US2015113270A1PendingUtilityA1
Method and System for Securing Documents on a Remote Shared Storage Resource
Est. expiryJun 8, 2031(~4.9 yrs left)· nominal 20-yr term from priority
Inventors:Robin Glover
G06F 2221/2111G06Q 10/101G06F 2221/2137G06F 2221/2149G06F 21/602H04L 63/083H04L 63/0807G06F 40/166G06F 21/6227G06F 21/62H04L 63/107H04L 9/0861
58
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
This invention discloses a novel system and method for displaying electronic documents on remote devices and enabling collaborative editing in conjunction with a content management system where the documents that are shared are securely encrypted on the system in a manner that avoids a single point of failure in the security.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . A method executed by a shared computer system of securing a set of content files stored on the shared computer system that are organized in a folder, said folder being associated with a folder originator, said originator being associated with a public/private encryption key pair, the method comprising:
creating a data structure representing a folder, said folder data structure being adapted to be associated with at least one content file; generating a public/private encryption key pair uniquely associated with the folder data structure; encrypting the folder private key with the public key associated with a folder originator associated with the folder; removing from computer data storage the unencrypted version of the folder private key.
2 . The method of claim 1 further comprising:
receiving a content file to be associated with the folder data structure;
generating a public/private encryption key associated with the content file;
encrypting the content file with the public key associated with the content file;
encrypting the private key associated with the content file using the public key of the folder; and
removing from computer data storage the unencrypted version of the content file private key.
3 . The method of claim 1 further comprising:
decrypting the folder private key using the originator private key;
obtaining a destination user public key;
encrypting the folder private key using the public key of the destination user.
4 . A computer system comprised of at least one central processing unit operatively connected to at least one data storage device, said system for storing shared content files comprising a database, said database comprised of:
data records, each associated with a user, each data record associated with a user comprised of an entry representing an encrypted version of the user's private key and an entry representing the user's public key; data records associated with folders, each folder associated with content files, each data record associated with folders comprised of an entry representing an encrypted version of the private key associated with the folder, and an entry representing the file public key, where said file private key is encrypted using the public key of the folder.
5 . A computer system for securing a set of content files stored on said system that are organized in a folder, said system being comprised of at least one central processing unit operatively connected to at least one data storage device and adapted to execute a method comprising of:
creating a data structure representing a folder, said folder data structure being adapted to be associated with at least one content file; generating a public/private encryption key pair uniquely associated with the folder data structure; encrypting the folder private key with the public key associated with a folder originator associated with the folder; removing from computer data storage the unencrypted version of the folder private key.
6 . The system of claim 5 further adapted to execute a method comprising:
receiving a content file to be associated with the folder data structure;
generating a public/private encryption key associated with the content file;
encrypting the content file with the public key associated with the content file;
encrypting the private key associated with the content file using the public key of the folder; and
removing from computer data storage the unencrypted version of the content file private key.
7 . The system of claim 6 further adapted to execute the method of:
decrypting the folder private key using the originator private key;
obtaining a destination user public key; and
encrypting the folder private key using the public key of the destination user.
8 . A non-transitory computer storage medium containing program code that, when executed by a computer system, causes the computer system to execute a method comprising of:
creating a data structure representing a folder, said folder data structure being adapted to be associated with at least one content file; generating a public/private encryption key pair uniquely associated with the folder data structure associated with the folder; encrypting the folder private key with the public key associated with a folder originator; removing from computer data storage the unencrypted version of the folder private key.
9 . The non-transitory storage medium of claim 8 further adapted so that the executed method is further comprised of:
receiving a content file to be associated with the folder data structure;
generating a public/private encryption key associated with the content file;
encrypting the content file with the public key associated with the content file;
encrypting the private key associated with the content file using the public key of the folder; and
removing from computer data storage the unencrypted version of the content file private key.
10 . The non-transitory storage medium of claim 8 further adapted so that the executed method is further comprised of:
decrypting the folder private key using the originator private key;
obtaining a destination user public key; and
encrypting the folder private key using the public key of the destination user.Join the waitlist — get patent alerts
Track US2015113270A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.