IP Library Granted Patent US 8,208,627
Granted Patent B2
US 8,208,627 · App. 12/432,258 · Granted Jun 26, 2012

Format-preserving cryptographic systems

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,208,627
App. No.
12/432,258
Granted
Jun 26, 2012
Kind
B2
Abstract

Format-preserving encryption and decryption processes are provided. The encryption and decryption processes may use a block cipher. A string that is to be encrypted or decrypted may be converted to a unique binary value. The block cipher may operate on the binary value. If the output of the block cipher that is produced is not representative of a string that is in the same format as the original string, the block cipher may be applied again. The block cipher may be repeatedly applied in this way during format-preserving encryption operations and during format-preserving decryption operations until a format-compliant output is produced. Selective access may be provided to portions of a string that have been encrypted using format-preserving encryption.

Claims (46)

1. A method for performing encryption at computing equipment, comprising:

with an encryption engine on computing equipment, obtaining an encoded binary value representing an unencrypted string in a given format, wherein obtaining the encoded binary value comprises:

obtaining the unencrypted string in the given format; and

encoding the unencrypted string to produce the encoded binary value;

with the encryption engine on the computing equipment, applying a block cipher to the encoded binary value to produce a block cipher output;

after each application of the block cipher, with the encryption engine on the computing equipment, determining whether the block cipher output is representative of a string in the given format;

whenever it is determined that the block cipher output is not representative of a string in the given format, with the encryption engine on the computing equipment, applying the block cipher an additional time to update the block cipher output; and

when it is determined that the block cipher output is representative of a string in the given format, with the encryption engine on the computing equipment, processing the block cipher output to produce an encrypted version of the unencrypted string.

2. The method defined in claim 1 wherein processing the block cipher output comprises converting the block cipher output from binary to characters.

3. The method defined in claim 1 wherein encoding the unencrypted string to produce the encoded binary value comprises encoding the string as a unique binary value.

4. The method defined in claim 3 wherein encoding the unencrypted string comprises converting the string to numeric values and multiplying the numeric values by coefficients.

5. The method defined in claim 4 , wherein a given one of the coefficients is associated with a given character in the string, the method further comprising with the encryption engine on the computing equipment, computing the given one of the coefficients by computing a product of a set of numbers each of which represents how many possible character values are associated with a respective character in the string prior to the given character.

6. A method for performing encryption at computing equipment, comprising:

with an encryption engine on computing equipment, obtaining an encoded binary value representing an unencrypted string in a given format;

with the encryption engine on the computing equipment, applying a block cipher to the encoded binary value to produce a block cipher output;

after each application of the block cipher, with the encryption engine on the computing equipment, determining whether the block cipher output is representative of a string in the given format;

whenever it is determined that the block cipher output is not representative of a string in the given format, with the encryption engine on the computing equipment, applying the block cipher an additional time to update the block cipher output; and

when it is determined that the block cipher output is representative of a string in the given format, with the encryption engine on the computing equipment, processing the block cipher output to produce an encrypted version of the unencrypted string, wherein processing the block cipher output comprises restoring removed string elements to the encrypted version of the unencrypted string.

7. A method for performing decryption at computing equipment, comprising:

with a decryption engine on computing equipment, obtaining an encoded binary value representing an encrypted string in a given format, wherein obtaining the encoded binary value comprises:

obtaining the encrypted string in the given format; and

encoding the encrypted string to produce the encoded binary value;

with the decryption engine on the computing equipment, applying a block cipher to the encoded binary value to produce a block cipher output;

after each application of the block cipher, with the decryption engine on the computing equipment, determining whether the block cipher output is representative of a string in the given format;

whenever it is determined that the block cipher output is not representative of a string in the given format, with the decryption engine on the computing equipment, applying the block cipher an additional time to update the block cipher output; and

when it is determined that the block cipher output is representative of a string in the given format, with the decryption engine on the computing equipment, processing the block cipher output to produce a decrypted version of the encrypted string.

8. The method defined in claim 7 wherein processing the block cipher output comprises converting the block cipher output from binary to characters.

9. The method defined in claim 7 wherein encoding the encrypted string to produce the encoded binary value comprises encoding the encrypted string as a unique binary value.

10. The method defined in claim 9 wherein encoding the encrypted string comprises converting the string to numeric values and multiplying the numeric values by coefficients.

11. The method defined in claim 10 , wherein a given one of the coefficients is associated with a given character in the string, the method further comprising with the decryption engine on the computing equipment, computing the given one of the coefficients by computing a product of a set of numbers each of which represents how many possible character values are associated with a respective character in the string prior to the given character.

12. A method for performing decryption at computing equipment, comprising:

with a decryption engine on computing equipment, obtaining an encoded binary value representing an encrypted string in a given format;

with the decryption engine on the computing equipment, applying a block cipher to the encoded binary value to produce a block cipher output;

after each application of the block cipher, with the decryption engine on the computing equipment, determining whether the block cipher output is representative of a string in the given format;

whenever it is determined that the block cipher output is not representative of a string in the given format, with the decryption engine on the computing equipment, applying the block cipher an additional time to update the block cipher output; and

when it is determined that the block cipher output is representative of a string in the given format, with the decryption engine on the computing equipment, processing the block cipher output to produce a decrypted version of the encrypted string, wherein processing the block cipher output comprises restoring removed string elements to the decrypted version of the encrypted string.

13. A method for using at least first and second cryptographic keys to provide at least first and second users with selective access to the contents of a string, comprising:

with format-preserving encryption at an encryption engine on computing equipment, encrypting a first plaintext part of the string using the first cryptographic key to produce first ciphertext that is in the same format as the first plaintext part while leaving a second plaintext part of the string unencrypted;

with format-preserving encryption at the encryption engine on the computing equipment following encryption of the first plaintext part of the string, encrypting both the second plaintext part of the string and the first ciphertext using the second cryptographic key to produce second ciphertext, wherein the second ciphertext is in the same format as the string;

providing the first and second keys to the first user; and

providing the second key to the second user without providing the first key to the second user.

14. The method defined in claim 13 further comprising:

at the second user, decrypting the second ciphertext for the second user to produce the first ciphertext part and the second plaintext part.

15. The method defined in claim 14 further comprising:

at the first user, decrypting the first ciphertext part to produce the first plaintext part.

16. The method defined in claim 15 wherein the decrypting the first ciphertext part comprises decrypting the first ciphertext part using a block cipher.

Assignments (11)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
CHANGE OF NAME Recorded Dec 22, 2021
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 058569/0152 →
CHANGE OF NAME Recorded Dec 17, 2018
From: VOLTAGE SECURITY, INC.
To: VOLTAGE SECURITY, LLC
Reel/Frame 051198/0611 →
MERGER AND CHANGE OF NAME Recorded Dec 17, 2018
From: VOLTAGE SECURITY, LLC; ENTIT SOFTWARE LLC
To: ENTIT SOFTWARE LLC
Reel/Frame 051199/0074 →
MERGER Recorded Oct 22, 2018
From: VOLTAGE SECURITY, LLC
To: ENTIT SOFTWARE LLC
Reel/Frame 047253/0802 →
ENTITY CONVERSION AND CHANGE OF NAME Recorded Oct 22, 2018
From: VOLTAGE SECURITY, INC.
To: VOLTAGE SECURITY, LLC
Reel/Frame 047276/0434 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
RELEASE OF SECURITY INTEREST Recorded Feb 27, 2015
From: VENTURE LENDING & LEASING VI, INC.; VENTURE LENDING & LEASING VII, INC.
To: VOLTAGE SECURITY, INC.
Reel/Frame 035110/0726 →
SECURITY AGREEMENT Recorded Feb 7, 2014
From: VOLTAGE SECURITY, INC.
To: VENTURE LENDING & LEASING VI, INC.; VENTURE LENDING & LEASING VII, INC.
Reel/Frame 032170/0273 →