US2015324303A1PendingUtilityA1

Systems and methods for secure hybrid third-party data storage

Assignee: SYMANTEC CORPPriority: May 7, 2014Filed: May 22, 2015Published: Nov 12, 2015
Est. expiryMay 7, 2034(~7.8 yrs left)· nominal 20-yr term from priority
Inventors:Walter Bogorad
G06F 2212/1052G06F 21/602G06F 12/1408H04L 9/14H04L 2209/24H04L 63/0281H04L 63/08H04L 63/045H04L 63/0428
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The disclosed computer-implemented method for secure hybrid third-party data storage may include (1) identifying, at a trusted proxy system, an access request from a client system to access an encrypted file stored under a user account at a third-party storage system, where the requested access requires decryption of the encrypted file, (2) retrieving, from the third-party storage system, (i) the encrypted file and (ii) a decryption key that has been encrypted with a cryptographic key, where an asymmetric key pair designated for the user account includes an encryption key and the encrypted decryption key, (3) decrypting, at the trusted proxy system, the decryption key with the cryptographic key, and (4) using the decryption key to access an unencrypted version of the encrypted file at the trusted proxy system. Various other methods, systems, and computer-readable media are also disclosed.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method for secure hybrid third-party data storage, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:
 identifying, at a trusted proxy system, an access request from a client system to access an encrypted file stored under a user account at a third-party storage system, wherein the requested access requires decryption of the encrypted file;   retrieving, in response to the request, from the third-party storage system and for the trusted proxy system:
 the encrypted file; 
 a decryption key that has been encrypted with a cryptographic key, wherein an asymmetric key pair designated for the user account comprises an encryption key and the encrypted decryption key; 
   decrypting, at the trusted proxy system, the decryption key with the cryptographic key;   using the decryption key to access an unencrypted version of the encrypted file at the trusted proxy system.   
     
     
         2 . The computer-implemented method of  claim 1 , further comprising retrieving the cryptographic key at the trusted proxy system and from a key store. 
     
     
         3 . The computer-implemented method of  claim 2 , wherein the trusted proxy system and the key store are located within a network and the third-party storage system is not located within the network. 
     
     
         4 . The computer-implemented method of  claim 2 , wherein:
 the trusted proxy system operates within a demilitarized zone of an enterprise network;   the key store exists within the enterprise network but outside the demilitarized zone;   retrieving the cryptographic key at the trusted proxy system and from the key store comprises retrieving the cryptographic key via a key store bridge within the demilitarized zone that communicates with the key store.   
     
     
         5 . The computer-implemented method of  claim 4 , wherein at least one of the trusted proxy system, the key store bridge, and the key store receive an authentication token from the client system that validates access to the cryptographic key from the key store. 
     
     
         6 . The computer-implemented method of  claim 1 , wherein the trusted proxy system is owned by an owner of the encrypted file and the third-party storage system is not owned by the owner of the encrypted file. 
     
     
         7 . The computer-implemented method of  claim 1 , wherein accessing the encrypted file comprises transmitting the unencrypted version of the encrypted file to the client system. 
     
     
         8 . The computer-implemented method of  claim 1 , wherein using the decryption key to access the unencrypted version of the encrypted file comprises:
 generating, at the trusted proxy system, metadata describing the unencrypted version of the encrypted file;   providing the metadata to at least one of the client system and the third-party storage system.   
     
     
         9 . The computer-implemented method of  claim 8 , wherein generating the metadata describing the unencrypted version of the encrypted file comprises at least one of:
 performing a scan on the unencrypted version of the encrypted file at the trusted proxy system;   creating, at the trusted proxy system, an index entry of the unencrypted version of the encrypted file based on content within the unencrypted version of the encrypted file;   generating, at the trusted proxy system, a preview of the unencrypted version of the encrypted file based on content within the unencrypted version of the encrypted file.   
     
     
         10 . The computer-implemented method of  claim 1 , wherein accessing the encrypted file comprises:
 identifying, at the trusted proxy system, a policy for scanning the unencrypted version of the encrypted file;   scanning, at the trusted proxy system, the unencrypted version of the encrypted file based on the policy.   
     
     
         11 . The computer-implemented method of  claim 1 , wherein using the decryption key to access the encrypted file comprises:
 retrieving, from the third-party storage system and for the trusted proxy system, a file key used to encrypt the encrypted file, wherein the file key is encrypted with the encryption key;   decrypting, at the trusted proxy system, the file key with the decryption key;   decrypting, at the trusted proxy system, the encrypted file with the file key.   
     
     
         12 . The computer-implemented method of  claim 1 , wherein:
 accessing the encrypted file comprises providing access to the unencrypted version of the encrypted file to an additional user account;   an additional asymmetric key pair is designated for the additional user account, the asymmetric key pair comprising an additional encryption key and an additional decryption key that has been encrypted with an additional cryptographic key.   
     
     
         13 . The computer-implemented method of  claim 12 , wherein providing access to the unencrypted version of the encrypted file to the additional user account comprises:
 retrieving, from the third-party storage system and for the trusted proxy system, the additional encryption key and a file key used to encrypt the encrypted file, wherein the file key is encrypted with the encryption key;   decrypting, at the trusted proxy system, the file key with the decryption key;   encrypting, at the trusted proxy system, a copy of the file key with the additional encryption key;   transmitting the encrypted copy of the file key from the trusted proxy system to the third-party storage system.   
     
     
         14 . The computer-implemented method of  claim 1 , further comprising:
 receiving, at the trusted proxy system, the unencrypted version of the encrypted file from the client system;   generating the encrypted file at the trusted proxy system by:
 generating a file key based on at least one characteristic of the unencrypted version of the encrypted file; 
 encrypting the unencrypted version of the encrypted file with the file key; 
 encrypting the file key with the encryption key; 
 transmitting the encrypted file and the encrypted file key to the third-party storage system. 
   
     
     
         15 . The computer-implemented method of  claim 14 , further comprising deduplicating the encrypted file with an additional encrypted file that is encrypted with the file key. 
     
     
         16 . The computer-implemented method of  claim 1 , wherein the third-party storage system lacks access to:
 the unencrypted version of the encrypted file;   an unencrypted version of the decryption key;   the cryptographic key.   
     
     
         17 . The computer-implemented method of  claim 1 , wherein using the decryption key to access the unencrypted version of the encrypted file comprises:
 retrieving, from the third-party storage system and for the trusted proxy system, an additional asymmetric key pair designated for a plurality of user accounts comprising the user account, the additional asymmetric key pair comprising an additional encryption key and an additional decryption key that has been encrypted with the encryption key;   decrypting, at the trusted proxy system, the additional decryption key with the decryption key;   retrieving, from the third-party storage system and for the trusted proxy system, a file key used to encrypt the encrypted file, wherein the file key is encrypted with the additional encryption key;   decrypting, at the trusted proxy system, the file key with the additional decryption key;   decrypting, at the trusted proxy system, the encrypted file with the file key.   
     
     
         18 . A system for secure hybrid third-party data storage, the system comprising:
 an identification module, stored in memory, that identifies, at a trusted proxy system, an access request from a client system to access an encrypted file stored under a user account at a third-party storage system, wherein the requested access requires decryption of the encrypted file;   a retrieving module, stored in memory, that retrieves, in response to the request, from the third-party storage system and for the trusted proxy system:
 the encrypted file; 
 a decryption key that has been encrypted with a cryptographic key, wherein an asymmetric key pair designated for the user account by an encryption key and the encrypted decryption key; 
   a decryption module, stored in memory, that decrypts, at the trusted proxy system, the decryption key with the cryptographic key;   a using module, stored in memory, that uses the decryption key to access an unencrypted version of the encrypted file at the trusted proxy system;   at least one physical processor that executes the identification module, the retrieving module, the decryption module, and the using module.   
     
     
         19 . The system of  claim 18 , further comprising a receiving module that retrieves the cryptographic key at the trusted proxy system and from a key store. 
     
     
         20 . A non-transitory computer-readable medium comprising one or more computer-readable instructions that, when executed by at least one processor of a computing device, cause the computing device to:
 identify, at a trusted proxy system, an access request from a client system to access an encrypted file stored under a user account at a third-party storage system, wherein the requested access requires decryption of the encrypted file;   retrieve, in response to the request, from the third-party storage system and for the trusted proxy system:
 the encrypted file; 
 a decryption key that has been encrypted with a cryptographic key, wherein an asymmetric key pair designated for the user account comprises an encryption key and the encrypted decryption key; 
   decrypt, at the trusted proxy system, the decryption key with the cryptographic key;   use the decryption key to access an unencrypted version of the encrypted file at the trusted proxy system.

Join the waitlist — get patent alerts

Track US2015324303A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.