IP Library › Granted Patent US 7,079,653
Granted Patent B2
US 7,079,653 · App. 10/147,433 · Granted Jul 18, 2006

Cryptographic key split binding process and apparatus

Assignee: Tecsec, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,079,653
App. No.
10/147,433
Granted
Jul 18, 2006
Kind
B2
Abstract

A cryptographic key split combiner includes a number of key split generators for generating cryptographic key splits from seed data, and a key split randomizer for randomizing the key splits to produce a cryptographic key. The key split generators can include a random split generator for generating random key splits, a token split generator for generating token key splits based on label data, a console split generator for generating console key splits based on maintenance data, a biometric split generator for generating biometric key splits based on biometric data, and a location split generator for generating location key splits based on location data. Label data can be read from storage, and can include user authorization data. A process for forming cryptographic keys includes randomizing or otherwise binding the splits to form the key.

Claims (78)

1. A cryptographic key split combiner, comprising:

a plurality of key split generators that each receive seed data and generate respective cryptographic key splits based on the seed data; and

a key split randomizer that randomizes the cryptographic key splits to produce a cryptographic key;

wherein said plurality of key split generators includes a location split generator that receives location seed data and generates a location key split based on the location seed data.

2. The cryptographic key split combiner of claim 1 , wherein the location split generator includes at least one data line that receives the location seed data from a location device.

3. The cryptographic key split combiner of claim 2 , wherein the location seed data is based at least in part on at least one of virtual location data, actual location data, and relative location data.

4. The cryptographic key split combiner of claim 2 , wherein the location seed data corresponds to at least one of virtual location data, actual location data, and relative location data.

5. The cryptographic key split combiner of claim 2 , wherein the location seed data is based at least in part on at least one of Global Positioning System receiver output data and Galileo receiver output data.

6. The cryptographic key split combiner of claim 2 , wherein the location seed data corresponds to at least one of Global Positioning System receiver output data and Galileo receiver output data.

7. The cryptographic key split combiner of claim 2 , wherein the location seed data is based at least in part on at least one of longitude, latitude, altitude, and satellite distance data.

8. The cryptographic key split combiner of claim 2 , wherein the location seed data corresponds to at least one of longitude, latitude, altitude, and satellite distance data.

9. The cryptographic key split combiner of claim 1 , wherein the location split generator includes memory that receives the location seed data from a geographic location device and stores the received location seed data.

10. The cryptographic key split combiner of claim 9 , wherein the memory is a buffer.

11. The cryptographic key split combiner of claim 9 , wherein the memory is a latch.

12. The cryptographic key split combiner of claim 1 , wherein the location split generator includes at least one data line that receives the location seed data from a computer network.

13. The cryptographic key split combiner of claim 12 , wherein the location seed data is based at least in part on a network location.

14. The cryptographic key split combiner of claim 12 , wherein the location seed data corresponds to a network location.

15. The cryptographic key split combiner of claim 13 , wherein the location seed data is based at least in part on at least one of an Internet Protocol address and a Media Access Control address.

16. The cryptographic key split combiner of claim 13 , wherein the location seed data corresponds to at least one of an Internet Protocol address and a Media Access Control address.

17. The cryptographic key split combiner of claim 13 , wherein the location seed data is based at least in part on network domain data.

18. The cryptographic key split combiner of claim 13 , wherein the location seed data corresponds to network domain data.

19. The cryptographic key split combiner of claim 1 , wherein the cryptographic key is a stream of symbols.

20. The cryptographic key split combiner of claim 1 , wherein the cryptographic key is at least one symbol block.

21. The cryptographic key split combiner of claim 1 , wherein the cryptographic key is a key matrix.

22. The cryptographic key split combiner of claim 1 , wherein said plurality of key split generators further include a random key split generator that generates a random split based on random seed data.

23. The cryptographic key split combiner of claim 1 , wherein said plurality of key split generators further include an organization key split generator that generates an organization split based on organization seed data.

24. The cryptographic key split combiner of claim 1 , wherein said plurality of key split generators further include a maintenance key split generator that generates a maintenance split based on maintenance seed data.

25. The cryptographic key split combiner of claim 1 , wherein said plurality of key split generators further include a random split generator that generates a random split based on random seed data, an organization key split generator that generates an organization split based on organization seed data, and a maintenance key split generator that generates a maintenance split based on maintenance seed data.

26. A process for forming cryptographic keys, comprising:

generating a plurality of cryptographic key splits, each based on seed data; and

randomizing the cryptographic key splits to produce a cryptographic key;

wherein generating a plurality of cryptographic key splits includes generating a location key split based on location seed data.

27. The process of claim 26 , further comprising receiving the location seed data from a geographic location device.

28. The process of claim 26 , wherein the location seed data is based at least in part on at least one of virtual location data, actual location data, and relative location data.

29. The process of claim 26 , wherein the location seed data corresponds to at least one of virtual location data, actual location data, and relative location data.

30. The process of claim 26 , wherein the location seed data is based at least in part on at least one of Global Positioning System receiver output data and Galileo receiver output data.

31. The process of claim 26 , wherein the location seed data corresponds to at least one of Global Positioning System receiver output data and Galileo receiver output data.

32. The process of claim 26 , wherein the location seed data is based at least in part on at least one of longitude, latitude, altitude, and satellite distance data.

33. The process of claim 26 , wherein the location seed data corresponds to at least one of longitude, latitude, altitude, and satellite distance data.

34. The process of claim 26 , further comprising receiving the location seed data from a computer network.

35. The process of claim 26 , wherein the location seed data is based at least in part on a network location.

36. The process of claim 26 , wherein the location seed data corresponds to a network location.

37. The process of claim 26 , wherein the location seed data is based at least in part on at least one of an Internet Protocol address and a Media Access Control address.

38. The process of claim 26 , wherein the location seed data corresponds to at least one of an Internet Protocol address and a Media Access Control address.

39. The process of claim 26 , wherein the location seed data is based at least in part on network domain data.

40. The process of claim 26 , wherein the location seed data corresponds to network domain data.

41. The process of claim 26 , wherein the cryptographic key is a stream of symbols.

42. The process of claim 26 , wherein the cryptographic key is at least one symbol block.

43. The process of claim 26 , wherein the cryptographic key is a key matrix.

44. The process of claim 26 , wherein generating a plurality of cryptographic key splits further includes generating a random key split based on random seed data.

45. The process of claim 26 , wherein generating a plurality of cryptographic key splits further includes generating an organization key split based on organization seed data.

46. The process of claim 26 , wherein generating a plurality of cryptographic key splits further includes generating a maintenance key split based on maintenance seed data.

47. The process of claim 26 , wherein generating a plurality of cryptographic key splits further includes generating a random key split based on random seed data, generating an organization key split based on organization seed data, and generating a maintenance key split based on maintenance seed data.

48. A storage medium comprising instructions for causing a data processor to generate a cryptographic key, wherein the instructions include:

generate a plurality of cryptographic key splits, each based on seed data; and

randomize the cryptographic key splits to produce a cryptographic key;

wherein generate a plurality of cryptographic key splits includes generate a location key split based on location seed data.

49. The storage medium of claim 48 , wherein the instructions further include receive the location seed data from a geographic location device.

50. The storage medium of claim 48 , wherein the location seed data is based at least in part on at least one of virtual location data, actual location data, and relative location data.

51. The storage medium of claim 48 , wherein the location seed data corresponds to at least one of virtual location data, actual location data, and relative location data.

52. The storage medium of claim 48 , wherein the location seed data is based at least in part on at least one of Global Positioning System receiver output data and Galileo receiver output data.

53. The storage medium of claim 48 , wherein the location seed data corresponds to at least one of Global Positioning System receiver output data and Galileo receiver output data.

54. The storage medium of claim 48 , wherein the location seed data is based at least in part on at least one of longitude, latitude, altitude, and satellite distance data.

55. The storage medium of claim 48 , wherein the location seed data corresponds to at least one of longitude, latitude, altitude, and satellite distance data.

56. The storage medium of claim 48 , wherein the instructions further include receive the location seed data from a computer network.

57. The storage medium of claim 48 , wherein the location seed data is based at least in part on a network location.

58. The storage medium of claim 48 , wherein the location seed data corresponds to a network location.

59. The storage medium of claim 48 , wherein the location seed data is based at least in part on at least one of an Internet Protocol address and a Media Access Control address.

60. The storage medium of claim 48 , wherein the location seed data corresponds to at least one of an Internet Protocol address and a Media Access Control address.

61. The storage medium of claim 48 , wherein the location seed data is based at least in part on network domain data.

62. The storage medium of claim 48 , wherein the location seed data corresponds to network domain data.

63. The storage medium of claim 48 , wherein the cryptographic key is a stream of symbols.

64. The process of claim 48 , wherein the cryptographic key is at least one symbol block.

65. The process of claim 48 , wherein the cryptographic key is a key matrix.

66. The storage medium of claim 48 , wherein generate a plurality of cryptographic key splits further includes generate a random key split based on random seed data.

67. The storage medium of claim 48 , wherein generate a plurality of cryptographic key splits further includes generate an organization key split based on organization seed data.

68. The storage medium of claim 48 , wherein generate a plurality of cryptographic key splits further includes generate a maintenance key split based on maintenance seed data.

69. The storage medium of claim 48 , wherein generate a plurality of cryptographic key splits further includes generate a random key split based on random seed data, generate an organization key split based on organization seed data, and generate a maintenance key split based on maintenance seed data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2002
From: SCHEIDT, EDWARD M.; WACK, C. JAY
To: TECSEC, INCORPORATED
Reel/Frame 013235/0083 →
Continuity (3)
Continuation In Part 0902367200 · Feb 13, 1998
Provisional Application 6035212300 · Jan 24, 2002
Related Publication 20030039358A1 · Feb 27, 2003