IP Library Granted Patent US 8,756,706
Granted Patent B2
US 8,756,706 · App. 12/902,638 · Granted Jun 17, 2014

Method for securing credentials in a remote repository

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,756,706
App. No.
12/902,638
Granted
Jun 17, 2014
Kind
B2
Abstract

A method of securing user credentials in a remote repository is provided. In accordance with one embodiment, there is provided a method comprising generating a first private key and a first public key pair from a registered password; generating a second private key and a second public key pair; generating a storage key from the second private key and the first public key; encrypting a set of credentials using the storage key; creating a encrypted credential signature from the encrypted set of credentials and the first private key; and storing the encrypted set of credentials, the encrypted credential signature, and the second public key in the remote repository.

Claims (53)

1. A method of securing user credentials in a remote repository by a communication device, the method comprising:

generating, from a password, using an elliptic curve cryptography scheme, a first private key and a first public key pair;

generating a second private key and a second public key pair;

generating a storage key from the second private key and the first public key;

encrypting a set of credentials using the storage key;

creating an encrypted credential signature from the encrypted set of credentials and the first private key; and

sending the encrypted set of credentials, the encrypted credential signature, and the second public key to the remote repository,

wherein the set of credentials include one or both of a user identification (user ID) or a credential password.

2. The method of claim 1 wherein generating the second private key and the second public key pair utilizes the elliptic curve cryptography scheme.

3. The method of claim 1 wherein generating the storage key from the second private key and the first public key utilizes an elliptic curve Diffie-Hellman scheme.

4. The method of claim 1 wherein creating an encrypted credential signature from the encrypted set of credentials and the first private key utilizes an elliptic curve digital signature algorithm.

5. The method of claim 1 wherein the first private key and first public key pair are a static key pair, and the second private key and second public key pair are an ephemeral key pair.

6. A communication device for securing user credentials in a remote repository, the communication device comprising:

a processor;

memory; and

an encryption module which, when executed by the processor, configures the processor to

generate, from a password, using an elliptic curve cryptography scheme, a first private key and a first public key pair;

generate a second private key and a second public key pair;

generate a storage key from the second private key and the first public key;

encrypt a set of credentials using the storage key;

create an encrypted credential signature from the encrypted set of credentials and the first private key; and

send the encrypted set of credentials, the encrypted credential signature, and the second public key to the remote repository,

wherein the set of credentials include one or both of a user identification (user ID) or a credential password.

7. A communication device for accessing secured user credentials in a remote repository, the communication device comprising:

a processor;

memory; and

a remote credential management module which, when executed by the processor, configures the processor to

receive an encrypted set of credentials, an encrypted credential signature, and a second public key from the remote repository,

wherein the set of credentials include one or both of a user identification (user ID) or a credential password;

generate a first private key from a password using an elliptic curve cryptography scheme;

verify the encrypted credential signature from the encrypted set of credentials and the first private key;

generate a storage key from the first private key and the second public key;

decrypt the encrypted set of credentials using the storage key; and

populate the device with the unencrypted set of credentials.

8. The communication device of claim 6 wherein generating the second private key and the second public key pair utilizes the elliptic curve cryptography scheme.

9. The communication device of claim 6 wherein generating the storage key from the second private key and the first public key utilizes an elliptic curve Diffie-Hellman scheme.

10. The communication device of claim 6 wherein creating an encrypted credential signature from the encrypted set of credentials and the first private key utilizes an elliptic curve digital signature algorithm.

11. The communication device of claim 6 wherein the first private key and first public key pair are a static key pair, and the second private key and second public key pair are an ephemeral key pair.

12. The communication device of claim 7 wherein generating the second private key and the second public key pair utilizes the elliptic curve cryptography scheme.

13. The communication device of claim 7 wherein generating the storage key from the second private key and the first public key utilizes an elliptic curve Diffie-Hellman scheme.

14. The communication device of claim 7 wherein creating an encrypted credential signature from the encrypted set of credentials and the first private key utilizes an elliptic curve digital signature algorithm.

15. The communication device of claim 7 wherein the first private key and first public key pair are a static key pair, and the second private key and second public key pair are an ephemeral key pair.

16. A server for securing user credentials in a remote repository, the server comprising:

a processor;

memory; and

an encryption module which, when executed by the processor, configures the processor to

generate, from a password, using an elliptic curve cryptography scheme, a first private key and a first public key pair;

generate a second private key and a second public key pair;

generate a storage key from the second private key and the first public key;

encrypt a set of credentials using the storage key;

create an encrypted credential signature from the encrypted set of credentials and the first private key; and

send the encrypted set of credentials, the encrypted credential signature, and the second public key to the remote repository,

wherein the set of credentials include one or both of a user identification (user ID) or a credential password.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
CHANGE OF NAME Recorded Feb 3, 2014
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 032153/0085 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2012
From: CERTICOM (U.S.) LIMITED
To: CERTICOM CORP.
Reel/Frame 028099/0039 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2010
From: CAMPAGNA, MATTHEW JOHN
To: CERTICOM (U.S.) LIMITED
Reel/Frame 025125/0765 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2010
From: CHIDAMBARAM, AVINASH
To: RESEARCH IN MOTION LIMITED
Reel/Frame 025125/0676 →