IP Library › Granted Patent US 10,523,644
Granted Patent B2
US 10,523,644 · App. 15/284,083 · Granted Dec 31, 2019

System and method for secure digital sharing based on an inter-system exchange of a two-tier double encrypted digital information key

Inventor: Oliver Werneyer (Zurich, CH)
Assignee: SWISS REINSURANCE COMPANY LTD.
H04L63/061G06F21/6218H04L63/0281H04L63/0442
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,523,644
App. No.
15/284,083
Granted
Dec 31, 2019
Kind
B2
Abstract

A system based on layered, two-tier double cryptographic keys providing a closed cryptosystem within a secured network environment, the system including a digital key management device and a network node. The digital key management device generates a first-tier cryptographic key, a second-tier cryptographic key and makes the first-tier and second-tier cryptographic keys publicly accessible within a first and a second secured walled regions that are accessible to a network node registered to a first authentication database associated with an access server of the system, encrypts a first and second content with the first-tier and second-tier cryptographic keys, and generates encrypted first and second content. The network node requests access to the first secured walled region, accesses the first-tier and the second-tier cryptographic keys, decrypts the first and second content, generates first and second data containers based on the decrypted content, and transfers the data containers to a client device.

Claims (46)

1. A system based on layered, two-tier double cryptographic keys providing a closed cryptosystem for secure content distribution within a secured network environment, the system comprising:

a digital key management device including digital key management circuitry configured to generate a first-tier cryptographic key and make the first-tier cryptographic key publicly accessible within a first secured walled region, wherein the first secured walled region is accessible to a supply network node registered to a first authentication database associated with an access server of the system, encrypt first content with the first-tier cryptographic key, generate encrypted first content,

generate a second-tier cryptographic key and make the second-tier cryptographic key publicly accessible to the supply network node within a second secured walled region,

encrypt second content with the second-tier cryptographic key, and generate encrypted second content,

supply network nodes including node circuitries configured to request, via a network interface, access to the first secured walled region, wherein the access server enables access to the first secured walled region for the supply network node upon authentication and/or authorization by the first authentication database, the first secured walled region being accessible to any supply network node registered to the first authentication database associated with the access server of the system,

access the first-tier cryptographic key via the first secured walled region, access and decrypt the encrypted first content using the first-tier cryptographic key,

generate a first data container based on the decrypted first content, transfer the first data container to a client device, wherein the digital key management circuitry assigns the client device the first-tier cryptographic key, and wherein the assignment is accessible to the supply network nodes registered to the first authentication database,

request access to the second secured walled region, wherein the access server enables access to the second secured walled region for the supply network nodes upon authentication and/or authorization from a second authentication database associated with the access server,

access the second-tier cryptographic key via the secured second walled region, access and decrypt the encrypted second content using the second-tier cryptographic key,

generate a second data container based on the decrypted second content, and transfer the second data container to the client device, wherein the digital key management circuitry is further configured to receive a first acceptance-confirmation of the content of the first data container, via the network interface, from the client device, and receive a second acceptance-confirmation of the content of the second data container, via the network interface, from the client device.

2. The system according to claim 1 , further comprising:

a billing gateway interface including billing gateway circuitry configured to access the access server and retrieve first access detail records of the supply network node; and

an assigned billing management database with first access and billing control data of each supply network node based on the access of the supply network node to the first-tier cryptographic key and/or encrypted first content.

3. The system according to claim 2 , wherein the first access detail records are generated upon the authentication and/or authorization from the first authentication database.

4. The system according to claim 2 , wherein the billing gateway circuitry is further configured to:

access the access server and retrieve second access detail records of the supply network node,

the billing management database comprising second access control data of each supply network node based on the access of the supply network node to the second-tier cryptographic key and/or encrypted second content.

5. The system according to claim 4 , wherein the second access detail records are generated upon the authentication and/or authorization by the second authentication database.

6. The system according to claim 5 , wherein the billing gateway circuitry is further configured to bill the supply network node for the access to the obtained first-tier cryptographic key and/or the obtained second-tier cryptographic key.

7. The system according to claim 6 , wherein only access to the second-tier cryptographic key and/or encrypted second content is billed, while the first-tier cryptographic key is made publicly accessible within the first secured walled region without billing.

8. The system according to claim 1 , wherein the first secured walled region and/or the second secured walled region is realized as a secured network region or a secured memory region blocked by controlling data transfers using a secure gateway control circuit or a Memory Management Unit (MMU).

9. The system according to claim 1 , wherein the first and/or second acceptance-confirmation is realized as transfer of a secured data packet structure comprising the acceptance-confirmation.

10. The system according to claim 9 , wherein the secured data packet structure includes secured packets containing application messages to which specific mechanisms are applicable,

wherein the application messages comprise commands and/or data exchanged between an application resident in the digital key management circuitry, and

wherein the digital key management circuitry is further configured to apply one or more security mechanisms to the application messages to turn the application messages into secured packets.

11. The system according to claim 10 , wherein the first authentication database includes first authentication circuitry configured to:

receive a license number associated with the supply network node,

retrieve a hardware fingerprint associated with the supply network node based on the license number, the hardware fingerprint being a unique identifier associated with the supply network node, and

determine whether the supply network node is registered with the digital key management circuitry based on the hardware fingerprint and the license number.

12. The system according to claim 1 , wherein the encryption of the first content with the first-tier cryptographic key and the encryption of the second content with the second-tier cryptographic key uses a single type of encryption,

wherein the digital key management circuitry is further configured to provide the encrypted content to the supply network node associated with the first-tier cryptographic key and the second-tier cryptographic key, and

wherein the first-tier cryptographic key and the second-tier cryptographic key are encrypted based on a hardware fingerprint of the supply network node and a private key stored at the supply network node.

13. The system according to claim 12 , wherein the digital key management circuitry is further configured to:

generate a first data stream including the encrypted first data content,

generate a locator for the encrypted first data content, and

generate a second data stream including the first cryptographic key and the locator of the content.

14. The system according to claim 12 , wherein the digital key management circuitry is further configured to:

generate a third data stream including the encrypted second data content,

generate a locator for the encrypted first data content, and

generate a third data stream including the second cryptographic key and the locator of the content.

15. The system according to claim 12 , wherein the private key stored in the supply network node is in an encrypted format, and

wherein the node circuitry is further configured to

decrypt the encrypted private key using a key derived from a the hardware fingerprint of the supply network node, and

decrypt the encrypted first cryptographic key and/or second cryptographic key using the decrypted stored private key.

16. The system according to claim 1 , wherein the second data container comprises different policies, wherein each of the different policies controls consumption of automatic risk transfer between the supply network node and the client device.

17. The system according to claim 1 , wherein the first secured walled region and/or the second secured walled region are segregated physically and/or logically from the rest of the system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2019
From: WERNEYER, OLIVER
To: SWISS REINSURANCE COMPANY LTD.
Reel/Frame 050758/0448 →
Continuity (2)
Continuation PCTEP2015071621 · Sep 21, 2015
Related Publication 20170093826A1 · Mar 30, 2017