IP Library Granted Patent US 9,621,344
Granted Patent B2
US 9,621,344 · App. 13/081,704 · Granted Apr 11, 2017

Method and system for recovering a security credential

Inventor: Salah Machani (Thornhill, CA)
Assignee: IMS HEALTH INC.
H04L9/0897G06F2221/2131H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,621,344
App. No.
13/081,704
Granted
Apr 11, 2017
Kind
B2
Abstract

A system and method for recovering a security credential is provided. A security credential stored in the storage of a computing device is encrypted using a first encryption key generated by a server. A first decryption key for decrypting the security credential and a second encryption key for re-encrypting the security credential are received. The first decryption key and the second encryption key are generated by the server. The security credential is decrypted using the first decryption key. The security credential is communicated to a user of the computing device. The security credential is re-encrypted in the storage of the computing device using the second encryption key.

Claims (48)

1. A method for recovering a security credential, comprising:

encrypting, by a computing device, a security credential stored in storage of the computing device using a first encryption key generated by a server, wherein the security credential is not transmitted between the computing device and said server;

controlling access to sensitive data on said computing device by requiring entry of said security credential;

receiving, by the computing device, a request to recover a forgotten security credential;

generating a request to the server for a first decryption key and a second encryption key in order to recover the forgotten security credential;

receiving by said computing device the first decryption key for decrypting said security credential, and the second encryption key for re-encrypting said security credential, said first decryption key and said second encryption key being generated by said server;

decrypting said security credential using said first decryption key;

communicating said security credential to a user of said computing device; and

re-encrypting said security credential in said storage of said computing device using said second encryption key.

2. The method of claim 1 , wherein said security credential is a password.

3. The method of claim 1 , further comprising: requiring a user of said computing device to change said security credential after said communicating; and modifying said access to said sensitive data by requiring entry of said changed security credential, and wherein said changed security credential is encrypted during said re-encrypting.

4. The method of claim 1 , wherein said security credential is used to encrypt said sensitive data.

5. The method of claim 1 , wherein said first encryption key and said first decryption key are asymmetric keys.

6. The method of claim 1 , wherein said second encryption key differs from said first encryption key.

7. The method of claim 1 , wherein said first decryption key and said second encryption key are communicated to said user, and said receiving comprises receiving said first decryption key and said second encryption key via user entry.

8. The method of claim 1 , wherein said encrypting and decrypting are performed by said computing device, and wherein said receiving comprises automatically receiving, by said computing device, said first decryption key and said second encryption key from said server.

9. A system for recovering a security credential, comprising:

a computing device;

an application executing on a processor of said computing device and providing access, upon entry of a security credential, to one of sensitive information stored in memory of said computing device and sensitive functionality; and

a server configured to:

generate a first encryption key; and

transmit said first encryption key to said computing device;

wherein the computing device is configured to:

encrypt said security credential using said first encryption key received from said server, wherein the security credential is not transmitted between the computing device and the server;

store, in said memory, said encrypted security credential;

receive a request to recover a forgotten security credential;

generate a request to the server for a first decryption key and a second encryption key in order to recover the forgotten security credential;

receive the first decryption key and the second encryption key from said server;

decrypt said security credential using the first decryption key;

communicate said security credential to a user of said computing device; and

re-encrypt said security credential stored in said memory of said computing device using said second encryption key.

10. The system of claim 9 , wherein said application controls access to sensitive data on said computing device by requiring provision of said security credential.

11. The system of claim 10 , wherein said security credential is a password.

12. The system of claim 10 , wherein said computing device requires that a user of said computing device change said security credential before encrypting said security credential using said second encryption key.

13. The system of claim 10 , wherein said computing device encrypts said sensitive data using said security credential.

14. The system of claim 10 , wherein said first encryption key and said first decryption key are asymmetric keys.

15. The system of claim 10 , wherein said second encryption key differs from said first encryption key.

16. The system of claim 10 , wherein said computing device receives said first decryption key and said second encryption key from said user.

17. The system of claim 10 , wherein said computing device receives said first decryption key and said second encryption key from said server and automatically decrypts said security credential.

18. A method for recovering a security credential, comprising:

encrypting, by a computing device, a security credential stored in storage of the computing device using a first encryption key generated by a server, wherein the security credential is not transmitted between the computing device and said server;

controlling access to sensitive data on said computing device by requiring entry of said security credential;

receiving, by the computing device, a request to recover a forgotten security credential;

generating a request to the server for a first password and a second password in order to recover the forgotten security credential;

receiving the first password for deriving a first decryption key for decrypting said security credential, and the second password for deriving a second encryption key for re-encrypting said security credential;

decrypting said security credential using said first decryption key;

communicating said security credential to a user of said computing device; and

re-encrypting said security credential in said storage of said computing device using said second encryption key.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Jun 15, 2026
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: IMS SOFTWARE SERVICES LTD.; IQVIA INC.; IQVIA RDS INC.; RULES-BASED MEDICINE, INC.
Reel/Frame 075844/0867 →
SECURITY INTEREST Recorded Mar 12, 2026
From: IMS SOFTWARE SERVICES LTD.; IQVIA INC.; IQVIA RDS INC.; RULES-BASED MEDICINE, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 075047/0061 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTIES INADVERTENTLY NOT INCLUDED IN FILING PREVIOUSLY RECORDED AT REEL: 065709 FRAME: 618. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT. Recorded Dec 6, 2023
From: IQVIA INC.; IQVIA RDS INC.; IMS SOFTWARE SERVICES LTD.; Q SQUARED SOLUTIONS HOLDINGS LLC
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 065790/0781 →
SECURITY INTEREST Recorded Nov 29, 2023
From: IQVIA INC.; IQVIA RDS INC.; IMS SOFTWARE SERVICES LTD.; Q SQUARED SOLUTIONS HOLDINGS LLC
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 065710/0253 →
SECURITY INTEREST Recorded Nov 29, 2023
From: IQVIA INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 065709/0618 →
SECURITY INTEREST Recorded May 24, 2023
From: IQVIA INC.; IQVIA RDS INC.; IMS SOFTWARE SERVICES LTD.; Q SQUARED SOLUTIONS HOLDINGS LLC
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 063745/0279 →
CHANGE OF NAME Recorded Oct 9, 2018
From: QUINTILES IMS INCORPORATED
To: IQVIA INC.
Reel/Frame 047207/0276 →
CHANGE OF NAME Recorded Sep 7, 2018
From: IMS HEALTH INCORPORATED
To: QUINTILES IMS INCORPORATED
Reel/Frame 047029/0637 →
SECURITY AGREEMENT Recorded Nov 6, 2013
From: IMS HEALTH INCORPORATED
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031592/0179 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2013
From: DIVERSINET CORP.
To: IMS HEALTH INC.
Reel/Frame 031268/0020 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2011
From: MACHANI, SALAH
To: DIVERSINET CORP.
Reel/Frame 026090/0521 →
Priority Claims (1)
CA 2701061 · Apr 19, 2010 · national
Continuity (1)
Related Publication 20110302406A1 · Dec 8, 2011