IP Library Granted Patent US 12675587
Granted Patent B2
US 12675587 · App. 18/510,059 · Granted Jul 7, 2026

Maintaining and determining confidentiality, authenticity and integrity of recorded data

Inventor: Malcolm A. C. Weir (Colorado Springs, CO)
Assignee: Ampex Data Systems Corporation
G06F21/606H04L9/0662H04L9/0822H04L9/0825H04L9/0869H04L9/0894H04L9/14H04L9/065H04L63/045H04L63/068H04L2463/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12675587
App. No.
18/510,059
Granted
Jul 7, 2026
Kind
B2
Abstract

The encryption system may include a host apparatus and a remote apparatus. The host apparatus may generate an asymmetric encryption key pair that comprises a first key and a second key. The host apparatus may deliver the first key to the remote apparatus. The remote apparatus may generate a symmetric encryption key. The remote apparatus may encrypt a key block using the first key. The encrypted key block may include the symmetric encryption key and a sequence field. The remote apparatus may record a dataset. The remote apparatus may encrypt the recorded dataset using the generated symmetric encryption key. The remote apparatus may send the recording file to the host apparatus. The host apparatus may decrypt the symmetric encryption key using the second key. The host apparatus may decrypt the encrypted dataset using the symmetric encryption key.

Claims (100)

1 . A method comprising:

at a remote apparatus:

(A) obtaining a key-encrypting key, the key-encrypting key being a first key of an asymmetric key pair;

(B) generating a symmetric encryption key;

(C) determining a key control block, the key control block comprising the symmetric encryption key and a sequence field;

(D) encrypting the key control block using the key-encrypting key to form an encrypted key control block;

(E) storing the encrypted key control block in a recording file;

(F) storing an encrypted dataset in the recording file, wherein the encrypted dataset comprises a dataset encrypted using the symmetric encryption key; and

(G) repeating act (F) until: (i) a predetermined time has elapsed since the recording file was opened, or (ii) a predetermined amount of data has been written to the recording file, and then

(H) closing the recording file and purging the symmetric encryption key; and then

(I) repeating acts (B) to (H) at least once,

wherein, in step (I):

(x) a repetition of step (B) generates another symmetric encryption key, and

(y) repetition of step (C) uses the other symmetric encryption key and another sequence field, distinct from a previous sequence field, and

(z) a repetition of step (E) uses another recording file, distinct from a previous recording file,

wherein a value of an initial sequence field is randomly generated by the remote apparatus, and wherein the remote apparatus increments the sequence field for each successive recording file created by the remote apparatus, and

wherein the sequence field indicates a place of the recording file in a recording order of a plurality of recording files, and

wherein the remote apparatus sends a series of multiple recording files to a host apparatus, and

wherein a plurality of sequence fields of a corresponding plurality of key control blocks of a plurality of recording files is used to determine if the remote apparatus was restarted, and

wherein data in the dataset comprise one or more of: video data, telemetry data, instrumentation data, image data, audio data, flight data, metadata, keyboard data, and other forms of time series data, and

wherein a recording file is closed upon the remote apparatus powering off, and

wherein the method further comprises,

upon the remote apparatus powering on:

forming a new encrypted key control block by: step (B) generating a new symmetric encryption key, and step (C) determining a new key control block, comprising the new symmetric encryption key and a new sequence field, and step (D) encrypting the new key control block using the key-encrypting key to form the new encrypted key control block.

2 . The method of claim 1 , wherein a second key of the asymmetric key pair is required to decrypt data encrypted with the first key, and wherein the remote apparatus does not have access to the second key.

3 . The method of claim 1 , wherein the remote apparatus does not have access to a key required to decrypt the encrypted key control block or any data encrypted with the first key.

4 . The method of claim 1 , wherein the remote apparatus does not have access to the symmetric encryption key used to encrypt the encrypted dataset in a closed recording file.

5 . The method of claim 1 , wherein the first key was provided to the remote apparatus by the host apparatus.

6 . The method of claim 5 , wherein the asymmetric key pair was generated at the host apparatus, and wherein the asymmetric key pair is valid from key generation until one or more of the following occur:

(i) a second key of the asymmetric key pair is compromised, where the second key is required to decrypt data encrypted with the first key, or

(ii) the first key is disclosed beyond the remote apparatus, or

(iii) another asymmetric key pair is generated.

7 . A non-transitory computer-readable storage medium storing one or more programs configured to be executed by one or more processors of a computer system, the one or more programs including instructions for performing the method of claim 1 .

8 . A device comprising:

one or more processors; and memory storing one or more programs configured to be executed by the one or more processors, the one or more programs including instructions for performing the method of claim 1 .

9 . A system comprising:

(X) at least one device having one or more processors; and memory storing one or more programs configured to be executed by the one or more processors, the one or more programs including instructions for performing the method of claim 1 ; and

(Y) the host apparatus comprising at least one processor configured to:

(p) generate an asymmetric encryption key pair that comprises a first key and a second key; and

(q) deliver the first key to the at least one device.

10 . The system of claim 9 , wherein the host apparatus is further configured to:

repeat acts (p) and (q) for a new asymmetric encryption key pair for policy or procedural reasons or when it is determined that:

(i) a second key of the asymmetric key pair is compromised, or

(ii) the first key is disclosed beyond a remote apparatus.

11 . The system of claim 10 , wherein the host apparatus is further configured to:

decrypt key control blocks from recorded files received from a remote apparatus; and

use sequence fields from decrypted key control blocks to determine integrity of recording files.

12 . A device comprising:

hardware, including one or more processors configured to, at a remote apparatus:

(A) obtain a key-encrypting key, the key-encrypting key being a first key of an asymmetric key pair;

(B) generate a symmetric encryption key;

(C) determine a key control block, the key control block comprising the symmetric encryption key and a sequence field;

(D) encrypt the key control block using the key-encrypting key to form an encrypted key control block;

(E) store the encrypted key control block in a recording file;

(F) store an encrypted dataset in the recording file, wherein the encrypted dataset comprises a dataset encrypted using the symmetric encryption key; and

(G) repeat (F) until (i) a predetermined time has elapsed since the recording file was opened, or (ii) a predetermined amount of data has been written to the recording file, and then

(H) close the recording file and purge the symmetric encryption key; and

(I) repeat (B) to (H) at least once,

wherein, in step (I):

(x) a repetition of (B) generates another symmetric encryption key, and

(y) a repetition of (C) uses the other symmetric encryption key and another sequence field, distinct from a previous sequence field, and

(z) a repetition of (E) uses another recording file, distinct from a previous recording file,

wherein a value of an initial sequence field is randomly generated by the remote apparatus, and wherein the remote apparatus increments the sequence field for each successive recording file created by the remote apparatus, and

wherein the sequence field indicates a place of the recording file in a recording order of a plurality of recording files, and

wherein the remote apparatus sends a series of multiple recording files to a host apparatus, and

wherein a plurality of sequence fields of a corresponding plurality of key control blocks of a plurality of recording files is used to determine if the remote apparatus was restarted, and

wherein data in the dataset comprise one or more of: video data, telemetry data, instrumentation data, image data, audio data, flight data, metadata, keyboard data, and other forms of time series data,

wherein the one or more processors are further configured to, upon the remote apparatus powering on:

form a new encrypted key control block by (B) generating a new symmetric encryption key, and (C) determining a new key control block, comprising the new symmetric encryption key and a new sequence field, and (D) encrypting the new key control block using the key-encrypting key to form the new encrypted key control block, and

wherein the recording file is closed upon the remote apparatus powering off.

13 . The device of claim 12 , wherein a second key of the asymmetric key pair is required to decrypt data encrypted with the first key, and the remote apparatus does not have access to the second key.

14 . The device of claim 12 , wherein the remote apparatus does not have access to a key required to decrypt the encrypted key control block or any data encrypted with the first key.

15 . The device of claim 12 , wherein the remote apparatus does not have access to the symmetric encryption key used to encrypt the encrypted dataset in a closed recording file.

16 . The device of claim 12 , wherein the asymmetric key pair is valid from key generation until one or more of the following occur:

(i) a second key of the asymmetric key pair is compromised, where the second key is required to decrypt data encrypted with the first key, or

(ii) the first key is disclosed beyond the remote apparatus, or

(iii) another asymmetric key pair is generated.

17 . The device of claim 12 , wherein another asymmetric key pair is generated for policy or procedural reasons.

18 . A method comprising:

at a remote apparatus:

(A) obtaining a key-encrypting key, the key-encrypting key being a first key of an asymmetric key pair;

(B) generating a symmetric encryption key;

(C) determining a key control block, the key control block comprising the symmetric encryption key and a sequence field;

(D) encrypting the key control block using the key-encrypting key to form an encrypted key control block;

(E) storing the encrypted key control block in a recording file;

(F) storing an encrypted dataset in the recording file, wherein the encrypted dataset comprises a dataset encrypted using the symmetric encryption key; and

(G) repeating act (F) until: (i) a predetermined time has elapsed since the recording file was opened, or (ii) a predetermined amount of data has been written to the recording file, and then

(H) closing the recording file and purging the symmetric encryption key; and then

(I) repeating acts (B) to (H) at least once,

wherein, in step (I):

(x) a repetition of step (B) generates another symmetric encryption key, and

(y) repetition of step (C) uses the other symmetric encryption key and another sequence field, distinct from a previous sequence field, and

(z) a repetition of step (E) uses another recording file, distinct from a previous recording file,

wherein a value of an initial sequence field is randomly generated by the remote apparatus, and wherein the remote apparatus increments the sequence field for each successive recording file created by the remote apparatus, and

wherein the sequence field indicates a place of the recording file in a recording order of a plurality of recording files, and

wherein data in the dataset comprise one or more of: video data, telemetry data, instrumentation data, image data, audio data, flight data, metadata, keyboard data, and other forms of time series data,

wherein the recording file is closed upon the remote apparatus powering off,

the method further comprising, upon the remote apparatus powering on:

forming a new encrypted key control block by: step (B) generating a new symmetric encryption key, and step (C) determining a new key control block, comprising the new symmetric encryption key and a new sequence field, and step (D) encrypting the new key control block using the key-encrypting key to form the new encrypted key control block, and

wherein a plurality of sequence fields of a corresponding plurality of key control blocks of a plurality of recording files is used to determine if the remote apparatus was restarted.