US2015249687A1PendingUtilityA1

Systems and methods for securing data in the cloud

Assignee: SECURITY FIRST CORPPriority: May 19, 2009Filed: May 15, 2015Published: Sep 3, 2015
Est. expiryMay 19, 2029(~2.8 yrs left)· nominal 20-yr term from priority
G06F 9/45558G06F 2009/45587G06F 21/602H04L 63/20H04L 9/085H04L 67/1095H04L 9/3263H04L 67/1097H04L 63/0428H04L 63/0823H04L 63/18H04L 9/0897H04L 9/3231H04L 63/061H04L 9/14H04L 9/321Y04S40/20G06F 21/62
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A secure data parser is provided that may be integrated into any suitable system for securely storing data in and communicating data with cloud computing resources. The secure data parser parses data and then splits the data into multiple portions that are stored or communicated distinctly. Encryption of the original data, the portions of data, or both may be employed for additional security.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A method of securing a virtual machine, the method comprising:
 providing a security module, in a first computing environment, accessible to applications running in a client computing environment, the security module configured to perform one or more security operations in response to receiving a request from an application;   receiving by a computing system a security operation request from an application running in a first virtual machine operating in the client computing environment; and   performing the security operation in response to receiving the request from the application running in the virtual machine.   
     
     
         3 . The method of  claim 2 , wherein the security operation request is received from a user level of the first virtual machine. 
     
     
         4 . The method of  claim 2 , wherein the first computing environment is a virtual machine operating in the client computing environment, different from the first virtual machine. 
     
     
         5 . The method of  claim 2 , wherein the first computing environment includes a processing device remote from the client computing environment. 
     
     
         6 . The method of  claim 2 , wherein the first virtual machine includes the first computing environment. 
     
     
         7 . The method of  claim 2 , wherein the client computing environment includes the first computing environment. 
     
     
         8 . The method of  claim 2 , wherein the security operation comprises integrity-checking data read in from a disk in the client computing environment. 
     
     
         9 . The method of  claim 2 , wherein the security operation comprises securing communications between the first virtual machine and at least one other virtual machine operating in the client computing environment. 
     
     
         10 . The method of  claim 2 , wherein performing the security operation comprises encrypting a data set indicated by the application running in the virtual machine. 
     
     
         11 . The method of  claim 10 , wherein performing the security operation further comprises generating a plurality of shares, each share comprising a distribution of data from the encrypted data set. 
     
     
         12 . The method of  claim 11 , wherein encrypting the data set and generating a plurality of shares comprise performing a two-factored secret sharing operation. 
     
     
         13 . The method of  claim 11 , further comprising:
 storing the plurality of shares in a file system of the first virtual machine.   
     
     
         14 . The method of  claim 13 , wherein storing the plurality of shares comprises storing a first number of shares, the first number of shares greater than a number of shares needed to reconstruct the data set. 
     
     
         15 . A system for securing a virtual machine, the system comprising:
 a security module running on a computing system in a first computing environment, accessible to applications running in a client computing environment, the security module configured to:
 perform one or more security operations in response to receiving a request from an application; 
 receive a security operation request from an application running in a first virtual machine operating in the client computing environment; and 
 perform the security operation in response to receiving the request from the application running in the virtual machine. 
   
     
     
         16 . The system of  claim 15 , wherein the security operation request is received from a user level of the first virtual machine. 
     
     
         17 . The system of  claim 15 , wherein the first computing environment is a virtual machine operating in the client computing environment, different from the first virtual machine. 
     
     
         18 . The system of  claim 15 , wherein the first computing environment includes a processing device remote from the client computing environment. 
     
     
         19 . The system of  claim 15 , wherein the first virtual machine includes the first computing environment. 
     
     
         20 . The system of  claim 15 , wherein the client computing environment includes the first computing environment. 
     
     
         21 . The system of  claim 15 , wherein the security operation comprises integrity-checking data read in from a disk in the client computing environment. 
     
     
         22 . The system of  claim 15 , wherein the security operation comprises securing communications between the first virtual machine and at least one other virtual machine operating in the client computing environment. 
     
     
         23 . The system of  claim 15 , wherein the security module performs the security operation by encrypting a data set indicated by the application running in the virtual machine. 
     
     
         24 . The system of  claim 23 , wherein the security module performs the security operation by generating a plurality of shares, each share comprising a distribution of data from the encrypted data set. 
     
     
         25 . The system of  claim 24 , wherein encrypting the data set and generating a plurality of shares comprise performing a two-factored secret sharing operation. 
     
     
         26 . The system of  claim 24 , wherein the computing system is further configured to store the plurality of shares in a file system of the first virtual machine. 
     
     
         27 . The system of  claim 26 , wherein storing the plurality of shares comprises storing a first number of shares, the first number of shares greater than a number of shares needed to reconstruct the data set. 
     
     
         28 . A machine-readable non-transitory medium comprising machine program logic recorded thereon which, when executed by a processor, causes a computing system to carry out the steps of:
 providing a security module, in a first computing environment, accessible to applications running in a client computing environment, the security module configured to perform one or more security operations in response to receiving a request from an application;   receiving by a computing system a security operation request from an application running in a first virtual machine operating in the client computing environment; and   performing the security operation in response to receiving the request from the application running in the virtual machine.   
     
     
         29 . The machine-readable non-transitory medium of  claim 28 , wherein the security operation request is received from a user level of the first virtual machine. 
     
     
         30 . The machine-readable non-transitory medium of  claim 28 , wherein the first computing environment is a virtual machine operating in the client computing environment, different from the first virtual machine. 
     
     
         31 . The machine-readable non-transitory medium of  claim 28 , wherein the first computing environment includes a processing device remote from the client computing environment. 
     
     
         32 . The machine-readable non-transitory medium of  claim 28 , wherein the first virtual machine includes the first computing environment. 
     
     
         33 . The machine-readable non-transitory medium of  claim 28 , wherein the client computing environment includes the first computing environment. 
     
     
         34 . The machine-readable non-transitory medium of  claim 28 , wherein the security operation comprises integrity-checking data read in from a disk in the client computing environment.

Join the waitlist — get patent alerts

Track US2015249687A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.