IP Library Granted Patent US 7,688,980
Granted Patent B2
US 7,688,980 · App. 11/005,880 · Granted Mar 30, 2010

Cryptographic-key generation and management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,688,980
App. No.
11/005,880
Granted
Mar 30, 2010
Kind
B2
Abstract

Methods and systems are provided of managing a cryptographic key. A first key component is received from a first key custodian. A second key component is received from a second key custodian. A key operation is performed on the first and second key components to generate the cryptographic key. A cryptographic-key number is assigned to the cryptographic key. A key form is printed specifying the cryptographic key. An association is recorded between the cryptographic-key number and an electromagnetic tag identifier coupled physically with the key form.

Claims (38)

1. A method of managing a cryptographic key, the method comprising:

assigning, by a microprocessor-based key terminal, a cryptographic-key number to the cryptographic key;

printing, from the microprocessor-based key terminal, a key form specifying the cryptographic key;

recording, by the microprocessor-based key terminal on a storage device, an association between the cryptographic-key number and an electromagnetic tag identifier coupled physically with the key form;

receiving, by the microprocessor-based key terminal, a first key component from a first key custodian;

receiving, by the microprocessor-based key terminal, a second key component from a second key custodian;

performing a key operation on the first and second key components to generate the cryptographic key;

authenticating, by the microprocessor-based key terminal, the first key custodian by reading a first card presented by the first key custodian, receiving a first personal identification number input by the first key custodian, and verifying consistency of information read from the first card with the first personal identification number;

authenticating, by the microprocessor-based key terminal, the second key custodian by reading a second card presented by the second key custodian, receiving a second personal identification number input by the second key custodian, and verifying consistency of information read from the second card with the second personal identification number; and

authenticating, by the microprocessor-based key terminal, a key manager who authorized the key custodians by reading a key-manager card presented by the key manager, receiving a key-manager personal identification number input by the key manager, and verifying consistency of information read from the key-manager card with the key-manager personal identification number.

2. A method for managing a cryptographic key, the method comprising:

authenticating, by a microprocessor-based key terminal, a key manager by reading a key-manager card presented by the key manager, receiving a key-manager personal identification number input by the key manager, and verifying consistency of information read from the key-manager card with the key-manager personal identification number;

authenticating, by the microprocessor-based key terminal, a first key custodian authorized by the authenticated key manager by reading a first key-custodian card presented by the first key custodian, receiving a first key-custodian personal identification number input by the first key custodian, and verifying consistency of information read from the first key-custodian card with the first key-custodian personal identification number;

receiving, by the microprocessor-based key terminal, a first key component from the authenticated first key custodian;

authenticating, by the microprocessor-based key terminal, a second key custodian authorized by the authenticated key manager by reading a second key-custodian card presented by the second key custodian, receiving a second key-custodian personal identification number input by the second key custodian, and verifying consistency of information read from the second key-custodian card with the second key-custodian personal identification number;

receiving, by the microprocessor-based key terminal, a second key component from the authenticated second key custodian;

performing a key operation on the first and second key components to generate the cryptographic key;

assigning, by the microprocessor-based key terminal, a cryptographic-key number to the cryptographic key;

printing, from the microprocessor-based key terminal, a key form identifying the cryptographic-key number with a one-dimensional bar code, specifying the cryptographic key with a two-dimensional bar code, and identifying the first and second key custodians; and

recording, by the microprocessor-based key terminal on a storage device, an association between the cryptographic-key number and an electromagnetic tag identifier coupled physically with the key form.

3. The method recited in claim 2 further comprising printing a label to be coupled physically with the key form, the label specifying the cryptographic-key number with the one-dimensional bar code.

4. A system for generating a cryptographic key, the system comprising:

a key terminal having an input device and a processor;

an output device coupled with the key terminal;

a storage device coupled with the key terminal; and

a host security module coupled with the key terminal,

wherein the processor has programming instructions to interact with the input device, the output device, the storage device, and the host security module to:

assign a cryptographic-key number to the cryptographic key;

print a key form specifying the cryptographic key with the output device;

record an association between the cryptographic-key number and an electromagnetic tag identifier coupled physically with the key form on the storage device;

receive a first key component from a first key custodian with the input device;

receive a second key component from a second key custodian with the input device; and

perform a key operation on the first and second key components with the host security module to generate the cryptographic key;

and wherein the input device comprises a keypad and a card reader; and

the processor further has programming instructions to:

authenticate the first key custodian by reading a first card presented by the first key custodian with the card reader, receive a first personal identification number input by the first key custodian with the keypad, and verify consistency of information read from the first card with the first personal identification number;

authenticate the second key custodian by reading a second card presented by the second key custodian with the card reader, receive a second personal identification number input by the second key custodian with the keypad, and verify consistency of information read from the second card with the second personal identification number; and

authenticate a key manager who authorized the key custodians by reading a key-manager card presented by the key manager with the card reader, receive a key-manager personal identification number input by the key manager with the keypad, and verify consistency of information read from the key-manager card with the key-manager personal identification number.

Assignments (9)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Aug 19, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: FIRST DATA CORPORATION; DW HOLDINGS, INC.; FIRST DATA RESOURCES, INC. (K/N/A FIRST DATA RESOURCES, LLC); FUNDSXPRESS FINANCIAL NETWORKS, INC.; INTELLIGENT RESULTS, INC. (K/N/A FIRST DATA SOLUTIONS, INC.); LINKPOINT INTERNATIONAL, INC.; MONEY NETWORK FINANCIAL, LLC; SIZE TECHNOLOGIES, INC.; TASQ TECHNOLOGY, INC.; TELECHECK INTERNATIONAL, INC.
Reel/Frame 050090/0060 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Aug 19, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: FIRST DATA CORPORATION; DW HOLDINGS, INC.; FIRST DATA RESOURCES, LLC; FUNDSXPRESS FINANCIAL NETWORK, INC.; FIRST DATA SOLUTIONS, INC.; LINKPOINT INTERNATIONAL, INC.; MONEY NETWORK FINANCIAL, LLC; SIZE TECHNOLOGIES, INC.; TASQ TECHNOLOGY, INC.; TELECHECK INTERNATIONAL, INC.
Reel/Frame 050091/0474 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Aug 19, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: FIRST DATA CORPORATION
Reel/Frame 050094/0455 →
RELEASE OF SECURITY INTEREST Recorded Jul 30, 2019
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: CARDSERVICE INTERNATIONAL, INC.; DW HOLDINGS INC.; FIRST DATA CORPORATION; FIRST DATA RESOURCES, LLC; FUNDSXPRESS, INC.; INTELLIGENT RESULTS, INC.; LINKPOINT INTERNATIONAL, INC.; SIZE TECHNOLOGIES, INC.; TASQ TECHNOLOGY, INC.; TELECHECK INTERNATIONAL, INC.; TELECHECK SERVICES, INC.
Reel/Frame 049902/0919 →
SECURITY AGREEMENT Recorded Jan 31, 2011
From: DW HOLDINGS, INC.; FIRST DATA RESOURCES, LLC; FUNDSXPRESS FINANCIAL NETWORKS, INC.; FIRST DATA SOLUTIONS, INC.; LINKPOINT INTERNATIONAL, INC.; MONEY NETWORK FINANCIAL, LLC; SIZE TECHNOLOGIES, INC.; TASQ TECHNOLOGY, INC.; TELECHECK INTERNATIONAL, INC
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 025719/0590 →
SECURITY AGREEMENT Recorded Nov 17, 2010
From: DW HOLDINGS, INC.; FIRST DATA RESOURCES, INC. (K/N/A FIRST DATA RESOURCES, LLC); FUNDSXPRESS FINANCIAL NETWORKS, INC.; INTELLIGENT RESULTS, INC. (K/N/A FIRST DATA SOLUTIONS, INC.); LINKPOINT INTERNATIONAL, INC.; MONEY NETWORK FINANCIAL, LLC; SIZE TECHNOLOGIES, INC.; TASQ TECHNOLOGY, INC.; TELECHECK INTERNATIONAL, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 025368/0183 →
SECURITY AGREEMENT Recorded Oct 31, 2007
From: FIRST DATA CORPORATION; CARDSERVICE INTERNATIONAL, INC.; FUNDSXPRESS, INC.; LINKPOINT INTERNATIONAL, INC.; TASQ TECHNOLOGY, INC.; TELECHECK SERVICES, INC.; DW HOLDINGS, INC.; FIRST DATA RESOURCES, INC.; INTELLIGENT RESULTS, INC.; SIZE TECHNOLOGIES, INC.; TELECHECK INTERNATIONAL, INC.
To: CREDIT SUISSE, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 020045/0165 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2006
From: KEAN, BRIAN; WHITE, KRISTI
To: FIRST DATA CORPORATION
Reel/Frame 017237/0567 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2005
From: KEAN, BRIAN
To: FIRST DATA CORPORATION
Reel/Frame 015806/0218 →