Patent No. US10187347 (titled "Data sharing system method") on Jun 24, 2016. The application was issued on Jan 22, 2019.
’347 is related to the field of secure data sharing systems and online social networks. It specifically addresses the technical challenge of maintaining absolute user privacy and data security in environments where information is stored and managed by a third-party service provider. The background context involves the inherent vulnerability of traditional social networks, where service providers or hackers can access personally identifiable information because the hosting servers typically possess the means to decrypt or view user content.
The underlying idea behind ’347 is the implementation of a zero-knowledge architecture where the service provider acts as a blind intermediary for encrypted data. The key inventive insight is shifting the entire burden of data transformation—both encryption and decryption—exclusively to the user's local device. By ensuring that the decryption keys never exist in an unencrypted state on the central server, the system creates a trustless environment where the host can store and route data packets based on metadata without ever having the technical capability to inspect the actual content.
The claims of ’347 focus on a method for multi-user data exchange that utilizes a third-party server as a storage and transmission relay for encrypted files. The process requires a local data obscuring module on each user's device to transform original files into encrypted versions before they reach the server. Central to the claims is the mechanism for selectively exchanging security keys between qualified users in a manner that bypasses the server’s ability to intercept or reveal those keys, thereby ensuring only authorized recipients can reconstitute the original data.
In practice, the invention works by establishing a key locker on the user's device, which manages the various keys needed to unlock content from different contacts. When a user creates content, the local client encrypts it using a symmetric or asymmetric key before transmission. The server then identifies the intended recipients through unencrypted attributes and forwards the ciphered package. The recipient's device automatically retrieves the corresponding key from its local locker to render the content, ensuring the plaintext only ever exists in the volatile memory of the end-users' devices.
This approach differs from prior solutions by removing the service provider's role as a trusted authority for key management. Unlike standard communal repositories where the host manages encryption in a way that is transparent but accessible to the provider, this system utilizes a blind relay model. By facilitating a key exchange protocol that is opaque to the server, the invention prevents the host from exploiting user data for advertising or analysis, effectively insulating the information from both internal provider abuse and external server-side breaches.
In the early 2010s when ’347 was filed, online social networking and data sharing systems were typically implemented using centralized server architectures where user data was stored and managed in unencrypted or server-side encrypted formats. At a time when systems commonly relied on the service provider to maintain and manage encryption keys, hardware and software constraints made the implementation of end-to-end privacy non-trivial, as servers required access to raw data for indexing, analysis, and distribution. Standard engineering practices often prioritized server-side control for data synchronization and recovery, meaning that while data might be encrypted during transmission, it remained accessible to the hosting entity’s internal processes and personnel.
The disclosed invention represents a meaningful technical advancement through an architectural shift that ensures absolute data privacy by maintaining user information in an obfuscated state at all times except during local client-side viewing. This integration of a client-side 'key locker'—which is itself doubly obfuscated—enables a secure data sharing environment where the central server facilitates distribution without ever possessing the means to de-obfuscate the content. The solution overcomes the technical constraint of server-side vulnerability by ensuring that decryption keys are exclusively held by the author and their designated contacts. This architecture enables a capability for secure, multi-user social interaction and data archiving where the service provider is technically precluded from exploiting or disclosing user data, even in the event of a server-level security breach.
The patent contains a total of 4 claims, with claim 1 serving as the sole independent claim. This independent claim focuses on a method for secure data exchange between users via a third-party server, utilizing a data obscuring module to encrypt files and a private security key exchange that prevents the third party from accessing the original content. The dependent claims serve to further refine the process by introducing identity verification protocols through server inquiries, device-specific response configurations, and automated disconnection mechanisms for enhanced security.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents