IP Library Granted Patent US 10,516,527
Granted Patent B1
US 10,516,527 · App. 14/869,150 · Granted Dec 24, 2019

Split-key based cryptography system for data protection and synchronization across multiple computing devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,516,527
App. No.
14/869,150
Granted
Dec 24, 2019
Kind
B1
Abstract

Split-key based cryptography techniques are provided for data protection and synchronization across multiple computing devices of a user. A method performed by a first device of a user comprises encrypting a data using a randomly-generated data encryption key; wrapping the data encryption key with a public key of a second device of the user; and sending the encrypted data and the wrapped data encryption key of the first device wrapped with the public key of the second device to a server. The server sends the encrypted data and the wrapped data encryption key of the first device wrapped with the public key of the second device to the second device. The first device or the second device can access the encrypted data by reconstructing their respective private key using a predefined number of shares obtained using a key splitting scheme.

Claims (31)

1. A method performed by a first device of a user, comprising:

encrypting data, by at least one processing device of said first device, with a randomly-generated data encryption key to generate encrypted data;

wrapping the randomly-generated data encryption key of said first device, by said at least one processing device of said first device, with a public key of a second device of the user to generate a wrapped data encryption key of the first device, wherein said encrypted data is distinct from said wrapped data encryption key of the first device; and

sending, by said at least one processing device of said first device, (i) the encrypted data, and (ii) the wrapped data encryption key of the first device to a server, wherein the server sends (i) the encrypted data, and (ii) the wrapped data encryption key of the first device to the second device, wherein a given one of the first and second devices of the user is configured to access the encrypted data by (a) unwrapping the wrapped data encryption key of the first device using a private key of the given one of the first and second devices of the user, wherein said private key of the given device is reconstructed using a predefined number of shares obtained using a key splitting scheme; and (b) decrypting the encrypted data using the unwrapped data encryption key of the first device, wherein the first device and the second device are distinct from one another.

2. The method of claim 1 , further comprising the steps of registering the first and second devices with said server and linking the first and second devices using a predefined value.

3. The method of claim 1 , wherein the key splitting scheme splits one or more of the private key of the first device and a randomly-generated private key wrapping key into a plurality of shares comprising a user password key share, a device key share stored by the first device and a remote key share stored by the server.

4. The method of claim 3 , wherein reconstruction of the private key requires the user password key share and the device key share when the first device is in an offline mode.

5. The method of claim 3 , wherein reconstruction of the private key requires the device key share and the remote key share when the first device is in an online mode.

6. The method of claim 3 , wherein the device key share is only released if the user authenticates to the first device using one or more predefined device unlock methods.

7. The method of claim 6 , wherein the one or more predefined device unlock methods comprise biometric verification, entering a predefined device unlock passcode, and use of a predefined proximity device.

8. The method of claim 3 , wherein the remote key share is only released if the first device authenticates to the server using a transport private key of the first device.

9. The method of claim 1 , wherein the first device further comprises a recovery private key and wherein the key splitting scheme splits one or more of the recovery private key of the first device and a randomly-generated private key wrapping key into a plurality of shares comprising a user password key share, a remote key share stored by the server and an emergency key share.

10. The method of claim 9 , wherein the user provides the emergency key share as one or more of a printed Quick Response code, stored in a wearable device, hidden in a picture, and as a message to at least one other person.

11. The method of claim 9 , further comprising a recovery step to reconstruct the recovery private key by combining the remote key share with one of the user password key share and the emergency key share.

12. The method of claim 11 , further comprising a recovery step to verify an integrity and validity of the emergency key share before requesting the remote key share from the server.

13. The method of claim 1 , wherein said encrypting and wrapping steps comprise encrypting the data using a public key of the first device when the data is smaller than a predefined threshold.

14. A non-transitory machine-readable recordable storage medium, wherein one or more software programs when executed by one or more processing devices implement the following steps:

encrypting, by at least one processing device of a first device of a user, data with a randomly-generated data encryption key to generate encrypted data;

wrapping the randomly-generated data encryption key of said first device, by said at least one processing device of said first device, with a public key of a second device of the user to generate a wrapped data encryption key of the first device, wherein said encrypted data is distinct from said wrapped data encryption key of the first device; and

sending, by said at least one processing device of said first device, (i) the encrypted data, and (ii) the wrapped data encryption key of the first device to a server, wherein the server sends (i) the encrypted data, and (ii) the wrapped data encryption key of the first device to the second device, wherein a given one of the first and second devices of the user is configured to access the encrypted data by (a) unwrapping the wrapped data encryption key of the first device using a private key of the given one of the first and second devices of the user, wherein said private key of the given device is reconstructed using a predefined number of shares obtained using a key splitting scheme; and (b) decrypting the encrypted data using the unwrapped data encryption key of the first device, wherein the first device and the second device are distinct from one another.

15. A first device of a user, comprising:

a memory; and

at least one processing device, coupled to the memory, operative to implement the following steps:

encrypting data, by said at least one processing device of said first device, with a randomly-generated data encryption key to generate encrypted data;

wrapping the randomly-generated data encryption key of said first device, by said at least one processing device of said first device, with a public key of a second device of the user to generate a wrapped data encryption key of the first device, wherein said encrypted data is distinct from said wrapped data encryption key of the first device; and

sending, by said at least one processing device of said first device, (i) the encrypted data, and (ii) the wrapped data encryption key of the first device to a server, wherein the server sends (i) the encrypted data, and (ii) the wrapped data encryption key of the first device to the second device, wherein a given one of the first and second devices of the user is configured to access the encrypted data by (a) unwrapping the wrapped data encryption key of the first device using a private key of the given one of the first and second devices of the user, wherein said private key of the given device is reconstructed using a predefined number of shares obtained using a key splitting scheme; and (b) decrypting the encrypted data using the unwrapped data encryption key of the first device, wherein the first device and the second device are distinct from one another.

16. The first device of claim 15 , wherein said at least one processing device is further configured to register the first and second devices with said server and link the first and second devices using a predefined value.

17. The first device of claim 15 , wherein the key splitting scheme splits one or more of the private key of the first device and a randomly-generated private key wrapping key into a plurality of shares comprising a user password key share, a device key share stored by the first device and a remote key share stored by the server.

18. The first device of claim 17 , wherein reconstruction of the private key requires the user password key share and the device key share when the first device is in an offline mode and the device key share and the remote key share when the first device is in an online mode.

19. The first device of claim 15 , wherein the first device further comprises a recovery private key and wherein the key splitting scheme splits one or more of the recovery private key of the first device and a randomly-generated private key wrapping key into a plurality of shares comprising a user password key share, a remote key share stored by the server and an emergency key share and wherein a recovery step reconstructs the recovery private key by combining the remote key share with one of the user password key share and the emergency key share.

20. The first device of claim 15 , wherein said at least one processing device is further configured to perform said encrypting and wrapping steps by encrypting the data using a public key of the first device when the data is smaller than a predefined threshold.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052216/0758) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0680 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST AF REEL 052243 FRAME 0773 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0152 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 26, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052243/0773 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 24, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052216/0758 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2019
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 050815/0154 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2016
From: MACHANI, SALAH; KRONROD, BORIS; BOWERS, KEVIN D.
To: EMC CORPORATION
Reel/Frame 037811/0949 →