IP Library Granted Patent US 8,638,938
Granted Patent B2
US 8,638,938 · App. 12/048,336 · Granted Jan 28, 2014

Symmetric key subscription

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,638,938
App. No.
12/048,336
Granted
Jan 28, 2014
Kind
B2
Abstract

A method and system for symmetric key subscription. A register R issues to a subject A a possession that stores a first symmetric key X or comprises a deriving means configured to derive the first symmetric key X. The register R receives from a counterparty B a request for a subscription to a symmetric key with respect to the subject A. In response to the received request, the register R derives a second symmetric key Y from both the first symmetric key X and a first value N. The register R transmits to the counterparty B the second symmetric key Y derived by the register R.

Claims (64)

1. A method for symmetric key subscription, said method comprising:

receiving, by the register R from a counterparty B, a request for a subscription to a symmetric key with respect to the subject A, said receiving the request having been performed after a possession has been issued by the register R to the subject A, said possession storing a first symmetric key X or comprising a deriving means configured to derive the first symmetric key X, said receiving the request performed by a processor of a computer system;

said processor generating, by the register R in response to the received request, a second symmetric key Y derived from both the first symmetric key X and a first value N, said N being a positive integer; and

said processor transmitting, by the register R to the counterparty B, the second symmetric key Y generated by the register R.

2. The method of claim 1 , wherein said transmitting comprises transmitting, by the register R to the counterparty B, the second symmetric key Y generated by the register R and the first value N.

3. The method of claim 2 , wherein the method further comprises:

sending, by the counterparty B to the subject A, the first value N after the counterparty B received the first value N that had been transmitted by the register R.

4. The method of claim 3 , wherein the method further comprises:

obtaining, by the subject A, the first symmetric key X by retrieving the stored first symmetric key X if the possession stores the first symmetric key or by using the deriving means to derive the first symmetric key X if the possession comprises the deriving means; and

generating, by the subject A after having received the first value N from the counterparty B and after having obtained the first symmetric key X, the second symmetric key Y derived from both the obtained first symmetric key X and the first value N received from the counterparty B.

5. The method of claim 4 , wherein the method further comprises after said generating by the subject A the second symmetric key Y: transacting data from a first entity to a second entity, wherein either the first entity is the subject A and the second entity is the counterparty B or the first entity is the counterparty B and the second entity is the subject A, and wherein said transacting data comprises:

the first entity encrypting transaction data using the second symmetric key Y;

the first entity sending the encrypted transaction data to the second entity;

the second entity receiving the encrypted transaction data sent by the first entity; and

the second entity decrypting the received encrypted transaction data using the second symmetric key Y to obtain the transaction data.

6. The method of claim 1 , wherein N denotes an Nth time in a history of R's relationship with A that any counterparty has requested a subscription to a symmetric key with respect to the subject A.

7. The method of claim 1 , wherein the possession is an identity card.

8. A computer system comprising a processor and a computer readable memory unit coupled to the processor, said memory unit containing program code that when executed by the processor implement a method for symmetric key subscription, said method comprising:

said processor receiving, by a register R from a counterparty B, a request for a subscription to a symmetric key with respect to a subject A, said receiving the request having been performed after a possession has been issued by the register R to the subject A, said possession storing a first symmetric key X or comprising a deriving means configured to derive the first symmetric key X;

said processor generating, by the register R in response to the received request, a second symmetric key Y derived from both the first symmetric key X and a first value N, said N being a positive integer; and

said processor transmitting, by the register R to the counterparty B, the second symmetric key Y generated by the register R.

9. The computer system of claim 8 , wherein the method further comprises:

receiving, by the counterparty B, the first value N after said transmitting the second symmetric key Y by the register R.

10. The computer system of claim 9 , wherein the method further comprises:

sending, by the counterparty B to the subject A, the first value N after the counterparty B received the first value N.

11. The computer system of claim 10 , wherein the method further comprises:

obtaining, by the subject A, the first symmetric key X by retrieving the stored first symmetric key X if the possession stores the first symmetric key or by using the deriving means to derive the first symmetric key X if the possession comprises the deriving means; and

generating, by the subject A after having received the first value N from the counterparty B and after having obtained the first symmetric key X, the second symmetric key Y derived from both the obtained first symmetric key X and the first value N received from the counterparty B.

12. The computer system of claim 11 , wherein the method further comprises after said generating by the subject A the second symmetric key Y: transacting data from a first entity to a second entity, wherein either the first entity is the subject A and the second entity is the counterparty B or the first entity is the counterparty B and the second entity is the subject A, and wherein said transacting data comprises:

the first entity encrypting transaction data using the second symmetric key Y;

the first entity sending the encrypted transaction data to the second entity;

the second entity receiving the encrypted transaction data sent by the first entity; and

the second entity decrypting the received encrypted transaction data using the second symmetric key Y to obtain the transaction data.

13. A computer program product, comprising a computer readable storage device having a computer readable program code stored therein, said computer readable program code containing instructions that when executed by a processor of a computer system implement a method for symmetric key subscription, said method comprising:

said processor receiving, by a register R from a counterparty B, a request for a subscription to a symmetric key with respect to a subject A, said receiving the request having been performed after a possession has been issued by the register R to the subject A, said possession storing a first symmetric key X or comprising a deriving means configured to derive the first symmetric key X;

said processor generating, by the register R in response to the received request, a second symmetric key Y derived from both the first symmetric key X and a first value N, said N being a positive integer; and

said processor transmitting, by the register R to the counterparty B, the second symmetric key Y generated by the register R.

14. The computer program product of claim 13 , wherein the method further comprises:

receiving, by the counterparty B, the first value N after said transmitting the second symmetric key Y by the register R.

15. The computer program product of claim 14 , wherein the method further comprises:

sending, by the counterparty B to the subject A, the first value N after the counterparty B received the first value N.

16. The computer program product of claim 15 , wherein the method further comprises:

obtaining, by the subject A, the first symmetric key X by retrieving the stored first symmetric key X if the possession stores the first symmetric key or by using the deriving means to derive the first symmetric key X if the possession comprises the deriving means; and

generating, by the subject A after having received the first value N from the counterparty B and after having obtained the first symmetric key X, the second symmetric key Y derived from both the obtained first symmetric key X and the first value N received from the counterparty B.

17. The computer program product of claim 16 , wherein the method further comprises after said generating by the subject A the second symmetric key Y: transacting data from a first entity to a second entity, wherein either the first entity is the subject A and the second entity is the counterparty B or the first entity is the counterparty B and the second entity is the subject A, and wherein said transacting data comprises:

the first entity encrypting transaction data using the second symmetric key Y;

the first entity sending the encrypted transaction data to the second entity;

the second entity receiving the encrypted transaction data sent by the first entity; and

the second entity decrypting the received encrypted transaction data using the second symmetric key Y to obtain the transaction data.

18. A process for providing a symmetric key subscription service, said process comprising implementing a method for symmetric key subscription, said method comprising:

receiving, by the register R from a counterparty B, a request for a subscription to a symmetric key with respect to the subject A, said receiving the request having been performed after a possession has been issued by the register R to the subject A, said possession storing a first symmetric key X or comprising a deriving means configured to derive the first symmetric key X, said receiving the request performed by a processor of a computer system;

said processor generating, by the register R in response to the received request, a second symmetric key Y derived from both the first symmetric key X and a first value N, said N being a positive integer; and

said processor transmitting, by the register R to the counterparty B, the second symmetric key Y generated by the register R.

19. The process of claim 18 , wherein said transmitting comprises transmitting, by the register R to the counterparty B, the second symmetric key Y generated by the register R and the first value N.

20. The process of claim 19 , wherein the method further comprises:

sending, by the counterparty B to the subject A, the first value N after the counterparty B received the first value N that had been transmitted by the register R.

21. The process of claim 20 , wherein the method further comprises:

obtaining, by the subject A, the first symmetric key X by retrieving the stored first symmetric key X if the possession stores the first symmetric key or by using the deriving means to derive the first symmetric key X if the possession comprises the deriving means; and

generating, by the subject A after having received the first value N from the counterparty B and after having obtained the first symmetric key X, the second symmetric key Y derived from both the obtained first symmetric key X and the first value N received from the counterparty B.

22. The process of claim 21 , wherein the method further comprises after said generating by the subject A the second symmetric key Y: transacting data from a first entity to a second entity, wherein either the first entity is the subject A and the second entity is the counterparty B or the first entity is the counterparty B and the second entity is the subject A, and wherein said transacting data comprises:

the first entity encrypting transaction data using the second symmetric key Y;

the first entity sending the encrypted transaction data to the second entity;

the second entity receiving the encrypted transaction data sent by the first entity; and

the second entity decrypting the received encrypted transaction data using the second symmetric key Y to obtain the transaction data.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: KYNDRYL, INC.
Reel/Frame 057885/0644 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2008
From: DARE, PETER ROY
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 020650/0975 →