US2016378689A1PendingUtilityA1

Systems and methods for secure multi-tenant data storage

Assignee: SECURITY FIRST CORPPriority: Aug 11, 2010Filed: Sep 7, 2016Published: Dec 29, 2016
Est. expiryAug 11, 2030(~4.1 yrs left)· nominal 20-yr term from priority
G06F 2212/1052G06F 12/1408H04L 63/061G06F 13/1663H04L 9/085H04L 9/3263H04L 9/3247H04L 9/3231H04L 9/14H04L 9/0894G06F 21/6218
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are provided for transmitting data for secure storage. For each of two or more data sets, a plurality of shares are generated containing a distribution of data from an encrypted version of the data set. The shares are then stored in a shared memory device, wherein a data set may be reconstructed from a threshold number of the associated plurality of shares using an associated key. Also provided are systems and methods for providing access to secured data. A plurality of shares containing a distribution of data from an encrypted version of a data set are stored in a memory device. A client is provided with a virtual machine that indicates the plurality of shares, and the capability to reconstruct the data set from the plurality of shares using an associated key.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A method of securely storing data in a multi-tenant data storage system, comprising:
 generating a first plurality of shares from a first data set;   generating a second plurality of shares from a second data set; and   storing at least one share of the first plurality of shares and at least one share of the second plurality of shares in a shared memory device of the multi-tenant data storage system without a physical partitioning or virtual partitioning of the shared memory device between the stored at least one share of the first plurality of shares and the stored at least one share of the second plurality of shares.   
     
     
         3 . The method of  claim 2 , wherein the first data set is a first encrypted data set, and the second data set is a second encrypted data set. 
     
     
         4 . The method of  claim 3 , wherein the first data set is encrypted with a first key and the second data set is encrypted with a second key different from the first key. 
     
     
         5 . The method of  claim 2 , wherein the first data set is received from a first data source, the second data set is received from an second data source, and the first and second data sources are unrelated. 
     
     
         6 . The method of  claim 2 , wherein the first data set is encrypted with the first key at a first server and the second data set is encrypted with the second key at a second server different from the first server. 
     
     
         7 . The method of  claim 2 , wherein the at least one share of the first plurality of shares and the at least one share of the second plurality of shares are stored contiguously in the shared memory device. 
     
     
         8 . The method of  claim 2 , wherein the shared memory device is a first shared memory device, and further comprising:
 storing some of the first plurality of shares and some of the second plurality of shares in a second shared memory device different from the first shared memory device.   
     
     
         9 . The method of  claim 8 , wherein at least one of the first plurality of shares is stored on both the first shared memory device and the second shared memory device. 
     
     
         10 . The method of  claim 2 , further comprising:
 storing at least two of the first plurality of shares and at least two of the second plurality of shares in the shared memory device.   
     
     
         11 . The method of  claim 2 , wherein access to an encryption key and a threshold number of the first plurality of shares are necessary to restore the first data set. 
     
     
         12 . A system for securely storing data in a multi-tenant data storage system, comprising:
 a shared memory device; and   at least one processing device configured to:
 generate a first plurality of shares from a first data set; 
 generate a second plurality of shares from a second data set; and 
 store at least one share of the first plurality of shares and at least one share of the second plurality of shares in a shared memory device of the multi-tenant data storage system without a physical partitioning or a virtual partitioning of the shared memory device between the stored at least one share of the first plurality of shares and the stored at least one share of the second plurality of shares. 
   
     
     
         13 . The system of  claim 12 , wherein the first data set is a first encrypted data set, and the second data set is a second encrypted data set. 
     
     
         14 . The system of  claim 13 , wherein the first data set is encrypted with a first key and the second data set is encrypted with a second key different from the first key. 
     
     
         15 . The system of  claim 12 , wherein the first data set is received from a first data source, the second data set is received from an second data source, and the first and second data sources are unrelated. 
     
     
         16 . The system of  claim 12 , wherein the at least one processing device comprises a first server and a second server, and wherein the first data set is encrypted with the first key at a first server and the second data set is encrypted with the second key at a second server different from the first server. 
     
     
         17 . The system of  claim 12 , wherein the at least one share of the first plurality of shares and the at least one share of the second plurality of shares are stored contiguously in the first shared memory device. 
     
     
         18 . The system of  claim 12 , wherein the shared memory device is a first shared memory device, and the at least one processing device is further configured to:
 store some of the first plurality of shares and some of the second plurality of shares in a second shared memory device different from the first shared memory device.   
     
     
         19 . The system of  claim 18 , wherein at least one of the first plurality of shares is stored on both the first shared memory device and the second shared memory device. 
     
     
         20 . The system of  claim 12 , wherein the at least one processing device is further configured to:
 store at least two of the first plurality of shares and at least two of the second plurality of shares in the shared memory device.   
     
     
         21 . The system of  claim 12 , wherein access to an encryption key and a threshold number of the first plurality of shares are necessary to restore the first data set.

Join the waitlist — get patent alerts

Track US2016378689A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.