Secure sharing
Abstract
Among other things, at a central server, management of a document sharing process includes uploading from client devices through a communication network, storing at the server, and downloading to client devices through the communication network documents that are shared between users of the client devices. Encryption keys are used to protect features of the documents from unauthorized or unintended disclosure. Operations are performed on encryption keys or encrypted data as a result of which protection of features of the documents from unauthorized or unintended disclosure may be compromised. A determination is made whether performance of a given one of the operations on any of the encryption keys or encrypted data meets predefined conditions for approval by members of an approval group. Performance of the operation on the encryption key or encrypted data is controlled based on a result of the determination.
Claims
exact text as granted — not AI-modified1 . A computer-implemented method comprising
applying a secret-sharing process to distribute a secret feature, the secret-sharing process being applied with respect to members of one or more approval groups, permitting a protected operation to be performed with respect to information stored on a server by retrieving the secret feature using the secret-sharing process for all of the groups and applying predefined conditions for approval by members of each of the approval groups of the protected operation, including the server in each of the approval groups, and based on the inclusion of the server in each of the approval groups, logging each protected operation that was performed based on approval by members of each of the approval groups.
2 . The method of claim 1 in which the secret feature comprises an encryption key.
3 . The method of claim 1 in which the encryption key is associated with a document sharing system.
4 . The method of claim 1 in which the secret-sharing comprises nested secret sharing.
5 . The method of claim 1 in which the protected operation is associated with a system for sharing documents.
6 . A computer-implemented method comprising
applying a secret-sharing process to distribute a secret feature, the secret-sharing process being applied with respect to members of an approval group, and permitting a protected operation to be performed by retrieving the secret feature using the secret-sharing process and applying predefined conditions for approval by members of the approval group of the protected operation.
7 . The method of claim 6 in which the secret feature comprises an encryption key.
8 . The method of claim 6 in which the encryption key is associated with a document sharing system.
9 . The method of claim 6 in which a server is part of the approval group.
10 . The method of claim 6 in which the secret-sharing comprises nested secret sharing.
11 . The method of claim 6 in which the protected feature is associated with a system for sharing documents.
12 . A computer-implemented method comprising
at a central server, managing a document sharing process that comprises uploading from client devices through a communication network, storing at the server, and downloading to client devices through the communication network documents that are shared between users of the client devices, controlling access to each of the users to the document sharing process through user interface features exposed to the user by one of the client devices, the control of access not requiring the use of user passwords.
13 . The method of claim 12 comprising
using encryption keys to protect features of the documents from unauthorized or unintended disclosure,
performing operations on encryption keys or encrypted data as a result of which protection of features of the documents from unauthorized or unintended disclosure might otherwise be subjected to compromise,
determining whether performance of a given one of the operations on any of the encryption keys or the encrypted data meets predefined conditions for approval by members of an approval group, and
controlling performance of the operation on the encryption key or the encrypted data based on a result of the determination.
14 . The method of claim 13 in which controlling performance of the operation on the encryption key comprises preventing the operation.
15 . The method of claim 13 in which controlling performance of the operation on the encryption key comprises tracking the operation.
16 . The method of claim 13 in which the operation on the encryption key comprises updating a user's key.
17 . The method of claim 13 in which the determination whether the performance of the operation meets the predefined conditions comprises an identification processor service receiving a signature of the approval group.
18 . The method of claim 13 in which the operation on the encryption key comprises recovering a key.
19 . The method of claim 18 in which the operation on the encryption key comprises recovering a user key.
20 . The method of claim 18 in which the operation on the encryption key comprises recovering a key associated with a collection of the documents.
21 . The method of claim 13 in which the operation on the encryption key comprises replacing one user key with another.
22 . The method of claim 21 in which the encryption key is secret-shared among members of the approval group.
23 . The method of claim 13 in which a server is part of the approval group.
24 . The method of claim 22 in which the secret-sharing comprises nested secret sharing.
25 . The method of claim 18 in which recovering the key comprises applying a secure multi-party computation among members of the approval group.
26 . The method of claim 25 in which applying the secure multi-party computation comprises decryption of a chain of keys.Join the waitlist — get patent alerts
Track US2018219687A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.