Private data sharing system

Patent No. US9397983 (titled "Private data sharing system") on Mar 4, 2015. The application was issued on Jul 19, 2016.

What is this patent about?

’983 is related to the field of secure data sharing systems (DSS) and online social networks. Traditional social platforms often store user data in a format accessible to the service provider, creating vulnerabilities to data mining, unauthorized employee access, and external hacking. The background context emphasizes a long-felt need for a system where privacy is mathematically guaranteed, ensuring that personally identifiable information remains confidential even from the entities hosting the infrastructure.

The underlying idea behind ’983 is the implementation of a zero-knowledge architecture where data is obfuscated at the source and remains encrypted throughout its entire lifecycle on the network. The key inventive insight is shifting the burden of decryption from the central server to the individual client nodes. By ensuring the server never possesses the de-obfuscation logic or keys, the system creates a trustless environment where the service provider acts merely as a blind postman, routing packets it cannot read.

The claims of ’983 focus on a multi-user data sharing method and client architecture that facilitates private exchange between at least three distinct users. The independent claims cover the specific mechanism where each user employs a unique data obfuscation value and/or program (DOVP) to secure their files before transmission. Crucially, the claims require that each recipient client must possess a specific, complementary de-obfuscation value provided directly or indirectly by the original author to successfully render the data.

In practice, the invention works by having each user initialize their client with a personal passphrase that generates a unique encryption profile. When a user shares a photo or message, the client encrypts the file locally before it ever hits the wire. The central server receives these obfuscated data packets (ODPs) and routes them to authorized contacts. Because each user has a different key, a recipient's client must maintain a key locker containing the specific decryption parameters for every individual friend in their network to decode the incoming stream.

This approach differentiates itself from prior solutions by eliminating the central authority's role in key management. Unlike standard communal repositories that use server-side encryption, this system ensures that the server lacks the de-obfuscation means entirely. Even if the server infrastructure is compromised, the data remains useless to the attacker. Furthermore, the system provides a secure recovery path by allowing users to retrieve lost keys from their trusted contacts, leveraging the distributed nature of the social graph to maintain availability without sacrificing privacy.

How does this patent fit in bigger picture?

Technical Landscape

In the early 2010s when ’983 was filed, online social networks and data sharing systems were typically implemented using centralized server architectures where user data was stored in a format accessible to the service provider. At a time when systems commonly relied on server-side encryption using provider-managed keys rather than client-side obfuscation, the privacy of personally identifiable information was often vulnerable to internal exploitation or external breaches. Furthermore, when hardware and software constraints made the seamless, automated exchange of private decryption keys between disparate client devices non-trivial, most platforms prioritized ease of access and data mining capabilities over absolute user-controlled data sovereignty.

Prosecution Position

The disclosed invention represents a meaningful technical advancement through the integration of a client-side obfuscation architecture that ensures neither the central server nor its operators can access or discern the underlying user data. This architectural shift is achieved by utilizing a local client program to encrypt data before transmission and managing a secure 'key locker' structure that is itself doubly encrypted, requiring both user-defined and system-supplied values for access. This configuration enables a novel capability where users can recover lost credentials through a distributed trust model with established contacts without exposing the keys to the central authority. By decoupling data storage from data de-obfuscation, the system overcomes the technical constraint of provider-side data vulnerability while maintaining the social functionality of shared archives and real-time communication.

Claims

This patent contains 63 claims, with claims 1, 3, 24, 37, 42, 45, and 54 being independent. The independent claims focus on methods, client architectures, and computer-readable media for facilitating private data sharing among multiple users by utilizing unique, user-specific obfuscation and de-obfuscation values or programs that ensure a central server cannot access the underlying data. The dependent claims serve to further define specific technical implementations, such as the use of encryption keys, the storage of obfuscated data on servers, the management of keys within secure lockers, and the verification of user credentials and sharing permissions within the network.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Data de-obfuscation value and/or program or portion of a program
(Claim 24, Claim 45)
When we want to refer to a means of data de-obfuscation without limitation as to its implementation and/or method of implementation, we will refer to the use of 'a data de-obfuscation value and/or program or portion of a program' (DDVP). For any particular means of obfuscation employed to 'hide' data, there will be a specific corresponding means of de-obfuscation. This includes the use of unique 'decryption keys' or customized algorithms for which customized programs and/or computer code is required.The specific key, code, or algorithmic component required to restore obfuscated data to its original, intelligible state.
Decryption key and/or a decryption methodology
(Claim 42)
Whenever a 'decryption key' is specified it should be understood to refer to any data value and/or customized computer code(s) capable of independently achieving data restoration. In an embodiment, a user's encryption key is an alphanumeric character string, also referred to as a 'passphrase'. The decryption keys required to access data are retained by the authors or uploaders of the data, and the system neither possesses nor has access to these keys.The specific alphanumeric string or algorithmic process used by a client to revert encrypted data back into its original format.
Key locker
(Claim 24 (indirectly via 'provided to'), Specification (defining the mechanism for Claim 24/45/54))
A key locker is a file and/or data structure containing the identifiers and values of the decryption keys of each of the user's friends and/or contacts. Each time a user adds a new key_id:key_value pair to his key locker the DSS client encrypts the augmented key locker and transmits that encrypted key locker to the DSS server for storage. This decrypted key locker will then allow the user to decrypt all of the encrypted user data sent to the user's DSS client by the DSS server.A secure data structure or file stored within the system that contains the collection of decryption keys a user has acquired from their contacts, itself protected by encryption.
Obfuscated data packet
(Claim 1, Claim 37, Claim 54)
Obfuscation can mean that the true nature and data contained in a body of data is hidden in a manner which may not be reasonably revealed in the absence of a specific means of de-obfuscation. This disclosure may refer to the data which is stored, transmitted, obfuscated, de-obfuscated, etc. as a body of data, a packet of data, a collection of data, a set of data, a data file, a data object, etc. All of these represent the same thing which is a unit of digital information which is manipulated, processed, transmitted and/or stored by the program in question.A unit of digital information that has been transformed such that its true nature and contents are hidden and cannot be reasonably revealed without a specific corresponding means of restoration.
Obfuscating algorithm and/or parameter
(Claim 37, Claim 54)
These data obfuscation methods may produce a result which is determined, at least in part, by some value or key which is input to the method along with the data to be obfuscated. If the means of obfuscation is a specific symmetric encryption algorithm, the product of such an encryption can be made unique through the use of a unique 'encryption key' or 'key'. The user enters this key at the start of each session, that is, each time the user's DSS client is initialized.A specific mathematical process or unique input value (such as a user-defined passphrase) used by a client to hide data before transmission.
Value, method and/or program or portion of a program
(Claim 1, Claim 24, Claim 45)
Embodiments also support the use of means of data obfuscation and de-obfuscation other than encryption and decryption. These means may involve the use of values analogous to keys which are used in combination with a corresponding algorithm or method to achieve a unique result. When the use of any means of data obfuscation and/or de-obfuscation is denoted, without limitation as to its implementation and/or method of implementation, it will be referred to as the use of a 'value, method and/or program or portion of a program' (VMP).A generic reference to the specific means (such as a cryptographic key or a custom algorithm) used to perform data obfuscation or de-obfuscation, regardless of the specific implementation method.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
2:25-cv-00316Mar 28, 2025Brian Moffat Private Data LLC v. Tresorit AG
2:25-cv-00315Mar 28, 2025Brian Moffat Private Data Llc V. Mega Limited

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US9397983

Application Number
US14638294A
Filing Date
Mar 4, 2015
Publication Date
Jul 19, 2016
External Links
Slate, USPTO , Google Patents