IP Library Granted Patent US 11,044,091
Granted Patent B1
US 11,044,091 · App. 16/129,698 · Granted Jun 22, 2021

System and method for securely transmitting non-pki encrypted messages

Inventors: Michael R. Feinberg (Irvine, CA); Richard J. Blech (Irvine, CA)
Assignee: Secure Channels Inc.
H04L9/3213H04L9/0656H04L9/0861H04L63/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,044,091
App. No.
16/129,698
Granted
Jun 22, 2021
Kind
B1
Abstract

An embodiment of an automatic key delivery system is described, An automatic key delivery system comprises the following operations. Herein, a first token is generated and provided to a first network device. Thereafter, a first key value pair, including the first token and a first key segment of a cryptographic key, is received by a first relay server and a second key value pair, including the first token and a second key segment of the cryptographic key, is received from a second relay server. In response, a second token to be provided to the first relay server and the second relay server. Thereafter, the first and second key segment are returned from the first and second relay servers based on usage of the second token as a lookup in order to recover the cryptographic key for decryption of an encrypted content from the first network device.

Claims (39)

1. A computerized method comprising:

generating a first token;

providing the first token to a first network device;

receiving a first key value pair including the first token and a first key segment of a cryptographic key by a first relay server and receiving a second key value pair including the first token and a second key segment of the cryptographic key from a second relay server different than the first relay server;

generating a second token to be provided to the first relay server and the second relay server in response to a change token request message from both the first relay server and the second relay server; and

returning the first key segment from the first relay server and the second key segment by the second relay server in response to receipt of a message requesting key segments associated with the cryptographic key and the message including the second token to recover the cryptographic key for decryption of an encrypted content from the first network device.

2. The computerized method of claim 1 further comprising:

maintaining a count value representing a number of tokens issued for a subscriber associated with the first network device for use in encrypting transmissions.

3. The computerized method of claim 1 , wherein the maintaining of the count value further comprising incrementing the count value pertaining to the subscriber in response to providing the first token to the first network device, the count value being used to determine a monetary amount to debit a pre-paid account associated with the subscriber.

4. The computerized method of claim 1 , wherein prior to returning the first key segment from the first relay server and the second segment by the second relay server, the method further comprising:

receiving a message from a second network device inquiring of a converted token value based on the first token; and

returning a message including the second token in response to receipt of the first token.

5. The computerized method of claim 1 , wherein the receiving of the first key value pair by the first relay server and the receiving of the second key value pair by the second relay server comprises

receiving the first key value pair including the first token and the first key segment of the cryptographic key by a third relay server and receiving the second key value pair including the first token and the second key segment of the cryptographic key by a fourth second relay server different than the third relay server; and

automatically retransmitting the first key value pair from the third relay server to the first relay server and the second key value pair from the fourth relay server to the second relay server.

6. The computerized method of claim 5 , wherein the first relay server, the second relay server, the third relay server and the fourth relay server within a public cloud network.

7. The computerized method of claim 1 , wherein the generating of second token to be provided to the first relay server and the second relay server is conducted by a token authority server including a token data store, token reassignment logic that, in response to the token change request message, generates the second token and associates the first token with the second token as a corresponding token pair with an entry of a data structure of the token data store, and a token lookup logic configured to access one or more entries within the data structure of the token data store using the first token as a lookup to recover the second token.

8. The computerized method of claim 1 , wherein the first relay server and the second relay server are deployed within a public cloud network.

9. The computerized method of claim 2 , wherein the generating of second token to be provided to the first relay server and the second relay server is conducted by a token authority server including a token data store, token reassignment logic that, in response to the token change request message, generates the second token and associates the first token with the second token as a corresponding token pair with an entry of a data structure of the token data store, and token counter logic that is configured to maintain and increase the count value associated with the subscriber, where the count value may be subsequently upload for billing of the subscriber via debiting a pre-paid account for the subscriber.

10. A computerized method comprising:

receiving a first key value pair including a first token and a first key segment of a cryptographic key from a first source and receiving a second key value pair including the first token and a second key segment of the cryptographic key from a second source different than the first source;

generating a second token to be provided to the first source and the second source in response to a change token request message from both the first source and the second source; and

returning the first key segment from the first source and the second key segment by the second source in response to receipt of one or more messages requesting key segments associated with the cryptographic key, the one or more messages including the second token for use by the first source to recover the first key segment and by the second source to recover the second key segment,

wherein the first key segment and the second key segment collectively forming the cryptographic key for decryption of an encrypted content transmitted over a network.

11. The computerized method of claim 10 further comprising:

generating a first token; and

providing the first token to a first network device that transmits the first key value pair to the first source and the second key value pair to the second source to transfer the cryptographic key from a first network device transmitting the encrypted content to a second network device receiving the encrypted content.

12. The computerized method of claim 11 further comprising:

maintaining a count value representing a number of tokens issued for a subscriber associated with the first network device for use in encrypting transmissions.

13. The computerized method of claim 12 , wherein the maintaining of the count value further comprising incrementing the count value pertaining to the subscriber in response to providing the first token to the first network device, the count value being used to determine a monetary amount to debit a pre-paid account associated with the subscriber.

14. The computerized method of claim 10 , wherein prior to returning the first key segment from the first relay server and the second segment by the second relay server, the method further comprising:

receiving a message from a second network device targeted to receive the encrypted content, the message inquiring of a converted token value based on the first token; and

returning a message including the second token in response to receipt of the first token.

15. The computerized method of claim 10 , wherein the receiving of the first key value pair from the first source and the receiving of the second key value pair from the second source comprises

receiving the first key value pair including the first token and the first key segment of the cryptographic key by a third source and receiving the second key value pair including the first token and the second key segment of the cryptographic key by a fourth source different than the third source; and

automatically retransmitting the first key value pair from the third source to the first source and the second key value pair from the fourth source to the second source.

16. The computerized method of claim 15 , wherein the first source, the second source, the third source and the fourth source being deployed as relay servers within a public cloud network.

17. The computerized method of claim 10 , wherein the generating of second token to be provided to the first source and the second source is conducted by a token authority server including a token data store, token reassignment logic that, in response to the token change request message, generates the second token and associates the first token with the second token as a corresponding token pair with an entry of a data structure of the token data store, and a token lookup logic configured to access one or more entries within the data structure of the token data store using the first token as a lookup to recover the second token.

18. The computerized method of claim 10 , wherein the first source and the second source comprise a plurality of relay servers deployed within a public cloud network.

Assignments (5)
FOUNDERS AGREEMENT Recorded Jun 3, 2022
From: BLECH, RICHARD J
To: SECURE CHANNELS INC
Reel/Frame 060269/0322 →
SECURITY INTEREST Recorded Apr 6, 2021
From: SECURE CHANNELS, INC.
To: PETNEDA HOLDINGS LIMITED
Reel/Frame 055843/0642 →
FIRST AMENDMENT TO ASSIGNMENT AND ASSUMPTION OF CONTRACTS Recorded Apr 6, 2021
From: PETNEDA HOLDINGS LIMITED
To: CHOL, INC.
Reel/Frame 055846/0320 →
ASSIGNMENT AND ASSUMPTION OF CONTRACTS Recorded Apr 6, 2021
From: PETNEDA HOLDINGS LIMITED
To: CHOL, INC.
Reel/Frame 055846/0722 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2021
From: FEINBERG, MICHAEL R.
To: SECURE CHANNELS INC.
Reel/Frame 055450/0613 →
Continuity (1)
Provisional Application 62643645 · Mar 15, 2018