IP Library Granted Patent US 10,511,436
Granted Patent B1
US 10,511,436 · App. 15/664,250 · Granted Dec 17, 2019

Protecting key material using white-box cryptography and split key techniques

Inventor: Salah Machani (Thornhill, CA)
Assignee: EMC IP Holding Company LLC
H04L9/085H04L9/0822H04L9/14H04L9/30H04L9/3247H04L9/3263H04L9/3271H04L2209/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,511,436
App. No.
15/664,250
Granted
Dec 17, 2019
Kind
B1
Abstract

Key material is protected using white-box cryptography and split key techniques. An exemplary method comprises splitting a secret key of a software application provider into a plurality of key shares, wherein a subset of the plurality of key shares is needed to reconstruct the secret key; using one key share to encrypt the remaining key shares to obtain a set of wrapped key shares; applying the one key share to a white-box cryptography compiler to generate a white-box cryptographic program; generating a user application linked to the white-box cryptography program; distributing the user application to a user; and providing one wrapped key share to a relying party, wherein, the relying party provides a challenge and the one wrapped key share of the relying party to the user application, wherein the user application provides the one wrapped key share of the relying party to the white-box cryptographic program and obtains a digital signature for the relying party, and wherein the relying party verifies the signature.

Claims (45)

1. A method, comprising:

splitting a secret key of a software application provider into a plurality of key shares, wherein a subset of said plurality of key shares is needed to reconstruct said secret key;

using one of said plurality of key shares to encrypt the remaining key shares of said plurality of key shares to obtain a set of wrapped key shares;

applying said one key share to a white-box cryptography compiler to generate a white-box cryptographic program;

generating a user application that is linked to the white-box cryptography program;

distributing said user application to at least one user; and

providing one of said set of wrapped key shares to a relying party,

wherein, upon said user application of said at least one user attempting to access a resource protected by said relying party, said relying party provides a challenge and said one wrapped key share of said relying party to said user application, wherein said user application provides at least said one wrapped key share of said relying party to said white-box cryptographic program to obtain a digital signature in response to said challenge to provide to said relying party, and wherein said relying party verifies the signature to determine whether the user device is authorized to access the resource.

2. The method of claim 1 , wherein said secret key comprises a private key of a public/private key pair, wherein said step of providing said one wrapped key share to said relying party further comprises providing a public key certificate of said public/private key pair to said relying party, and wherein said relying party verifies the signature using the public key certificate of the software application provider to verify one or more of whether the user device is authorized to access the resource and an authenticity of an application attempting to access said resource.

3. The method of claim 1 , wherein said secret key comprises a master key used for one or more of encryption/decryption of data, secure communication between a client and a server, deriving other keys, and user authentication, wherein said master key is split into a plurality of master key shares, and wherein said master key and one wrapped master key share are sent securely to said relying party.

4. The method of claim 1 , wherein said user application provides said at least said one wrapped key share of said relying party and said challenge to said white-box cryptographic program and wherein said white-box cryptographic program generates said digital signature in response to said challenge that said user application provides to said relying party.

5. The method of claim 1 , wherein said user application provides said one wrapped key share of said relying party to said white-box cryptographic program, and wherein said white-box cryptographic program uses said one key share to unwrap said one wrapped key share of said relying party, generates said secret key of said software application provider and provides said secret key to said user application, wherein said user application generates said digital signature in response to said challenge to provide to said relying party.

6. The method of claim 1 , wherein the step of distributing said user application to at least one user comprises publishing the application to an application store for distributions to said at least one user.

7. The method of claim 1 , wherein the step of providing one of said set of wrapped key shares to said relying party is performed by one or more middleware entities.

8. A computer program product, comprising a tangible machine-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by at least one processing device perform the following steps:

splitting a secret key of a software application provider into a plurality of key shares,

wherein a subset of said plurality of key shares is needed to reconstruct said secret key;

using one of said plurality of key shares to encrypt the remaining key shares of said plurality of key shares to obtain a set of wrapped key shares;

applying said one key share to a white-box cryptography compiler to generate a white-box cryptographic program;

generating a user application that is linked to the white-box cryptography program;

distributing said user application to at least one user; and

providing one of said set of wrapped key shares to a relying party,

wherein, upon said user application of said at least one user attempting to access a resource protected by said relying party, said relying party provides a challenge and said one wrapped key share of said relying party to said user application, wherein said user application provides at least said one wrapped key share of said relying party to said white-box cryptographic program to obtain a digital signature in response to said challenge to provide to said relying party, and wherein said relying party verifies the signature to determine whether the user device is authorized to access the resource.

9. The computer program product of claim 8 , wherein said secret key comprises a private key of a public/private key pair, wherein said step of providing said one wrapped key share to said relying party further comprises providing a public key certificate of said public/private key pair to said relying party, and wherein said relying party verifies the signature using the public key certificate of the software application provider to verify one or more of whether the user device is authorized to access the resource and an authenticity of an application attempting to access said resource.

10. The computer program product of claim 8 , wherein said secret key comprises a master key used for one or more of encryption/decryption of data, secure communication between a client and a server, deriving other keys, and user authentication, wherein said master key is split into a plurality of master key shares, and wherein said master key and one wrapped master key share are sent securely to said relying party.

11. The computer program product of claim 8 , wherein said user application provides said at least said one wrapped key share of said relying party and said challenge to said white-box cryptographic program and wherein said white-box cryptographic program generates said digital signature in response to said challenge that said user application provides to said relying party.

12. The computer program product of claim 8 , wherein said user application provides said one wrapped key share of said relying party to said white-box cryptographic program, and wherein said white-box cryptographic program uses said one key share to unwrap said one wrapped key share of said relying party, generates said secret key of said software application provider and provides said secret key to said user application, wherein said user application generates said digital signature in response to said challenge to provide to said relying party.

13. The computer program product of claim 8 , wherein the step of providing one of said set of wrapped key shares to said relying party is performed by one or more middleware entities.

14. A system, comprising:

a memory; and

at least one processing device, coupled to the memory, operative to implement the following steps:

splitting a secret key of a software application provider into a plurality of key shares,

wherein a subset of said plurality of key shares is needed to reconstruct said secret key;

using one of said plurality of key shares to encrypt the remaining key shares of said plurality of key shares to obtain a set of wrapped key shares;

applying said one key share to a white-box cryptography compiler to generate a white-box cryptographic program;

generating a user application that is linked to the white-box cryptography program;

distributing said user application to at least one user; and

providing one of said set of wrapped key shares to a relying party,

wherein, upon said user application of said at least one user attempting to access a resource protected by said relying party, said relying party provides a challenge and said one wrapped key share of said relying party to said user application, wherein said user application provides at least said one wrapped key share of said relying party to said white-box cryptographic program to obtain a digital signature in response to said challenge to provide to said relying party, and wherein said relying party verifies the signature to determine whether the user device is authorized to access the resource.

15. The system of claim 14 , wherein said secret key comprises a private key of a public/private key pair, wherein said step of providing said one wrapped key share to said relying party further comprises providing a public key certificate of said public/private key pair to said relying party, and wherein said relying party verifies the signature using the public key certificate of the software application provider to verify one or more of whether the user device is authorized to access the resource and an authenticity of an application attempting to access said resource.

16. The system of claim 14 , wherein said secret key comprises a master key used for one or more of encryption/decryption of data, secure communication between a client and a server, deriving other keys, and user authentication, wherein said master key is split into a plurality of master key shares, and wherein said master key and one wrapped master key share are sent securely to said relying party.

17. The system of claim 14 , wherein said user application provides said at least said one wrapped key share of said relying party and said challenge to said white-box cryptographic program and wherein said white-box cryptographic program generates said digital signature in response to said challenge that said user application provides to said relying party.

18. The system of claim 14 , wherein said user application provides said one wrapped key share of said relying party to said white-box cryptographic program, and wherein said white-box cryptographic program uses said one key share to unwrap said one wrapped key share of said relying party, generates said secret key of said software application provider and provides said secret key to said user application, wherein said user application generates said digital signature in response to said challenge to provide to said relying party.

19. The system of claim 14 , wherein the step of distributing said user application to at least one user comprises publishing the application to an application store for distributions to said at least one user.

20. The system of claim 14 , wherein the step of providing one of said set of wrapped key shares to said relying party is performed by one or more middleware entities.

Assignments (20)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDINGS COMPANY LLC
Reel/Frame 054510/0818 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (043775/0082) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 054166/0131 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 5, 2018
From: MACHANI, SALAH
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 045987/0803 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 043775/0082 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 043772/0750 →
Cited By (12)
US 12,200,099 US 12,223,097 US 12,244,697 US 12,425,233 US 12,445,277 US 12,476,826 US 12,483,397 US 12,494,922 US 12,499,206 US 12,542,658 US 12,647,282 US 12,712,713