IP Library Granted Patent US 10,498,704
Granted Patent B2
US 10,498,704 · App. 16/409,380 · Granted Dec 3, 2019

System and method for enhanced data protection

Inventors: Cody Pollet (Austin, TX); Charles Burgess (Cedar Park, TX); Courtney Roach (Frisco, TX); Brandon Hart (Dallas, TX)
Assignee: Encryptics, LLC
H04L63/0435H04L63/0442H04L63/08H04L2463/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,498,704
App. No.
16/409,380
Granted
Dec 3, 2019
Kind
B2
Abstract

In one embodiment, a method of secure network transmission is performed by a computer system. The method includes encrypting a payload via a first symmetric key and encrypting the first symmetric key via a second symmetric key. The method further includes encrypting an author header comprising the encrypted first symmetric key and a recipient list via a third symmetric key, wherein the recipient list comprises at least one recipient. The method also includes encrypting the third symmetric key via a public asymmetric key associated with an authentication server. Furthermore, the method includes transmitting the encrypted author header and the encrypted third symmetric key to the authentication server for use in recipient-initiated pre-access authentication. In addition, the method includes transmitting the encrypted payload and the second symmetric key over a computer network to the at least one recipient.

Claims (48)

1. A method comprising, by a computer system:

receiving a transmission comprising a container that encapsulates:

an encrypted payload, wherein the encrypted payload has been encrypted via a first symmetric key; and

a second symmetric key;

generating a recipient header comprising metadata related to the encrypted payload;

transmitting the recipient header to an authentication server so as to initiate pre-access authentication using a particular authentication header relating to the transmission, the particular authentication header comprising:

a third symmetric key that is distinct from the first symmetric key and the second symmetric key; and

an author header that has been encrypted via the third symmetric key, the author header comprising an encrypted subportion that has been encrypted via the second symmetric key, the encrypted subportion comprising the first symmetric key;

responsive to the transmitting, receiving an encrypted package from the authentication server, wherein the encrypted package has been encrypted via a public asymmetric key associated with the recipient, the encrypted package comprising the encrypted subportion;

decrypting the encrypted package via a private asymmetric key associated with the computer system;

decrypting the first symmetric key from the encrypted subportion via the second symmetric key; and

decrypting the encrypted payload via the decrypted first symmetric key.

2. The method of claim 1 , wherein the received transmission comprises at least a portion of the metadata related to the encrypted payload.

3. The method of claim 1 , wherein the recipient header comprises user credentials associated with the computer system.

4. The method of claim 1 , wherein the recipient header comprises the public asymmetric key associated with the computer system.

5. The method of claim 1 , wherein receipt of the encrypted package is indicative of successful authentication by the authentication server.

6. A computer system comprising a processor and memory, wherein the processor and memory in combination are operable to perform a method comprising:

receiving a transmission comprising a container that encapsulates:

an encrypted payload, wherein the encrypted payload has been encrypted via a first symmetric key; and

a second symmetric key;

generating a recipient header comprising metadata related to the encrypted payload;

transmitting the recipient header to an authentication server so as to initiate pre-access authentication using a particular authentication header relating to the transmission, the particular authentication header comprising:

a third symmetric key that is distinct from the first symmetric key and the second symmetric key; and

an author header that has been encrypted via the third symmetric key, the author header comprising an encrypted subportion that has been encrypted via the second symmetric key, the encrypted subportion comprising the first symmetric key;

responsive to the transmitting, receiving an encrypted package from the authentication server, wherein the encrypted package has been encrypted via a public asymmetric key associated with the recipient, the encrypted package comprising the encrypted subportion;

decrypting the encrypted package via a private asymmetric key associated with the computer system;

decrypting the first symmetric key from the encrypted subportion via the second symmetric key; and

decrypting the encrypted payload via the decrypted first symmetric key.

7. The computer system of claim 6 , wherein the received transmission comprises at least a portion of the metadata related to the encrypted payload.

8. The computer system of claim 6 , wherein the recipient header comprises user credentials associated with the computer system.

9. The computer system of claim 6 , wherein the recipient header comprises the public asymmetric key associated with the computer system.

10. The computer system of claim 6 , wherein receipt of the encrypted package is indicative of successful authentication by the authentication server.

11. A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method performed by a computer system, the method comprising:

receiving a transmission comprising a container that encapsulates:

an encrypted payload, wherein the encrypted payload has been encrypted via a first symmetric key; and

a second symmetric key;

generating a recipient header comprising metadata related to the encrypted payload;

transmitting the recipient header to an authentication server so as to initiate pre-access authentication using a particular authentication header relating to the transmission, the particular authentication header comprising:

a third symmetric key that is distinct from the first symmetric key and the second symmetric key; and

an author header that has been encrypted via the third symmetric key, the author header comprising an encrypted subportion that has been encrypted via the second symmetric key, the encrypted subportion comprising the first symmetric key;

responsive to the transmitting, receiving an encrypted package from the authentication server, wherein the encrypted package has been encrypted via a public asymmetric key associated with the recipient, the encrypted package comprising the encrypted subportion;

decrypting the encrypted package via a private asymmetric key associated with the computer system;

decrypting the first symmetric key from the encrypted subportion via the second symmetric key; and

decrypting the encrypted payload via the decrypted first symmetric key.

12. The computer-program product of claim 11 , wherein the received transmission comprises at least a portion of the metadata related to the encrypted payload.

13. The computer-program product of claim 11 , wherein the recipient header comprises user credentials associated with the computer system.

14. The computer-program product of claim 11 , wherein the recipient header comprises the public asymmetric key associated with the computer system.

15. The computer-program product of claim 11 , wherein receipt of the encrypted package is indicative of successful authentication by the authentication server.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2020
From: ENCRYPTICS, LLC
To: KEYAVI DATA CORP
Reel/Frame 053771/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2019
From: POLLET, CODY; BURGESS, CHARLES; ROACH, COURTNEY; HART, BRANDON
To: ENCRYPTICS, LLC
Reel/Frame 050778/0437 →
Continuity (4)
Continuation 15946965 · Apr 6, 2018
Continuation 15136142 · Apr 22, 2016
Provisional Application 62152178 · Apr 24, 2015
Related Publication 20190334878A1 · Oct 31, 2019