Nova Patents
US20120321086A1

Cloud key escrow system

Claim Score by NHIP

Read claim 1, the broadest

Abstract

Embodiments are directed to allowing a user to store encrypted, third-party-accessible data in a data store and to providing third party data access to a user's encrypted data according to a predefined policy. A data storage system receives encrypted data from a user at a data storage system. The data is encrypted using the user's private key. The data storage system stores the received encrypted data according to a predefined policy. The encryption prevents the storage system from gaining access to the encrypted data, while the policy allows the encrypted data to be released upon receiving a threshold number of requests from verified third parties. The data storage system implements a verifiable secret sharing scheme to verify that the encrypted data can be reconstituted without the data storage system accessing the encrypted data. The data storage system synchronously acknowledges that the received encrypted data has been verified and successfully stored.

US20120321086A1, drawing sheet 1
Sheet 1 of 5

Term

5 yearsto projected expiry

Projected expiry 20 September 2031, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

20 claims: 3 independent, 17 dependent

  1. 1
    Broadest claimClaim Score 53, average(NHIP)At a computer system including at least one processor and a memory, in a computer networking environment including a plurality of computing systems, a computer-implemented method for allowing a user to store encrypted, third-party-accessible data in a data store, the method comprising:an act of receiving encrypted data from a user at a data storage system, wherein the encrypted data is encrypted using the user's private key;an act of storing the received encrypted data in the data storage system according to a predefined policy, the encryption preventing the storage system from gaining access to the encrypted data, the policy allowing the encrypted data to be released upon receiving a threshold number of requests from verified third parties;an act of the data storage system implementing a verifiable secret sharing scheme to verify that the encrypted data can be reconstituted without the data storage system accessing the encrypted data;and an act of synchronously acknowledging to the user that the received encrypted data has been verified and successfully stored.
  2. 13
    A computer program product for implementing a method for providing third party data access to a user's encrypted data according to a predefined policy, the computer program product comprising one or more computer-readable storage media having stored thereon computer-executable instructions that, when executed by one or more processors of the computing system, cause the computing system to perform the method, the method comprising:an act of receiving a request from a third party to access a user's stored, encrypted data, the data being stored in a data storage system according to a predefined policy, the encryption preventing the storage system from gaining access to the encrypted data, the policy allowing the encrypted data to be released upon receiving a threshold number of requests from verified third parties;an act of sending a query to a plurality of the verified third parties, requesting permission from the verified third parties to access the user's stored, encrypted data according to the predefined policy;an act of receiving permission from at least a threshold number of the verified third parties;and an act of allowing the requesting third party to access the user's stored, encrypted data according to the predefined policy.
  3. 18
    A computer system comprising the following:one or more processors;system memory;one or more computer-readable storage media having stored thereon computer-executable instructions that, when executed by the one or more processors, causes the computing system to perform a method for allowing a user to store encrypted, third-party-accessible data in a data store, the method comprising the following: an act of receiving encrypted data from a user at a data storage system, wherein the encrypted data is encrypted using the user's private key;an act of storing the received encrypted data in the data storage system according to a predefined policy, the encryption preventing the storage system from gaining access to the encrypted data, the policy allowing the encrypted data to be released upon receiving a threshold number of requests from verified third parties, wherein the received encrypted key is stored as a plurality of shares, the shares being mathematical transformations of the user's private key, and wherein each share is provided to one of the verified third parties;an act of the data storage system implementing a verifiable secret sharing scheme to verify that the encrypted data can be reconstituted without the data storage system accessing the encrypted data;an act of synchronously acknowledging to the user that the received encrypted data has been verified and successfully stored;an act of receiving a request from the user requesting the user's encrypted data;and an act of the data storage system providing the user's stored encrypted data based on the user's request.