IP Library Granted Patent US 10,020,935
Granted Patent B1
US 10,020,935 · App. 15/469,871 · Granted Jul 10, 2018

Systems and methods for encryption and provision of information security using platform services

Inventors: Adam Ghetti (Atlanta, GA); Jeffrey Howard (Annapolis, MD); James Jordan (Roswell, GA); Nicholas Smith (Atlanta, GA); Jeremy Eckman (Annapolis, MD); Ryan Speers (Silver Spring, MD); Sohaib Bhatti (Canton, GA)
Assignee: Ionic Security Inc.
H04L9/083G06F21/62H04L9/0819H04L9/0861H04L63/04H04L63/0428H04L63/062H04L63/0815H04L63/10H04L63/102G06F2221/2113
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,020,935
App. No.
15/469,871
Granted
Jul 10, 2018
Kind
B1
Abstract

Systems and methods for securing or encrypting data or other information arising from a user's interaction with software and/or hardware, resulting in transformation of original data into ciphertext. Generally, the ciphertext is generated using context-based keys that depend on the environment in which the original data originated and/or was accessed. The ciphertext can be stored in a user's storage device or in an enterprise database (e.g., at-rest encryption) or shared with other users (e.g., cryptographic communication). The system generally allows for secure federation across organizations, including mechanisms to ensure that the system itself and any other actor with pervasive access to the network cannot compromise the confidentially of the protected data.

Claims (73)

1. A method for enrolling a user of an electronic computing device in a multi-party encryption and key management system, comprising the steps of:

receiving, at a server, an enrollment request from the electronic computing device corresponding to a user of the electronic computing device for enrollment in the multi-party encryption and key management system, the enrollment request comprising identity data corresponding to the user and routing data for routing the enrollment request, wherein at least the identity data is authenticated;

determining, based on the routing data, a key space corresponding to a tenant affiliated with the user;

transmitting the enrollment request from the server to a key service corresponding to the determined key space;

receiving, at the server, a response from the key service, wherein the response comprises a tenant-specific device identifier and cryptographic enrollment data for enrolling the user, wherein the response was generated at the key service based on the enrollment request; and

transmitting the cryptographic enrollment data and tenant-specific device identifier from the server to the electronic computing device for enrollment of the user with the multi-party encryption and key management system.

2. The method of claim 1 , wherein the identity data further comprises cryptographic information corresponding to the enrollment request.

3. The method of claim 2 , wherein the cryptographic enrollment data is encrypted by the key service using the cryptographic information corresponding to the enrollment request prior to transmission to the server.

4. The method of claim 2 , wherein the response further comprises the cryptographic information corresponding to the enrollment request.

5. The method of claim 4 , further comprising the steps of:

generating, at the server, cryptographic server enrollment data;

transforming the cryptographic server enrollment data using the cryptographic information corresponding to the enrollment request; and

transmitting the transformed cryptographic server enrollment data along with the transformed cryptographic enrollment data and tenant-specific device identifier from the server to the electronic computing device.

6. The method of claim 5 , further comprising the step of storing the cryptographic server enrollment data in association with the tenant-specific device identifier.

7. The method of claim 1 , wherein the identity data further comprises an enrollment request identifier.

8. The method of claim 7 , further comprising the steps of:

prior to receiving the enrollment request, generating, at an enrollment server, the enrollment request identifier;

generating an enrollment package comprising the enrollment request identifier and cryptographic information corresponding to the key service; and

transmitting the enrollment package to the electronic computing device, wherein at least the identity data is authenticated using the cryptographic information corresponding to the key service.

9. The method of claim 7 , further comprising the steps of:

prior to receiving the enrollment request, generating, at an enrollment server, the enrollment request identifier;

generating an enrollment package comprising the enrollment request identifier and cryptographic information corresponding to the key service;

receiving, at the enrollment server, a request for the enrollment package from the electronic computing device;

authenticating the request for the enrollment package; and

transmitting, based on the authentication, the enrollment package from the enrollment server to the electronic computing device, wherein the identity data is authenticated using the cryptographic information corresponding to the key service.

10. The method of claim 1 , wherein the multi-party encryption and key management system comprises the server.

11. The method of claim 1 , further comprising the step of extracting, at the server prior to the step of determining the key space, the routing data from the enrollment request.

12. The method of claim 11 , wherein the step of determining the key space further comprises analyzing the extracted routing data to determine the tenant affiliated with the user and then identifying the key space associated with the tenant affiliated with the user.

13. The method of claim 1 , wherein the step of determining the key space further comprises the step of determining, based on the key space, the key service corresponding to the determined key space.

14. The method of claim 1 , wherein the user comprises a computing service.

15. A system for enrolling a user of an electronic computing device in a multi-party encryption and key management system, comprising:

the electronic computing device that transmits, to a key service, an enrollment request corresponding to a user of the electronic computing device for enrollment in the multi-party encryption and key management system, the enrollment request comprising identity data corresponding to the user and routing data for routing the enrollment request, wherein at least the identity data is authenticated;

the key service that receives the enrollment request, wherein the key service generates, based on the enrollment request, a response comprising a tenant-specific device identifier and cryptographic enrollment data for enrolling the user and transmits the response to the electronic computing device; and

the electronic computing device that receives the response from the key service, wherein the electronic computing device enrolls the user, based on the cryptographic enrollment data and tenant-specific device identifier, in the multi-party encryption and key management system.

16. The system of claim 15 , wherein the electronic computing device, to transmit the enrollment request to the key service, transmits the enrollment request to a server, further comprising:

the server that receives the enrollment request from the electronic computing device, wherein the server determines, based on the routing data, a key space corresponding to a tenant affiliated with the user and transmits the enrollment request to the key service, wherein the key service corresponds to the determined key space.

17. The system of claim 16 , wherein the key service, to transmit the response to the electronic computing device, transmits the response to the server, further comprising:

the server that receives the response from the key service, wherein the server transmits the response to the electronic computing device.

18. The system of claim 17 , wherein the identity data further comprises cryptographic information corresponding to the enrollment request.

19. The system of claim 18 , wherein the key service encrypts, prior to transmission to the server, the cryptographic enrollment data using the cryptographic information corresponding to the enrollment request.

20. The system of claim 18 , wherein the response further comprises the cryptographic information corresponding to the enrollment request.

21. The system of claim 20 , wherein the server, after receiving the response from the key service:

generates cryptographic server enrollment data;

encrypts the cryptographic server enrollment data using the cryptographic information corresponding to the enrollment request; and

transmits the transformed cryptographic server enrollment data along with the transformed cryptographic enrollment data and tenant-specific device identifier to the electronic computing device.

22. The system of claim 17 , wherein the identity data further comprises an enrollment request identifier.

23. The system of claim 22 , further comprising an enrollment server, wherein the enrollment server, prior to receiving the enrollment request:

generates the enrollment request identifier;

generates an enrollment package comprising the enrollment request identifier and cryptographic information corresponding to the key service; and

transmits the enrollment package to the electronic computing device, wherein at least the identity data is authenticated using the cryptographic information corresponding to the key service.

24. The system of claim 22 , further comprising an enrollment server, wherein the enrollment server, prior to receiving the enrollment request:

generates the enrollment request identifier;

generates an enrollment package comprising the enrollment request identifier and cryptographic information corresponding to the key service;

receives a request for the enrollment package from the electronic computing device;

authenticates the request for the enrollment package; and

transmits, based on the authentication, the enrollment package to the electronic computing device, wherein the identity data is authenticated using the cryptographic information corresponding to the key service.

25. The system of claim 17 , wherein the multi-party encryption and key management system comprises the server.

26. The system of claim 17 , wherein the user comprises a computing service.

27. A method for enrolling a user of an electronic computing device in a multi-party encryption and key management system, comprising the steps of:

generating, at the electronic computing device, an enrollment request corresponding to a user of the electronic computing device for enrollment in the multi-party encryption and key management system, wherein the enrollment request comprises identity data corresponding to the user and routing data for routing the enrollment request;

cryptographically signing, at the electronic computing device, at least the identity data with cryptographic information;

transmitting the enrollment request from the electronic computing device to a server; and

receiving, at the electronic computing device, a response from the server, wherein the response comprises a tenant-specific device identifier and cryptographic enrollment data for enrolling the user, wherein the response was generated both at the server and a key service capable of verifying the cryptographically-signed identity data.

28. The method of claim 27 , wherein the identity data further comprises first cryptographic information corresponding to the enrollment request.

29. The method of claim 28 , wherein the cryptographic enrollment data comprises cryptographic key service enrollment data and cryptographic server enrollment data, wherein at least the cryptographic key service enrollment data was authenticated by the key service using the first cryptographic information corresponding to the enrollment request and at least the cryptographic server enrollment data was authenticated by the server.

30. The method of claim 29 , wherein the electronic computing device decrypts at least the cryptographic key service enrollment data and the cryptographic server enrollment data using second cryptographic information corresponding to the enrollment request.

31. The method of claim 27 , wherein the identity data further comprises an enrollment request identifier.

32. The method of claim 31 , further comprising the steps of:

prior to generating the enrollment request, generating a request for an enrollment package from an enrollment server;

transmitting the request for the enrollment package from the electronic computing device to the enrollment server;

receiving, at the electronic computing device, the enrollment package from the server, wherein the enrollment package comprises the enrollment request identifier and cryptographic information corresponding to the key service; and

encrypting the identity data using the cryptographic information corresponding to the key service.

33. The method of claim 27 , wherein the multi-party encryption and key management system comprises the server.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Apr 14, 2021
From: SILICON VALLEY BANK
To: IONIC SECURITY INC.
Reel/Frame 055918/0374 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 22, 2020
From: IONIC SECURITY INC.
To: SILICON VALLEY BANK
Reel/Frame 051662/0386 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR SOHAIB BHATTI'S FIRST NAME PREVIOUSLY RECORDED ON REEL 041751 FRAME 0089. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 5, 2017
From: GHETTI, ADAM; HOWARD, JEFFREY; JORDAN, JAMES; SMITH, NICHOLAS; ECKMAN, JEREMY; SPEERS, RYAN; BHATTI, SOHAIB
To: IONIC SECURITY INC.
Reel/Frame 042160/0682 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2017
From: GHETTI, ADAM; HOWARD, JEFFREY; JORDAN, JAMES; SMITH, NICHOLAS; ECKMAN, JEREMY; SPEERS, RYAN; BHATTI, BHATTI
To: IONIC SECURITY INC.
Reel/Frame 041751/0089 →
Continuity (2)
Continuation 15017284 · Feb 5, 2016
Provisional Application 62112638 · Feb 5, 2015
Cited By (3)
US 12,413,562 US 12,659,330 US 12,694,139