Data sharing system method

Patent No. US10187347 (titled "Data sharing system method") on Jun 24, 2016. The application was issued on Jan 22, 2019.

What is this patent about?

’347 is related to the field of secure data sharing systems and online social networks. It specifically addresses the technical challenge of maintaining absolute user privacy and data security in environments where information is stored and managed by a third-party service provider. The background context involves the inherent vulnerability of traditional social networks, where service providers or hackers can access personally identifiable information because the hosting servers typically possess the means to decrypt or view user content.

The underlying idea behind ’347 is the implementation of a zero-knowledge architecture where the service provider acts as a blind intermediary for encrypted data. The key inventive insight is shifting the entire burden of data transformation—both encryption and decryption—exclusively to the user's local device. By ensuring that the decryption keys never exist in an unencrypted state on the central server, the system creates a trustless environment where the host can store and route data packets based on metadata without ever having the technical capability to inspect the actual content.

The claims of ’347 focus on a method for multi-user data exchange that utilizes a third-party server as a storage and transmission relay for encrypted files. The process requires a local data obscuring module on each user's device to transform original files into encrypted versions before they reach the server. Central to the claims is the mechanism for selectively exchanging security keys between qualified users in a manner that bypasses the server’s ability to intercept or reveal those keys, thereby ensuring only authorized recipients can reconstitute the original data.

In practice, the invention works by establishing a key locker on the user's device, which manages the various keys needed to unlock content from different contacts. When a user creates content, the local client encrypts it using a symmetric or asymmetric key before transmission. The server then identifies the intended recipients through unencrypted attributes and forwards the ciphered package. The recipient's device automatically retrieves the corresponding key from its local locker to render the content, ensuring the plaintext only ever exists in the volatile memory of the end-users' devices.

This approach differs from prior solutions by removing the service provider's role as a trusted authority for key management. Unlike standard communal repositories where the host manages encryption in a way that is transparent but accessible to the provider, this system utilizes a blind relay model. By facilitating a key exchange protocol that is opaque to the server, the invention prevents the host from exploiting user data for advertising or analysis, effectively insulating the information from both internal provider abuse and external server-side breaches.

How does this patent fit in bigger picture?

Technical Landscape

In the early 2010s when ’347 was filed, online social networking and data sharing systems were typically implemented using centralized server architectures where user data was stored and managed in unencrypted or server-side encrypted formats. At a time when systems commonly relied on the service provider to maintain and manage encryption keys, hardware and software constraints made the implementation of end-to-end privacy non-trivial, as servers required access to raw data for indexing, analysis, and distribution. Standard engineering practices often prioritized server-side control for data synchronization and recovery, meaning that while data might be encrypted during transmission, it remained accessible to the hosting entity’s internal processes and personnel.

Prosecution Position

The disclosed invention represents a meaningful technical advancement through an architectural shift that ensures absolute data privacy by maintaining user information in an obfuscated state at all times except during local client-side viewing. This integration of a client-side 'key locker'—which is itself doubly obfuscated—enables a secure data sharing environment where the central server facilitates distribution without ever possessing the means to de-obfuscate the content. The solution overcomes the technical constraint of server-side vulnerability by ensuring that decryption keys are exclusively held by the author and their designated contacts. This architecture enables a capability for secure, multi-user social interaction and data archiving where the service provider is technically precluded from exploiting or disclosing user data, even in the event of a server-level security breach.

Claims

The patent contains a total of 4 claims, with claim 1 serving as the sole independent claim. This independent claim focuses on a method for secure data exchange between users via a third-party server, utilizing a data obscuring module to encrypt files and a private security key exchange that prevents the third party from accessing the original content. The dependent claims serve to further refine the process by introducing identity verification protocols through server inquiries, device-specific response configurations, and automated disconnection mechanisms for enhanced security.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Data obscuring module
(Claim 1)
The DSS client also encrypts new data which the user creates, edits, uploads, or otherwise introduces to the system. The DSS client also decrypts all encrypted user data and contact data which it receives from the computers, servers, and/or programs which form the server of the DSS. These means of data obfuscation and de-obfuscation may involve the use of values analogous to keys which are used in combination with a corresponding algorithm or method to achieve a unique result.A software component or set of computer codes residing on a user's local device responsible for transforming original data into an unreadable format (obfuscation) and restoring it (de-obfuscation) using specific values or keys.
Reconstituting the original data
(Claim 1)
The DSS client also decrypts all encrypted user data and contact data which it receives from the computers, servers, and/or programs which form the server of the DSS. It then composes the decrypted graphics, text and/or other types of media, within a user interface, on a user's computing device, thereby allowing the user to view, read, edit and/or otherwise interact with those that data and/or media. 'De-obfuscation' can mean that the true nature and data contained in a body of data is hidden in a manner which may not be reasonably revealed in the absence of a specific means of 'de-obfuscation.'The process of de-obfuscating or decrypting an encrypted data file back into its original, intelligible format (such as text, photos, or video) using a corresponding security key.
Security keys
(Claim 1)
The decryption keys required to access data are retained by the 'owners' (i.e. the authors and/or uploaders) of the data. In an embodiment, a user's encryption key is an alphanumeric character string. This arrangement ensures that a user's data cannot be examined by anyone other than the user or the user's contacts.Unique alphanumeric strings or cryptographic values (symmetric or asymmetric) used by the data obscuring module to encrypt or decrypt data, which are kept in the sole possession of users and their authorized contacts.
Third party data sharing server
(Claim 1)
The DSS server is responsible for, among other things, the storage and transmission of encrypted user data. This arrangement ensures that a user's data cannot be examined by anyone other than the user or the user's contacts. The system neither possesses nor has access to these keys, and the operators of such a system are therefore unable to access, view, read, disclose or exploit user data.A centralized or distributed network of computers that facilitates the storage and transmission of encrypted data packets between users without possessing the means to decrypt or view the content.
User identification confirmation protocol
(Claim 1)
Following a successful system log in (achieved through the submission of a valid username and password) the DSS client is responsible for receiving from a user that user's primary encryption key. The DSS server is responsible for validating the login usernames and passwords of users. The identities of a user on all subsequent interactions with the system are verified by means of the username and password originally specified by a user at the time of account creation.A security procedure, typically involving a unique username and password, used by the server to validate a user's identity and right to access specific account data before allowing data exchange.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
2:25-cv-00316Mar 28, 2025Brian Moffat Private Data LLC v. Tresorit AG
2:25-cv-00315Mar 28, 2025Brian Moffat Private Data Llc V. Mega Limited

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US10187347

Application Number
US15192584A
Filing Date
Jun 24, 2016
Publication Date
Jan 22, 2019
External Links
Slate, USPTO , Google Patents