Nova Patents
CA2529042A1

Secure data parser method and system

Abstract

The present invention provides a method and system for securing sensitive data from unauthorized access or use. The method and system of the present invention is useful in a wide variety of settings, including commercial settings generally available to the public which may be extremely large or small with respect to the number of users. The method and system of the present invention is also useful in a more private setting, such as with a corporation or governmental agency, as well as between corporation, governmental agencies or any other entity.

CA2529042A1, drawing sheet 1
Sheet 1 of 30

Term

Term ended

Projected expiry passed 10 June 2024, 2.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

66 claims: 7 independent, 59 dependent

  1. 1
    CA 02529042 2005-12-09 WO 2004/111791 PCT/US2004/018426 WHAT IS CLAIMED IS:1. A method, comprising: a) encrypting a data set to provide an encrypted data set;b) separating the encrypted data set into two or more portions of data;c) encrypting one or more of the portions of data from step b);and d) storing the encrypted portions of data from step c) at one or more locations on one or more data depositories.
  2. 10
    A method, comprising:a) separating a data set into two or more portions of data;b) encrypting one or more of the portions of data of step a);and c) storing the one or more encrypted portions of data of step b) on one or more locations on one or more data depository.
  3. 20
    A method, comprising:a) generating an encryption master key and encrypting a data set using the encryption master key;b) separating each of the encryption master key and the encrypted data set into two or more portions according to one separating pattern and appending an encryption master key portion to an encrypted data set portion;c) generating one or more encryption keys for the portions of data from step b) and encrypting said portions of data using said encryption key;and d) storing the encrypted portions of data from step c) and the encryption keys from step c) on at least one data depository.
  4. 30
    A method, comprising:a) generating an encryption master key and encrypting a data set using the encryption master key;-104CA 02529042 2005-12-09 WO 2004/111791 PCT/US2004/018426 b) separating each of the encryption master key and the encrypted data set into two or more portions according to one separating pattern and storing the encryption master key portions on one or more locations of one or more data depositories;c) generating one or more encryption keys for the encrypted data set portions of step b) and encrypting said portions of data using said encryption key;and d) storing the encrypted portions from step c) and the encryption keys from step c) on at least one location of at least one data depository, wherein said data depositories are different from the data depositories of step b).
  5. 40
    A system, comprising:a) a data splitting module;b) a cryptographic handling module;and c) a data assembling module.
  6. 44
    A method, comprising:-106CA 02529042 2005-12-09 WO 2004/111791 PCT/US2004/018426 a) encrypting a data set to provide an encrypted data set;b) separating the encrypted data set into two or more portions of data according to the contents of a unique key value;c) encrypting one or more of the portions of data from step b);and d) storing the encrypted portions of data from step c) at one or more locations on one or more data depositories.
  7. 53
    54. A method, comprising:a) splitting a data set into N number of data units;b) selecting X number of shares for data unit storage;c) generating N number of random numbers that correspond to the X number of shares;d) assigning the random numbers to the data units;and e) storing the data units and the random number in the share that corresponds to the random number.
  8. 55
    56. A system, comprising:a) a data splitting module;b) a cryptographic handling module;and c) a data assembling module, wherein said system performs the method of claim 1.
  9. 56
    57. A system, comprising:a) a data splitting module;b) a cryptographic handling module;and c) a data assembling module, -108CA 02529042 2005-12-09 WO 2004/111791 PCT/US2004/018426 wherein said system performs the method of claim 1, and optionally, wherein the encrypting of step c) is performed using an encryption algorithm that is different from the encryption algorithm used in step a).
  10. 57
    58. A system, comprising:a) a data splitting module;b) a cryptographic handling module;and c) a data assembling module, wherein said system performs the method of claim 10.
  11. 58
    59. A system, comprising:a) a data splitting module;b) a cryptographic handling module;and c) a data assembling module, wherein said system performs the method of claim 10, and optionally, wherein the encrypting of step c) is performed using an encryption algorithm that is different from the encryption algorithm used in step a).
  12. 59
    60. A system, comprising:a) a data splitting module;b) a cryptographic handling module;and c) a data assembling module, wherein said system performs the method of claim 20.
  13. 60
    61. A system, comprising:a) a data splitting module;b) a cryptographic handling module;and c) a data assembling module, wherein said system performs the method of claim 20, and optionally, wherein the encrypting of step c) is performed using an encryption algorithm that is different from the encryption algorithm used in step a). -109CA 02529042 2005-12-09 WO 2004/111791 PCT/US2004/018426
  14. 61
    62. A system, comprising:a) a data splitting module;b) a cryptographic handling module;and c) a data assembling module, wherein said system performs the method of claim 30.
  15. 62
    63. A system, comprising:a) a data splitting module;b) a cryptographic handling module;and c) a data assembling module, wherein said system performs the method of claim 30, and optionally, wherein the encrypting of step c) is performed using an encryption algorithm that is different from the encryption algorithm used in step a).
  16. 63
    64. A system, comprising:a) a data splitting module;b) a cryptographic handling module;and c) a data assembling module, wherein said system performs the method of claim 44.
  17. 64
    65. A system, comprising:a) · a data splitting module;b) a cryptographic handling module;and c) a data assembling module, wherein said system performs the method of claim 44, and optionally, wherein the encrypting of step c) is performed using an encryption algorithm that is different from the encryption algorithm used in step a).
  18. 65
    66. A system, comprising:-110CA 02529042 2005-12-09 WO 2004/111791 PCT/US2004/018426 a) a data splitting module;b) a cryptographic handling module;and c) a data assembling module, wherein said system performs the method of claim 54.
  19. 66
    67. A system, comprising:a) a data splitting module;b) a cryptographic handling module;and c) a data assembling module, wherein said system performs the method of claim 54, and optionally, wherein the encrypting of step c) is performed using an encryption algorithm that is different from the encryption algorithm used in step a). -Ill-