IP Library Granted Patent US 11,184,335
Granted Patent B1
US 11,184,335 · App. 15/165,303 · Granted Nov 23, 2021

Remote private key security

Inventors: Serguei M. Beloussov (Costa Del Sol, SG); Alexander Tormasov (Moscow, RU); Stanislav Protasov (Moscow, RU)
H04L63/0442H04L63/061H04L63/0861H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,184,335
App. No.
15/165,303
Granted
Nov 23, 2021
Kind
B1
Abstract

A method for remote private key security is described. The method may include generating a private key and may further include generating encrypted data by encrypting data using an encryption algorithm, wherein the data is stored at a first location and the private key is for the encrypted data. The method may also include transmitting the private key to a remote private key deposit at a second location. The method may additionally include transmitting the encrypted data to a remote data center at a third location. Moreover, the method may include permitting access to the private key at the remote private key deposit to an individual at the second location in response to confirming an identity of the individual present at the second location.

Claims (46)

1. A method for remote private key security, the method comprising:

generating a private key;

generating encrypted data by encrypting data using an encryption algorithm, wherein the data is stored at a first location and the private key is for the encrypted data, the encryption algorithm running on a computer-based encryption system;

transmitting the private key, using a transmitter, to a remote private key deposit at a second location, wherein the private key is retained at the remote private key deposit to be accessed by an individual at the second location; and

permitting access, using a computer-based confirmation system, to the private key at the remote private key deposit to the individual at the second location in response to confirming an identity of the individual present at the second location, wherein confirming comprises the individual physically visiting the second location.

2. The method of claim 1 , further comprising:

transmitting the encrypted data to a remote data center at a third location.

3. The method of claim 2 , further comprising:

deleting the data stored at the first location in response to transmitting the encrypted data to the remote data center at the third location.

4. The method of claim 2 , further comprising:

transmitting the encrypted data to a temporary remote data center at a fifth location prior to transmitting the encrypted data to the remote data center at the third location.

5. The method of claim 4 , wherein the fourth location is the same as the fifth location.

6. The method of claim 2 , wherein the second location is the same as the third location.

7. The method of claim 1 , further comprising:

deleting the private key for the encrypted data in response to transmitting the private key to the remote private key deposit at the second location.

8. The method of claim 1 , further comprising:

transmitting the private key to a temporary remote private key deposit at a fourth location prior to transmitting the private key to the remote private key deposit at the second location.

9. The method of claim 1 , wherein the individual was previously selected to access the private key at the remote private key deposit on condition that the identity of the individual is confirmed at the second location.

10. The method of claim 1 , further comprising:

confirming the identity of the individual present at the second location based upon, at least in part, biometric information provided by the individual at the second location.

11. The method of claim 10 , wherein the biometric information is related to a biometric identifier selected from the group consisting of: a fingerprint, a retina, an iris, DNA, a palm, a hand, a handwriting sample, a biopsy, a behavior or a behavior identification, a body motoric, a gesture, a facial gesture and a voice.

12. The method of claim 1 , wherein the private key is stored and deleted based upon, at least in part, a defined retention policy.

13. The method of claim 12 , wherein the private key is inherited based upon, at least in part, the defined retention policy.

14. The method of claim 1 , wherein the individual is present at the second location at the time access is permitted to the private key, wherein the first location and the second location are different legal jurisdictions.

15. A system for remote private key security, the system comprising:

a computer-based private key generator that generates a private key;

a computer-based encryption system configured to execute an encryption algorithm, wherein the data is stored at a first location and the private key is for decrypting data encrypted using the encryption algorithm;

a first transmitter that transmits the private key to a remote private key deposit at a second location, wherein the private key is retained at the remote private key deposit to be accessed by an individual; and

a computer-based confirmation system configured to confirm identity of the individual, wherein the computer-based confirmation system is physically present at the second location and permits access to the private key at the remote private key deposit to the individual at the second location in response to confirming an identity of the individual present at the second location, wherein confirming comprises the individual physically visiting the second location.

16. The system of claim 15 , further comprising:

a second transmitter that transmits the encrypted data to a remote data center at a third location.

17. The system of claim 16 , wherein the data stored at the first location is deleted in response to transmitting the encrypted data to the remote data center at the third location.

18. The system of claim 15 , wherein the private key for the encrypted data is deleted in response to transmitting the private key to the remote private key deposit at the second location.

19. The system of claim 15 , wherein the confirmation system confirms the identity of the individual present at the second location based upon, at least in part, biometric information provided by the individual at the second location.

20. The system of claim 19 , wherein the biometric information is related to a biometric identifier selected from the group consisting of: a fingerprint, a retina, an iris, DNA, a palm, a hand, a handwriting sample, a biopsy, a behavior or a behavior identification, a body motoric, a gesture, a facial gesture and a voice.

21. The method of claim 15 , wherein the individual is present at the second location at the time access is permitted to the private key, wherein the first location and the second location are different legal jurisdictions.

22. A system for remote private key security, the system comprising:

a remote private key deposit at a second location that receives a private key for encrypted data from a first location, wherein the private key is retained at the remote private key deposit to be accessed by an individual; and

a computer-based confirmation system configured to confirm identity of the individual, wherein the computer-based confirmation system permits access to the private key at the remote private key deposit to the individual at the second location in response to confirming an identity of the individual present at the second location, wherein confirming comprises the individual physically visiting the second location.

23. The system of claim 22 , further comprising:

a remote data center at a third location that receives the encrypted data from the first location.

24. The system of claim 23 , wherein data corresponding to the encrypted data is deleted from the first location in response to receiving the encrypted data at the remote data center at the third location.

25. The system of claim 22 , wherein the private key for the encrypted data is deleted from the first location in response to receiving the private key at the remote private key deposit at the second location.

26. The system of claim 22 , wherein the confirmation system confirms the identity of the individual present at the second location based upon, at least in part, biometric information provided by the individual at the second location.

27. The system of claim 26 , wherein the biometric information is related to a biometric identifier selected from the group consisting of: a fingerprint, a retina, an iris, DNA, a palm, a hand, a handwriting sample, a biopsy, a behavior or a behavior identification, a body motoric, a gesture, a facial gesture and a voice.

28. The method of claim 22 , wherein the first location and the second location are different legal jurisdictions.

Assignments (5)
REAFFIRMATION AGREEMENT Recorded Aug 28, 2022
From: ACRONIS AG; ACRONIS INTERNATIONAL GMBH; ACRONIS SCS, INC.; ACRONIS, INC.; GROUPLOGIC, INC.; NSCALED INC.; ACRONIS MANAGEMENT LLC; 5NINE SOFTWARE, INC.; ACRONIS GERMANY GMBH; ACRONIS NETHERLANDS B.V.; ACRONIS BULGARIA EOOD; DEVICELOCK, INC.; DEVLOCKCORP LTD; ACRONIS INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 061330/0818 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2021
From: BELOUSSOV, SERGUEI M.; TORMASOV, ALEXANDER; PROTASOV, STANISLAV
To: ACRONIS INTERNATIONAL GMBH
Reel/Frame 057818/0690 →
SECURITY INTEREST Recorded Dec 19, 2019
From: ACRONIS INTERNATIONAL GMBH
To: MIDCAP FINANCIAL TRUST
Reel/Frame 051418/0119 →
RELEASE OF SECURITY INTEREST Recorded Oct 21, 2019
From: OBSIDIAN AGENCY SERVICES, INC.
To: ACRONIS INTERNATIONAL GMBH; GROUPLOGIC, INC.
Reel/Frame 050783/0893 →
SECURITY INTEREST Recorded Jul 26, 2017
From: ACRONIS INTERNATIONAL GMBH; GROUPLOGIC, INC.
To: OBSIDIAN AGENCY SERVICES, INC., AS COLLATERAL AGENT
Reel/Frame 043350/0186 →
Continuity (1)
Provisional Application 62168027 · May 29, 2015
Cited By (2)
US 12,250,291 US 12,488,391