IP Library Granted Patent US 11,777,720
Granted Patent B2
US 11,777,720 · App. 16/900,391 · Granted Oct 3, 2023

Distributed anonymized compliant encryption management system

Inventor: Tommaso Gagliardoni (Lausanne, CH)
Assignee: NAGRAVISION SÀRL
H04L9/085H04L9/3268H04L63/0421H04L63/0428H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,777,720
App. No.
16/900,391
Granted
Oct 3, 2023
Kind
B2
Abstract

A method for data security implemented as an application on a device includes generating a request for one or more secret shares needed to reconstruct a key. The device stores a first secret share in its memory. The method also includes signing the request with a certificate that identifies the request as valid without identifying the device, and sending the request, signed with the certificate, to at least one other device. The method further includes receiving, from the at least one other device, the one or more secret shares, determining whether the one or more secret shares received from the at least one other device is sufficient to reconstruct the key, and reconstructing the key using the first secret share and the one or more secret shares upon determining that the one or more secret shares are sufficient to reconstruct the key.

Claims (52)

1. A method for data security implemented as an application on a first device, comprising:

generating a request for secret shares needed to reconstruct a key from the secret shares;

signing the request with a certificate that identifies the request as valid using a pseudonym of the first device;

sending the request, signed with the certificate, to at least one second device without identifying the first device;

receiving, from the at least one second device, one or more secret shares in a multi-party computation view;

determining whether the one or more secret shares received from the at least one second device are sufficient to reconstruct the key; and

reconstructing the key using the one or more secret shares upon determining that the one or more secret shares are sufficient to reconstruct the key.

2. The method according to claim 1 , further comprising:

retrieving encrypted data from a data storage device using the key reconstructed from the one or more secret shares.

3. The method according to claim 2 , wherein the encrypted data is retrieved by decrypting the data with the key reconstructed from the one or more secret shares.

4. The method according to claim 1 , wherein the first device sends the request to the at least one second device by uploading the request to a distributed ledger which the at least one second device monitors.

5. The method according to claim 4 , wherein the first device anonymously uploads the request to the distributed ledger.

6. The method according to claim 5 , wherein the first device anonymously uploads the request to the distributed ledger using The Onion Router (Tor).

7. The method according to claim 4 , wherein the distributed ledger is a block chain.

8. The method according to claim 1 , further comprising:

receiving a first secret share from a server that manages the secret shares and the key, the first secret share being one of the one or more secret shares; and

combining the one or more secret shares to reconstruct the key.

9. The method according to claim 1 , wherein the one or more secret shares received by the first device include signatures based on at least one certificate of the at least one second device from which the one or more secret shares are received.

10. The method according to claim 9 , further comprising validating the one or more secret shares received based on the signatures included therein.

11. The method according to claim 10 , wherein, as part of the validating, the method further comprises querying a server that manages device certificates to determine whether the signatures included in the one or more secret shares are valid.

12. The method according to claim 10 , wherein, as part of the validating, the method further comprises determining validity of the one or more secret shares based on a list obtained from a distributed ledger and the signatures included in the one or more secret shares.

13. The method according to claim 12 , wherein the list is a certificate revocation list, and the first device determines the request to be invalid if a certificate with which the request is signed is indicated as invalid in the certificate revocation list.

14. The method according to claim 1 , further comprising:

receiving an other request from another device;

validating the other request based on internal policies of the first device; and

sending a first secret share to the other device when the other request is determined to be valid.

15. The method according to claim 14 , further comprising:

using regional information to validate the other request; and

determining the other request to be invalid if the regional information indicates that the other device is not in a region where data encrypted by the key can be accessed.

16. A data security system, comprising:

a first device configured to:

encrypt data using a key and transmit the encrypted data to a data storage device via a network,

generate secret shares based on the key, and

distribute, using a multi-party computation view, the secret shares to a plurality of terminals via the network;

a second device configured to:

generate certificates corresponding to the plurality of terminals, each of the certificates including a pseudonym of a respective one of the plurality of terminals and validating communications from the respective one of the plurality of terminals without disclosing an identity of the respective one of the plurality of terminals, and

distribute the certificates to the plurality of terminals via the network; and

the plurality of terminals, each of the plurality of terminals being configured to:

store one of the secret shares distributed by the first device,

generate a request signed with a respective one of the certificates distributed by the second device,

anonymously transmit the request to at least one other terminal of the plurality of terminals,

anonymously receive responses from the at least one other terminal of the plurality of terminals, the responses including one or more secret shares distributed by the first device,

reconstruct the key using the one or more secret shares, and

access the encrypted data stored in the data storage device using the key.

17. The data security system according to claim 16 , wherein each of the plurality of terminals is further configured to:

receive a request from a second terminal of the plurality of terminals,

determine whether the request is valid based on a certificate included in the request from the second terminal of the plurality of terminals, the certificate corresponding to the second terminal of the plurality of terminals, and

upon determining that the request from the second terminal of the plurality of terminals is valid, sending a respective secret share to the second terminal of the plurality of terminals.

18. The data security system according to claim 16 , wherein

the second device is configured to maintain a revocation list indicating validity for the certificates corresponding to the plurality of terminals,

each of the plurality of terminals is configured to query the second device to determine whether another certificate included in a communication from a third terminal of the plurality of terminals is valid, and

wherein the second device responds to the query based on the revocation list.

Assignments (2)
CHANGE OF NAME Recorded May 8, 2023
From: NAGRAVISION SA
To: NAGRAVISION SÀRL
Reel/Frame 063566/0842 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 12, 2020
From: GAGLIARDONI, TOMMASO
To: NAGRAVISION S.A.
Reel/Frame 052929/0920 →
Continuity (1)
Related Publication 20210391982A1 · Dec 16, 2021