Outer Rim Archives
Archives · 2021 · 20210176222

Application (pre-grant publication)

Domain Transcendent File Cryptology Network

Number
20210176222
Published
2021-06-10
Filed
2019-12-09
Assignee
Disney Enterprises, Inc.
Inventors
Scott; Thomas C., Estes; Matthew D., Hill; Douglas A.
CPC
H04L9/0866; H04L9/3239; H04L9/083; H04L63/06; H04L63/0471; H04L9/3228; H04L9/0894; H04L63/0876
Verdict
Set aside file encryption network, cybersecurity
Source
Google Patents · FreePatentsOnline

Abstract

A domain transcendent file cryptology network includes a first data cryptology node in a first data domain having a first security protocol. A hardware processor of the first data cryptology node executes a first instantiation of a software code to receive a request to transfer a data file from the first data domain to a second data domain having a second, different, security protocol, obtain one or more characteristics of the data file, and generate an authentication tag for the data file based on the characteristic(s). The first instantiation of the software code also encrypts the data file and transmits the encrypted data file, the authentication tag, and a decryption key to a second data cryptology node in the second data domain. The decryption key to and the authentication tag enable decryption of the encrypted data file by a second instantiation of the software code on the second data cryptology node.

Background

BACKGROUND

Some modern data workflows require the transfer and coordination of data files between distinct data domains maintained by different cloud providers and governed by different security protocols. For example, cloud services provided by MICROSOFT®, AMAZON®, and GOOGLE®, each offers a distinct authentication and encryption solution. Consequently, when a workload extends across two or more different cloud service providers, that workload typically requires separate key management solutions that can impose significant administrative overhead to track and protect data assets.

One conventional solution for avoiding the direct burdens of working with multiple key management solutions is to outsource these functions to a third party vendor. However, reliance on a third party key management and data security service requires licensing, and imposes its own set of administrative costs. Moreover, outsourced security solutions can be vulnerable to attacks and malicious software, and may need to be carefully monitored to ensure that they are continuously kept up to date. Thus, there is a need in the art for a cryptology solution providing robust data tracking and security, while enabling seamless workflows across multiple cloud service providers. SUMMARY

There are provided domain transcendent file cryptology networks and methods for use by such networks, substantially as shown in and/or described in connection with at least one of the figures, and as set fort

Claims

1. A domain transcendent file cryptology network comprising: a first data cryptology node in a first data domain governed by a first security protocol, the first data cryptology node having a hardware processor and a memory storing a first instantiation of a software code; the hardware processor being configured to execute the first instantiation of the software code to: receive a request to transfer a data file stored in the first data domain to a second data domain governed by a second security protocol different from the first security protocol; obtain one or more characteristics of the data file; generate an authentication tag for the data file based on the one or more characteristics of the data file; encrypt the data file to generate an encrypted data file; and transmit, in response to the request, the encrypted data file, the authentication tag, and a decryption key for decrypting the encrypted data file to a second data cryptology node in the second data domain; wherein the decryption key and the authentication tag enable decryption of the encrypted data file by a second instantiation of the software code resident on the second data cryptology node. || 11. A method for use by a domain transcendent file cryptology network including a first data cryptology node in a first data domain governed by a first security protocol, the first data cryptology node having a hardware processor and a memory storing a first instantiation of a software code, the method comprising: receiving, by the first instantiation of the software code executed by the hardware processor of the first data cryptology node, a request to transfer a data file stored in the first data domain to a second data domain governed by a second security protocol different from the first security protocol; obtaining, by the first instantiation of the software code executed by the hardware processor of the first data cryptology node, one or more characteristics of the data file; generating, by the first instantiation of the software code executed by the hardware processor of the first data cryptology node, an authentication tag for the data file based on the one or more characteristics of the data file; encrypting, by the first instantiation of the software code executed by the hardware processor of the first data cryptology node, the data file to generate an encrypted data file; and transmitting, in response to the request, by the first instantiation of the software code executed by the hardware processor of the first data cryptology node, the encrypted data file, the authentication tag, and a decryption key for decrypting the encrypted data file to a second data cryptology node in the second data domain; wherein the decryption key and the authentication tag enable decryption of the encrypted data file by a second instantiation of the software code resident on the second data cryptology node.