US2013212405A1PendingUtilityA1
Secure data parser method and system
Est. expirySep 20, 2019(expired)· nominal 20-yr term from priority
G06F 2221/2115G06F 21/32H04L 2209/56G06Q 20/12H04L 63/0853H04L 2209/805H04L 63/0428H04L 2209/68G06F 21/31H04L 9/3247H04L 9/3231G06F 21/33G06F 21/60G06Q 20/3823H04L 63/105H04L 9/3263G06F 21/62G06F 21/41G07F 7/1016H04L 9/0816G06Q 20/04G06Q 20/02G06F 21/602G06F 2221/2117H04L 63/10G06Q 20/3829H04L 9/0894H04L 9/085H04L 2209/24G06F 2221/2113G06F 21/40G06Q 20/38215
55
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
The present invention provides a method and system for securing sensitive data from unauthorized access or use. The method and system of the present invention is useful in a wide variety of settings, including commercial settings generally available to the public which may be extremely large or small with respect to the number of users. The method and system of the present invention is also useful in a more private setting, such as with a corporation or governmental agency, as well as between corporation, governmental agencies or any other entity.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of securely storing data in a network, the method comprising:
receiving data from a client device; splitting the data into a predetermined number of secondary units of data by performing a cryptographic operation on the data and causing the secondary units of data to be substantially randomly distributed in a plurality of shares; encrypting the plurality of shares with a corresponding number of different keys; and storing the plurality of shares and the different keys used to encrypt the shares to one or more physical storage devices.
2 . The method of claim 1 , wherein the encrypted plurality of shares are associated with a workgroup of a user capable of accessing the data.
3 . The method of claim 2 , further comprising storing a workgroup encryption key on a key management server.
4 . The method of claim 1 , wherein the plurality of shares contain a substantially random distribution of the data in at least one secondary unit of data.
5 . The method of claim 1 , wherein the data is restorable from at least two of the plurality of shares.
6 . The method of claim 1 , wherein storing the plurality of shares comprises storing each of the plurality of shares in a different physical storage device.
7 . A method of securing data in a network, the method comprising:
receiving at a secure storage appliance data for storage on a volume, the volume associated with a plurality of shares distributed across a plurality of physical storage devices; splitting the data received by the secure storage appliance into a plurality of secondary data units by performing a cryptographic operation on the data and causing the secondary data units to be substantially randomly distributed in the plurality of shares; and encrypting each of the plurality of secondary data units with a different key, each key associated with at least one of the plurality of shares.
8 . The method of claim 7 , further comprising storing each secondary data unit remotely from the secure storage appliance.
9 . The method of claim 8 , further comprising storing each key locally to the secure storage appliance.
10 . The method of claim 7 , further comprising, upon initializing the secure storage appliance, retrieving one or more of the different keys from a remote physical storage device for use by the secure storage appliance.
11 . The method of claim 7 , wherein the data is received from a client device.
12 . The method of claim 7 , wherein the encrypted plurality of secondary data units are associated with a workgroup of a user capable of accessing the data.
13 . The method of claim 7 , wherein the plurality of secondary data units contain a substantially random distribution of the data.
14 . The method of claim 7 , wherein the data is restorable from at least two of the plurality of secondary data units.
15 . A secure storage appliance comprising a programmable circuit configured to execute program instructions which, when executed, configure the secure storage appliance to:
receive from a client device data for storage on a volume, the volume associated with a plurality of shares distributed across a plurality of physical storage devices; split the data into a plurality of secondary data units by performing a cryptographic operation on the data and causing the secondary data units to be substantially randomly distributed in the plurality of shares; and encrypt each of the plurality of secondary data units with a different key, each key associated with at least one of the plurality of shares.
16 . The secure storage appliance of claim 15 further configured to transmit each secondary data unit remote from the secure storage appliance.
17 . The secure storage appliance of claim 15 , wherein the encrypted plurality of secondary data units are associated with a workgroup of a user capable of accessing the data.
18 . The secure storage appliance of claim 15 , wherein the plurality of secondary data units contain a substantially random distribution of the data.
19 . The secure storage appliance of claim 15 , wherein the data is restorable from at least two of the plurality of secondary data units.
20 . A secure data storage network comprising:
a client device; a plurality of physical storage devices; a secure storage appliance communicatively connected to the client device and the plurality of physical storage devices, the secure storage appliance including a programmable circuit configured to execute program instructions which, when executed, cause the secure storage appliance to:
receive from the client device data for storage on a volume, the volume associated with a plurality of shares distributed across the plurality of physical storage devices;
split the data into a plurality of secondary data units by performing a cryptographic operation on the data and causing the secondary data units to be substantially randomly distributed in the plurality of shares; and
encrypt each of the plurality of secondary data units with a different key, each key associated with at least one of the plurality of shares.
21 . The secure data storage network of claim 20 , wherein the secure storage applicant is further configured to transmit each secondary data unit remote from the secure storage appliance.
22 . The secure data storage network of claim 20 , wherein the encrypted plurality of secondary data units are encrypted with a workgroup key.
23 . The secure data storage network of claim 22 , further comprising a key server configured to store the workgroup key.
24 . The secure data storage network of claim 22 , wherein the workgroup key is associated with a group of users, the group of users including a user of the client device.
25 . The secure data storage network of claim 20 , wherein the plurality of secondary data units contain a substantially random distribution of the data.
26 . The secure data storage network of claim 20 , wherein the data is restorable from at least two of the plurality of secondary data units.Join the waitlist — get patent alerts
Track US2013212405A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.