Patent No. US9015281 (titled "Private data sharing system") on Oct 11, 2011. The application was issued on Apr 21, 2015.
’281 is related to the field of secure data sharing systems and online social networks. It addresses the inherent privacy risks in centralized platforms where service providers or hackers can access and exploit unencrypted personal information. The background context involves the need for a system where data remains private to a user and their designated contacts, even when stored on third-party servers.
The underlying idea behind ’281 is the implementation of a zero-knowledge architecture where the central server acts merely as a blind relay and storage vault. The key inventive insight is shifting all encryption and decryption processes to the client-side, ensuring that the server never possesses the keys or the logic required to view the raw data. By utilizing user-defined keys and a secure peer-to-peer key exchange mechanism, the system creates a private ecosystem where data is only intelligible to the sender and their authorized recipients.
The claims of ’281 focus on a multi-user data sharing method and architecture where a central server facilitates the exchange of obfuscated data packets between at least three distinct clients. The independent claims specifically cover the server's role in receiving and redistributing these packets while explicitly lacking the value, method, or program needed to de-obfuscate them. Furthermore, the architecture requires each user to initialize their own unique obfuscation logic, which is then shared directly with other clients via the server in a protected manner.
In practice, the invention works by having the client program manage a key locker, which is a secure data structure containing the decryption keys for all of a user's contacts. When a user posts content, the client encrypts it before it ever hits the network. The server then routes this encrypted payload to the intended friends, whose own clients retrieve the necessary key from their local locker to render the content visible. This ensures that even if the server's database is compromised, the attacker only finds useless, scrambled bits.
This approach differs from prior solutions by removing the service provider's ability to act as a trusted intermediary for decryption. Unlike standard cloud storage that might use server-side encryption, this system prevents the host from performing data mining or complying with broad data requests, as they physically cannot access the content. The invention further differentiates itself through a secure key exchange protocol that uses asymmetric cryptography to pass private symmetric keys between users without the server ever seeing the underlying key values.
In the early 2010s when ’281 was filed, online social networking and data sharing systems were typically implemented using centralized server architectures where user data was stored in a format accessible to the service provider. At a time when systems commonly relied on server-side encryption managed by the host rather than client-side obfuscation, service providers generally maintained the ability to decrypt, analyze, and exploit user information for monetization or administrative purposes. When hardware and software constraints made the seamless, automated exchange of private cryptographic keys between disparate client devices non-trivial, users were often forced to choose between the convenience of communal repositories and the robust privacy of isolated, local encryption.
The disclosed invention represents a meaningful technical advancement by establishing a private data sharing architecture that ensures the service provider remains technically incapable of accessing user content. This architectural shift is achieved through a client-side obfuscation model where encryption and decryption keys are generated and held exclusively by users and their designated contacts, rather than the central server. The system integrates a novel 'key locker' structure that is itself doubly encrypted, enabling the secure storage and synchronization of third-party decryption keys across a user's devices without exposing those keys to the host. This configuration overcomes the technical constraint of maintaining user privacy in a networked environment, enabling secure social interactions and data distribution while preventing unauthorized data exploitation by both external hackers and internal system operators.
This patent contains a total of 35 claims, with claims 1 and 17 serving as the independent claims. The independent claims focus on a data sharing system and method for facilitating private communication between multiple clients through a server that facilitates the exchange of obfuscated data packets without possessing the necessary keys or programs to de-obfuscate the information. The dependent claims serve to further define the technical implementation by specifying the use of distribution lists, encryption methods, storage protocols for obfuscated files, and the management of de-obfuscation values through secure key lockers retrieved from the server.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents