IP Library Granted Patent US 8,144,866
Granted Patent B2
US 8,144,866 · App. 12/693,177 · Granted Mar 27, 2012

Method and system for securing data utilizing redundant secure key storage

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,144,866
App. No.
12/693,177
Granted
Mar 27, 2012
Kind
B2
Abstract

A system and method which protects a data processing system against encryption key errors by providing redundant encryption keys stored in different locations, and providing the software with the ability to select an alternate redundant key if there is any possibility that the encryption key being used may be corrupted. In the preferred embodiment, a memory control module in the data processing device is configured to accommodate the storage of multiple (for example up to four or more) independent password/key pairs, and the control module duplicates a password key at the time of creation. The redundant passwords and encryption keys are forced into different memory slots for later retrieval if necessary. The probability of redundant keys being corrupted simultaneously is infinitesimal, so the system and method of the invention ensures that there is always an uncorrupted encryption key available.

Claims (26)

1. A data processing device, comprising:

an encryption device for encrypting and decrypting data using an encryption key;

a key generating device adapted to generate a first encryption key associated with a first password using the first password, a first key seed, and a current key, and to generate a second encryption key associated with a second password, wherein the first encryption key is used to encrypt or decrypt a first set of data, and wherein the second encryption key is used to encrypt or decrypt a second set of data; and

at least one memory adapted to store the first set of data and the second set of data.

2. The data processing device of claim 1 , wherein the key generating device is further adapted to generate at least one redundant encryption key corresponding to the first encryption key by generating said at least one redundant encryption key from the first password, the first key seed, and the current key, and wherein one of the at least one redundant encryption key is used to encrypt or decrypt the first set of data upon occurrence of a particular event.

3. The data processing device of claim 2 , wherein the particular event is selected from one of:

a determination that the first encryption key may be corrupted;

detection of a faulty data signature; or

detection of a faulty javascript execution.

4. The data processing device of claim 1 , wherein the key generating device is adapted to generate the second encryption key from the second password, a second key seed, and a current key.

5. The data processing device of claim 1 , further comprising an EEPROM memory adapted to store the first encryption key and the second encryption key.

6. The data processing device of claim 5 , wherein the key generating device is comprised in an EEPROM control block in communication with the EEPROM memory.

7. The data processing device of claim 1 , wherein each of the first and second encryption keys is associated with a different type of data.

8. The data processing device of claim 1 , wherein the first set of data comprises one of private system data, data associated with a software application, email data, or appointment data, and the second set of data comprises a different one of private system data, data associated with a software application, email data, or appointment data.

9. The data processing device of claim 1 , wherein the data processing device is comprised in a mobile communication device.

10. A data processing device, comprising:

means adapted to encrypt and decrypt data using an encryption key;

means adapted to generate a first encryption key for a first set of data, the first encryption key being associated with a first password and being generated from the first password, a first key seed, and a current key, and to generate a second encryption key for a second set of data, the second encryption key being associated with a second password and being generated from the second password, a second key seed, and the current key; and

means adapted to store the first encryption key and the associated first password, the second encryption key and the second associated password, the first set of data, and the second set of data.

11. The data processing device of claim 10 , further comprising means adapted to generate at least one redundant encryption key corresponding to the first encryption key by generating said at least one redundant encryption key from the first password, the first key seed, and the current key, wherein one of the at least one redundant encryption key is used to encrypt or decrypt the first set of data upon occurrence of a particular event.

12. The data processing device of claim 11 , wherein the particular event is selected from one of:

a determination that the first encryption key may be corrupted;

detection of a faulty data signature; or

detection of a faulty javascript execution.

13. The data processing device of claim 10 , wherein each of the first and second encryption keys is associated with a different type of data.

14. The data processing device of claim 10 , wherein the first set of data comprises one of private system data, data associated with a software application, email data, or appointment data, and the second set of data comprises a different one of private system data, data associated with a software application, email data, or appointment data.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064269/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded Nov 4, 2014
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 034161/0056 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2010
From: RANDELL, JERROLD R.
To: RESEARCH IN MOTION LIMITED
Reel/Frame 023842/0577 →