IP Library Granted Patent US 8,031,875
Granted Patent B1
US 8,031,875 · App. 12/188,686 · Granted Oct 4, 2011

Key distribution in unidirectional channels with applications to RFID

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,031,875
App. No.
12/188,686
Granted
Oct 4, 2011
Kind
B1
Abstract

A technique for securing information involves encrypting raw data into encrypted data based on an initial key. The technique further involves generating a set of key shares from the initial key via application of error correction code encoding. Each key share has a size which is independent of a size of the initial key. The technique further involves electronically storing each key share on a respective memory device of a set of memory devices (e.g., RFID tags). The initial key is reconstructable from a predetermined number of the key shares read from their respective memory devices to enable decryption of the encrypted data.

Claims (79)

1. A method of securing information, the method comprising:

encrypting raw data into encrypted data based on an initial key, the initial key having a key size;

generating a set of key shares from the initial key via application of error correcting code (ECC) encoding, each key share having a size which is independent of the key size;

electronically storing each key share on a respective memory device of a set of memory devices, the initial key being reconstructable from a predetermined minimum number of the key shares read from their respective memory devices to enable decryption of the encrypted data; and

while electronically storing a particular key share on the respective memory device of that particular key share, electronically storing at least a portion of the encrypted data on the respective memory device;

wherein:

the set of electronic memory devices are radio frequency identification (RFID) tags;

electronically storing the particular key share and the encrypted data on the respective memory device includes writing the particular key share and the encrypted data to memory of a particular RFID tag;

each RFID tag is attached to a product;

encrypting the raw data into the encrypted data based on the initial key includes encrypting product data of the raw data, the product data indicating that the product belongs to a particular product class among multiple product classes; and

the method further comprises:

reconstructing the initial key from at least the predetermined minimum number of the key shares;

decrypting the encrypted data using the initial key to obtain the raw data;

extracting the product data from the raw data to identify the particular product class to which the product belongs; and

after extracting the product data from the raw data to identify the particular product class to which the product belongs, updating an inventory database based on the particular product class identified by the extracted product data.

2. A method as in claim 1 wherein each key share has a bit length which is shorter than that of the initial key.

3. A method as in claim 2 wherein each key share reveals partial information about the initial key in an imperfect secret-sharing manner.

4. A method as in claim 1 , further comprising:

after reconstructing the initial key, dispersing the RFID tags to prevent further reconstruction of the initial key.

5. A method as in claim 4 wherein electronically storing each key share on the respective memory device of the set of memory devices is carried out at a first location; and

wherein reconstructing the initial key and dispersing the RFID tags is carried out at a second location which is substantially different than the first location.

6. A method as in claim 1 wherein reconstructing the initial key from at least the predetermined number of the key shares includes:

for each of the predetermined number of key shares, associating a respective index to that key share based on a unique RFID tag identifier; and

providing the initial key based on the predetermined minimum number of key shares and their associated respective indexes.

7. A method as in claim 1 wherein the set of key shares includes X key shares where X is a positive integer; and wherein reconstructing the initial key from at least the predetermined number of the key shares includes:

providing the initial key based on exactly Y key shares where Y is a positive integer which is less than X.

8. A method as in claim 1 wherein encrypting raw data into encrypted data based on the initial key includes:

deriving a key from a one-way function of the initial key; and

encrypting the raw data using the derived key, the derived key having shorter bit length than that of the initial key.

9. A method as in claim 1 , further comprising:

electronically storing a chaff key share on at least one memory device of the set of memory devices, the chaff share to inhibit reconstruction of the initial key under an attempt to reconstruct the initial key using the chaff key share.

10. A method as in claim 1 wherein generating the set of key shares from the initial key via application of ECC encoding includes:

inputting the initial key into a Reed-Solomon ECC encoder circuit and reading an output of the encoder circuit.

11. A method of securing information, the method comprising:

encrypting raw data into encrypted data based on an initial key;

generating a set of key shares from the initial key via application of error correcting code (ECC) encoding, each key share revealing partial information about the initial key in an imperfect secret-sharing manner;

electronically storing each key share on a respective radio frequency identification (RFID) tag of a set of RFID tags, the initial key being reconstructable from a predetermined number of the key shares read from their respective RFID tags to enable decryption of the encrypted data; and

while electronically storing a particular key share on the respective RFID tag of that particular key share, electronically storing at least a portion of the encrypted data on the RFID tag;

wherein:

electronically storing the particular key share and the encrypted data on the respective RFID tag includes writing the particular key share and the encrypted data to memory of a particular RFID tag;

each RFID tag is attached to a product;

encrypting the raw data into the encrypted data based on the initial key includes encrypting product data of the raw data, the product data indicating that the product belongs to a particular product class among multiple product classes; and

the method further comprises:

reconstructing the initial key from at least the predetermined minimum number of the key shares;

decrypting the encrypted data using the initial key to obtain the raw data;

extracting the product data from the raw data to identify the particular product class to which the product belongs; and

after extracting the product data from the raw data to identify the particular product class to which the product belongs, updating an inventory database based on the particular product class identified by the extracted product data.

12. A method of securing information, the method comprising:

encrypting raw data into encrypted data based on an initial key;

generating a set of key shares from the initial key via application of error correcting code (ECC) encoding;

electronically storing each key share on a respective memory device of a set of memory devices, the initial key being reconstructable from a predetermined minimum number of the key shares read from their respective memory devices to enable decryption of the encrypted data;

transferring the set of memory devices from a first location to a second location in segregated groups, the second location being substantially different than the first location, and each group containing less than the predetermined minimum number of the key shares; and

while electronically storing a particular key share on the respective memory device of that particular key share, electronically storing at least a portion of the encrypted data on the respective memory device;

wherein:

the set of electronic memory devices are radio frequency identification (RFID) tags;

electronically storing the particular key share and the encrypted data on the respective memory device includes writing the particular key share and the encrypted data to memory of a particular RFID tag;

each RFID tag is attached to a product;

encrypting the raw data into the encrypted data based on the initial key includes encrypting product data of the raw data, the product data indicating that the product belongs to a particular product class among multiple product classes; and

the method further comprises:

reconstructing the initial key from at least the predetermined minimum number of the key shares;

decrypting the encrypted data using the initial key to obtain the raw data;

extracting the product data from the raw data to identify the particular product class to which the product belongs; and

after extracting the product data from the raw data to identify the particular product class to which the product belongs, updating an inventory database based on the particular product class identified by the extracted product data.

13. A system for securing information, the system comprising:

encryption circuitry constructed and arranged to encrypt raw data into encrypted data based on an initial key, the initial key having a key size;

an encoder coupled to the encryption circuitry, the encoder being constructed and arranged to generate a set of key shares from the initial key via application of error correcting code (ECC) encoding, each key share having a size which is independent of the key size; and

an interface coupled to the encoder, the interface being constructed and arranged to electronically store each key share on a respective memory device of a set of memory devices, the initial key being reconstructable from a predetermined minimum number of the key shares read from their respective memory devices to enable decryption of the encrypted data;

the interface, while electronically storing a particular key share on the respective memory device of that particular key share, being further constructed and arranged to electronically store at least a portion of the encrypted data on the respective memory device;

wherein:

the set of electronic memory devices are radio frequency identification (RFID) tags;

electronically storing the particular key share and the encrypted data on the respective memory device includes writing the particular key share and the encrypted data to memory of a particular RFID tag;

each RFID tag is attached to a product;

encrypting the raw data into the encrypted data based on the initial key includes encrypting product data of the raw data, the product data indicating that the product belongs to a particular product class among multiple product classes; and

the system further comprises:

a decoder constructed and arranged to reconstruct the initial key from at least the predetermined minimum number of the key shares; and

decryption circuitry coupled to the decoder, the decryption circuit being constructed and arranged to decrypt the encrypted data using the initial key to obtain the raw data; and

additional circuitry constructed and arranged to:

extract the product data from the raw data to identify the particular product class to which the product belongs; and

after extracting the product data from the raw data to identify the particular product class to which the product belongs, update an inventory database based on the particular product class identified by the extracted product data.

Assignments (14)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023975/0453 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023975/0151 →
MERGER Recorded Jan 27, 2010
From: RSA SECURITY INC
To: RSA SECURITY LLC
Reel/Frame 023852/0644 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023825/0109 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023824/0729 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2008
From: JUELS, ARI; PARNO, BRYAN
To: RSA SECURITY INC.
Reel/Frame 021443/0172 →