IP Library Granted Patent US 8,745,379
Granted Patent B2
US 8,745,379 · App. 13/589,894 · Granted Jun 3, 2014

Systems and methods for securing data in motion

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,745,379
App. No.
13/589,894
Granted
Jun 3, 2014
Kind
B2
Abstract

Two approaches are provided for distributing trust among a set of certificate authorities. Each approach may be used to secure data in motion. One approach provides methods and systems in which the secure data parser is used to distribute trust in a set of certificate authorities during initial negotiation (e.g., the key establishment phase) of a connection between two devices. Another approach provides methods and systems in which the secure data parser is used to disperse packets of data into shares. A set of tunnels is established within a communication channel using a set of certificate authorities, keys developed during the establishment of the tunnels are used to encrypt shares of data for each of the tunnels, and the shares of data are transmitted through each of the tunnels. Accordingly, trust is distributed among a set of certificate authorities in the structure of the communication channel itself.

Claims (43)

1. A method for computing at least one shared encryption key, the method comprising:

generating original secret information;

obtaining public keys from unique certificate authorities;

dispersing the secret information into shares;

encrypting each one of the shares based on, at least in part, the public key of a different one of the unique certificate authorities, wherein the shares are restorable from at least a subset of the shares by recombining at least a threshold number of the shares, wherein the threshold number of shares includes fewer than all of the shares;

computing a first shared encryption key based on a set of substantially random numbers and the original secret information;

recombining the at least a threshold number of the shares; and

computing a second shared encryption key based on the set of substantially random numbers and the recombined shares.

2. The method of claim 1 , further comprising

transmitting data based on the recombined shares.

3. The method of claim 1 , further comprising:

comparing the first and second shared encryption key;

determining whether to transmit data based on the comparison; and

transmitting data based on the determination.

4. The method of claim 1 , further comprising encrypting each one of the shares based on a keywrap.

5. The method of claim 4 , wherein the keywrap is based on a workgroup key.

6. The method of claim 1 , further comprising:

generating a certificate authority hierarchy, wherein the certificate authority hierarchy comprises root certificate authorities; and

encrypting each one of the shares based on a certificate issued by a unique root certificate authority of the certificate authority hierarchy.

7. A system for computing at least one shared encryption key, the system comprising:

first processing circuitry configured to:

generate original secret information;

obtain public keys from unique certificate authorities;

disperse the secret information into shares;

compute a first shared encryption key based on a set of substantially random numbers and the original secret information; and

encrypt each one of the shares based on the public key of a different one of the unique certificate authorities, wherein the shares are restorable from at least a subset of the shares by recombining at least a threshold number of the shares, wherein the threshold number of shares includes fewer than all of the shares; and

second processing circuitry configured to:

recombine the at least a threshold of the shares; and

compute a second shared encryption key based on the set of substantially random numbers and the recombined shares.

8. The system of claim 7 , wherein the second processing circuitry is further configured to transmit data based on the recombined shares.

9. The system of claim 7 , wherein the second processing circuitry is further configured to:

compare the first and second shared encryption key;

determine whether to transmit data based on the comparison; and

transmit data based on the determination.

10. The system of claim 7 , wherein the first processing circuitry is further configured to encrypt each one of the shares based on a keywrap.

11. The system of claim 10 , wherein the keywrap is based on a workgroup key.

12. The system of claim 7 , wherein the first processing circuitry is further configured to:

generate a certificate authority hierarchy, wherein the certificate authority hierarchy comprises root certificate authorities; and

encrypt each one of the shares based on a certificate issued by a unique root certificate authority of the certificate authority hierarchy.

13. The system of claim 7 , wherein the first processing circuitry is further configured to:

generate a certificate authority hierarchy, wherein the certificate authority hierarchy comprises a set of minor certificate authorities; and

encrypt each one of the shares based on a certificate issued by a unique minor certificate authority of the certificate authority hierarchy.

14. The system of claim 7 , wherein the first processing circuitry is located in a first device, and wherein the second processing circuitry is located in a second device, the second device being different than the first device.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1 C/O FAMILY OFFICE SOLUTIONS; O'REILLY, COLIN; COOPER ROAD LLC.; COYDOG FOUNDATION C/O FAMILY OFFICE SOLUTIONS; DASA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; LAKOFF, DAVID E.; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C.; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JOR, GERALD R, JR.; GRANDPRIX LIMITED C/O LOEB BLOCK & PARTNERS L.P.; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC.; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M.; MERCER, ROBERT; ROLA INVESTMENTS LLC C/O FAMILY OFFICE SOLUTIONS; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC.; BARTON, WESLEY W.; ZUG VENTURES LLC C/O KATHY COOK, FUSION GROUP; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
To: SECURITY FIRST CORP.
Reel/Frame 061578/0505 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: SECURITY FIRST CORP
To: SECURITY FIRST INNOVATIONS, LLC
Reel/Frame 061262/0865 →
PATENT SECURITY AGREEMENT Recorded Jun 24, 2016
From: SECURITY FIRST CORP.
To: GYENES, ANDY; AUBER INVESTMENTS LTD.; SIMONS, BARBARA; BLT1; O'REILLY, COLIN; COOPER ROAD LLC; COYDOG FOUNDATION; DASA INVESTMENTS LLC; LAKOFF, DAVID E; LEES, DAVID; O'REILLY, DAVID; OKST, DAVID; KEHLER, DEAN C; KOBAK, DOROTHY; CRAWFORD, ELIZABETH; ALTMANN, ERIC; JORDAN, GERALD R, JR; GRANDPRIX LIMITED; RAUTENBERG, H.W.; HARPEL, JAMES W.; WU, JASPER; PEISACH, JAIME; LG MANAGEMENT LLC; LTE PARTNERS; RAUTENBERG, MARK; PINTO, MAURICE; MEYTHALER INVESTMENT PARTNERS LLC; MASELLI, MICHAEL; GYENES, PETER; GINTHER, RAYMOND; BERKELEY, RICHARD M; MERCER, ROBERT; ROLA INVESTMENTS LLC; SOS & CO.; BARLE, STANKO; STRAUS, SANDOR; MIROCHNIKOFF, SYLVAIN; MERCER, REBEKAH; TOPSPIN SFC HOLDINGS LLC; BARTON, WESLEY W; ZUG VENTURES LLC; ZUCKER, CHARLES; COLEMAN, ROGER T.; COLEMAN, MARGARET E.; COLEMAN, THERESA M.; COLEMAN, JOHN T.; PERLBINDER, STEPHEN
Reel/Frame 039153/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2012
From: ORSINI, RICK L.; O'HARE, MARK S.; BONO, STEPHEN C.; LANDAU, GABRIEL D.; NIELSON, SETH JAMES
To: SECURITY FIRST CORP.
Reel/Frame 028817/0768 →