IP Library Granted Patent US 8,489,901
Granted Patent B2
US 8,489,901 · App. 12/115,390 · Granted Jul 16, 2013

Methods and systems for secure encryption of data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,489,901
App. No.
12/115,390
Granted
Jul 16, 2013
Kind
B2
Abstract

Provided is a data acquisition module. The data acquisition module includes a memory and a controller. The controller includes an encryption module configured to encrypt information written to the memory using a key included in the controller. The key is unique to the controller. Also provided is a method for processing identification information. The method includes encrypting information with a key included in a controller and storing the encrypted information. The key is unique to the controller.

Claims (38)

1. A sensor data acquisition module for use in a system for identifying a person, comprising:

a sensor for obtaining information representing an identification characteristic of a person, and wherein said identification characteristic includes a fingerprint;

a first memory;

a key module comprising a one-time programmable (OTP) memory, being a second memory, for storing information representing a key, and wherein said key has a value that is cryptographically random; and

an encryption module configured for employing said key for encrypting said information representing said identification characteristic of a person prior to storing said information into said first memory; and

wherein said storing of said key is preserved by circuitry including a first plurality of fuses, and wherein at least a subset of said first plurality of fuses, being a second plurality of fuses, are at least partially blown during manufacture of said key module; and

wherein each of said second plurality of fuses retains an amount of charge to maintain integrity of said information storing said key prior to a package containing the second memory being breached after manufacture, and wherein upon said package being breached after manufacture, said information storing said key is at least partially destroyed.

2. The sensor data acquisition module of claim 1 wherein the second memory is shielded from electromagnetic scanning.

3. The sensor data acquisition module of claim I wherein said key is not recorded during manufacture of the data acquisition unit.

4. The sensor data acquisition module of claim 1 , wherein the encryption module is configured to generate a session key from a host key stored in the second memory in accordance with a Diffie-Helman of a Secure hash algorithm.

5. The sensor data acquisition module of claim 1 wherein information representing an identification characteristic of a known person is stored into said first memory.

6. The sensor data acquisition module of claim 5 including a comparison module to compare information representing an identification characteristic of an unknown person with that of said known person.

7. The sensor data acquisition module of claim 1 including an authorization module configured to determine privileges to be granted to a person based upon a determined identity of said person.

8. An identification and authorizing system, comprising:

a sensor for obtaining information representing an identification characteristic of a person, and wherein said identification characteristic includes a fingerprint;

a first memory;

a key module comprising a one-time programmable (OTP) memory, being a second memory, for storing information representing a key, and wherein said key has a value that is cryptographically random; and

an encryption module configured for employing said key for encrypting said information representing said identification characteristic of a person prior to storing said information into said first memory; and

wherein said storing of said key is preserved by circuitry including a first plurality of fuses, and wherein at least a subset of said first plurality of fuses, being a second plurality of fuses, are at least partially blown during manufacture of said key module; and

wherein each of said second plurality of fuses retains an amount of charge to maintain integrity of said information storing said key prior to a package containing the second memory being breached after manufacture, and wherein upon said package being breached after manufacture, said information storing said key is at least partially destroyed.

9. The system of claim 8 wherein the second memory is shielded from electromagnetic scanning.

10. The system of claim 8 wherein said key is not recorded during manufacture of the data acquisition unit.

11. The system of claim 8 wherein the encryption module is configured to generate a session key from a host key stored in the second memory in accordance with a Diffie-Helman of a Secure hash algorithm.

12. The system of claim 8 wherein information representing an identification characteristic of a known person is stored into said first memory.

13. The system of claim 8 including an authorization module configured to determine privileges to be granted to a person based upon a determined identity of said person.

14. The system of claim 12 including a comparison module to compare information representing an identification characteristic of an unknown person with that of said known person.

15. A method for processing sensor data for identifying a person, comprising the steps of:

providing a sensor for obtaining information representing an identification characteristic of a person, and wherein said identification characteristic includes a fingerprint;

providing a first memory;

providing a key module comprising a one-time programmable (OTP) memory, being a second memory, for storing information representing a key, and wherein said key has a value that is cryptographically random; and

providing an encryption module configured for employing said key for encrypting said information representing said identification characteristic of a person prior to storing said information into said first memory; and

wherein said storing of said key is preserved by circuitry including a first plurality of fuses, and wherein at least a subset of said first plurality of fuses, being a second plurality of fuses, are at least partially blown during manufacture of said key module; and

wherein each of said second plurality of fuses retains an amount of charge to maintain integrity of said information storing said key prior to a package containing the second memory being breached after manufacture, and wherein upon said package being breached after manufacture, said information storing said key is at least partially destroyed.

16. The method of claim 15 wherein the second memory is shielded from electromagnetic scanning.

17. The method of claim 15 wherein the encryption module is configured to generate a session key from a host key stored in the second memory in accordance with a Diffie-Helman of a Secure hash algorithm.

18. The method of claim 15 wherein information representing an identification characteristic of a known person is stored into said first memory.

19. The method of claim 15 including an authorization module configured to determine privileges to be granted to a person based upon a determined identity of said person.

20. The method of claim 18 including a comparison module to compare information representing an identification characteristic of an unknown person with that of said known person.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 9, 2025
From: BRAZOS CAPITAL MANAGEMENT LLC
To: SONAVATION TECHNOLOGIES, LLC
Reel/Frame 071977/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2024
From: SONAVATION INC.
To: BRAZOS CAPITAL MANAGEMENT LLC
Reel/Frame 068598/0339 →
SECURITY INTEREST Recorded May 19, 2022
From: SONAVATION, INC.
To: HEALTHCARE INVESTMENTS, LLC; LOCKE LORD LLP; BOARD OF REGENTS OF THE UNIVERSITY OF TEXAS SYSTEM ON BEHALF OF THE UNIVERSITY OF TEXAS M.D. ANDERSON CANCER CENTER; SONINVEST LLC; WEINTZ, KARL F.
Reel/Frame 063271/0954 →
SECURITY INTEREST Recorded Apr 26, 2021
From: SONAVATION, INC.
To: CROSS MATCH TECHNOLOGIES, INC.
Reel/Frame 056041/0805 →
ASSIGNMENT OF SECURITY INTEREST Recorded Sep 23, 2010
From: SONAVATION, INC.
To: CROSS MATCH TECHNOLOGIES, INC.
Reel/Frame 025066/0580 →
SECURITY AGREEMENT Recorded Oct 22, 2009
From: SONAVATION, INC.
To: JOHNSON, COLLATERAL AGENT, THEODORE M.
Reel/Frame 023409/0336 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2008
From: BOUDREAUX, JOHN
To: SONAVATION, INC.
Reel/Frame 020907/0083 →