IP Library Patent Application 12315141
Patent Application
App. No. 12/315,141

System for and method of locking and unlocking a secret using a fingerprint

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/315,141
Abstract

The present invention provides a way to lock a secret in a portable package. The package contains the key needed to unlock it. The key is dispersed throughout the encrypted data so that an attacker has no way to feasibly recover it. The package also contains information that uniquely identifies users who are authorized to unlock the secret. In a preferred embodiment, the information is fingerprint image data, such as fingerprint templates. The locked secret thus has several levels of security, requiring information needed to recover and assemble the key, information about the decryption algorithm that uses the key to unlock the secret, and biometric information needed to grant a user permission to unlock the secret.

Claims (51)

1 . A method of formatting ciphertext comprising:

encrypting clear data with a key to thereby produce ciphertext;

embedding blocks of key data corresponding to the key at multiple predetermined locations within the ciphertext; and

associating biometric information with the ciphertext, wherein the biometric information corresponds to one or more users authorized to decrypt the ciphertext.

2 . The method of claim 1 , wherein associating biometric information with the ciphertext comprises appending the biometric information to the ciphertext.

3 . The method of claim 1 , wherein associating biometric information with the ciphertext comprises appending an identifier of the biometric information to the ciphertext.

4 . The method of claim 3 , wherein the identifier of the biometric information comprises an address of the biometric information.

5 . The method of claim 1 , wherein the biometric information is encrypted using the key before the biometric information is associated with the ciphertext.

6 . The method of claim 1 , further comprising encrypting the key to generate the key data.

7 . The method of claim 1 , wherein the biometric information comprises one or more hashes of biometric templates.

8 . The method of claim 7 , wherein the biometric templates are templates of fingerprint images.

9 . The method of claim 8 , wherein each of the one or more hashes is generated using one of MD-5, Secure Hash Algorithm-1, and a checksum.

10 . The method of claim 1 , wherein the key is generated using any one of Data Encryption Standard, Advanced Encryption Standard, and Blowfish.

11 . The method of claim 1 , wherein encrypting clear data comprises appending pad bits to the ciphertext if a length of the ciphertext is less than a predetermined threshold value.

12 . The method of claim 1 , wherein each of the blocks is a multiple of one byte long.

13 . The method of claim 1 , wherein each of the blocks is 1 bit long.

14 . The method of claim 1 , further comprising appending an authentication code for the ciphertext to the ciphertext.

15 . The method of claim 14 , wherein the authentication code is a message authentication code.

16 . The method of claim 15 , wherein the message authentication code is a cryptographic hashing algorithm selected from the group consisting of Universal Hashing Message Authentication Code (UMAC), Hash Message Authentication Code (HMAC), and Poly 1305-AES.

17 . The method of claim 1 , wherein a predetermined locations are dependent on an identity of the key.

18 . The method of claim 1 , further comprising encrypting one or more biometric templates associated with users authorized to access ciphertext on a file system and appending the encrypted one or more biometric templates to the ciphertext.

19 . A method of recovering plain text from ciphertext comprising:

successfully matching first biometric information to second biometric information, wherein the second biometric information is associated with a user authorized to recover the plain text;

combining segments of key data embedded throughout the ciphertext to thereby retrieve a decryption key; and

using the decryption key to decrypt the ciphertext to thereby recover the plain text.

20 . The method of claim 19 , wherein the first biometric information and the second biometric information are both hashes of biometric templates.

21 . The method of claim 20 , wherein the biometric templates are templates of fingerprint images.

22 . The method of claim 19 , wherein combining segments of key data comprises appending the segments and filtering the appended segments to retrieve the encryption key.

23 . The method of claim 22 , wherein the appended segments form encrypted key data and filtering comprises decrypting the appended segments.

24 . The method of claim 19 , further comprising comparing a characteristic of the recovered plain text with a corresponding characteristic stored for the recovered plain text to thereby ensure that the plain text has not been tampered with.

25 . The method of claim 24 , wherein the unique characteristic is generated by performing a hashing algorithm on the recovered ciphertext.

26 . A data storage system comprising:

a plurality of data blocks, each data block comprising:

ciphertext containing segmented key data derived from a key used to encrypt it embedded throughout; and

template information identifying one or more users authorized to decrypt the ciphertext to recover corresponding plain text.

27 . The data storage system of claim 26 , wherein for each data block, the template information is appended to the ciphertext.

28 . The data storage system of claim 26 , wherein the key data for the plurality of data blocks are different from one another.

29 . The data storage system of claim 26 , wherein the template information for each of the data blocks is a fingerprint template.

30 . The data storage system of claim 26 , further comprising a computer-readable medium containing computer-executable instructions for performing a method comprising:

encrypting plain text to generate ciphertext;

generating key data from a key;

embedding segments of the key data at predetermined locations within ciphertext; and

associating first biometric information with the ciphertext containing the embedded segments of the key data.

31 . The data storage system of claim 30 , wherein the method further comprises:

successfully matching second biometric information with the first biometric information;

retrieving the embedded key data from the ciphertext;

recovering the key from the key data; and

using the key to decrypt the ciphertext to thereby recover the plain text.

32 . The data storage system of claim 31 , wherein recovering the key from the key data comprises combining segments of the key data.

33 . The data storage system of claim 32 , wherein recovering the key from the key data further comprises decrypting the key data.

34 . The data storage system of claim 31 , wherein the method further comprises verifying that the ciphertext has not been tampered with.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2015
From: AUTHENTEC, INC.
To: APPLE INC.
Reel/Frame 035552/0286 →
NUNC PRO TUNC ASSIGNMENT Recorded Oct 3, 2012
From: RUSSO, ANTHONY P.
To: ATRUA TECHNOLOGIES, INC.
Reel/Frame 029072/0021 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2012
From: ATRUA TECHNOLOGIES, INC.
To: ATRUA, LLC
Reel/Frame 028591/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2009
From: ATRUA, LLC
To: AUTHENTEC, INC.
Reel/Frame 022980/0901 →