发明名称 High privacy of file synchronization with sharing functionality
摘要 Systems and methods for providing privacy of file synchronization with sharing functionality are presented. In embodiments, a file synchronization system comprises one or more folders associated with one or more non-shared encryption keys, which may be a managed key shared across an organization, and/or a personal key that is not shared or has limited third-party sharing. The one or more non-shared encryption keys are not known to the data storage service. The file synchronization system may also include one or more folders associated with a shared encryption key that is shared with the data storage service, and in embodiments, with a set of users of the service. The system may include a mapping correlating folders to encryption type so items in each folder can be handled appropriately. The system may have additional folders, such as one or more public folders that may be available with limited or no restrictions.
申请公布号 US8996884(B2) 申请公布日期 2015.03.31
申请号 US201414223888 申请日期 2014.03.24
申请人 VMware, Inc.;Decho Corporation 发明人 Hartley David John
分类号 H04L29/06;G06F21/60;G06F17/30;G06F21/62;H04L9/32;G06F11/30;G06F12/14 主分类号 H04L29/06
代理机构 代理人
主权项 1. A synchronization system client for synchronizing files and providing sharing capabilities, comprising: at least one not-shared-key folder for storing items to be encrypted with a not-shared key and to be synchronized with a remote datastore, wherein the not-shared key is not shared with the remote datastore; at least one shared-key folder for storing items to be encrypted with a shared key and to be synchronized with the remote datastore, wherein at least the client system and the remote datastore have access to the shared key; a folder encryption map that associates the not-shared key with the at least one not-shared-key folder and associates the shared key with the at least one shared-key folder; and a differential encryption component that, responsive to an item changing within at least one of the at least one not-shared-key folder and the at least one shared-key folder, interfaces with the folder encryption map to access and encrypt the item to be transmitted to and stored at the remote datastore.
地址 Palo Alto CA US