US2014201538A1PendingUtilityA1

Systems and methods for securing data

Assignee: SECURITY FIRST CORPPriority: Jan 27, 2011Filed: Jan 27, 2014Published: Jul 17, 2014
Est. expiryJan 27, 2031(~4.5 yrs left)· nominal 20-yr term from priority
G06F 21/602H04L 67/1097G06F 21/32H04L 63/0428
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are provided for securing data. A processing device receives a data set and identifies a first subset of data from a first dimension of a multi-dimensional representation of the data set. The processing device encrypts the first subset of data using a first encryption technique to yield a first encrypted subset of data and replaces the first subset of data in the multi-dimensional representation of the data set with the first subset of encrypted data. The processing device then identifies a second subset of data from a second dimension of the multi-dimensional representation of the data set, with the second subset of data including at least a portion of the first subset of encrypted data, and encrypts the second subset of data using a second encryption technique to yield a second encrypted subset of data.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A method for securing data, comprising:
 receiving a data set by processing circuitry;   identifying a first subset of data based on a first attribute of the data set;   encrypting the first subset of data using a first encryption technique to yield a first encrypted subset of data;   identifying a second subset of data based on a second attribute of the data set, wherein the second subset of data includes overlapping data that corresponds to at least a portion of the first encrypted subset of data, and wherein the second attribute is different from the first attribute; and   encrypting the second subset of data using a second encryption technique to yield a second encrypted subset of data, thereby encrypting the overlapping data using the first encryption technique and the second encryption technique.   
     
     
         3 . The method of  claim 2 , further comprising:
 producing two or more shares of data from the second encrypted subset of data, each share containing a selection of data from the second encrypted subset of data; and   outputting via an output, the two or more shares for storage at separate storage locations.   
     
     
         4 . The method of  claim 2 , wherein the first and second encryption techniques are different encryption techniques. 
     
     
         5 . The method of  claim 2 , wherein the first and second encryption techniques are the same encryption techniques but use different keys. 
     
     
         6 . The method of  claim 2 , wherein the first subset of data is identified deterministically. 
     
     
         7 . The method of  claim 2 , wherein the first subset of data is identified according to a keyed arrangement technique. 
     
     
         8 . The method of  claim 3 , wherein the second encrypted subset of data includes a cipherblock of data encrypted using the second encryption technique, and the two or more shares are produced such that no share includes all of the cipherblock. 
     
     
         9 . The method of  claim 2 , wherein the first encrypted subset of data includes a cipherblock of data encrypted using the first encryption technique, and the second subset of data does not include all of the cipherblock. 
     
     
         10 . The method of  claim 2 , wherein the first subset of data is identified as a row of a two-dimensional representation of the data set. 
     
     
         11 . The method of  claim 10 , wherein the second subset of data is identified as a column of the two-dimensional representation of the data set. 
     
     
         12 . A system for securing data, comprising:
 a data input; and   a processing circuitry in communication with the data input port and configured to:   receive, via the data input, a data set;   identify a first subset of data based on a first attribute of the data set;   encrypt the first subset of data using a first encryption technique to yield a first encrypted subset of data;   identify a second subset of data based on a second attribute of the data set, wherein the second subset of data includes overlapping data that corresponds to at least a portion of the first encrypted subset of data, and wherein the second attribute is different from the first attribute; and   encrypt the second subset of data using a second encryption technique to yield a second encrypted subset of data, thereby encrypting the overlapping data using the first encryption technique and the second encryption technique.   
     
     
         13 . The system of  claim 12 , further comprising a data output in communication with the processing circuitry, wherein the processing circuitry is further configured to:
 produce two or more shares of data from the second encrypted subset of data, each share containing a selection of data from the second encrypted subset of data; and   output, via the data output, the two or more shares for storage at separate storage locations.   
     
     
         14 . The system of  claim 12 , wherein the first and second encryption techniques are different encryption techniques. 
     
     
         15 . The system of  claim 12 , wherein the first and second encryption techniques are the same encryption techniques but use different keys. 
     
     
         16 . The system of  claim 12 , wherein the first subset of data is identified deterministically. 
     
     
         17 . The system of  claim 12 , wherein the first subset of data is identified according to a keyed arrangement technique. 
     
     
         18 . The system of  claim 13 , wherein the second encrypted subset of data includes a cipherblock of data encrypted using the second encryption technique, and the two or more shares are produced such that no share includes all of the cipherblock. 
     
     
         19 . The system of  claim 12 , wherein the first encrypted subset of data includes a cipherblock of data encrypted using the first encryption technique, and the second subset of data does not include all of the cipherblock. 
     
     
         20 . The system of  claim 12 , wherein the first subset of data is identified as a row of a two-dimensional representation of the data set. 
     
     
         21 . The system of  claim 20 , wherein the second subset of data is identified as a column of the two-dimensional representation of the data set. 
     
     
         22 . A non-transitory computer readable medium storing computer executable instructions which, when executed by a processor, cause a method for securing data to be performed, the method comprising:
 receiving a data set;   identifying a first subset of data based on a first attribute of the data set;   encrypting the first subset of data using a first encryption technique to yield a first encrypted subset of data;   identifying a second subset of data based on a second attribute of the data set, wherein the second subset of data includes overlapping data that corresponds to at least a portion of the first encrypted subset of data, and wherein the second-attribute is different from the first attribute; and   encrypting the second subset of data using a second encryption technique to yield a second encrypted subset of data, thereby encrypting the overlapping data using the first encryption technique and the second encryption technique.   
     
     
         23 . The non-transitory computer readable medium of  claim 22 , further comprising:
 producing two or more shares of data from the second encrypted subset of data, each share containing a selection of data from the second encrypted subset of data; and   outputting the two or more shares for storage at separate storage locations.   
     
     
         24 . The non-transitory computer readable medium of  claim 22 , wherein the first and second encryption techniques are different encryption techniques. 
     
     
         25 . The non-transitory computer readable medium of  claim 22 , wherein the first and second encryption techniques are the same encryption techniques but use different keys. 
     
     
         26 . The non-transitory computer readable medium of  claim 22 , wherein the first subset of data is identified deterministically. 
     
     
         27 . The non-transitory computer readable medium of  claim 22 , wherein the first subset of data is identified according to a keyed arrangement technique. 
     
     
         28 . The non-transitory computer readable medium of  claim 22 , wherein the second encrypted subset of data includes a cipherblock of data encrypted using the second encryption technique, and the two or more shares are produced such that no share includes all of the cipherblock. 
     
     
         29 . The non-transitory computer readable medium of  claim 22 , wherein the first encrypted subset of data includes a cipherblock of data encrypted using the first encryption technique, and the second subset of data does not include all of the cipherblock. 
     
     
         30 . The non-transitory computer readable medium of  claim 22 , wherein the first subset of data is identified as a row of a two-dimensional representation of the data set. 
     
     
         31 . The non-transitory computer readable medium of  claim 30 , wherein the second subset of data is identified as a column of the two-dimensional representation of the data set.

Join the waitlist — get patent alerts

Track US2014201538A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.