IP Library Granted Patent US 7,921,292
Granted Patent B1
US 7,921,292 · App. 10/406,938 · Granted Apr 5, 2011

Secure messaging systems

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,921,292
App. No.
10/406,938
Granted
Apr 5, 2011
Kind
B1
Abstract

A system is provided that uses cryptographic techniques to support secure messaging between senders and recipients. A sender may encrypt a message for a recipient using the recipient's public key. The sender may send the encrypted message to the message address of a given recipient. A server may be used to decrypt the encrypted message for the recipient, so that the recipient need not install a decryption engine on the recipient's equipment.

Claims (31)

1. A method for securely conveying a message over a communications network from a sender to a recipient, wherein the recipient has a message address and has a public key and a private key for use in encryption and decryption, comprising:

with the computing equipment at the sender, encrypting the message for the recipient using the public key of the recipient;

sending the encrypted message from the computing equipment at the sender to the message address of the recipient over the communications network;

adding forwarding notification information to the encrypted message in the form of instructions for the recipient that direct the recipient to forward the encrypted message for decryption, wherein the encrypted message with the added forwarding notification information is provided to the recipient;

at a server, receiving from the computing equipment at the sender the encrypted message addressed to the recipient;

providing the recipient with an interactive message access prompt formed from a universal resource locator to which the recipient can respond by clicking on the universal resource locator to begin obtaining access to a decrypted version of the message;

using the server to obtain credentials from the recipient when the recipient responds to the interactive message access prompt by clicking on the universal resource locator;

with a decryption engine on the server, using the recipient's credentials to obtain a copy of the recipient's private key;

with the decryption engine on the server, decrypting the encrypted message using the copy of the recipient's private key to produce the decrypted version of the message; and

with the server, providing the recipient with access to the decrypted version of the message, wherein the recipient's public key is an IBE public key and the recipient's private key is an IBE private key, wherein the sender encrypts the message using the recipient's IBE public key, wherein decrypting the encrypted message comprises decrypting the encrypted message at the server using the IBE private key of the recipient to produce the decrypted version of the message.

2. The method defined in claim 1 wherein providing the recipient with access to the decrypted version of the message comprises providing the recipient with access to the decrypted version of the message over a secure communications link between the server and the recipient.

3. The method defined in claim 1 wherein using the server to obtain credentials from the recipient comprises using the server to obtain credentials from the recipient over a secure communications link.

4. The method defined in claim 1 , wherein the recipient has a web browser, the method further comprising using the server to provide the recipient with access to the decrypted version of the message in the form of a web page provided to the recipient by the server over a secure communications link.

5. The method defined in claim 1 wherein using the server to obtain credentials from the recipient comprises obtaining a username and password from the recipient using the server.

6. The method defined in claim 1 wherein using the recipient's credentials to obtain a copy of the recipient's private key comprises using the server to present the recipient's public key to an IBE private key generator with a request for a copy of the recipient's IBE private key.

7. The method defined in claim 1 further comprising, at the server, storing the encrypted message in an encrypted message database.

8. The method defined in claim 1 further comprising, at the server, storing the decrypted message in a decrypted message database.

9. The method defined in claim 1 further comprising using the server to send the recipient a notification message that contains the encrypted message and that contains the forwarding notification information, wherein the forwarding notification information directs the recipient to forward the encrypted message to the server for decryption.

10. The method defined in claim 1 wherein adding the forwarding notification information comprises adding the forwarding notification information to the encrypted message at the sender.

11. The method defined in claim 1 wherein adding the forwarding notification information comprises adding the forwarding notification information to the encrypted message at the server.

12. The method defined in claim 1 wherein adding the forwarding notification information comprises adding the forwarding notification information to the encrypted message at an intermediate mail server that lies in a communications path between the sender and the recipient.

13. The method defined in claim 1 wherein providing the recipient with the interactive message access prompt comprises using the server to provide the recipient with an interactive message access prompt to which the recipient can respond to begin obtaining access to the decrypted version of the message.

14. The method defined in claim 1 wherein providing the recipient with the interactive message access prompt comprises using the server to send the recipient an interactive message containing the interactive message access prompt to which the recipient can respond to begin obtaining access to the decrypted version of the message.

15. The method defined in claim 1 further comprising storing the encrypted message received from the sender at the server, wherein providing the recipient with the interactive message access prompt comprises using the server to send the recipient an interactive message that informs the recipient that the encrypted message has been received and that contains the interactive message access prompt to which the recipient can respond to begin obtaining access to the decrypted version of the message.

16. The method defined in claim 1 wherein providing the recipient with the interactive message access prompt comprises using the server to send the recipient an interactive message when the server receives a forwarded encrypted message from the recipient, wherein the interactive message contains the interactive message access prompt to which the recipient can respond to begin obtaining access to the decrypted version of the message.

17. The method defined in claim 1 wherein providing the recipient with the interactive message access prompt comprises adding the interactive message access prompt to the encrypted message at the sender.

18. The method defined in claim 1 wherein providing the recipient with the interactive message access prompt comprises adding the interactive message access prompt to the encrypted message at the server.

19. The method defined in claim 1 wherein providing the recipient with the interactive message access prompt comprises adding the interactive message access prompt to the encrypted message at an intermediate mail server that lies in a communications path between the sender and the recipient.

20. The method defined in claim 1 further comprising at the sender, sending a copy of the encrypted message to a message address for the server.

21. The method defined in claim 20 further comprising using the server to provide the recipient with the interactive message access prompt when the server receives the copy of the encrypted message sent to the message address of the server by the sender.

22. The method defined in claim 1 wherein the server is within the same organization as the recipient, the method further comprising using the server to provide the recipient with access to the decrypted version of the message without installing a decryption engine at the recipient for decrypting the encrypted message.

Assignments (12)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
CHANGE OF NAME Recorded Dec 22, 2021
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 058569/0152 →
CHANGE OF NAME Recorded Dec 17, 2018
From: VOLTAGE SECURITY, INC.
To: VOLTAGE SECURITY, LLC
Reel/Frame 051198/0611 →
MERGER AND CHANGE OF NAME Recorded Dec 17, 2018
From: VOLTAGE SECURITY, LLC; ENTIT SOFTWARE LLC
To: ENTIT SOFTWARE LLC
Reel/Frame 051199/0074 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
RELEASE OF SECURITY INTEREST Recorded Feb 27, 2015
From: VENTURE LENDING & LEASING VI, INC.; VENTURE LENDING & LEASING VII, INC.
To: VOLTAGE SECURITY, INC.
Reel/Frame 035110/0726 →
SECURITY AGREEMENT Recorded Feb 7, 2014
From: VOLTAGE SECURITY, INC.
To: VENTURE LENDING & LEASING VI, INC.; VENTURE LENDING & LEASING VII, INC.
Reel/Frame 032170/0273 →
RELEASE OF SECURITY INTEREST Recorded Jul 1, 2009
From: VENTURE LENDING & LEASING IV, INC.
To: VOLTAGE SECURITY, INC.
Reel/Frame 022902/0722 →
SECURITY INTEREST Recorded Oct 24, 2006
From: VOLTAGE SECURITY, INC.
To: VENTURE LENDING & LEASING IV, INC.
Reel/Frame 018454/0073 →
CHANGE OF NAME Recorded Sep 15, 2003
From: IDENTICRYPT, INC.
To: VOLTAGE SECURITY, INC.
Reel/Frame 014496/0426 →