IP Library Granted Patent US 6,931,133
Granted Patent B2
US 6,931,133 · App. 10/232,624 · Granted Aug 16, 2005

Method and system of securely escrowing private keys in a public key infrastructure

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,931,133
App. No.
10/232,624
Granted
Aug 16, 2005
Kind
B2
Abstract

A method of restricting access to private keys in a public key infrastructure provides for storage of an encrypted private key at a primary site. A masked session key is stored at a secondary site, where the masked session key enables recovery of the private key. By using distributed storage architecture for recovery data, simplification can be achieved without sacrificing security.

Claims (69)

1. A method for escrowing a private key in a public key infrastructure, comprising:

creating a key pair including a private key and a public key;

creating a session key;

encrypting the private key using the session key;

creating a session key mask;

storing the encrypted private key and the session key mask;

creating a masked session key by exclusive-ORing the session key and the session key mask;

deleting the session key; and

sending the masked session key and a digital certificate to a secondary site.

2. The method of claim 1 , further comprising:

sending a key recovery request, including the digital certificate, to the secondary site;

receiving the masked session key from the secondary site;

recreating the session key by exclusive-ORing the masked session key and the session key mask; and

recovering the private key by decrypting the encrypted private key using the recreated session key.

3. The method of claim 1 , wherein the session key is a symmetric key.

4. The method of claim 1 , wherein said creating the session key includes using a triple-data encryption standard and an initialization vector.

5. The method of claim 1 , wherein the session mask is a random string having a bit-length equal to the session key.

6. The method of claim 1 , wherein the session mask is a pseudo-random string having a bit-length equal to the session key.

7. The method of claim 2 , wherein the key recovery request includes a plurality of digital certificates.

8. The method of claim 2 , further comprising:

combining the decrypted private key with a corresponding key pair certificate.

9. The method of claim 2 , further comprising:

creating an audit trail at the secondary site associated with the key recovery request.

10. A computer readable medium including instructions adapted to be executed by a processor to perform a method for escrowing a private key in a public key infrastructure, the method comprising:

creating a key pair including a private key and a public key;

creating a session key;

encrypting the private key using the session key;

creating a session key mask;

storing the encrypted private key and the session key mask;

creating a masked session key by exclusive-ORing the session key and the session key mask;

deleting the session key; and

sending the masked session key and a digital certificate to a secondary site.

11. The computer readable medium of claim 10 , wherein the method further comprises:

sending a key recovery request, including the digital certificate, to the secondary site;

receiving the masked session key from the secondary site;

recreating the session key by exclusive-ORing the masked session key and the session key mask; and

recovering the private key by decrypting the encrypted private key using the recreated session key.

12. The computer readable medium of claim 10 , wherein the session key is a symmetric key.

13. The computer readable medium of claim 10 , wherein said creating the session key includes using a triple-data encryption standard and an initialization vector.

14. The computer readable medium of claim 10 , wherein the session mask is a random string having a bit-length equal to the session key.

15. The computer readable medium of claim 10 , wherein the session mask is a pseudo-random string having a bit-length equal to the session key.

16. The computer readable medium of claim 11 , wherein the key recovery request includes a plurality of digital certificates.

17. The computer readable medium of claim 11 , wherein the method further comprises:

combining the decrypted private key with a corresponding key pair certificate.

18. The computer readable medium of claim 11 , wherein the method further comprises:

creating an audit trail at the secondary site associated with the key recovery request.

19. A system for escrowing a private key in a public key infrastructure, comprising:

a secondary site, coupled to the network, including a secondary database and a control center; and

a primary site, coupled to a network, including a primary database and a key management server, adapted to:

create a key pair including a private key and a public key,

create a session key,

encrypt the private key using the session key,

create a session key mask,

store the encrypted private key and the session key mask in the primary database,

create a masked session key by exclusive-ORing the session key and the session key mask,

delete the session key, and

send the masked session key and a digital certificate to the secondary site for storage within the secondary database.

20. The system of claim 19 , wherein the primary site is further adapted to:

send a key recovery request, including the digital certificate, to the secondary site;

receive the masked session key from the secondary site;

recreate the session key by exclusive-ORing the masked session key and the session key mask; and

recover the private key by decrypting the encrypted private key using the recreated session key.

21. The system of claim 19 , wherein the session key is a symmetric key.

22. The system of claim 19 , wherein said creating the session key includes using a triple-data encryption standard and an initialization vector.

23. The system of claim 19 , wherein the session mask is a random string having a bit-length equal to the session key.

24. The system of claim 19 , wherein the session mask is a pseudo-random string having a bit-length equal to the session key.

25. The system of claim 20 , wherein the key recovery request includes a plurality of digital certificates.

26. The system of claim 20 , wherein the primary site is further adapted to:

combine the decrypted private key with a corresponding key pair certificate.

Assignments (13)
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON OCTOBER 16, 2019 AT REEL 050741 FRAME 0918 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072947/0157 →
SECOND LIEN NOTICE OF SUCCESSION OF AGENCY Recorded Jul 30, 2025
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS PRIOR AGENT
To: UBS AG, STAMFORD BRANCH, AS SUCCESSOR AGENT
Reel/Frame 072300/0068 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 19, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS SUCCESSOR AGENT
Reel/Frame 055345/0042 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050747/0001 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050746/0973 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 050741/0918 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 050741/0899 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044710/0529 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044681/0556 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2017
From: SYMANTEC CORPORATION
To: DIGICERT, INC.
Reel/Frame 044344/0650 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2017
From: VERISIGN, INC.
To: SYMANTEC CORPORATION
Reel/Frame 043560/0271 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 14, 2010
From: VERISIGN, INC.
To: SYMANTEC CORPORATION
Reel/Frame 025499/0882 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2004
From: ANDREWS, RICHARD F.; HUANG, ZHIYONG; RUAN, TOM QI XIONG
To: VERISIGN, INC.
Reel/Frame 015863/0278 →