System and method for encrypting and decrypting data files

The system empowers users to manage encryption keys and permissions within a software application, addressing vulnerabilities and compliance issues by controlling encryption and decryption processes, ensuring secure file transmission and viewing.

WO2025243262A1PCT designated stage Publication Date: 2025-11-27IONOCO HOLDINGS LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/055370
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-23
Filing Date
2025-05-23
Publication Date
2025-11-27

AI Technical Summary

Technical Problem

Users lack direct control over encryption and decryption processes when relying on third-party services, leading to vulnerabilities, security breaches, and regulatory compliance issues.

Method used

A system and method that allows users to generate and manage unique encryption keys, control file permissions, and perform encryption and decryption within a software application, ensuring secure file transmission and viewing without writing decrypted data to storage.

Benefits of technology

Enables users to maintain control over encryption and decryption processes, reducing vulnerabilities and compliance risks while ensuring secure, real-time viewing and transmission of encrypted files.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025055370_27112025_PF_FP_ABST
    Figure IB2025055370_27112025_PF_FP_ABST
Patent Text Reader

Abstract

A system and method for encrypting and decrypting data files using a software application that securely manages encryption keys, permissions, and access control. The method comprises logging in using user credentials, creating transmitting and receiving user profiles, and generating a unique encryption key associated with each profile and hardware device. Data files are encrypted block-by-block, where a block is sized in bits according to the data files' data structure, using this key, and may include metadata such as user identity, permissions, and audit trails in an encrypted file header. Decryption occurs directly in memory to allow real- time playback or viewing without writing decrypted data to a storage medium, unless permitted.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SYSTEM AND METHOD FOR ENCRYPTING AND DECRYPTING DATA FILES

[0002] FIELD OF APPLICATION OF THE INVENTION

[0003] The present invention relates to a system and method for encrypting a data file. More particularly, the invention related to a software application which is capable of encrypting a data file in blocks specific to the structure of the data to be encrypted with a uniquely generated encryption key and decrypting a data file with the uniquely generated encryption key allowing for the encrypted blocks of the data file to be viewed in turn within the same software application securely

[0004] BACKGROUND TO THE INVENTION

[0005] Throughout history, the practice of securing information through encryption has been pivotal in safeguarding sensitive data from unauthorized access. With the advent of digital technology, file encryption has emerged as a critical component in preserving privacy and confidentiality in electronic communications and data storage. Understanding the evolution of digital file encryption provides insights into its significance, challenges, and implications for modern cybersecurity.

[0006] In the early days of computing, encryption primarily served military and government purposes, with limited accessibility to the general public due to its complexity and resource-intensive nature. However, as technology advanced and personal computing became widespread, the need for user-friendly encryption solutions grew exponentially. This led to the development of various encryption algorithms and software tools tailored for commercial and individual use. One of the earliest breakthroughs in digital file encryption came with the introduction of the Data Encryption Standard (DES) in the 1970s. Developed by IBM and later adopted by the U.S. government, DES represented a significant advancement in cryptographic techniques, laying the groundwork for subsequent encryption standards. However, as computing power increased, vulnerabilities in DES were exposed, prompting the development of more robust encryption algorithms like the Advanced Encryption Standard (AES). The proliferation of the internet and the rise of digital communication platforms further underscored the importance of file encryption in protecting sensitive information transmitted over networks. Encryption protocols such as Secure Sockets Layer (SSL) and its successor, T ransport Layer Security (TLS), became essential for securing online transactions, communications, and data transfers. Despite its undeniable benefits, file encryption also presents certain disadvantages, particularly when users rely on third-party services for encryption tasks. One notable drawback is the potential risk of entrusting sensitive data to third-party providers who may not uphold adequate security standards. In scenarios where users delegate encryption responsibilities to external entities, they relinquish direct control over the encryption process, leaving their data vulnerable to security breaches and unauthorized access. Moreover, relying on third-party encryption services introduces dependency issues, as users become reliant on external providers for safeguarding their data. This dependency can pose significant challenges in situations where the third-party service experiences disruptions or fails to deliver on its encryption commitments. Additionally, outsourcing encryption tasks to external entities may raise concerns regarding data privacy and confidentiality, as users must entrust their sensitive information to potentially unknown or untrusted parties.

[0007] Furthermore, the use of third-party encryption services can introduce complexities in regulatory compliance and legal liability, as users may bear responsibility for any breaches or violations resulting from inadequate encryption practices by the service provider. This lack of direct oversight and accountability can expose users to legal and financial repercussions, underscoring the importance of exercising caution when delegating encryption tasks to third parties. In conclusion, while file encryption offers invaluable protection against unauthorized access and data breaches, users must carefully consider the implications of relying on third- party services for encryption purposes. By understanding the advantages and disadvantages of encryption, individuals and organizations can make informed decisions to mitigate risks and safeguard their digital assets effectively.

[0008] Given the above, it is clear that there exists a present need for a system and method which is capable of reliability allowing a user to control the encryption and decryption of data files whilst maintaining their encryption whilst being viewed.

[0009] OBJECT OF THE INVENTION

[0010] Accordingly, it is an object of the present invention to provide a system and method which is capable of reliability allowing a user to control the encryption and decryption, of data files whilst maintaining the encryption of the file whilst it is being viewed. SUMMARY OF THE INVENTION

[0011] According to a first aspect thereof, there is provided a method of encrypting and decrypting data files, the method comprising the steps of: a) allowing a user to use an input means coupled to a user interface to log in to an encryption software application by providing unique user credentials, wherein the encryption software application is stored and accessible on a storage medium communicatively coupled to the user interface and a processor that is capable of executing instructions stored on the storage medium; b) utilising the input means to allow the user to input user information to generate a file transmitting user profile or a file receiving user profile, wherein the user profiles are stored on the storage medium, and wherein data files are only capable of being transmitted from a file transmitting user profile to a file receiving user profile; c) generating, by executing instructions with the processor, a unique encryption key associated with each user profile and a hardware device used to log in to the software application; d) storing the unique encryption key on the storage medium, wherein the unique encryption key is capable of being transmitted to an external device associated with the file receiving user profile, the external device comprising input means and a user interface to allow a receiving user to log in to the encryption software application and access the corresponding file receiving user profile and the unique encryption key; e) using an upload module within the encryption software application to upload a data file that is capable of being temporarily stored on the storage medium; f) using an encryption module within the encryption software application, wherein the encryption module is capable of executing an encryption method to encrypt the data file in blocks sized in bits relevant to the structure of the data file using the unique encryption key to generate an encrypted data file, wherein the encrypted data file is capable of being stored on the storage medium; g) transmitting the encrypted data file to an external device by selecting the corresponding file receiving user profile on the user interface; and h) decrypting, using a decryption module within the encryption software application, one or more blocks of the encrypted data file, wherein each decrypted block corresponds to a portion of the data file relevant to the structure of the data in the original file.

[0012] The unique user credentials may be a username and password. The user interface may be configured to implement two-factor authentication to permit the user to log in to the encryption software application. The unique encryption key may be generated by using the user information and machinespecific identifiers derived from internal hardware components of the hardware device.

[0013] The encryption method may allow for one or more permissions associated with the data file to be set or modified during encryption or re-encryption, wherein the permissions are embedded in the encrypted file header and are selected from the group consisting of permission to reencrypt the data file to one or more additional users, permission to decrypt the data file to a non-encrypted format and store it on a storage medium, permission to view or process the data file only within the encryption software application, permission relating to file validity, wherein a date and / or time is hardcoded into the file metadata after which the data file can no longer be decrypted or accessed, regardless of user credentials or device identity, or combinations thereof.

[0014] The method may comprise a further step of re-encrypting the encrypted data file, once permission to do so has been provided, by using decryption and encryption modules accessible on the encryption software application of the receiving user’s device. The reencryption may be performed on a block-by-block basis in memory, wherein the re-encrypted data file is associated with a different target user profile, thereby enabling the receiving user to transmit the re-encrypted data file to an additional user with updated encryption and permission metadata.

[0015] The method may comprise a further step of fully decrypting the encrypted data file, where permission has been granted by the original encryptor, by using the decryption module accessible on the encryption software application of the receiving user’s device, wherein the decryption allows the receiving user to manipulate the data file in a non-encrypted state on the receiving user’s device, and wherein the decrypted data file is stored on the device only if such permission includes authorisation to write the file to the storage medium.

[0016] The decrypting step may comprise decrypting one or more blocks of the encrypted data file directly into memory to enable viewing or processing of the file, or a portion thereof, without writing the decrypted data to a storage medium. The decrypting step may further comprise writing the decrypted data exclusively to memory, wherein the memory excludes persistent storage media such as a hard disk drive. The decrypted data residing in memory may be reencrypted for another user without storing the data in a non-volatile storage medium. The method may comprise providing the encryption software application with a plurality of subscription plans, wherein each subscription plan enables or restricts one or more features accessible by the user based on the user’s selected plan. The features enabled or restricted by the subscription plans may be selected from the group consisting of the number of machines the user is permitted to log into, the number of other users for whom the user may encrypt data files, the number of users permitted to save encrypted or decrypted data files on a user’s storage medium, the types of data files that may be encrypted and decrypted by the user; the devices on which data files may be encrypted or decrypted, the permissions granted to one or more users to access, modify, or manipulate the encrypted data files, or combinations thereof.

[0017] The encryption method may comprise inspecting an unencrypted source file and determining a block size appropriate to the file type selected from video, audio, text, image, or other data formats, generating a file header notionally in JSON format, containing encrypted metadata selected from the group consisting of user identity, target user identity, file permissions, audit history, file validity information, an audit trail comprising records of prior encryption or access events, or combinations thereof; selecting a first block of data from the source file and encrypting it using the target user’s unique encryption key; appending the encrypted block to the file after the header; and successively selecting and encrypting subsequent blocks using the unique key and appending them to the file until the source file is fully encrypted. The last block may be padded with zero data to ensure it is the required size.

[0018] The audit trail may comprise a permission architecture and history of when the digital files were decrypted and re-encrypted by one or more users and machines with different permissions. The audit trail may be embedded in an encrypted digital file.

[0019] The software application may decrypt only those blocks of the encrypted data file required for the current viewing position and dynamically disposes of the decrypted data from memory as the viewed portion of the file changes.

[0020] The method may provide hardware-bound encryption, controlled transmission of encrypted files between predefined user profiles, and block-based decryption of the encrypted files to mitigate unauthorized access.

[0021] The method may comprise a further step of operating the encryption software application in a streaming transmission mode, wherein the multimedia viewer module is configured to receive the data as a data stream, divide the data stream into blocks based on the data type, encrypt each block using the unique encryption key associated with the intended recipient, and transmit the encrypted blocks over a digital transmission network using a transmission protocol selected from the group consisting of RIST, UDP, TCP / IP or other digital transmission method and wherein each encrypted block is sliced into sequentially numbered packets prior to transmission.

[0022] According to a second aspect thereof, there is provided a computer program comprising instructions arranged such that when executed by a computing system the instructions cause the computing system to perform the method as described above.

[0023] According to a third aspect thereof, there is provided a non-transitory computer-readable medium storing a computer program comprising instructions which, when executed by a processor, cause a computing system to perform the method as described above.

[0024] According to a fourth aspect thereof, there is provided a system for encrypting and decrypting data files, the system comprising:

[0025] - a processor;

[0026] - a storage medium communicatively coupled to the processor, the storage medium storing an encryption software application;

[0027] - a user interface and input means configured to allow a user to log in to the encryption software application by providing unique user credentials, wherein the processor is configured to execute instructions of the encryption software application and its associated modules stored on the storage medium;

[0028] - a profile creation module configured to receive user information via the input means and generate a file-transmitting user profile or a file-receiving user profile, the user profiles being stored on the storage medium, and wherein data files are only capable of being transmitted from a file-transmitting user profile to a file-receiving user profile;

[0029] - a key generator module configured to generate a unique encryption key associated with each user profile and a hardware device used to log in to the encryption software application;

[0030] - an upload module configured to allow a user to upload a data file that is capable of being temporarily stored on the storage medium;

[0031] - an encryption module configured to encrypt the data file using the unique encryption key to generate an encrypted data file, the encrypted data file being stored on the storage medium; - a communication module configured to transmit the encrypted data file to an external device associated with the file-receiving user profile, the external device comprising an input means and a user interface for accessing the encryption software application and the corresponding file-receiving user profile and unique encryption key; and

[0032] - a decryption module configured to decrypt one or more blocks of the encrypted data file, each decrypted block corresponding to a portion of the original data file.

[0033] The storage medium may be volatile memory or non-volatile memory, or volatile and nonvolatile memory in combination.

[0034] The user information may comprise information selected from the group consisting of a user’s friendly name, machine name, unique identifier, hardware identifier, software license information, user tier level, or combinations thereof.

[0035] The hardware device and the external device are each an electronic device selected from the group consisting of a desktop computer, a laptop computer, an industrial or ruggedised computer, a tablet, a smartphone, a media playback device, a smart television, a gaming console, a wearable device, a networked storage device, or combinations thereof.

[0036] The system may further comprise a communication module within the encryption software application to transmit the encrypted data file to the external device and to receive encrypted data files from other devices via a secure communication channel.

[0037] The encryption module may be configured to generate an encrypted file header as part of the encrypted data file. The encrypted file header may comprise data file information selected from the group consisting of the identity of the file owner, audit data including the date and time of encryption or access events, identifiers of previous users in the file exchange chain, permissions associated with the data file, permission to decrypt the data file, and file validity parameters defining a date and / or time after which the file may no longer be viewed, reencrypted, decrypted or accessed, or combinations thereof.

[0038] The key generator module may be configured to generate the unique encryption key based on a combination of user information and hardware identifiers derived from internal components of the hardware device used to log in / run the software. The decryption module may decrypt only the blocks required for current playback or display of the data and dynamically discards decrypted data from memory as the viewed portion of the file changes.

[0039] The decryption module may be configured to decrypt the encrypted data file directly into memory to enable viewing or processing via the user interface, without writing the decrypted data to a storage medium.

[0040] The encryption software application may further comprise a permission architecture embedded in the encrypted file header, the permissions comprising at least one of permission to decrypt, permission to re-encrypt, permission to write to storage, and validity constraints based on date and / or time.

[0041] The software application may further comprise a multimedia viewer module configured to display encrypted and unencrypted data files via the user interface, wherein encrypted data files are decrypted block-by-block and rendered directly into memory for real-time playback or viewing, and wherein the decrypted data is not written to the storage medium unless permission to do so has been granted by the original encryptor.

[0042] The multimedia viewer module may be configured to decode selected portions of the encrypted data file directly in memory, without decrypting the entire file to the storage medium, thereby maintaining the security of the encrypted data file throughout playback.

[0043] The multimedia viewer module configured to operate in a streaming transmission mode, receive data as a stream, divide the stream into blocks, encrypt each block using the recipient’s unique encryption key, and transmit the encrypted blocks as sequentially numbered packets over a digital network.

[0044] As used herein, the term "module" refers to a functional component of the system implemented in the form of a set of instructions, code, or logic that is configured to perform a specified task or function when executed by one or more processors. It will be understood that a module does not necessarily correspond to a physical unit or separate executable file, and that multiple modules may be implemented within a single software application or program or distributed across multiple devices. Each module may be implemented as software, firmware, hardware, or any combination thereof, and is intended to carry out its associated functionality within the encryption software application or system described. The above and other characteristics, features and advantages of the present invention will become apparent from the following detailed description, taken in conjunction with the accompanying drawing which illustrate, by way of example, the principles of the invention. This description is given for the sake of example only, without limiting the scope of the invention. The reference figures quoted below refer to the attached drawings.

[0045] BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Preferred embodiments of the invention are described below with reference to the accompanying figures, wherein:

[0047] Figure 1-10 includes a series of panels of an encryption software application for encrypting and decrypting files;

[0048] Figure 11-15 illustrates a plurality of flowcharts to show how the system and method executes various steps to perform a variety of functions to encrypt and decrypt files in blocks relevant to the data structure; and

[0049] Figures 16 - 17 illustrate the flowcharts to show how the system and method executes various steps to encrypt data, stream block so the data across a digital transport technology receive and decrypt the same.

[0050] The presently disclosed subject matter will now be described more fully hereinafter with reference to the accompanying Examples, in which representative embodiments are shown. The presently disclosed subject matter can, however, be embodied in different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the embodiments to those skilled in the art.

[0051] DESCRIPTION OF PREFERRED EMBODIMENTS OF THE INVENTION

[0052] A non-limiting example of a preferred embodiment of the invention is described in more detail below, with reference to Figures 1 to 17.

[0053] Login: One or more users register and sign in to the software application (in this embodiment, entitled (Content Vault) using a user-specific user name and password. Users are allocated a unique identifier. Where the user has purchased a license to use the application, said user is required to verify their license through use of a two-factor authentication (“2FA”) method (see Figure 1). Once registered, they can pay and subscribe to different tier levels unlocking different features. Tier levels include a free and pro license version including different features such as the number of machines the user can log into; how many users they can encrypt multimedia files for and save in their local database; whether they can decrypt multimedia files made for their user and machine; and what permissions they can give to encrypted files. The Video Vault encryption software can be downloaded from available links for the MAC, PC, iOS, Android versions. The user downloads the version of the application for their operating system.

[0054] Encryption key: With reference to Figure 2, there is provided a panel of the software application displayed several clickable elements. To share a Digital / Device Encryption Key, the user selects the “My Account” page, followed by “My Device Key”. The user then selects “Save Encrypted Device Key” and a dialog box is shown for the location to where the user wants to save their ,CVK(Shared Device Key) file (see Figure 3) - the file is encrypted and secure. The user can share this file with other users of the software application so that they can make encrypted media for the user. Depending on the software licence the user has registered and paid for, a user can have more than one registered device - each device (target device) has its own unique Device Key for that user. If multiple users share a device, then a Device Key for each user of that device is generated and stored. The User of the application can export an encrypted file, a ,CVK(Shared Device Key) file, that is encrypted using an application specific Device Key and holds their name and unique identifier that can be given to other users of the application. When a ,CVK(Shared Device Key) file is imported into the application, the user’s friendly name, machine name and unique identifier are extracted from the encrypted file using the application Device Key. The machine specific Device Key and the user’s unique identifier are used to encrypt files and media.

[0055] Adding users: With reference to Figure 4, there is provided a panel of the software application for adding a user to the user list. The User selects the “My Account” page, followed by selecting the “Recipient List” button. The user either selects the “Open Key File” button to open a file dialog to browse to the exported Users .CVK file or simply drags the .CVK file onto the application. The imported Users details including the User’s friendly name, machine name and unique identifier are automatically filled in and can be edited by the User. When the User is satisfied, they select the “Save” button to complete importing the Users Details into their application.

[0056] Viewing files: With reference to Figure 5, there is provided a panel of the software application for viewing an encrypted or non-encrypted multimedia file. The user selects the “Encrypt and Send” element at the top, followed by the “Open Media” button to browse to the multimedia file they want to view, or they simply drag the multimedia file into the application. The application has controls for Playing, Showing, stopping, seeking to a location, changing the volume, viewing information, viewing encryption details, viewing file permission, viewing the alpha channel, and modifying the application into a full-screen mode for an immersive viewing experience. The ‘Alpha’ channel is a channel included in some video and image files and describes the transparency of the image / frame. Sometimes described as ARGB where A is Alpha, R is RED, G is Green and B is Blue. Allowing the user to turn the alpha processing off whilst viewing is a feature that graphic artists would use when sharing encrypted graphic files.

[0057] Encrypting files: To encrypt a media file, the user selects the “Encrypt and Send” element (see Figure 5), whereafter the user selects either the “Open Media” button to browse to the multimedia file they want to encrypt, or they simply drag the multimedia file into the application. Once the multimedia file is loaded into the Encrypt and Send page, they can select the “Select User” button. This displays a list of the Users they have in their user’s database (see Figure 6). The User selects the remote user they want to encrypt the file for. The User selects the “Forwarding Options” button which brings up a list of selectable permissions they can set on the encrypted file (see Figure 7). When the User is satisfied with the settings, the User selects the “Encrypt” button which brings up a dialog box for where the User wants to save the encrypted file and allows the default filename to be changed (see Figure 8). By default, a folder is created for the User in a subdirectory of the application’s “Base Path” (not shown) which is changeable from the “Settings Button” on the “My Account” page. Once the User selects the “Save” button on the dialog box, the file is encrypted for the selected User with selected permissions embedded within it. When the encryption is complete a message is displayed with a button, “Open Location” that will open the location of the encrypted file in the operating system’s browser. A previously encrypted file can be opened in the software application to view its permissions (see Figure 9), and if both the User and the file has permissions embedded therein, the file can be re-encrypted for another User. Where a user does not have the necessary permissions to view or decrypt a file, an error will be displayed upon attempting to access the file (see Figure 10) in either the software platform, or any other media playback platform.

[0058] Encryption is performed by the application using AES encryption using a pre shared Device Key that is generated from a mix of a machine specific data using internal chip information and the unique identifier of the intended receiving user. An encrypted file header (notionally JSON) is generated containing information on the file owner, audit data such as date, time and previous users in the file exchange chain, permissions such as permission to re-encrypt to other users, decrypt the file and, file validity (a date / time after which the file can no longer be opened. The software generates the header in memory. If the source media is unencrypted, then the JSON header is set to include the unique user identifier and name of the encryptor and the intended receiver. Standard file writer creates the output file. An ‘identifier string’ is written to the output file.

[0059] The JSON headers permissions table is set from the encryptors selection, specifies if the intended receiver can just view the media, re-encrypt for other users, or decrypt the media for general use. The JSON Header Size is written to the output file. The JSON header is encrypted using the application Device Key. The JSON Header is written to the output file. Encryption is processed in blocks of a specific fixed size; this block size being determined by the application software based on the type of content.

[0060] If the source media is encrypted already, the following series of steps are followed: The source content is read in blocks; the block is encrypted using the pre shared encryption Device Key; the encrypted block is written to the output file; if the source file is near the end, the partial block is read and encrypted; this is repeated until the input file is completely read and encrypted; close the output file; and / or if the source media is encrypted already, the process is the same with the addition of transferring the relevant permissions and other data such as the list of previous encryptors, their unique identifiers to the new file header.

[0061] Decrypt files: To decrypt a file, a media file should be opened using the “Open Media” button shown in Figure 8, and provided the necessary permissions are embedded in the file, and the User’s licence permits decryption, the decrypt button will be accessible to allow for the encrypted file. This opens a dialog box for where the User wants the decrypted multimedia file to be saved, and they can also change the filename from the default given. By default, a folder is created for the User “Me” in a subdirectory of the application’s “Base Path” which is changeable from the “Settings Button” on the “My Account” page. By default, the filename of the Decrypted multimedia file is the original filename before the multimedia file was encrypted. When the User selects the “Save” button, the encrypted file is decrypted into the location and filename specified.

[0062] When using the software platform to decrypt and view a file, the decryption step provides a unique feature as it only deciphers the blocks into memory that are needed to view that portion of the content, never writing decrypted data to the hard drive. Moreover, re-encryption uses this block-by-block method. As such, the only time a file is written to a drive in a decrypted form is when the user originating the file had given this permission and the target user selects the decrypt function. Decryption is performed using a AES algorithm or AES decryption by using a pre shared Device Key that is generated from a mix of a machine specific data using hardware’s internal chips and the unique identifier of the intended receiving user.

[0063] File loader: The software platform includes a file loader which is a standard software mechanism that is an interface to basic low-level functionality for file based read operations. It is customised within the software to emulate the following standard file-based operations, such as file open, file seek, file read of data, or file close.

[0064] File open: Opening passes in the path of the file to be loaded, comprising the steps of: Open the file using standard file input calls; Look to see if the ‘identifier string’ is at the beginning of file; If yes, assume that the file is encrypted; and / or if no, assume that file is not encrypted.

[0065] If the file is encrypted, the steps comprise: read number of bytes the header take; read the header; decrypt the header into memory using application Device Key; and / or set the file loader offset to the end of the header. If the file is not encrypted, the steps comprise: set the file loader offset to 0, i.e. the beginning of the file.

[0066] File seek: Seeking passes in the seek position. If the file is encrypted, Use file seek position to the nearest divisible block size + the loader offset. If the file is not encrypted, seek to the passed in position in the file.

[0067] File read: Comprises the steps of: Reading passes in the required amount of memory to fill in bytes; if we have left over bytes from a previous call, start satisfying the request with those decrypted bytes; if the requested bytes are not satisfied; begin Loop; Read block size data bytes into memory; decrypt the block using a Device Key generated from the unique machine identifier and local user unique identifier; repeat Loop until at least the number of requested bytes is satisfied; and return a copy of the decrypted memory of requested size bytes back to the callback function.

[0068] File close: The file is closed for reading using standard file calls.

[0069] Decoding media files: Media is decoded using a standard open-source multimedia API or Application Programming Interface, and comprises the steps of: The API has a custom file loader specified; Create file loader; Open the Media using the file loader; Create the custom file loader; Tell the Multimedia API to use the custom file loader for file-based operations; Open the Media using the file loader; The Multimedia API calls the file loaders seek and read callback functions as needed to decode the multimedia file; and Media is displayed in the application.

[0070] The invention is capable of being utilized and benefitting various industries. Some examples include and are summarised below:

[0071] Healthcare: T elemedicine and remote patient monitoring rely on sharing sensitive patient data and medical images securely. By utilising video vault this imagery can be shared securely and in line with numerous data laws such as HIPPA in the US.

[0072] Law enforcement and Legal: Securely transmitting evidence and confidential legal documents is crucial. Maintaining lawyer-client privilege and protecting sensitive case materials. In the case of police and other blue light services video evidence can be shared securely amongst agencies.

[0073] Finance and Banking: Secure transmission of video conferences for clients and sensitive financial information. Compliance with financial regulations (e.g., PCI DSS) is vital.

[0074] Education: Protecting student work and sensitive research data and intellectual property. Ensuring the privacy of recorded virtual classrooms and online exams.

[0075] Government and Military: For transferring and storage of classified and sensitive information. This includes protecting national security interests and confidential communications such as surveillance videos or war crime videos.

[0076] Media and Entertainment: Protecting unreleased content, IP and exclusive videos. Preventing unauthorised access and distribution of copyrighted material. Video Vault can be used to share collaborative imagery between contracted studios working on projects involving video editing.

[0077] Social Media and Communication Apps: Ensuring privacy for users' private videos, building trust, and maintaining user loyalty by offering strong security from end to end. This way unique content is not shared publicly.

[0078] Manufacturing and Research: Safeguarding proprietary designs, research data, and sensitive production processes. Maintaining a competitive edge in the global market and helping to combat industrial espionage and IP theft.

[0079] Insurance: Protecting claims data and client information. Ensuring the confidentiality of insurance negotiations and assessments with protected video evidence.

[0080] Transportation and Logistics: Securing video feeds and evidence from surveillance cameras, especially in sensitive areas. Protecting information related to cargo and passenger safety onboard vessels and portside. Figures 11 to 12 provide flow charts pertaining to the encryption of digital files, reading and seeking of encrypted files, and writing of encrypted files. Figures 13 illustrates a graphical schematic diagram of the encryption process. Figures 14 illustrates a schematic diagram of the encryption process. Figures 15 illustrates a schematic diagram of the encryption file reading process.

[0081] With reference to Figure 16, there is provided a e-Streamer software application which enables real-time encryption and transmission of live data streams such as video, audio, GPS, LIDAR, and sensor data. Instead of saving data to a file, e-Streamer reads raw data as it is captured, divides it into blocks based on the data type, encrypts each block using the destination's encryption key, and immediately transmits it over a digital network using protocols like RIST or UDP. Each encrypted block is further sliced into sequentially numbered packets for transmission. On the receiving end, these packets are reassembled into blocks and presented directly to a viewer application. If any packet is lost, the system discards the incomplete block and waits for the start of the next one. This approach enables secure, live data streaming without needing to write unencrypted data to storage. With reference to Figure 17, there is provided a e-Streamer receiver that is designed to reconstruct and display live encrypted data streams transmitted from an e-Streamer sender. It listens for incoming packets over a digital network, reassembles them into complete encrypted blocks using their sequential packet numbers, and decrypts each block once fully received. The decrypted content is then presented directly to the multimedia viewer or destination device in real time. If any packet is missing or corrupted, the receiver discards the incomplete block to maintain data integrity and waits for the start of the next block. This ensures secure, low-latency playback or visualization of encrypted live data without writing decrypted content to storage.

[0082] An important advantage of the present invention is that contrary to other services and alternatives where data files are vulnerable to remote force encryption key regeneration on a user’s device which allows for remote decrypting of media and digital files without a user even being alerted thereto, the present invention allows for a user to control the encryption process by even logging off a network connection and encrypting data files. The present invention is therefore a unique method of sharing and storing end-to-end encrypted digital files.

Claims

CLAIMS1. A method of encrypting and decrypting data files, the method comprising the steps of: a) allowing a user to use an input means coupled to a user interface to log in to an encryption software application by providing unique user credentials, wherein the encryption software application is stored and accessible on a storage medium communicatively coupled to the user interface and a processor that is capable of executing instructions stored on the storage medium; b) utilising the input means to allow the user to input user information to generate a file transmitting user profile or a file receiving user profile, wherein the user profiles are stored on the storage medium, and wherein data files are only capable of being transmitted from a file transmitting user profile to a file receiving user profile; c) generating, by executing instructions with the processor, a unique encryption key associated with each user profile and a hardware device used to log in to the software application; d) storing the unique encryption key on the storage medium, wherein the unique encryption key is capable of being transmitted to an external device associated with the file receiving user profile, the external device comprising input means and a user interface to allow a receiving user to log in to the encryption software application and access the corresponding file receiving user profile and the unique encryption key; e) using an upload module within the encryption software application to upload a data file that is capable of being temporarily stored on the storage medium; f) using an encryption module within the encryption software application, wherein the encryption module is capable of executing an encryption method to encrypt the data file in blocks sized in bits relevant to the data format using the unique encryption key to generate an encrypted data file, wherein the encrypted data file is capable of being stored on the storage medium; g) transmitting the encrypted data file to the external device by selecting the corresponding file receiving user profile on the user interface; and h) decrypting, using a decryption module within the encryption software application, one or more blocks of the encrypted data file, wherein each decrypted block corresponds to a portion of the data file.

2. The method according to claim 1 , wherein two-factor authentication is required in step a) to permit the user to log in to the encryption software application.

3. The method according to claim 1 , wherein the unique encryption key is generated by using the user information and machine-specific identifiers derived from internal hardware components of the hardware device.

4. The method according to claim 1 , wherein the encryption method allows for one or more permissions associated with the data file to be modified during encryption, wherein the one or more permissions are selected from the group consisting of permission to reencrypt the data file to one or more additional users, permission to decrypt the data file to a non-encrypted format and store it on a storage medium, permission to view or process the data file only within the encryption software application, permission relating to file validity, wherein a date and / or time is hardcoded into the file metadata after which the data file can no longer be decrypted or accessed, regardless of user credentials or device identity, or combinations thereof.

5. The method according to claim 4, wherein the permissions are embedded in the encrypted file header.

6. The method according to claim 1 comprising a further step of re-encrypting the encrypted data file, once permission to do so has been provided, by using decryption and encryption modules accessible on the encryption software application of the receiving user’s device.

7. The method according to claim 6 wherein the re-encryption is performed on a block-by- block basis in memory, wherein the re-encrypted data file is associated with a different target user profile, thereby enabling the receiving user to transmit the re-encrypted data file to an additional user with updated encryption and permission metadata.

8. The method according to claim 1 , wherein the step of decrypting comprises decrypting the entire encrypted data file into a non-encrypted state on the external device associated with the file receiving user profile to enable manipulation of the data file, and wherein the decrypted data file is stored on the external device only if the file-transmitting user has granted permission to write the file to the storage medium.

9. The method according to claim 1 wherein the step of decrypting comprises decrypting one or more blocks of the encrypted data file directly into memory to allow real-timeplayback or viewing of the decrypted content of the file, or a portion thereof, without writing the decrypted data to a storage medium.

10. The method according to claim 1 wherein the step of decrypting is performed directly into memory to allow real-time playback or viewing of the decrypted content without writing the decrypted data to the storage medium. The decrypting step may further comprise writing the decrypted data exclusively to memory, wherein the memory excludes persistent storage media such as a hard disk drive. The decrypted data residing in memory may be re-encrypted for another user without storing the data in a non-volatile storage medium.

11. The method according to claim 1 comprising a further step of providing the encryption software application with a plurality of subscription plans, wherein each subscription plan enables or restricts one or more features accessible by the user based on the user’s selected plan.

12. The method according to claim 11 wherein the features enabled or restricted by the subscription plans is selected from the group consisting of the number of machines the user is permitted to log into, the number of other users for whom the user may encrypt data files, the number of users permitted to save encrypted or decrypted data files on a user’s storage medium, the types of data files that may be encrypted and decrypted by the user; the devices on which data files may be encrypted or decrypted, the permissions granted to one or more users to access, modify, or manipulate the encrypted data files, or combinations thereof.

13. The method according to claim 1 , wherein the encryption method further comprises the steps of inspecting an unencrypted source file and determining a block size appropriate to a file type selected from video, audio, text, image, or other formats; generating a file header notionally in JSON format, the file header comprising encrypted metadata selected from the group consisting of user identity, file receiving user profile identity, file permissions, audit history, file validity information, an audit trail comprising records of prior encryption or access events, or combinations thereof; selecting a first block of data from the source file and encrypting it using the target user’s unique encryption key; appending the encrypted first block to the file after the header; and successively selecting andencrypting subsequent blocks using the unique encryption key and appending the encrypted blocks to the file until the source file is fully encrypted.

14. The method according to claim 13, wherein the audit trail comprises a permission architecture and history of when the digital files were decrypted and re-encrypted by one or more users and machines with different permissions.

15. The method according to claim 1 wherein the step of decrypting comprises decrypting only those blocks of the encrypted data file required for the current viewing position and dynamically disposes of the decrypted data from memory as the viewed portion of the file changes.

16. The method according to claim 1 , wherein the method provides hardware-bound encryption, controlled transmission of encrypted files between predefined user profiles, and block-based decryption of the encrypted files to mitigate unauthorized access.

17. The method according to claim 1 comprising a further step of operating the encryption software application in a streaming transmission mode, wherein the encryption software application comprises a multimedia viewer module configured to receive the data file as a data stream, divide the data stream into blocks based on the data type, encrypt each block using the unique encryption key associated with the intended recipient, and transmit the encrypted blocks over a digital transmission network using a transmission protocol selected from the group consisting of RIST, UDP, TCP / IP or other digital transmission method, and wherein each encrypted block is sliced into sequentially numbered packets prior to transmission.

18. A computer program comprising instructions which, when executed by a processor of a computing system, cause the computing system to perform the method according to any one of the preceding claims.

19. A non-transitory computer-readable medium storing a computer program comprising instructions which, when executed by a processor, cause a computing system to perform the method according to any one of the preceding claims.

20. A system for encrypting and decrypting data files, the system comprising:- a processor;- a storage medium communicatively coupled to the processor, the storage medium storing an encryption software application;- a user interface and input means configured to allow a user to log in to the encryption software application by providing unique user credentials, wherein the processor is configured to execute instructions of the encryption software application and its associated modules stored on the storage medium;- a profile creation module configured to receive user information via the input means and generate a file-transmitting user profile or a file-receiving user profile, the user profiles being stored on the storage medium, and wherein data files are only capable of being transmitted from a file-transmitting user profile to a file-receiving user profile;- a key generator module configured to generate a unique encryption key associated with each user profile and a hardware device used to log in to the encryption software application;- an upload module configured to allow a user to upload a data file that is capable of being temporarily stored on the storage medium;- an encryption module configured to encrypt the data file using the unique encryption key to generate an encrypted data file, the encrypted data file being stored on the storage medium;- a communication module configured to transmit the encrypted data file to an external device associated with the file-receiving user profile, the external device comprising an input means and a user interface for accessing the encryption software application and the corresponding file-receiving user profile and unique encryption key; and- a decryption module configured to decrypt one or more blocks of the encrypted data file, each decrypted block corresponding to a portion of the original data file.21 . The system according to claim 20, wherein the storage medium is volatile memory or nonvolatile memory, or volatile and non-volatile memory in combination.

22. The system according to claim 20, wherein the user information comprises information selected from the group consisting of a user’s friendly name, machine name, unique identifier, hardware identifier, software license information, user tier level, or combinations thereof.

23. The system according to claim 20, wherein the hardware device and the external device are each an electronic device selected from the group consisting of a desktop computer,a laptop computer, an industrial or ruggedised computer, a tablet, a smartphone, a media playback device, a smart television, a gaming console, a wearable device, a networked storage device, or combinations thereof.

24. The system according to claim 20 further comprising a communication module within the encryption software application to transmit the encrypted data file to the external device and to receive encrypted data files from other devices via a secure communication channel.

25. The system according to claim 20, wherein the encryption module is configured to generate an encrypted file header as part of the encrypted data file.

26. The system according to claim 25, wherein the encrypted file header comprises information selected from the group consisting of the identity of the file owner, audit data including the date and time of encryption or access events, identifiers of previous users in the file exchange chain, permissions associated with the data file, permission to decrypt the data file, and file validity parameters defining a date and / or time after which the file may no longer be decrypted or accessed, or combinations thereof.

27. The system according to claim 20, wherein the key generator module is configured to generate the unique encryption key based on a combination of user information and hardware identifiers derived from internal components of the hardware device used to log in.

28. The system according to claim 20, wherein the decryption module decrypts only the blocks required for current playback or display and dynamically discards decrypted data from memory as the viewed portion of the file changes.

29. The system according to claim 20, wherein the decryption module is configured to decrypt the encrypted data file directly into memory to enable viewing or processing via the user interface, without writing the decrypted data to a storage medium.

30. The system according to claim 20, wherein the encryption software application further comprises a permission architecture embedded in the encrypted file header, wherein the permission is selected from the group consisting of permission to re-encrypt the data fileto one or more additional users, permission to decrypt the data file to a non-encrypted format and store it on a storage medium, permission to view or process the data file only within the encryption software application, permission relating to file validity, wherein a date and / or time is hardcoded into the file metadata after which the data file can no longer be decrypted or accessed, regardless of user credentials or device identity, or combinations thereof.

31. The system according to claim 20, wherein the encryption software application further comprises a multimedia viewer module configured to display encrypted and unencrypted data files via the user interface, wherein encrypted data files are decrypted block-by-block and rendered directly into memory for real-time playback or viewing, and wherein the decrypted data is not written to the storage medium unless permission to do so has been granted by the original encryptor.

32. The system according to claim 31 , wherein the multimedia viewer module is configured to decode selected blocks of the encrypted data file directly in memory, without decrypting the entire file to the storage medium, thereby maintaining the security of the encrypted data file throughout playback.

33. The system according to claim 31 , wherein the multimedia viewer module is configured to operate in a streaming transmission mode, receive data as a stream, divide the stream into blocks, encrypt each block using the recipient’s unique encryption key, and transmit the encrypted blocks as sequentially numbered packets over a digital network.

Citation Information

Patent Citations

  • Secure layered encryption of data streams

    US20180331824A1

  • Data encryption

    US20200287880A1

  • Security processor configured to authenticate user and authorize user for user data and computing system including the same

    US20210165909A1

  • Secure messaging service with digital rights management using blockchain technology

    US20220207118A1

  • Sharing Encrypted Documents Within and Outside an Organization

    US20230361988A1