the payload may be encrypted using a group key associated with the stored key-value pair. The group key may be encrypted using a key known to the retrieving user.

Claims

exact text as granted — not AI-modified
1 . A system configured to form and protect a key-value pair, the system comprising:
 a computer;   a crypto service module implemented by the computer and configured to encrypt a payload using a group key, and to encrypt the group key using a public key of a device authorized to retrieve the key-value pair; and   a registration process implemented by the computer and configured to generate the group key, and a registration key that uniquely identifies the computer, and an access list that includes a pair comprising the encrypted group key and a unique identifier of the authorized device, and to form the key-value pair by pairing the registration key and data that includes the access list and the encrypted payload.   
     
     
         2 . The system of  claim 1  further comprising the registration process further configured for constructing a registration message comprising the key-value pair, and for registering the key-value pair with a network by sending the registration message to nodes of the network. 
     
     
         3 . The system of  claim 2  wherein the registered key-value pair is stored in at least one of the nodes of the network. 
     
     
         4 . The system of  claim 1  wherein the registration key corresponds to a user of the computer. 
     
     
         5 . The system of  claim 1  wherein the unique identifier indicates that the authorized device is authorized by the computer to retrieve the key-value pair. 
     
     
         6 . The system of  claim 1  wherein the unique identifier is derived from a key corresponding to the authorized device. 
     
     
         7 . The system of  claim 1  wherein the network is a peer-to-peer network. 
     
     
         8 . A method of forming and protecting a key-value pair, the method comprising:
 generating, by a computer, a group key;   encrypting a payload using the group key;   encrypting the group key using a public key of a device authorized to retrieve the key-value pair; and   generating, by a computer, a registration key that uniquely identifies the computer;   generating an access list that includes a pair comprising the encrypted group key and a unique identifier of the authorized device; and   forming the key-value pair by pairing the registration key and data that includes the access list and the encrypted payload.   
     
     
         9 . The method of  claim 8  further comprising:
 constructing a registration message comprising the key-value pair; and 
 registering the key-value pair of the registration message with a network. 
 
     
     
         10 . The method of  claim 9  wherein the registered key-value pair is stored in a distributed hash table of at least one node of the network. 
     
     
         11 . The method of  claim 8  wherein the registration key corresponds to a user of the computer. 
     
     
         12 . The method of  claim 8  wherein the unique identifier indicates that the authorized device is authorized by the computer to retrieve the key-value pair. 
     
     
         13 . The method of  claim 8  wherein the unique identifier is derived from a key corresponding to the authorized device. 
     
     
         14 . The method of  claim 8  wherein the network is a peer-to-peer network. 
     
     
         15 . At least one computer storage medium that includes instructions that, when executed by a computer, cause the computer to perform a method of forming and protecting a key-value pair, the method comprising:
 generating a group key;   encrypting a payload using the group key;   encrypting the group key using a public key of a device authorized to retrieve the key-value pair; and   generating a registration key that uniquely identifies the computer;   generating an access list that includes a pair comprising the encrypted group key and a unique identifier of the authorized device; and   forming the key-value pair by pairing the registration key and data that includes the access list and the encrypted payload.   
     
     
         16 . The at least one computer storage medium of  claim 8 , the method further comprising:
 constructing a registration message comprising the key-value pair; and   registering the key-value pair of the registration message with a network.   
     
     
         17 . The at least one computer storage medium of  claim 16  wherein the registered key-value pair is stored in a distributed hash table of at least one node of the network. 
     
     
         18 . The at least one computer storage medium of  claim 15  wherein the registration key corresponds to a user of the computer. 
     
     
         19 . The at least one computer storage medium of  claim 15  wherein the unique identifier indicates that the authorized device is authorized by the computer to retrieve the key-value pair. 
     
     
         20 . The at least one computer storage medium of  claim 15  wherein the unique identifier is derived from a key corresponding to the authorized device.

Join the waitlist — get patent alerts

Track US2011047380A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.