Network-based client side encryption

US9800579B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9800579-B2
Application numberUS-201514620724-A
CountryUS
Kind codeB2
Filing dateFeb 12, 2015
Priority dateFeb 12, 2015
Publication dateOct 24, 2017
Grant dateOct 24, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A device may provide an upload request to upload a file. The device may receive, based on the upload request, a unique identifier associated with the device. The device may obtain a file key for encrypting the file and a security key for encrypting the file key. The security key may be obtained based on the unique identifier. The device may encrypt the file, using the file key, to create an encrypted file. The device may encrypt the file key, using the security key, to create an encrypted file key. The device may provide the encrypted file and the encrypted file key for storage by a storage device.

First claim

Opening claim text (preview).

What is claimed is: 1. A device, comprising: a memory storing instructions; and one or more processors to execute the instructions to: provide, by a first application associated with the device, an upload request to upload a file; receive, based on the upload request and based on an authentication of the device, a first unique identifier associated with the device; obtain a file key for encrypting the file; generate a first security key for encrypting the file key using the first unique identifier; encrypt the file, using the file key, to create an encrypted file; encrypt the file key, using the first security key, to create a first encrypted file key; provide, by the first application, the encrypted file and the first encrypted file key for storage by a storage device; receive a second unique identifier associated with the device, the second unique identifier being different than the first unique identifier; generate a second security key based on the second unique identifier, the second security key being different than the first security key; receive the first encrypted file key; decrypt, using the first security key, the first encrypted file key to recover the file key; encrypt, using the second security key, the file key to create a second encrypted file key; provide the second encrypted file key for storage by the storage device; provide, by a second application associated with the device, a download request, the second application being different than the first application; obtain, by the second application and based on the download request, the encrypted file and the second encrypted file key; decrypt the second encrypted file key, using the second security key, to recover the file key; and decrypt the encrypted file, using the file key, to recover the file. 2. The device of claim 1 , where the one or more processors, when providing the download request, are to: provide the download request to a network device for authentication; and where the one or more processors, when obtaining the encrypted file and the second encrypted file key, are to: obtain the encrypted file and the second encrypted file key based on the download request being authenticated by the network device. 3. The device of claim 1 , where the one or more processors are further to: provide, to the storage device and in association with the encrypted file and the second encrypted file key, the second unique identifier; and where the one or more processors, when obtaining the encrypted file and the second encrypted file key, are to: obtain the encrypted file and the second encrypted file key based on the second unique identifier. 4. The device of claim 1 , where the one or more processors, when providing the upload request, are to: provide the upload request to a network device for determining the first unique identifier; and where the one or more processors, when receiving the first unique identifier, are to: receive the first unique identifier from the network device or the storage device. 5. The device of claim 1 , where the one or more processors, when generating the first security key using the first unique identifier, are to: generate the first security key by applying a hashing algorithm to the first unique identifier. 6. The device of claim 1 , where the one or more processors are further to: delete the first security key. 7. The device of claim 1 , where the one or more processors, when providing the encrypted file, are to: provide the encrypted file via a secure session. 8. A computer-readable medium storing instructions, the instructions comprising: one or more instructions that, when executed by one or more processors, cause the one or more processors to: provide, by a first application, an upload request to upload a file; receive, based on the upload request and based on an authentication of a device, a first unique identifier associated with the device; obtain a file key for encrypting the file; generate a first security key for encrypting the file key using the first unique identifier; encrypt the file, using the file key, to create an encrypted file; encrypt the file key, using the first security key, to create a first encrypted file key; provide, by the first application, the encrypted file and the first encrypted file key for storage by a storage device; receive a second unique identifier associated with the device, the second unique identifier being different than the first unique identifier; generate a second security key based on the second unique identifier, the second security key being different than the first security key; receive the first encrypted file key; decrypt, using the first security key, the first encrypted file key to recover the file key; encrypt, using the second security key, the file key to create a second encrypted file key; provide the second encrypted file key for storage by the storage device; provide, by a second application, a download request, the second application being different than the first application; obtain, by the second application and based on the download request, the encrypted file and the second encrypted file key; decrypt the second encrypted file key, using the second security key, to recover the file key; and decrypt the encrypted file, using the file key, to recover the file. 9. The computer-readable medium of claim 8 , where the one or more instructions, that cause the one or more processors to provide the download request, cause the one or more processors to: provide the download request to a network device for authentication; and where the one or more instructions, that cause the one or more processors to receive the encrypted file and the second encrypted file key, cause the one or more processors to: receive the encrypted file and the second encrypted file key based on the authentication by the network device. 10. The computer-readable medium of claim 8 , where the one or more instructions, when executed by the one or more processors, further cause the one or more processors to: provide, to the storage device and in association with the encrypted file and the second encrypted file key, the second unique identifier; and where the one or more instructions, that cause the one or more processors to receive the encrypted file and the second encrypted file key, cause the one or more processors to: receive the encrypted file and the second encrypted file key based on the second unique identifier. 11. The computer-readable medium of claim 8 , where the one or more instructions, that cause the one or more processors to provide the upload request, cause the one or more processors to: provide the upload request to a network device for determining the first unique identifier; and where the one or more instructions, that cause the one or more processors to receive the first unique identifier, cause the one or more processors to: receive the first unique identifier from the network device or the storage device. 12. The computer-readable medium of claim 8 , where the first unique identifier is not received based on a failure to authenticate the device. 13. The computer-readable medium of claim 8 , where the one or more instructions, that cause the one or more processors to provide the first encrypted file key, cause the one or more processors to: provide the first encrypted file key via a secure session. 14. The computer-readable medium of claim 8 , where the one or more instructions, when executed by the one or more processors, further cause the one or more processors to: delete the fi

Assignees

Inventors

Classifications

  • G06F21/602Primary

    Providing cryptographic facilities or services · CPC title

  • Authentication · CPC title

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

  • Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title

  • Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9800579B2 cover?
A device may provide an upload request to upload a file. The device may receive, based on the upload request, a unique identifier associated with the device. The device may obtain a file key for encrypting the file and a security key for encrypting the file key. The security key may be obtained based on the unique identifier. The device may encrypt the file, using the file key, to create an enc…
Who is the assignee on this patent?
Verizon Patent & Licensing Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/602. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Oct 24 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).