IP Library Granted Patent US 9,455,978
Granted Patent B2
US 9,455,978 · App. 15/002,225 · Granted Sep 27, 2016

System and method to enable PKI- and PMI- based distributed locking of content and distributed unlocking of protected content and/or scoring of users and/or scoring of end-entity access means—added

Inventors: David W. Kravitz (Fairfax, VA); Donald Houston Graham, III (Pasadena, CA); Josselyn L. Boudett (Clearwater, FL); Russell S. Dietz (Los Gatos, CA)
Assignee: T-Central, Inc.
H04L63/08H04L9/0894H04L9/3247H04L63/061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,455,978
App. No.
15/002,225
Granted
Sep 27, 2016
Kind
B2
Abstract

A central server configured with an Attribute Authority (“AA”) acting as a Trusted Third Party mediating service provider and using X.509-compatible PKI and PMI, VPN technology, device-side thin client applications, security hardware (HSM, Network), cloud hosting, authentication, Active Directory and other solutions. This ecosystem results in real time management of credentials, identity profiles, communication lines, and keys. It is not centrally managed, rather distributes rights to users. Using its Inviter-Invitee protocol suite, Inviters vouch for the identity of Invitees who successfully complete the protocol establishing communication lines. Users establish and respond to authorization requests and other real-time verifications pertaining to accessing each communication line (not end point) and sharing encrypted digital files. These are auditable, brokered, trusted-relationships where such relationships/digital agreements can each stand-alone (for privacy) or can leverage build-up of identity confidence levels across relationships. The service is agnostic to how encrypted user content is transported or stored.

Claims (24)

1. A method of secure communication, comprising:

downloading, using a trusted third party server, a first app for execution on a first electronic device, the first app creating a first set of encryption keys including a first public encryption key and a first private encryption key on the first electronic device;

generating, using the trusted third party server, an invitation to establish a secure communications line between the first electronic device and a second electronic device based on receiving an invitation request for the invitation from a first user of the first electronic device, the invitation request including identification and authentication information to identify and authenticate a second user of the second electronic device together with requested terms of digital agreement covering the secure communications line;

transmitting, by the trusted third party server, the invitation to the first electronic device;

transmitting, by the trusted third party server, a second app for execution on the second electronic device upon request by the second electronic device, the second app creating a second set of encryption keys including a second public encryption key and a second private encryption key on the second electronic device; and

authenticating, at the trusted third party server, the second user of the second electronic device based at least in part on an acceptable response to the identification and authentication information provided to the trusted third party server by the first user in the invitation request and based at least in part on acknowledgement of an installation of the second app on the second electronic device and acceptance of the requested terms in the digital agreement covering the secure communications line;

wherein the trusted third party server makes available the first public encryption key of the first user to the second app and the second public encryption key of the second user to the first app to authenticate the first public encryption key and second public encryption key;

wherein the first app generates an encrypted digital asset by encrypting a digital asset on the first electronic device using a symmetric encryption key;

wherein the first app generates an encrypted symmetric encryption key by encrypting the symmetric encryption key using the second public encryption key of the second user;

wherein the first electronic device transfers the encrypted digital asset and the encrypted symmetric encryption key to the second electronic device, such that the second user is able to decrypt the encrypted symmetric encryption key using the second private encryption key and decrypt the encrypted digital asset using the then decrypted symmetric encryption key to thereby establish the secure communications line; and

wherein the invitation includes a client app with a digital identity token, e-mail address, designated attributes, authentication question, answer to authentication question, or a cryptographic digital signature.

2. A trusted third party system, comprising:

a memory device to store instructions; and

one or more processing units to execute the instructions stored in the memory device to:

transmit a first app to a first electronic device, the first app creating a first set of encryption keys including a first public encryption key and a first private encryption key on the first electronic device;

generate, based at least in part on receiving an invitation request from a first user of the first electronic device, an invitation to establish a secure communications line between the first electronic device and a second electronic device, the invitation request including identification or authentication information to identify or authenticate and request terms of digital agreement covering the secure communications line between a first user of the first electronic device and a second user of the second electronic device;

transmit the invitation to the first electronic device;

transmit a second app to the second electronic device based at least in part on a request by the second user of the second electronic device, the second app creating a second set of encryption keys including a second public encryption key and a second private encryption key on the second electronic device;

authenticate the second user of the second electronic device based at least in part on an acceptable response to the identification or authentication information provided to the trusted third party server by the second user in response to the first user transmitting the invitation to the second user and based at least in part on acknowledgement of an installation of the second app on the second electronic device and acceptance of the requested terms in the digital agreement covering the secure communications line;

wherein the trusted third party server makes available the first public encryption key of the first user to the second app and the second public encryption key of the second user to the first app to authenticate the first public encryption key and second public encryption key;

wherein the first app generates an encrypted digital asset by encrypting a digital asset on the first electronic device using a symmetric encryption key;

wherein the first app generates an encrypted symmetric encryption key by encrypting the symmetric encryption key using the second public encryption key of the second user;

wherein the first electronic device transfers the encrypted digital asset and the encrypted symmetric encryption key to the second electronic device, such that the second user is able to decrypt the encrypted symmetric encryption key using the second private encryption key and decrypt the encrypted digital asset using the then decrypted symmetric encryption key to thereby establish the secure communications line between the first user and the second user; and

wherein the invitation includes a client app with a digital identity token, e-mail address, designated attributes, authentication question, answer to authentication question, or a cryptographic digital signature.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 20, 2016
From: KRAVITZ, DAVID W; GRAHAM, DONALD; BOUDETT, JOSSELYN; DIETZ, RUSSELL
To: T-CENTRAL, INC.
Reel/Frame 037538/0831 →
Continuity (11)
Continuation 14218897 · Mar 18, 2014
Continuation In Part 13481553 · May 25, 2012
Continuation In Part 13096764 · Apr 28, 2011
Provisional Application 61792927 · Mar 15, 2013
Provisional Application 61490952 · May 27, 2011
Provisional Application 61650866 · May 23, 2012
Provisional Application 61330226 · Apr 30, 2010
Provisional Application 61367574 · Jul 26, 2010
Provisional Application 61367576 · Jul 26, 2010
Provisional Application 61416629 · Nov 23, 2010
Related Publication 20160248760A1 · Aug 25, 2016