IP Library Granted Patent US 10,218,680
Granted Patent B2
US 10,218,680 · App. 14/566,345 · Granted Feb 26, 2019

Mechanism for efficient private bulk messaging

Inventor: David Jevans (Los Altos, CA)
Assignee: Axway Inc.
H04L63/0428H04L9/083H04L9/0825H04L63/0435H04L63/0442H04L63/0471H04L63/061H04L63/062H04L63/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,218,680
App. No.
14/566,345
Granted
Feb 26, 2019
Kind
B2
Abstract

Secure bulk messaging mechanism in which, roughly described, a sender first encrypts a message once. The message can be decrypted with a message decryption key. These can be symmetric or asymmetric keys. For each recipient, the sender then encrypts the message decryption key with the recipient's public key. The sender then sends the encrypted message and the encrypted message decryption keys to a store-and-forward server. Subsequently, one or more recipients connect to the server and retrieve the encrypted message and the message encryption key that has been encrypted with the recipient's public key. Alternatively, the server can forward these items to each individual recipient. The recipient then decrypts the encrypted message decryption key with the recipient's private key, resulting in an un-encrypted message decryption key. The recipient then decrypts the message using the un-encrypted message decryption key.

Claims (43)

1. A document management system comprising:

a server coupled into a transmission path between a sender and target recipients to receive from the sender and to provide to at least some of the target recipients a message, wherein the provided message is encrypted at least for storage at the server using a sender key and is decryptable using a corresponding message decryption key that is, in turn, separately encrypted for each of the target recipients using respective encryption keys associated with the target recipients themselves, thereby resulting in a plurality of recipient-associated encrypted decryption keys;

the sender providing a digital signature and a list of recipient-associated encrypted decryption keys to the server, wherein the sender digests at least a portion of the list, but not the message itself, to form a digest and encrypts the digest with the sender's private key of a public-private pair to create the digital signature;

the server providing each of the target recipients with at least a respective one of the recipient-associated encrypted decryption keys for decryption by the respective target recipient to recover the underlying message decryption key and to thereby provide the respective target recipient with access to the encrypted message.

2. The document management system of claim 1 ,

wherein responsive to the sender, the server changes the underlying message stored at the server, but not the recipient-associated encrypted decryption keys themselves or the sender key itself which remain unchanged.

3. The document management system of claim 2 ,

wherein the sender sends the recipient-associated encrypted decryption keys to the server for inclusion in a list of authorized encrypted decryption keys, and wherein the underlying message is changed, but not the list of authorized encrypted decryption keys themselves which remain unchanged.

4. The document management system of claim 2 ,

wherein the changed message is encrypted at least for storage at the server using the sender key.

5. The document management system of claim 4 ,

wherein the sender provides a first recipient-associated encrypted decryption key of the plurality of recipient-associated encrypted decryption keys to a first recipient.

6. The document management system of claim 5 ,

wherein the first target recipient retrieves the encrypted changed message and the first recipient-associated encrypted decryption key from the server.

7. The document management system of claim 6 ,

wherein the first target recipient decrypts the first recipient-associated encrypted decryption key to recover the first underlying message decryption key.

8. The document management system of claim 7 ,

wherein the first target recipient decrypts the encrypted changed message using the first recovered message decryption key.

9. The document management system of claim 8 ,

wherein the sender provides a second recipient-associated encrypted decryption key of the plurality of recipient-associated encrypted decryption keys to a second target recipient.

10. The document management system of claim 9 ,

wherein the second target recipient retrieves the encrypted changed message and the second recipient-associated encrypted decryption key from the server.

11. The document management system of claim 10 ,

wherein the second target recipient decrypts the second recipient-associated encrypted decryption key to recover the second underlying message decryption key.

12. The document management system of claim 11 ,

wherein the second target recipient decrypts the encrypted changed message provided by the server.

13. The document management system of claim 12 ,

wherein the second target recipient decrypts the encrypted changed message using the second recovered message decryption key.

14. The document management system of claim 1 ,

wherein the message is an e-mail message.

15. The document management system of claim 1 ,

wherein the message is a document.

16. The document management system of claim 1 ,

wherein the server does not allow the target recipients to change the underlying message.

17. The document management system of claim 1 ,

wherein the digital signature is not dependent on the message.

18. The document management system of claim 1 ,

wherein the recipient-associated encrypted decryption keys in the list are stored separate from the encrypted message.

19. The document management system of claim 1 , comprising:

an auditor that decrypts the digital signature using the sender's public key of the public-private pair to recover a second digest and compares the first digest to the second digest,

wherein the server provides each of the target recipients with at least the respective one of the recipient-associated encrypted decryption keys if the first and second digests are the same.

20. The document management system of claim 1 ,

wherein the server packages the encrypted message and the recipient-associated encrypted decryption keys into a single message and broadcasts the single message to the target recipients and at least one recipient that is not a target recipient of the message.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2015
From: JEVANS, DAVID
To: VALICERT, INC.
Reel/Frame 037244/0414 →
MERGER Recorded Dec 9, 2015
From: VALICERT, INC.
To: TUMBLEWEED COMMUNICATIONS CORP.
Reel/Frame 037244/0441 →
MERGER Recorded Dec 9, 2015
From: TUMBLEWEED COMMUNICATIONS CORP.
To: AXWAY INC.
Reel/Frame 037244/0446 →
Continuity (5)
Continuation 13717297 · Dec 17, 2012
Continuation 11107679 · Apr 15, 2005
Continuation 09792949 · Feb 26, 2001
Provisional Application 60184785 · Feb 24, 2000
Related Publication 20150207784A1 · Jul 23, 2015