IP Library Granted Patent US 11,829,506
Granted Patent B2
US 11,829,506 · App. 15/488,276 · Granted Nov 28, 2023

System and method for generation, storage, administration and use of one or more digital secrets in association with a portable electronic device

Inventor: Hans Reisgies (San Jose, CA)
Assignee: TIS INC.
G06F21/6245G06F21/45G06F21/606G06F21/6209G06F21/72H04L9/0897H04L2209/805
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,829,506
App. No.
15/488,276
Granted
Nov 28, 2023
Kind
B2
Abstract

A system for generation, storage, administration and use of one or more digital secrets in association with a portable electronic device. The system comprises a highly secured memory that stores only one or more master keys; a keystore implemented in the portable electronic device outside of the highly secured memory; one or more cryptography applets implemented in the portable electronic device outside of the highly secured memory; and a highly trusted intermediary module (ThIM) implemented outside of the highly secured memory, the ThIM establishes and manages a highly trusted communication conduit between the highly secured memory, the keystore, the one or more cryptography applets, and at least one third party application, wherein the ThIM polls the portable electronic device, the highly secured memory, the keystore, the one or more cryptography applets to determine a trust score, initialization cost, and transaction cost for each component in the portable electronic device, the ThIM providing a trusted third party application acceptable interaction parameters based on the trust score, the initialization cost, and the transaction cost, the ThIM managing highly trusted communications between the trusted third party application and the highly secured memory in accordance with the acceptable interaction parameters.

Claims (26)

1. A system for generation, storage, administration and use of one or more digital secrets in association with a portable electronic device, the system compromising:

a highly secured memory in the portable electronic device, storing only one or more issuer keys;

an other device memory in the portable electronic device which is distinct from the highly secured memory and is not comprised of either a physical secure element or a microprocessor with a trusted execution environment;

a keystore implemented in the portable electronic device outside of the highly secured memory in the other device memory;

one or more cryptography applets implemented in the portable electronic device outside of the highly secured memory in the other device memory; and

a trusted intermediary module (ThIM) implemented outside of the highly secured memory in the portable electronic device, the ThIM establishes and manages a trusted secured communication conduit between the highly secured memory, the keystore, the one or more cryptography applets, and at least one third party application, wherein the ThIM polls the portable electronic device, the highly secured memory, the keystore, the one or more cryptography applets to determine a trust score, initialization cost, and transaction cost for each component in the portable electronic device, the ThIM providing a trusted third party application acceptable interaction parameters based on the trust score, the initialization cost, and the transaction cost, the ThIM managing trusted communications between the trusted third party application and the highly secured memory in accordance with the acceptable interaction parameters;

wherein each of the one or more issuer keys comprises a cryptographic key provided for use by said at least one third party application.

2. The system of claim 1 , wherein the highly secured memory is selected from the group consisting of a physical secure element and a microprocessor with a trusted execution environment.

3. A system for generation, storage, administration and use of one or more digital secrets in association with a portable electronic device, the system compromising:

a highly secured memory in the portable electronic device, storing only one or more issuer keys;

an other device memory in the portable electronic device which is distinct from the highly secured memory and is not comprised of either a physical secure element or a microprocessor with a trusted execution environment;

a keystore implemented in the portable electronic device outside of the highly secured memory in the other device memory;

one or more cryptography applets implemented in the portable electronic device outside of the highly secured memory in the other device memory; and

a trusted intermediary module (ThIM) implemented outside of the highly secured memory in the portable electronic device, the ThIM establishes and manages a trusted communication conduit between the highly secured memory, the keystore, the one or more cryptography applets, and at least one third party application, wherein the ThIM polls the portable electronic device, the highly secured memory, the keystore, the one or more cryptography applets to determine a trust score for each component, the ThIM allowing a trusted third party application to determine acceptable interaction parameters based on the trust score, the ThIM managing trusted communications between the trusted third party application and the highly secured memory in accordance with the acceptable interaction parameters;

wherein each of the one or more issuer keys comprises a cryptographic key provided for use by said at least one third party application.

4. The system on claim 3 wherein the acceptable interaction parameters may further include unique data provided by the trusted third party application to the ThIM.

5. The system of claim 3 , wherein the highly secured memory is selected from the group consisting of a physical secure element and a microprocessor with a trusted execution environment.

6. A system for generation, storage, administration and use of one or more digital secrets implemented within a portable electronic device, the system compromising:

a highly secured memory in the portable electronic device, storing only one or more issuer keys;

an other device memory in the portable electronic device which is distinct from the highly secured memory and is not comprised of either a physical secure element or a microprocessor with a trusted execution environment;

a keystore implemented in the portable electronic device outside of the highly secured memory in the other device memory;

one or more cryptography applets implemented in the portable electronic device outside of the highly secured memory in the other device memory; and

a trusted intermediary module (ThIM) implemented outside of the highly secured memory in the portable electronic device;

wherein the ThIM establishes and manages a trusted secured communication conduit between the highly secured memory, the keystore, the one or more cryptography applets, and at least one third party application; and

wherein each of the one or more issuer keys comprises a cryptographic key provided for use by said at least one third party application.

7. The system of claim 6 , wherein the highly secured memory is selected from the group consisting of a physical secure element and a microprocessor with a trusted execution environment.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2023
From: SEQUENT SOFTWARE, INC.
To: TIS INC.
Reel/Frame 064105/0348 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2023
From: REISGIES, HANS
To: SEQUENT SOFTWARE INC.
Reel/Frame 063513/0906 →
SECURITY INTEREST Recorded Dec 22, 2022
From: SEQUENT SOFTWARE INC.
To: TIS INC.
Reel/Frame 062179/0639 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2020
From: GFA WORLDWIDE, INC.
To: SEQUENT SOFTWARE, INC.
Reel/Frame 051513/0424 →
SECURITY INTEREST Recorded Jun 27, 2019
From: SEQUENT SOFTWARE INC.; GFA WORLDWIDE, INC.
To: TIS INC.
Reel/Frame 049623/0638 →
RELEASE OF SECURITY INTEREST Recorded Jun 11, 2019
From: COMERICA BANK
To: SEQUENT SOFTWARE INC.
Reel/Frame 049437/0802 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2017
From: SEQUENT SOFTWARE, INC.
To: GFA WORLDWIDE, INC.
Reel/Frame 044432/0366 →
Continuity (2)
Provisional Application 62322288 · Apr 14, 2016
Related Publication 20170300716A1 · Oct 19, 2017