IP Library Granted Patent US 8,494,969
Granted Patent B2
US 8,494,969 · App. 12/542,468 · Granted Jul 23, 2013

Cryptographic server with provisions for interoperability between cryptographic systems

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,494,969
App. No.
12/542,468
Granted
Jul 23, 2013
Kind
B2
Abstract

The invention is a cryptographic server providing interoperability over multiple algorithms, keys, standards, certificate types and issuers, protocols, and the like. Another aspect of the invention is to provide a secure server, or trust engine, having server-centric keys, or in other words, storing cryptographic keys on a server. The server-centric storage of keys provides for user-independent security, portability, availability, and straightforwardness, along with a wide variety of implementation possibilities.

Claims (32)

1. A method of managing a cryptographic system to avoid continual reissue of keys due to theft, damage, or loss, the method comprising:

generating a cryptographic key pair within a secure server without releasing at least one key of the cryptographic key pair to any individual;

storing the at least one key within the secure server; and

providing server-side cryptographic functionality to a user without releasing the at least one key to any individual including the user,

wherein the at least one key is generated, stored, and utilized to provide the server-side cryptographic functionality without releasing the at least one key to any individual.

2. The method of claim 1 , wherein the at least one key of the cryptographic key pair comprises a private key and the other key of the cryptographic key pair comprises a public key.

3. The method of claim 2 , further comprising:

reusing the public key to request a plurality of digital certificates for the user, wherein at least some of the digital certificates correspond to differing digital certificate protocols or standards.

4. The method of claim 2 , further comprising:

reusing the private key to perform a plurality of digital signatures of the user without releasing the private key to the user, wherein at least some of the digital signatures correspond to differing digital signature protocols or standards.

5. The method of claim 1 , wherein the server-side cryptographic functionality includes encryption of at least one symmetric key, thereby reducing the mathematical computations performed by a computing device used by the user to access the secured server.

6. The method of claim 1 , wherein the user is of a remote computing device.

7. The method of claim 1 , wherein providing server-side cryptographic functionality to the user without releasing the at least one key to the user comprises performing one or more cryptographic functions corresponding to a request using the one or more keys.

8. The method of claim 7 , wherein the one or more keys are generated within a trust engine and not released form the trust engine.

9. The method of claim 7 , wherein the request is from an application executing on a remote computing device.

10. The method of claim 9 , further comprising transmitting a response to the application.

11. Storage media comprising executable instructions, the instructions being executable by a processor for performing a method managing a cryptographic system to avoid continual reissue of keys due to theft, damage, or loss, the method comprising:

generating a cryptographic key pair within a secure server without releasing at least one key of the cryptographic key pair to any individual;

storing the at least one key within the secure server; and

providing server-side cryptographic functionality to the user without releasing the at least one key to any individual including the user,

wherein the at least one key is generated, stored, and utilized to provide the server-side cryptographic functionality without releasing the at least one key to any individual.

12. The storage media of claim 11 , wherein the at least one key of the cryptographic key pair comprises a private key and the other key of the cryptographic key pair comprises a public key.

13. The storage media of claim 12 , wherein the method further comprises:

reusing the public key to request a plurality of digital certificates for the user, wherein at least some of the digital certificates correspond to differing digital certificate protocols or standards.

14. The storage media of claim 12 , wherein the method further comprises:

reusing the private key to perform a plurality of digital signatures of the user without releasing the private key to the user, wherein at least some of the digital signatures correspond to differing digital signature protocols or standards.

15. The storage media of claim 11 , wherein the server-side cryptographic functionality includes encryption of at least one symmetric key, thereby reducing the mathematical computations performed by a computing device used by the user to access the secured server.

16. The storage media of claim 11 , wherein the user is of a remote computing device.

17. The storage media of claim 11 , wherein providing server-side cryptographic functionality to the user without releasing the at least one key to the user comprises performing one or more cryptographic functions corresponding to a request using the one or more keys.

18. The storage media of claim 17 , wherein the one or more keys are generated within a trust engine and not released form the trust engine.

19. The storage media of claim 17 , wherein the request is from an application executing on a remote computing device.

20. The storage media of claim 19 , wherein the method further comprises transmitting a response to the application.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1 C/O FAMILY OFFICE SOLUTIONS; O'REILLY, COLIN; COOPER ROAD LLC.; COYDOG FOUNDATION C/O FAMILY OFFICE SOLUTIONS; DASA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; LAKOFF, DAVID E.; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C.; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JOR, GERALD R, JR.; GRANDPRIX LIMITED C/O LOEB BLOCK & PARTNERS L.P.; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC.; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M.; MERCER, ROBERT; ROLA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC.; BARTON, WESLEY W.; ZUG VENTURES LLC C/O KATHY COOK, FUSION GROUP; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
To: SECURITY FIRST CORP.
Reel/Frame 061578/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: SECURITY FIRST CORP
To: SECURITY FIRST INNOVATIONS, LLC
Reel/Frame 061262/0865 →
PATENT SECURITY AGREEMENT Recorded Jun 24, 2016
From: SECURITY FIRST CORP.
To: O'REILLY, COLIN; COOPER ROAD LLC; GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1; COYDOG FOUNDATION; DASA INVESTMENTS LLC; LAKOFF, DAVID E; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JORDAN, GERALD R, JR; GRANDPRIX LIMITED; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M; MERCER, ROBERT; ROLA INVESTMENTS LLC; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC; BARTON, WESLEY W; ZUG VENTURES LLC; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
Reel/Frame 039153/0321 →