IP Library Granted Patent US 8,904,181
Granted Patent B1
US 8,904,181 · App. 13/682,040 · Granted Dec 2, 2014

System and method for secure three-party communications

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,904,181
App. No.
13/682,040
Granted
Dec 2, 2014
Kind
B1
Abstract

A system and method for communicating information between a first party and a second party, comprising the steps of receiving, by an intermediary, an identifier of desired information and accounting information for a transaction involving the information from the first party, transmitting an identifier of the first party to the second party, and negotiating, by the intermediary, a comprehension function for obscuring at least a portion of the information communicated between the first party and the second party. The data transmission may be made secure with respect to the intermediary by providing an asymmetric key or direct key exchange for encryption of the communication between the first and second party. The data transmission may be made secure with respect to the second party by maintaining the information in encrypted format at the second party, with the decryption key held only by the intermediary, and transmitting a secure composite of the decryption key and a new encryption key to the second party for transcoding of the data record, and providing the new decryption key to the first party, so that the information transmitted to the first party can be comprehended by it.

Claims (34)

1. A key handler, comprising:

an interface to a memory which stores a plurality of encrypted records, each encrypted record having an associated asymmetric encryption key pair and being encrypted with a first component of the associated asymmetric encryption key pair;

at least one automated processor operating in a privileged processing environment, configured to receive a selected encrypted record from the memory through the interface, to negotiate at least one asymmetric session key, and to transcrypt the encrypted message to a transcrypted message in an integral process substantially without intermediate decryption, using a transcryption key derived at least in part from the at least one asymmetric session key; and

a communication port configured to conduct the negotiation for the at least one asymmetric session key and to communicate the transcrypted record.

2. The key handler according to claim 1 , wherein the transcryption key has as components at least: a second asymmetric component of the associated asymmetric key pair, and the at least one asymmetric session key, to result in a transcrypted message encrypted with at least one asymmetric session key.

3. The key handler according to claim 1 , wherein the at least one asymmetric session key comprises at least two asymmetric session keys negotiated with at least two respectively different parties, at least one of the at least two respectively different parties being a non-recipient of the transcrypted record.

4. The key handler according to claim 3 , wherein the transcryption key has as components at least: a second component of the associated asymmetric encryption key pair, the at least one asymmetric session key, and a received asymmetric key component, to result in a transcrypted message encrypted with at least one asymmetric session key and the received asymmetric key component.

5. The key handler according to claim 1 , wherein the at least one automated processor is configured to compute: C1=C2 d1·e1·d2 mod n, wherein d1 and d2 are respectively private asymmetric keys maintained by the key handler and e1 is a public asymmetric key received by the key handler, and n is a common modulus for each of the asymmetric keys.

6. The key handler according to claim 1 , configured to communicate with the memory through a virtual private network.

7. The key handler according to claim 1 , wherein the at least one asymmetric session key comprises a first session key pair generated internally by the key handler and a second session key pair generated through an external key exchange negotiation.

8. The key handler according to claim 1 , wherein the associated asymmetric key pair comprises a Diffie-Hellman type key.

9. The key handler according to claim 1 , wherein the associated asymmetric key pair comprises a Rivest-Shamir-Adler type key.

10. The key handler according to claim 1 , wherein the associated asymmetric key pair comprises at least one of an elliptic curve key pair and an ElGamal key pair.

11. A method, comprising:

storing a plurality of encrypted records, each encrypted record having an associated asymmetric encryption key pair and being encrypted with a first component of the associated asymmetric encryption key pair, in a database;

receiving an encrypted record by an automated key handler operating in a privileged processing environment, through an interface;

negotiating, by the automated key handler, at least one asymmetric session key;

transcrypting, by the automated key handler, the encrypted message to a transcrypted message in an integral process substantially without intermediate decryption, using a transcryption key; and

communicating the transcrypted record.

12. The method according to claim 11 , wherein the transcryption key has as components at least: a second component of the associated asymmetric key pair, and the at least one asymmetric session key, to result in a transcrypted message encrypted with at least one asymmetric session key.

13. The method according to claim 11 , wherein the at least one asymmetric session key comprises at least two asymmetric session keys negotiated with at least two respectively different parties, at least one of the at least two respectively different parties being a non-recipient of the transcrypted record.

14. The method according to claim 13 , wherein the transcryption key has as components at least: the second component of the associated asymmetric key pair, the at least one asymmetric session key, and a received asymmetric key component, to result in a transcrypted message encrypted with at least one asymmetric session key and the received asymmetric key component.

15. The method according to claim 11 , further comprising communicating between the automated key handler and the database through a virtual private network.

16. The method according to claim 11 , wherein the at least one asymmetric session key comprises a first session key pair generated internally by the automated key handler and a second session key pair generated through key exchange negotiation.

17. The method according to claim 11 , wherein the associated asymmetric key pair comprises at least one of a Diffie-Hellman type key, a Rivest-Shamir-Adler type key, an elliptic curve key, and an ElGamal key.

18. A method, comprising:

storing a plurality of encrypted records, each encrypted record having an associated asymmetric encryption key pair and being encrypted with a first component of the associated asymmetric encryption key pair, in a memory;

receiving an encrypted record by an automated key handler operating in a privileged processing environment;

generating at least one asymmetric transcryption key pair by the automated key handler;

negotiating, by the automated key handler, at least one asymmetric session key pair, with an external system, through a communication port;

transcrypting, by the automated key handler, the encrypted message to a transcrypted message in an integral process substantially without intermediate decryption, using a transcryption key having as components at least: a component of the at least one asymmetric transcryption key pair and a component of the at least one asymmetric session key pair, to result in a transcrypted message which is decryptable with at least a corresponding component of the at least one asymmetric transcryption key pair and a corresponding component of the at least one asymmetric session key pair; and

communicating the transcrypted record through the communication port.

19. The method according to claim 18 , further comprising communicating the corresponding component of the at least one asymmetric transcryption key pair to the recipient in a communication separate from the transcrypted record, wherein the separate communication is associated with at least one of an authentication of the recipient, an auditing of the communication, and an accounting of the communication.

20. The method according to claim 19 , further comprising conducting a payment transaction in consideration of the communication, wherein the separate communication occurs subsequent to the payment transaction.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Oct 26, 2020
From: JEFFERIES FINANCE LLC
To: RPX CORPORATION
Reel/Frame 054486/0422 →
PATENT SECURITY AGREEMENT Recorded Oct 23, 2020
From: RPX CLEARINGHOUSE LLC; RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 054198/0029 →
PATENT SECURITY AGREEMENT Recorded Oct 23, 2020
From: RPX CLEARINGHOUSE LLC; RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 054244/0566 →
SECURITY INTEREST Recorded Jun 29, 2018
From: RPX CORPORATION
To: JEFFERIES FINANCE LLC
Reel/Frame 046486/0433 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 5, 2017
From: ST. LUKE TECHNOLOGIES, LLC
To: RPX CORPORATION
Reel/Frame 042601/0251 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2015
From: FELSHER, DAVID P
To: ST. LUKE TECHNOLOGIES, LLC
Reel/Frame 036418/0949 →