IP Library Granted Patent US 9,960,919
Granted Patent B2
US 9,960,919 · App. 14/652,454 · Granted May 1, 2018

Method for providing security using secure computation

Inventor: Yehuda Lindell (Givat Shmuel, IL)
Assignee: BAR-ILAN UNIVERSITY
H04L9/3226G06F21/31G06F21/62H04L9/085H04L9/3228H04L9/3231H04L9/3271H04L63/06H04L63/0838H04L63/0861G06F2221/2103H04L2209/46
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,960,919
App. No.
14/652,454
Filed
Jun 16, 2015
Granted
May 1, 2018
Kind
B2
Art Unit
2438
USPC
713/168
Abstract

A method of securing data, the method comprising: dividing a secret key into a plurality of secret key shares; storing each of the plurality of secret key shares in a different server of a plurality of servers so that none of the servers has access to the secret key and to the secret key share stored in another of the servers; using a server of the plurality of servers to execute a secure computation protocol to determine a value of a function responsive to all of the plurality of secret key shares without providing any of the plurality of servers with access to the secret key and to the secret key share stored in another of the servers; and using the calculated value of the function to secure the data.

Claims (13)

1. A method of authenticating a party for participation in an activity, the method comprising:

dividing a first secret key into a plurality of secret key shares;

storing each of the plurality of the first secret key shares in a different server of a plurality of servers so that none of the servers has access to the secret key share stored in another of the servers;

transmitting a challenge to the party and requesting that the party encrypt the challenge using a second key;

after the party encrypts the challenge using the second key, receiving the encrypted challenge from the party;

executing at the plurality of servers a secure computation protocol to generate encryption of the challenge using the plurality of secret key shares without providing any of the plurality of servers with access to the first secret key and to the secret key share stored in another of the servers;

comparing the encrypted challenge received from the party and the encrypted challenge generated by the plurality of servers to determine whether the second key is equal to the first key; and

enabling the party to participate in the activity if and only if it was determined that the first and second keys are equal.

2. The method according to claim 1 wherein the activity comprises establishing a virtual private network communication channel.

3. The method according to claim 1 wherein the party comprises a communication device.

4. The method of securing data according to claim 1 wherein the first secret key comprises a key used in a Kerberos protocol and the challenge comprises an encryption of a ticket granting ticket (TGT) used by the secure computation protocol.

5. The method of securing data according to claim 1 wherein the first secret key comprises a key used in a Kerberos protocol and the challenge comprises an encryption of a service ticket (ST) used by the secure computation protocol.

6. The method of securing data according to claim 1 wherein the first secret key comprises a feature vector representing a biometric feature.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2022
From: BAR ILAN UNIVERSITY
To: UNBOUND SECURITY LTD
Reel/Frame 059289/0592 →
CHANGE OF NAME Recorded Mar 17, 2022
From: UNBOUND SECURITY LTD
To: COINBASE IL RD LTD
Reel/Frame 059380/0994 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2018
From: LINDELL, YEHUDA
To: BAR-ILAN UNIVERSITY
Reel/Frame 045032/0331 →
Continuity (2)
Provisional Application 61749943 · Jan 8, 2013
Related Publication 20150349958A1 · Dec 3, 2015