Nova Patents
AU2005299317A1

Secure data parser method and system

Abstract

A secure data parser is provided that may be integrated into any suitable system for securely storing and communicating data. The secure data parser parses data and then splits the data into multiple portions that are stored or communicated distinctly. Encryption of the original data, the portions of data, or both may be employed for additional security. The secure data parser may be used to protect data in motion by splitting original data into portions of data, that may be communicated using multiple communications paths.

Term

Term ended

Projected expiry passed 25 October 2025, 0.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

85 claims: 22 independent, 63 dependent

  1. 1
    What is claimed is:1. A method for securing communication of a data set from a first location to a second location, the method comprising: ' generating at the first location at least two portions 1 of data from the data set, wherein each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the data set;communicating from the first location to the second location the at least two portions of data over at least one communications path, wherein the at least two portions of data are communicated separately from each other;and restoring at the second location the data set from at least a subset of the at least two portions of data.
  2. 18
    A method for securing a data set, the method comprising:generating at least two portions of data from the data set, wherein each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the data set;WO 2006/047694 PCT/US2005/038806 storing the at least two portions of data on at least two data depositories, wherein the at least two data depositories are physically separate from each other;and using at least one of the at least two portions of data stored on at least one of the at least two data depositories as an authentication key stored in an authentication depository in order to restore the data set.
  3. 22
    A method for securing a data set, the method comprising:generating at least two portions of data from the data set, wherein each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the data set;generating respective integrity information for each of the at least two portions of data;WO 2006/047694 PCT/US2005/038806 writing the respective integrity information to each of the at least two portions of data;storing each of the at least two portions of data separately;and restoring the data set from at least a subset of the at least two portions of data when the respective integrity information of the at least a subset of the at least two portions of data has been verified.
  4. 26
    A method for securing a data set, the method comprising:generating at least two portions of data from the data set, wherein each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the data set ;storing each of the at least two portions of data separately;and restoring the data set from at least a subset of the at least two portions of data, wherein at WO 2006/047694 PCT/US2005/038806 least one particular portion of data is required in order to restore the data set.
  5. 30
    A method for securing a data set, the method comprising:generating at least two portions of data from the data set, wherein each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the data set, and wherein the probability that data from the data set is distributed to at least one of the at least two portions of data is less than the probability that data from the data set is distributed to a remainder of the at least two portions of data;WO 2006/047694 PCT/US2005/038806 storing each of the at least two portions of data separately;and restoring the data set from at least a subset of the at least two portions of data.
  6. 31
    A method for securing a data set, the method comprising:generating at least two portions of data from the data set, wherein each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the data set, and wherein at least one of the at least two portions of data has a predetermined size;storing each of the at least two portions of data separately;and restoring the data set from at least a subset of the at least two portions of data.
  7. 34
    A method for securing a data set, the method comprising:WO 2006/047694 PCT/US2005/038806 generating at least two portions of data from the data set, wherein each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the data set, and wherein the probability that data from the data set is distributed to each of the at least two portions of data is substantially equal;storing each of the at least two portions of data separately;and restoring the data set from at least a subset of the at least two portions of data.
  8. 35
    A method for securing a data set, the method comprising:generating, according to a splitting key, at least two portions of data from the data set, wherein each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the data set;generating, according to a Shamir algorithm, splitting key information that is capable of being used to generate the splitting key, wherein the splitting key information is distributed among the at least two portions of data;storing each of the at least two portions of data separately;and restoring the data set from at least a subset of the at least two portions of data.
  9. 37
    A method for securing a data set, the method comprising:encrypting the data set using an encryption key;generating at least two portions of data from the encrypted data set, wherein each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the encrypted data set;generating, according to a Shamir algorithm, encryption key information that is capable of being used to generate the encryption key, wherein the splitting key information is distributed among the at least two portions of data;storing each of the at least two portions of data separately;and restoring the encrypted data set from at least a subset of the at least two portions of data.
  10. 39
    A method for securing a data set, the method comprising:generating at least two portions of data from the data set, wherein each of the at least two portions of data respectively contains a substantially WO 2006/047694 PCT/US2005/038806 random distribution of a respective subset of the data set ;encrypting the at least two portions of data using the encryption key;generating, according to a Shamir algorithm, encryption key information that is capable of being used to generate the encryption key, wherein the splitting key information is distributed among the at least two portions of data;storing the at least two encrypted portions of data separately from each other;and restoring the data set using a subset of the at least two encrypted portion of data.
  11. 41
    A method for securing a data set, the method comprising:determining a number of portions of data into which to distribute the data set;generating a substantially random number;determining into which of the portions of data to distribute each unit of data from the data set based on corresponding data from the substantially random number and distributing accordingly;storing the portions of data separately;and restoring the data set from at least a subset of the portions of data. WO 2006/047694 PCT/US2005/038806
  12. 47
    A method for securing a data set, the method comprising:determining a number of portions of data into which to distribute the data set;generating a substantially random number;for each unit of data of the data set, splitting the unit of data into a left segment and a right segment by determining, based on correspodning data from the substantially random number, a splitting location wherein bits to the left of the splitting location represent the left segment and bits to the right of the splitting location represent the right segment;determining into which of the portions of data to distribute each of the left segment and the right segment of each unit of data from the data set based on corresponding data from the substantially random number and distributing accordingly;storing the portions of data separately;and restoring the data set from at least a subset of the portions of data.
  13. 53
    The method of 47 wherein the determining into which of the portions of data to distribute each of the left segment and the right segment comprises WO 2006/047694 PCT/US2005/038806 determining into which of the portions of data to distribute each of the left segment and the right segment of each unit of data from the data set based on a hash function of corresponding data from the substantially random number and based on a table containing an array of all possible distributions of the right segment and the left segment, wherein the hash function of the corresponding data from the substantially random number indicates which entry in the table to use, the entry indicating a destination portion for the left segment and a destination portion for the right segment.
  14. 55
    A method for securing a data set, the method comprising:encrypting the data set using an encryption key;transforming the encryption key using an All or Nothing Transform into a transformed encryption key;generating at least two portions of data from the encrypted data set, wherein each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the encrypted data set;WO 2006/047694 PCT/US2005/038806 generating tranformed encryption key information that is capable of being used to generate the transformed encryption key, wherein the transformed encryption key information is distributed among the at least two portions of data;storing each of the at least two portions of data separately;and restoring the encrypted data set from at least a subset of the at least two portions of data.
  15. 57
    A method for securing a data set, the method comprising:generating at least two portions of data from the data set, wherein each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the data set ;encrypting each of the at least two portions of data using an encryption key into at least two portions of encrypted data;transforming the encryption key using an All or Nothing Transform into a transformed encryption key;WO 2006/047694 PCT/US2005/038806 generating tranformed encryption key information that is capable of being used to generate the transformed encryption key, wherein the transformed encryption key information is distributed among the at least two portions of data;storing each of the at least two portions of encrypted data separately;and restoring the data set from at least a subset of the at least two portions of data.
  16. 59
    A method for securing a data set, the method comprising:generating, using a splitting key, at least two portions of data from the data set, wherein each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the data set;transforming the splitting key using an All or Nothing Transform into a transformed splitting key;generating tranformed splitting key information that is capable of being used to generate the transformed splitting key, wherein the transformed WO 2006/047694 PCT/US2005/038806 splitting key information is distributed among the at least two portions of data;storing each of the at least two portions of data separately;and restoring the data set from at least a subset of the at least two portions of data.
  17. 61
    A method for securing a data set, the method comprising:encrypting the data set using an encryption key into an encrypted data set;encrypting the encryption key;generating at least two portions of data from the encrypted data set, wherein each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the encrypted data set;storing each of the at least two portions of the encrypted data set separately;restoring the encrypted data set from at least a subset of the at least two portions of the encrypted data set;decrypting the encryption key;and decrypting the data set from the encrypted data set using the encryption key. WO 2006/047694 PCT/US2005/038806
  18. 63
    A method for securing a data set, the method comprising:generating at least two portions of data from the data set, wherein each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the data set ;encrypting the at least two portions of data using an encryption key into at least two encrypted portions of data;encrypting the encryption key;storing each of the at least two encrypted portions of data separately;and restoring the data set from at least a subset of the at least two encrypted portions of data, the restoring comprising: decrypting the encryption key, and decrypting the at least a subset of the at least two encrypted portions of data using the encryption key.
  19. 65
    A method for securing a data set, the method comprising:generating, using a splitting key, at least two portions of data from the data set, wherein WO 2006/047694 PCT/US2005/038806 each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the data set;encrypting the splitting key using an encryption key;storing each of the at least two portions of the data set separately;and restoring the data set from at least a subset of the at least two portions of the data set, the restoring comprising: decrypting the splitting key, and restoring, using the splitting key, the data set from the at least a subset of the at least two portions of data.
  20. 67
    A method for securing a data set, the method comprising:determining a number of portions of data into which to distribute the data set;sequentially distributing substantially equal shares of data from the data set into each of the data portions, respectively;appending redundancy data to each of the portions of data;storing each of the data portions separately;and restoring the data set from a subset of the data portions. WO 2006/047694 PCT/US2005/038806
  21. 68
    A method for securing a data set, the method comprising:determining a number of portions of data into which to distribute the data set;sequentially distributing the data set, one bit at a time, into each of the data portions, respectively, in a round-robin manner until all bits of the data set have been distributed;appending redundancy data to each of the portions of data;storing each of the data portions separately;and restoring the data set from a subset of the data portions.
  22. 69
    A system for securing communication of a data set from a first location to a second location, the system comprising:a first processor for generating at the first location at least two portions of data from the data set, wherein each of the at least two portions of data respectively contains a substantially random distribution of a respective subset of the data set;at least one communications path over which are communicated the at least two portions of data from the first location to the second location, wherein the at least two portions of data are communicated separately from each other;and a second processor for restoring at the second location the data set from at least a subset of the at least two portions of data. WO 2006/047694 PCT/US2005/038806
  23. 81
    communications communications The system of claim 74, wherein wireless path comprises a satellite path.
Independent claims23