IP Library Granted Patent US 7,831,829
Granted Patent B2
US 7,831,829 · App. 12/181,308 · Granted Nov 9, 2010

Identity-based encryption system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,831,829
App. No.
12/181,308
Granted
Nov 9, 2010
Kind
B2
Abstract

A system is provided that uses identity-based encryption to support secure communications. Messages from a sender to a receiver may be encrypted using the receiver's identity and public parameters that have been generated by a private key generator associated with the receiver. The private key generator associated with the receiver generates a private key for the receiver. The encrypted message may be decrypted by the receiver using the receiver's private key. The system may have multiple private key generators, each with a separate set of public parameters. Directory services may be used to provide a sender that is associated with one private key generator with appropriate public parameters to use when encrypting messages for a receiver that is associated with a different private key generator. A certification authority may be used to sign directory entries for the directory service. A clearinghouse may be used to avoid duplicative directory entries.

Claims (20)

1. A method for using identity-based encryption to support encrypted communications in a system in which users at user equipment communicate over a communications network, wherein the system has a plurality of private key generators and a plurality of respective associated sets of public parameters, wherein each private key generator generates private keys for a group of associated users, wherein each user's private key may be used by that user to decrypt messages for the user that have been encrypted using the user's identity and the set of public parameters associated with the private key generator that generates that user's private key, and wherein computers coupled to the communications network are used to store the plurality of sets of public parameters, comprising:

at a sender having user equipment coupled to the communications network, downloading an appropriate one of the stored plurality of sets of the public parameters to use to encrypt a message for a receiver at user equipment coupled to the communications network, wherein the sender and the receiver are not associated with a common private key generator.

2. The method defined in claim 1 further comprising using the Internet Domain Name System (DNS) in downloading the appropriate set of public parameters.

3. The method defined in claim 1 wherein the receiver belongs to an organization having an associated domain name, the method further comprising using the domain name in downloading the appropriate set of public parameters.

4. The method defined in claim 1 wherein the receiver belongs to an organization having an associated domain name, the method further comprising using the domain name in determining which of the sets of public parameters to download.

5. The method defined in claim 1 wherein the receiver belongs to an organization having an associated domain name and wherein the receiver has an associated email address, the method further comprising using the email address and the domain name in determining which of the sets of public parameters is appropriate to download.

6. The method defined in claim 1 further comprising using at least a partial domain name in determining which of the sets of public parameters is appropriate to download.

7. The method defined in claim 1 further comprising:

at the sender, using the downloaded set of public parameters to encrypt the message for the receiver.

8. The method defined in claim 1 wherein the receiver's identity includes email address information, the method further comprising:

at the sender, using the email address information of the receiver and the downloaded set of public parameters to encrypt the message for the receiver.

9. A method for using identity-based encryption to support encrypted communications in a system in which users at user equipment communicate over a communications network, wherein the system has a plurality of private key generators and a plurality of respective associated sets of public parameters, wherein each private key generator generates private keys for a group of associated users, wherein each user's private key may be used by that user to decrypt messages for the user that have been encrypted using the user's identity and the set of public parameters associated with the private key generator that generates that user's private key, wherein a given sender having user equipment coupled to the communications network downloads an appropriate set of the public parameters to use to encrypt a message for a receiver at user equipment coupled to the communications network, and wherein the given sender and the receiver are not associated with a common private key generator, comprising:

using computers coupled to the communications network to store the plurality of sets of public parameters including the appropriate set of public parameters that the given sender downloads.

10. The method defined in claim 9 further comprising:

using at least one of the computers coupled to the communications network, providing the given sender with the appropriate set of the public parameters over the communications network.

11. The method defined in claim 10 further comprising using the Internet Domain Name System (DNS) in providing the appropriate set of public parameters to the given sender.

12. The method defined in claim 10 wherein the receiver belongs to an organization having an associated domain name, the method further comprising using the domain name in providing the appropriate set of public parameters to the given sender.

13. The method defined in claim 10 wherein the receiver belongs to an organization having an associated domain name, the method further comprising using the domain name in determining which of the sets of public parameters to provide to the given sender.

14. The method defined in claim 10 wherein the receiver belongs to an organization having an associated domain name and wherein the receiver has an associated email address, the method further comprising using the email address and the domain name in determining which of the sets of public parameters is appropriate to provide to the given sender.

15. The method defined in claim 10 further comprising using at least a partial domain name in determining which of the sets of public parameters is appropriate to provide to the given sender.

Assignments (11)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
CHANGE OF NAME Recorded Dec 22, 2021
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 058569/0152 →
CHANGE OF NAME Recorded Dec 17, 2018
From: VOLTAGE SECURITY, INC.
To: VOLTAGE SECURITY, LLC
Reel/Frame 051198/0611 →
MERGER AND CHANGE OF NAME Recorded Dec 17, 2018
From: VOLTAGE SECURITY, LLC; ENTIT SOFTWARE LLC
To: ENTIT SOFTWARE LLC
Reel/Frame 051199/0074 →
MERGER Recorded Oct 22, 2018
From: VOLTAGE SECURITY, LLC
To: ENTIT SOFTWARE LLC
Reel/Frame 047253/0802 →
ENTITY CONVERSION AND CHANGE OF NAME Recorded Oct 22, 2018
From: VOLTAGE SECURITY, INC.
To: VOLTAGE SECURITY, LLC
Reel/Frame 047276/0434 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
RELEASE OF SECURITY INTEREST Recorded Feb 27, 2015
From: VENTURE LENDING & LEASING VI, INC.; VENTURE LENDING & LEASING VII, INC.
To: VOLTAGE SECURITY, INC.
Reel/Frame 035110/0726 →
SECURITY AGREEMENT Recorded Feb 7, 2014
From: VOLTAGE SECURITY, INC.
To: VENTURE LENDING & LEASING VI, INC.; VENTURE LENDING & LEASING VII, INC.
Reel/Frame 032170/0273 →