The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 31, 2021

Filed:

Apr. 02, 2019
Applicant:

Zettaset, Inc., Mountain View, CA (US);

Inventor:

Eric A. Murray, Los Gatos, CA (US);

Assignee:

ZETTASET, INC., Mountain View, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 9/54 (2006.01); G06F 21/60 (2013.01); G06F 21/62 (2013.01); H04L 9/06 (2006.01); H04L 9/08 (2006.01); H04L 9/32 (2006.01); G06F 16/00 (2019.01);
U.S. Cl.
CPC ...
H04L 63/061 (2013.01); G06F 9/54 (2013.01); G06F 16/00 (2019.01); G06F 21/602 (2013.01); G06F 21/6218 (2013.01); H04L 9/0637 (2013.01); H04L 9/088 (2013.01); H04L 9/0822 (2013.01); H04L 9/0891 (2013.01); H04L 9/3242 (2013.01); H04L 63/0435 (2013.01); H04L 63/0876 (2013.01); H04L 63/101 (2013.01); G06F 2221/2107 (2013.01); H04L 63/08 (2013.01); H04L 63/0807 (2013.01); H04L 2463/062 (2013.01);
Abstract

A computer system and methods for securing files in a file system with storage resources accessible to an authenticable user using an untrusted client device in a semi-trusted client threat model. Each file is secured in the file system in one or more ciphertext blocks along with the file metadata. Each file is assigned a unique file key FK to encrypt the file. A wrapping key WK assigned to the file is used for encrypting the file key FK to produce a wrapped file key WFK. A key manager is in charge of generating and storing keys. The file is encrypted block by block to produce corresponding ciphertext blocks and corresponding authentication tags. The authentication tags are stored in the file metadata, along with an ID of the wrapping key WK, wrapped file key WFK, last key rotation time, an Access Control List (ACL), etc. The integrity of ciphertext blocks is ensured by authentication tags and the integrity of the metadata is ensured by a message authentication code (MAC).


Find Patent Forward Citations

Loading…