Nova Patents
EP2625820B1

Private data sharing system

Abstract

This record has no abstract on file.

EP2625820B1, drawing sheet 1
Sheet 1 of 21

Term

5 yearsleft in the term

Expires 11 October 2031.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

19 claims: 2 independent, 17 dependent

  1. 1
    A data sharing system ,DSS, including:a DSS server (204, 213, 317, 1117);a first computing device (208, 1101) having operatively thereon a first DSS client (205, 302, 1105) which is initialized by a first user (201, 301) with at least a first user encryption/decryption key ("K1" of 308), the DSS server configured to upload an encrypted first key locker (307) to the first DSS client after successful login of the first DSS client, the first key locker comprising a file and/or data structure containing an identifier and value of the decryption keys of the first user's contacts stored therein;a second computing device (209, 1102) having operatively thereon a second DSS client (206, 333, 1106) which is initialized by a second user (202, 337) with at least a second user encryption/decryption key ("K2" of 325), the DSS server configured to upload an encrypted second key locker (331) to the second DSS client after successful login of the second DSS client, the second key locker comprising a file and/or data structure containing an identifier and value of the decryption keys of the second user's contacts stored therein;a third computing device (210, 1103) having operatively thereon a third DSS client (207, 346, 1107) which is initialized by a third user (203, 350) with at least a third user encryption/decryption key ("K3" of 338), the DSS server configured to upload an encrypted third key locker (344) to the third DSS client after successful login of the third DSS client, the third key locker comprising a file and/or data structure containing an identifier and value of the decryption keys of the third user's contacts stored therein;wherein the first user encryption/decryption key ("K1" of 308) is not the same as the second user encryption/decryption key ("K2" of 325);wherein the first user encryption/decryption key ("K1" of 308) is not the same as the third user encryption/decryption key ("K3" of 338);wherein the second user encryption/decryption key ("K2" of 325) is not the same as the third user encryption/decryption key ("K3" of 338);wherein: the first DSS client (205, 302), using the first user encryption/decryption key ("K1" of 308), is configured to obfuscate a data file (303) of the first user and to transmit (315) the obfuscated data file ,ODF, (311) over a data distribution network (211, 1113-1117) for receipt by at least the second (206, 333, 1106) and third (207, 346, 1107) DSS clients, respectively;the second DSS client (206, 333, 1106), using the second user encryption/decryption key ("K2" of 325), is configured to obfuscate a data file (324) of the second user and to transmit (321) the ODF (328) over the data distribution network (211, 1113-1117) for receipt by at least the first (205, 302, 1105) and third (207, 346, 1107) DSS clients, respectively;the third DSS client (207, 346, 1107), using the third user encryption/decryption key ("K3" of 338), is configured to obfuscate a data file (347) of the third user and to transmit (323) the ODF (341) over a data distribution network (211, 1113-1117) for receipt by at least the first (205, 302, 1105) and second (206, 333, 1106) DSS clients, respectively;the first DSS client (205, 302, 1105) is configured to de-obfuscate the ODF (314, 312) of the second user (202, 337) using a second user decryption key ("K2" of 309) which the second user (202, 337), directly or indirectly, provided to the first user (201, 301) and which is stored in the first key locker (307) within the first DSS client (205, 302, 1105);the first DSS client (205, 302, 1105) is configured to de-obfuscate the ODF (316, 313) of the third user (203, 350) using the third user decryption key ("K3" of 310) which the third user (203, 350), directly or indirectly, provided to the first user (201, 301) and which is stored in the first key locker (307) within the first DSS client (205, 302, 1105);the second DSS client (206, 333, 1106) is configured to de-obfuscate the ODF (319, 329) of the first user (201, 301) using a first user decryption key ("K1" of 326) which the first user (201, 301), directly or indirectly, provided to the second user (202, 337) and which is stored in a second key locker (331) within the second DSS client (206, 333, 1106);the second DSS client (206, 333, 1106) is configured to de-obfuscate the ODF (320, 330) of the third user (203, 350) using the third user decryption key ("K3" of 327) which the third user (203, 350) provided, directly or indirectly, to the second user (202, 337) and which is stored in the second key locker (331) within the second DSS client (206, 333, 1106);the third DSS client (207, 346, 1107) is configured to de-obfuscate the ODF (322, 342) of the first user (201, 301) using the first user decryption key ("K1" of 339) which the first user (201, 301) provided, directly or indirectly, to the third user (203, 350) and which is stored in the third key locker (344) within the third DSS client (207, 346, 1107);the third DSS client (207, 346, 1107) is configured to de-obfuscate the ODF (324, 343) of the second user (202, 337) using the second user decryption key ("K2" of 340) which the second user (202, 337) provided, directly or indirectly, to the third user (203, 350) and which is stored in the third key locker (344) within the third DSS client (207, 346, 1107);and wherein the first, second and third DSS clients are each configured to transmit updated respective first second and third encrypted key lockers, comprising updated identifiers and values of the decryption keys of the respective first, second and third user's contacts, to the DSS server for storage therein .
  2. 8
    A method of operating a data sharing system ,DSS, by a DSS client (205, 302, 1105) of a first user (201, 301), comprising:initializing the DSS client by the first user (201, 301) with at least a first user encryption/decryption key ("K1" of 308), and receiving an encrypted first key locker (307) from a DSS server after successful login, the first key locker comprising a file and/or data structure containing an identifier and value of the decryption keys of the first user's contacts stored therein;using the first user encryption/decryption key ("K1" of 308) to obfuscate a first data file (303) of the first user (201, 301) to create a first obfuscated data file, ODF, (311);using the first user encryption/decryption key ("K1" of 308) to obfuscate a second data file (303) of the first user (201, 301) to create a second ODF (311);transmitting (315) the first and second ODFs (311) to a second DSS client (206, 333, 1106) of a second user (202, 337) and via a data distribution network (211, 1113-1117);transmitting (315) the first and second ODFs to a third DSS client (207, 346, 1107) of a third user (203, 350) and via a data distribution network (211, 1113-1117);receiving third and fourth ODFs (314, 312) from the second DSS client (206, 333, 1106) of the second user (202, 337) and via a data distribution network (211, 1113-1117);wherein the third and fourth ODFs (314, 312) were obfuscated by the second DSS client (206, 333, 1106) using at least a second user encryption/decryption key ("K2" of 325) unique to the second user (202, 337);receiving fifth and sixth ODFs (316, 313) from the third DSS client (207, 346, 1107) of the third user (203, 350) and via a data distribution network (211, 1113-1117);wherein the fifth and sixth ODFs (316, 313) were obfuscated by the third DSS client (207, 346, 1107) using at least a third user encryption/decryption key ("K3" of 338) unique to, the third user (203, 350);de-obfuscating the third and fourth ODFs (312, 314) using at least the second user decryption key ("K2" of 309) which is stored in the first key locker (307) within the first DSS client (205, 302, 1105);de-obfuscating the fifth and sixth ODFs (313, 316) using at least a third user decryption key ("K3" of 310) which is stored in the first key locker (307) within the first DSS client (205, 302, 1105);wherein the method comprises;transmitting an updated first encrypted key locker, comprising updated identifiers and values of the decryption keys of the first user's contacts, to the DSS server for storage therein.