IP Library Granted Patent US 8,751,809
Granted Patent B2
US 8,751,809 · App. 13/513,047 · Granted Jun 10, 2014

Method and device for securely sharing images across untrusted channels

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,751,809
App. No.
13/513,047
Granted
Jun 10, 2014
Kind
B2
Abstract

A method and device for securely sharing images across untrusted channels includes downloading an encrypted image from a remote server to a computing device. The encrypted image may be encrypted at the time of uploading by another user. The current user of the computing device is authenticated using a facial recognition procedure. If the current user is authenticated and is determined to be authorized to view the decrypted image, the encrypted image is decrypted and displayed to the user. If the user becomes unauthenticated (e.g., the user leaves the computing device or another user replaces the current user), the encrypted image is displayed in place of the decrypted image such that the decrypted image is displayed only for authorized persons physically present at the computing device.

Claims (46)

1. A method comprising:

downloading an encrypted image and an image of an authorized user to a computing device, the encrypted image including additional information useable to identify the authorized user;

receiving an image of a current user of the computing device from a camera communicatively coupled to the computing device;

authenticating the current user by performing a facial recognition procedure on the image of the current user using the image of the authorized user to verify that the current user is the authorized user;

determining whether the authenticated current user is authorized to view a decrypted image of the encrypted image based on the additional information included with the encrypted image;

in response to the authenticated current user being authorized to view the decrypted image, (i) decrypting the encrypted image and (ii) displaying the decrypted image on the computing device;

in response to the authenticated current user not being authorized to view the decrypted image, displaying the encrypted image on the computing device; and

continually authenticating the user while the decrypted image is displayed on the computing device.

2. The method of claim 1 , wherein downloading an encrypted image comprises downloading a webpage including the encrypted image from the remote server using a web browser of the computing device.

3. The method of claim 1 , wherein downloading an encrypted image comprises downloading an encrypted image including an encrypted key, and

wherein determining whether the authenticated current user is authorized to view the decrypted image comprises determining whether a private key associated with the authenticated current user can decrypt the encrypted key.

4. The method of claim 3 , wherein decrypting the encrypted image comprises (i) decrypting the encrypted key and (ii) decrypting the encrypted image using the decrypted key.

5. The method of claim 3 , wherein the encrypted key is encrypted using a public key generated as a function of an image of the authenticated current user.

6. The method of claim 1 , wherein receiving an image of the current user comprises receiving an image generated by the camera in real-time.

7. The method of claim 1 , wherein authenticating the current user comprises performing a facial recognition procedure on the image of the current user using a processor graphics circuitry of the computing device.

8. The method of claim 1 , wherein determining whether the authenticated current user is authorized to view a decrypted image comprises retrieving a private key of the current user and determining whether the private key can decrypt an encrypted symmetric key that is usable to decrypt the encrypted image.

9. The method of claim 1 , wherein decrypting the encrypted image comprises decrypting the encrypted image using a symmetric key that was previously decrypted using a private key of the current user.

10. The method of claim 1 , wherein displaying the decrypted image comprises displaying the decrypted image only while the current user is authenticated using the facial recognition procedure.

11. The method of claim 1 , further comprising displaying the encrypted image in place of the decrypted image in response to the current user no longer being authenticated.

12. A computing device comprising:

a processor graphics circuitry;

a processor; and

a memory having stored therein a plurality of instructions that, in response to being executed by the processor, causes the processor to:

download a webpage including an encrypted image and an image of an authorized user that is authorized to view the decrypted image, the encrypted image including additional information useable to identify the authorized user;

authenticate a current user of the computing device by performing a facial recognition procedure on a real-time image of the current user;

determine whether the authenticated current user is authorized to view a decrypted image of the encrypted image based on the additional information included with the encrypted image;

in response to the authenticated current user being authorized to view the decrypted image, (i) decrypt the encrypted image and (ii) display the decrypted image on the computing device;

in response to the authenticated current user not being authorized to view the decrypted image, display the encrypted image on the computing device; and

continually authenticate the user while the decrypted image is displayed on the computing device;

wherein the processor graphics circuitry is to perform the facial recognition procedure on the real-time image of the current user to verify that the current user is the authorized user.

13. The computing device of claim 12 , wherein the processor graphics circuitry is located on a common die with the central processing unit.

14. The computing device of 12 , wherein the processor graphics circuitry is located on a peripheral graphics card of the computing device.

15. The computing device of claim 12 , wherein:

the encrypted image comprises an encrypted symmetric key, and

to determine whether the current user is authorized to view the decrypted image comprises to determine whether a private key of the current user can decrypt the encrypted symmetric key.

16. The computing device of claim 15 , wherein to decrypt the encrypted image comprises to decrypt the encrypted image using the decrypted symmetric key.

17. The computing device of claim 15 , wherein the encrypted symmetric key is encrypted using a public key generated as a function of a previously-generated image of the current user.

18. The computing device of claim 12 , wherein to display the decrypted image comprises to display the decrypted image only while the current user is authenticated by the computing device.

19. One or more non-transitory, computer readable media comprising a plurality of instructions that, in response to being execute, cause a computing device to:

download an encrypted image and an image of an authorized user, the encrypted image including additional information useable to identify the authorized user;

receive an image of a current user of the computing device from a camera communicatively coupled to the computing device;

authenticate the current user by performing a facial recognition procedure on the image of the current user using the image of the authorized user to verify that the current user is the authorized user;

determine whether the authenticated current user is authorized to view a decrypted image of the encrypted image based on the additional information included with the encrypted image;

in response to the authenticated current user being authorized to view the decrypted image, (i) decrypting the encrypted image and (ii) displaying the decrypted image on the computing device;

in response to the authenticated current user not being authorized to view the decrypted image, displaying the encrypted image on the computing device; and

continually authenticate the user while the decrypted image is displayed on the computing device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2022
From: INTEL CORPORATION
To: TAHOE RESEARCH, LTD.
Reel/Frame 061175/0176 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2012
From: DEWAN, PRASHANT; KANG, XIAOZHU; GREWAL, KARANVIR S.; DURHAM, DAVID
To: INTEL CORPORATION
Reel/Frame 028542/0238 →