IP Library Granted Patent US 9,369,276
Granted Patent B2
US 9,369,276 · App. 14/209,167 · Granted Jun 14, 2016

Digital signature authentication without a certification authority

Inventors: Carlisle Adams (Nepean, CA); Guy-Vincent Jourdan (Ottawa, CA)
Assignee: Signority Inc.
H04L9/0844
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,369,276
App. No.
14/209,167
Granted
Jun 14, 2016
Kind
B2
Abstract

Systems and methods for managing private and public encryption keys without the need for a third party certification authority. An initial value is generated by an authentication server. The initial value is divided into at least two portions and each portion is communicated with a user using different communication channels. The user receives the portions and enters a secret string value (i.e. a secret sentence) known only to the user. The portions are concatenated together to recreate the initial value. The portions, the initial value, and the secret string value are then used to create public and private keys for use by the user. Any recipient can authenticate digital signatures without needing the secret string value or the user's device can authenticate a digital signature using the portions and the secret string value.

Claims (60)

1. A method for generating public and private keys in a public key-private key cryptographic scheme, the method comprising:

a) receiving, at a computing device from a server, multiple portions comprising at least a first portion p1 and a second portion p2 of an initial value e by way of different communication channels, each of said multiple portions being transmitted by a communication channel which is separate and different from communication channels used to transmit other portions of said initial value;

b) receiving, at said computing device from a user, a secret string value generated by said user;

c) converting, at said computing device, said secret string value into a digital secret string value s;

d) concatenating, at said computing device, said multiple portions p1 and p2 to recreate said initial value e;

e) receiving, at said computing device, at least one system parameter r from said server;

f) using said multiple portions, said initial value, said at least one system parameter, and said digital secret string value to generate a public key-private key pair for said scheme at said computing device by:

g1) determining a value p=first prime number after s p1 mod r;

g2) determining a value q=first prime number after s p2 mod r;

g3) determining a value n=pq where p and q are from steps g1) and g2);

g4) determining a value φ=(p−1)(q−1);

g5) determining a value d=e −1 (mod φ);

wherein said public key comprises said value n and said value e; and said private key comprises said value d;

wherein said cryptographic scheme further comprises, at a further computing device configured to receive a communication from said computing device:

h1) extracting a digital signature from said communication;

h2) converting said digital signature into a numeric value;

h3) determining a first signature value equal to sig e mod n where sig is said numeric value;

h4) producing a hash value of said communication to result in a second signature value;

h5) comparing said first signature value to said second signature value; and

h6) concluding that said communication is authentic in the event said first signature value is equal to said second signature value.

2. A method for generating public and private keys in a public key-private key cryptographic scheme, the method comprising:

a) receiving, at a computing device from a server, multiple portions comprising at least a first portion p1 and a second portion p2 of an initial value g by way of different communication channels, each of said multiple portions being transmitted by a communication channel which is separate and different from communication channels used to transmit other portions of said initial value;

b) receiving, at said computing device from a user, a secret string value generated by said user;

c) converting, at said computing device, said secret string value into a digital secret string value s;

d) receiving, at said computing device, system parameters r, p and q and a further portion g′ of said initial value g from said server;

e) concatenating, at said computing device, said multiple portions p1, p2 and g′ to recreate said initial value g;

f) using said multiple portions, said initial value, said system parameters, and said digital secret string value to generate a public key-private key pair for said scheme at said computing device by:

g1) determining a value x=(s p1 mod r)⊕(s p2 mod r)

g2) determining a value y=g x mod p;

wherein

said private key comprises said value x; and

said public key comprises said value y.

3. A method according to claim 2 wherein said cryptographic scheme further comprises, at a further computing device configured to receive a communication from said computing device, the communication including a message m, a digital signature comprising values s′ and r′:

h1) extracting said digital signature s′, r′ from said communication;

h2) determining a number of values as follows:

w=s′ −1 mod q

u 1 =H ( m )* w mod q

u 2 =r′*w mod q

v =(( g u1 y u2 ) mod p ) mod q

h3) confirming that said communication is authentic in the event v=r′.

4. A non-transitory computer readable medium having encoded thereon computer readable and computer executable instructions which, when executed by a processor, implements a method for generating public and private keys in a public key-private key cryptographic scheme, the method comprising:

a) receiving, at a computing device from a server, multiple portions comprising at least a first portion p1 and a second portion p2 of an initial value e by way of different communication channels, each of said multiple portions being transmitted by a communication channel which is separate and different from communication channels used to transmit other portions of said initial value;

b) receiving, at said computing device from a user, a secret string value generated by said user;

c) converting, at said computing device, said secret string value into a digital secret string value s;

d) concatenating, at said computing device, said multiple portions p1 and p2 to recreate said initial value e;

e) receiving, at said computing device, at least one system parameter r from said server;

f) using said multiple portions, said initial value, said at least one system parameter, and said digital secret string value to generate a public key-private key pair for said scheme at said computing device by:

g1) determining a value p=first prime number after s p1 mod r;

g2) determining a value q=first prime number after s p2 mod r;

g3) determining a value n=pq where p and q are from steps g1) and g2);

g4) determining a value φ=(p−1)(q−1);

g5) determining a value d=e −1 mod φ);

wherein said public key comprises said value n and said value e; and said private key comprises said value d:

wherein said cryptographic scheme further comprises, at a further computing device configured to receive a communication from said computing device:

h1) extracting a digital signature from said communication;

h2) converting said digital signature into a numeric value;

h3) determining a first signature value equal to sig e mod n where sig is said numeric value;

h4) producing a hash value of said communication to result, in a second signature value;

h5) comparing said first signature value to said second signature value; and

h6) concluding that said communication is authentic in the event said first signature value is equal to said second signature value.

Assignments (4)
SECURITY INTEREST Recorded Dec 20, 2024
From: CODELATHE TECHNOLOGIES INC.; SIGNORITY INC.
To: LEVEL STRUCTURED CAPITAL II, L.P.
Reel/Frame 069654/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2024
From: HE, JANE
To: SIGNORITY INC.
Reel/Frame 067431/0961 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2018
From: SIGNORITY INC.
To: HE, JANE
Reel/Frame 045255/0348 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2015
From: ADAMS, CARLISLE; JOURDAN, GUY VINCENT
To: SIGNORITY INC.
Reel/Frame 036980/0784 →
Continuity (2)
Provisional Application 61783368 · Mar 14, 2013
Related Publication 20140270160A1 · Sep 18, 2014