IP Library Granted Patent US 7,961,879
Granted Patent B1
US 7,961,879 · App. 12/534,040 · Granted Jun 14, 2011

Identity-based-encryption system with hidden public key attributes

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,961,879
App. No.
12/534,040
Granted
Jun 14, 2011
Kind
B1
Abstract

A system is provided that uses identity-based encryption (IBE) to allow a sender to securely convey information in a message to a recipient over a communications network. IBE public key information may be used to encrypt messages and corresponding IBE private key information may be used to decrypt messages. Information on which IBE public key information was used in encrypting a given message may be provided to the message recipient with the message. Multiple IBE public keys may be used to encrypt a single message. A less sensitive IBE public key may be used to encrypt a more sensitive public key, so that the more sensitive public key can remain hidden as it is sent to the recipient.

Claims (26)

1. A method for using multi-layer identity-based encryption (IBE) to support encryption and decryption using computing equipment in a system, comprising:

encrypting digital information with the computing equipment using at least two layers of IBE encryption by using an inner layer of encryption having an associated inner-layer IBE public key to encrypt the digital information and by using an outer layer of encryption having an associated outer-layer IBE public key to encrypt the inner-layer IBE public key; and

decrypting the encrypted digital information using an outer-layer IBE private key corresponding to the outer-layer IBE public key and using an inner-layer IBE private key corresponding to the inner layer IBE public key.

2. The method defined in claim 1 wherein using the outer layer of encryption to encrypt the inner-layer IBE public key comprises encrypting the inner-layer IBE public key with the outer-layer IBE public key without using a symmetric key.

3. The method defined in claim 1 wherein using the outer layer of encryption to encrypt the inner-layer IBE public key comprises encrypting the inner-layer IBE public key with a symmetric key and encrypting the symmetric key with the outer-layer IBE public key.

4. The method defined in claim 3 wherein decrypting the encrypted digital information further comprises using the outer-layer IBE private key in decrypting the encrypted inner-layer IBE public key to produce an unencrypted version of the inner-layer IBE public key.

5. The method defined in claim 1 wherein encrypting the digital information comprises encrypting the digital information using at least three layers of IBE encryption and wherein the outer layer is not an outermost layer.

6. The method defined in claim 1 wherein encrypting the digital information comprises encrypting the digital information using a symmetric key.

7. The method defined in claim 6 wherein encrypting the digital information comprises encrypting the digital information using the symmetric key and encrypting the symmetric key using the inner-layer IBE public key.

8. The method defined in claim 7 wherein encrypting the digital information further comprises encrypting the inner-layer IBE public key using the outer-layer IBE public key.

9. The method defined in claim 8 wherein decrypting the encrypted digital information comprises:

using the outer-layer IBE private key to decrypt the inner-layer IBE public key that has been encrypted using the outer-layer IBE public key;

using the inner-layer IBE private key to decrypt the symmetric key that has been encrypted using the inner-layer IBE public key; and

using the symmetric key that has been decrypted using the inner-layer IBE private key to decrypt the digital information that was encrypted using the symmetric key.

10. The method defined in claim 1 wherein the outer-layer IBE public key is less sensitive than the inner-layer IBE public key and wherein encrypting the digital information comprises using the outer-layer IBE public key to encrypt the inner-layer IBE public key to conceal the inner-layer IBE public key.

11. The method defined in claim 10 wherein encrypting the digital information comprises encrypting the digital information using at least three layers of IBE encryption and wherein the outer layer is not an outermost layer.

12. The method defined in claim 1 wherein the digital information is provided in an XML data structure containing data attributes, the method further comprising using at least some of the data attributes in forming the inner-layer IBE public key and the outer-layer IBE public key.

13. The method defined in claim 12 wherein at least one of the data attributes has an associated sensitivity level and wherein encrypting the digital information comprises using the sensitivity level in determining how to encrypt the digital information.

14. The method defined in claim 13 further comprising:

obtaining information on the associated sensitivity level in the form of an XML record.

15. The method defined in claim 1 wherein the digital information comprises content having an age-based access policy criteria and wherein encrypting the digital information comprises using the age-based access criteria as at least part of the inner-layer IBE public key.

16. The method defined in claim 1 wherein encrypting the digital information comprises encrypting an email message.

17. The method defined in claim 1 wherein encrypting the digital information comprises encrypting an instant message.

18. The method defined in claim 1 wherein the inner-layer IBE public key and the outer-layer IBE public key have overlapping components and wherein encrypting the digital information comprises performing the inner layer of the encryption using the inner-layer IBE public key that has overlapping components.

19. The method defined in claim 1 wherein encrypting the digital information further comprises using an additional-layer IBE public key to perform an additional layer of IBE encryption on the digital information, wherein the additional-layer IBE public key is less sensitive than the outer-layer IBE public key and is used to encrypt the outer-layer IBE public key.

20. The method defined in claim 19 wherein the inner-layer IBE public key, the outer-layer IBE public key, and the additional-layer IBE public key each have corresponding IBE public key components and wherein each IBE public key component in the additional-layer IBE public key is contained in the outer-layer IBE public key and wherein each IBE public key component in the outer-layer IBE public key is contained in the inner-layer IBE public key.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Dec 17, 2018
From: VOLTAGE SECURITY, INC.
To: VOLTAGE SECURITY, LLC
Reel/Frame 051198/0611 →
MERGER AND CHANGE OF NAME Recorded Dec 17, 2018
From: VOLTAGE SECURITY, LLC; ENTIT SOFTWARE LLC
To: ENTIT SOFTWARE LLC
Reel/Frame 051199/0074 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
RELEASE OF SECURITY INTEREST Recorded Feb 27, 2015
From: VENTURE LENDING & LEASING VI, INC.; VENTURE LENDING & LEASING VII, INC.
To: VOLTAGE SECURITY, INC.
Reel/Frame 035110/0726 →
SECURITY AGREEMENT Recorded Feb 7, 2014
From: VOLTAGE SECURITY, INC.
To: VENTURE LENDING & LEASING VI, INC.; VENTURE LENDING & LEASING VII, INC.
Reel/Frame 032170/0273 →