IP Library Granted Patent US 9,270,663
Granted Patent B2
US 9,270,663 · App. 14/218,897 · Granted Feb 23, 2016

System and method to enable PKI- and PMI-based distributed locking of content and distributed unlocking of protected content and/or scoring of users and/or scoring of end-entity access means—added

Inventors: David W. Kravitz (Fairfax, VA); Donald Houston Graham, III (Pasadena, CA); Josselyn L. Boudett (Clearwater, FL); Russell S. Dietz (Los Gatos, CA)
Assignee: T-CENTRAL, INC.
H04L63/08H04L9/0822H04L9/0894H04L9/3247H04L63/061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,270,663
App. No.
14/218,897
Granted
Feb 23, 2016
Kind
B2
Abstract

A central server configured with an Attribute Authority (“AA”) acting as a Trusted Third Party mediating service provider and using X.509-compatible PKI and PMI, VPN technology, device-side thin client applications, security hardware (HSM, Network), cloud hosting, authentication, Active Directory and other solutions. This ecosystem results in real time management of credentials, identity profiles, communication lines, and keys. It is not centrally managed, rather distributes rights to users. Using its Inviter-Invitee protocol suite, Inviters vouch for the identity of Invitees who successfully complete the protocol establishing communication lines. Users establish and respond to authorization requests and other real-time verifications pertaining to accessing each communication line (not end point) and sharing encrypted digital files. These are auditable, brokered, trusted-relationships where such relationships/digital agreements can each stand-alone (for privacy) or can leverage build-up of identity confidence levels across relationships. The service is agnostic to how encrypted user content is transported or stored.

Claims (30)

1. A system of establishing and authenticating a persistent and revocable secure line of communication comprising:

a plurality of client devices, each of the plurality of client devices including a client app that includes a local key store module (LKSM) and a digital identity token; and

a trusted third party server including a user facing domain and a key escrow domain;

wherein the user facing domain securely relates to the plurality of client devices via the client app and includes a login interface, a hardware security module (HSM), or a lightweight directory access protocol application (LDAP);

wherein the key escrow domain authenticates secure lines of communication among the plurality of client devices and includes registration authority, certificate authority, or attribute authority;

wherein the trusted third party server is configured to execute an invitation protocol including:

authenticating a first client device and a second client device;

conveying an invitation from the first client device to the second device to establish a communication line between the first client device and the second client device;

providing downloaded software to the second client device;

triggering a series of authentication steps to be performed by the second device to ensure the downloaded software is correctly provisioned;

receiving a response to the invitation from the second device at the first device; storing a created public key corresponding to the established communication line; storing only a portion of a created private key corresponding to the established communication line;

wherein the first client device or the second client device is configured to reconstruct a complete version of the created private key with information retrieved from the trusted third party server after authenticating the trusted third party server; and

wherein the invitation includes a client app with a digital identity token, email address, designated attributes, authentication question, answer to authentication question, or a cryptographic digital signature.

2. A non-transitory computer-readable storage medium encoded with instructions that, when executed by a processing device, establish a machine performing a computer-implemented method of establishing and authenticating a persistent and revocable secure line of communication comprising:

authenticating a first client device and a second client device using a trusted third party server;

enabling the first client device to invite a second client device to establish a communication line with the first client device;

enabling the second client device to download software in response to the invitation;

providing an authenticated public encryption key of the first client device to the second client device;

creating a local key storage module (LKSM) at the first client device and the second client device;

performing a series of authentication steps in a predetermined manner on the second client device to ensure to the first client device by the trusted third party server that the downloaded software was correctly provisioned;

creating a public key/private key pair corresponding to the communication line between the first client device and the second client device;

storing the created public key at the trusted third party server;

splitting and storing the created private key such that neither the first client device nor the second client device nor the trusted third party server store a complete copy of the created private key;

storing portions of the created private key in the LKSM of the first client device or the second client device; and

enabling the first client device or the second client device to reconstruct the created private key by retrieving portions when the first client device or the second client device authenticate with the trusted third party server;

wherein the first client device or the second client device includes a corresponding client app;

wherein the corresponding client app includes the LKSM and a digital identity token;

wherein the trusted third party server includes a user facing domain or a key escrow domain;

wherein the user facing domain securely relates to the plurality of client devices via the client app and includes a login interface, a hardware security module (HSM), or a lightweight directory access protocol application (LDAP); and

wherein the key escrow domain authenticates secure lines of communication among the plurality of client devices and includes registration authority, certificate authority, or attribute authority.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2014
From: GRAHAM, DONALD
To: T-CENTRAL, INC.
Reel/Frame 034381/0309 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2014
From: BOUDETT, JOSSELYN
To: T-CENTRAL, INC.
Reel/Frame 034381/0349 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2014
From: KRAVITZ, DAVID W
To: T-CENTRAL, INC.
Reel/Frame 034381/0357 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2014
From: DIETZ, RUSSELL
To: T-CENTRAL, INC.
Reel/Frame 034381/0567 →
Continuity (9)
Continuation In Part 13481553 · May 25, 2012
Continuation In Part 13096764 · Apr 28, 2011
Provisional Application 61792927 · Mar 15, 2013
Provisional Application 61650866 · May 23, 2012
Provisional Application 61330226 · Apr 30, 2010
Provisional Application 61367574 · Jul 26, 2010
Provisional Application 61367576 · Jul 26, 2010
Provisional Application 61416629 · Nov 23, 2010
Related Publication 20150312233A1 · Oct 29, 2015