IP Library Granted Patent US 7,146,009
Granted Patent B2
US 7,146,009 · App. 10/062,551 · Granted Dec 5, 2006

Secure electronic messaging system requiring key retrieval for deriving decryption keys

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,146,009
App. No.
10/062,551
Granted
Dec 5, 2006
Kind
B2
Abstract

A secure electronic messaging system permits communication between registered users, with the assistance of a key server. The system requires a recipient to submit key retrieval information to a key server, and obtain decryption key information. The decryption key information is necessary for the recipient to form the decryption key which is used to read a message encrypted by the sender. The decryption key information may be an encrypted version of a decryption key, or portions thereof, or may be portions of an unencrypted version of a decryption key, among others. Typically, the key retrieval information may either be sent to the recipient by the sender, or may be generated by the recipient, based on information sent by the sender.

Claims (22)

1. A method for secure communication of a message M between a sender and a recipient, with the assistance of a key server, the method comprising:

the sender obtaining a symmetric key Ks and encrypting the message M with the symmetric key Ks thereby forming an encrypted message Me;

the sender encrypting the symmetric key Ks with a public encryption key Ke associated with the recipient thereby forming an encrypted symmetric key Kse;

the sender forming first and second split-key fragments Kse 1 and Kse 2 , respectively, from the encrypted symmetric key Kse;

the sender sending the second split-key fragment Kse 2 to the key server;

the key server storing decryption key information, wherein the decryption key information is formed from the second split-key fragment Kse 2 , and wherein the decryption key information comprises information needed by the recipient to form a decryption key suitable for decrypting the encrypted message Me, the sender obtaining the key retrieval information Kr, wherein Kr is necessary to permit the recipient to retrieve decryption key information from the key server;

the sender transmitting to the recipient the encrypted message Me, the first split-key fragment Kse 1 and the key retrieval information Kr;

the recipient transmitting the key retrieval information Kr to the key server and receiving the decryption key information in response thereto;

the recipient forming the encrypted symmetric key Kse from the first split-key fragment Kse 1 and Kse 2 , Kse 2 being derived from the decryption key information;

the recipient decrypting the encrypted symmetric key Kse with a private decryption key Kd of the recipient thereby forming the symmetric key Ks; and

the recipient derypting the encrypted message Me with the symmetric key Ks to read the original message M.

2. The method according to claim 1 , further comprising adding at least one of signing data and timestamp data to the message M before encrypting the message with the symmetric key Ks.

3. The method according to claim 1 , wherein the decryption key information comprises the second split-key fragment Kse 2 .

4. The method according to claim 1 , wherein the sender generates the symmetric key Ks.

5. The method according to claim 1 further comprising, by the sender, establishing at least one policy governing the retrieval of decryption key information.

6. The method according to claim 1 further comprising:

updating a first audit log at the key server to reflect at least one of storing the decryption key information and sending the decryption key information to the recipient; and

updating a second audit log at the sender to reflect transmission of a message from the sender to the recipient.

7. The method according to claim 6 , further comprising; verifying a correspondence between entries in the first audit log that correspond to messages sent by the sender, with entries in the second audit log.

8. The method according to claim 1 further comprising: the sender requesting that the recipient attest to sender's identity.

9. The method according to claim 1 , wherein the sender obtaining the key retrieval information Kr comprises the sender obtaining the key retrieval information Kr through a mechanism selected from the group consisting of obtaining the key retrieval information Kr from the key server and creating the key retrieval information Kr from information available to the sender and the key server.

10. The method of claim 1 , wherein the key server generates the symmetric key Ks.

Assignments (8)
SECURITY AGREEMENT Recorded Jul 3, 2010
From: SURETY, LLC
To: FISCHER, ADDISON
Reel/Frame 024630/0302 →
SECURITY AGREEMENT Recorded Dec 27, 2006
From: SURETY, LLC
To: FISCHER, ADDISON
Reel/Frame 018731/0404 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2005
From: WORLDGATE MANAGEMENT, LLC
To: SURETY, LLC
Reel/Frame 016226/0552 →
CORRECTIVE TO REMOVE INCORRECT PATENT NUMBER (5,37,3561) AND REPLACE IT WITH CORRECT PATENT NUMBER (5,771,629) PREVIOUSLY RECORDED ON REEL 015341 FRAME 0069 Recorded Jan 27, 2005
From: SURETY, INC.
To: WORLDGATE MANAGEMENT, LLC
Reel/Frame 016195/0489 →
MERGER Recorded May 27, 2004
From: WORLDGATE MANAGEMENT, LLC
To: SURETY, LLC
Reel/Frame 015418/0271 →
MERGER Recorded May 18, 2004
From: WORLDGATE MANAGEMENT, LLC
To: SURETY, LLC
Reel/Frame 015334/0966 →
MERGER Recorded May 18, 2004
From: SURETY, INC.
To: WORLDGATE MANAGEMENT, LLC
Reel/Frame 015341/0069 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2002
From: ANDIVAHIS, DIMITRIOS; CARNELL, SHAWN MICHAEL EDWARDS; FISCHER, ADDISON MCELROY; WETTLAUFER, ALBERT J.
To: SURETY, INC.
Reel/Frame 012739/0251 →