IP Library Granted Patent US 12,212,659
Granted Patent B2
US 12,212,659 · App. 17/295,049 · Granted Jan 28, 2025

Private key cloud storage

Inventors: Hervé Retaureau (Cheseaux-sur-Lausanne, CH); Antony Celletti (Cheseaux-sur-Lausanne, CH)
Assignee: NAGRAVISION SARL
H04L9/0825H04L9/085H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,212,659
App. No.
17/295,049
Granted
Jan 28, 2025
Kind
B2
Abstract

A system ( 1 ) for asymmetrical cryptography, comprising a device ( 10 ) and a network storage ( 30 ), wherein the device is communicatively connected to the network storage, wherein the network storage is configured to store a private key, wherein the device is configured to retrieve the private key from the network storage to perform a cryptographic operation using the private key in a secure execution environment ( 12 ) of the device, and wherein the secure execution environment is configured to only temporarily store the private key for the cryptographic operation.

Claims (76)

1. A system comprising:

a customer device that is communicatively connected to a network storage, wherein the network storage is configured to store an encrypted private key comprising a private key of an asymmetrical key pair that has been encrypted using a customer secret, and wherein the customer device comprises:

one or more processors;

memory accessible to the one or more processors, the memory storing instructions which, upon execution by the one or more processors, causes the one or more processors to:

retrieve the encrypted private key from the network storage; and

obtain a customer secret; and

a secure execution environment and configured to:

decrypt the encrypted private key using the customer secret to obtain the private key;

temporarily store the private key for use in a cryptographic operation;

perform the cryptographic operation using the private key;

after performing the cryptographic operation using the private key, delete the private key from a memory of the secure execution environment; and

provide a result of the cryptographic operation.

2. The system according to claim 1 , wherein the instructions, upon execution by the one or more processors, further causes the one or more processors to:

configure a first secure link between the secure execution environment of the customer device and an application executing on the customer device; and

obtain the customer secret via the first secure link,

wherein the secure execution environment is configured to provide the result of the cryptographic operation to the application via the first secure link.

3. The system according to claim 1 , wherein the instructions, upon execution by the one or more processors, further causes the one or more processors to:

configure a second secure link for transmission of the encrypted private key between the network storage and the customer device, and/or wherein the secure execution environment is further configured to:

create the asymmetrical key pair comprising the private key;

temporarily store the private key until stored in the network storage; and

encrypt the private key using the customer secret before transmission to the network storage,

wherein the customer device is further configured to transmit the encrypted private key to the network storage.

4. The system of claim 1 , wherein the secure execution environment is embedded in the customer device.

5. The system of claim 1 , wherein the secure execution environment is detachably connected to the customer device.

6. A customer device comprising:

one or more processors;

memory accessible to the one or more processors, the memory storing instructions which, upon execution by the one or more processors, causes the one or more processors to:

retrieve an encrypted private key of an asymmetrical key pair from a network storage; and

obtain a customer secret; and

a secure execution environment and configured to:

decrypt the encrypted private key using the customer secret to obtain a private key;

temporarily store the private key for use in a cryptographic operation;

perform the cryptographic operation using the private key;

after performing the cryptographic operation using the private key, delete the private key from a memory of the secure execution environment; and

provide a result of the cryptographic operation.

7. The customer device according to claim 6 , wherein the instructions, upon execution by the one or more processors, further causes the one or more processors to:

configure a first secure link between a secure execution environment of the customer device and an application executing on the customer device; and

obtain the customer secret via the first secure link,

wherein the secure execution environment is configured to provide the result of the cryptographic operation to the application via the first secure link.

8. The customer device of claim 6 , wherein the secure execution environment is embedded in the customer device.

9. The customer device of claim 6 , wherein the secure execution environment is detachably connected to the customer device.

10. A method comprising:

storing an encrypted private key in a network storage, the encrypted private key comprising a private key of an asymmetrical key pair that has been encrypted using a customer secret;

retrieving, by a customer device, the encrypted private key from the network storage;

decrypting, by a secure execution environment of the customer device, the encrypted private key using the customer secret to obtain the private key;

temporarily storing, by the secure execution environment, the private key for use in a cryptographic operation;

performing, by the secure execution environment, the cryptographic operation using the private key;

after performing the cryptographic operation using the private key, deleting the private key from a memory of the secure execution environment; and

providing a result of the cryptographic operation.

11. The method according to claim 10 , further comprising:

configuring a first secure link between the secure execution environment of the customer device and an application executing on the customer device;

obtaining the customer secret via the first secure link in the secure execution environment; and

providing the result of the cryptographic operation to the application via the first secure link.

12. The method according to claim 11 , further comprising: configuring a second secure link for transmission of the private key between the network storage and the secure execution environment.

13. The method according to claim 10 , further comprising:

creating the asymmetrical key pair comprising the private key in the secure execution environment;

temporarily storing the private key in the secure execution environment until stored in the network storage;

encrypting the private key in the secure execution environment using the customer secret before transmission to the network storage; and

transmit the encrypted private key from the customer device to the network storage.

14. A method comprising:

retrieving, by a customer device, an encrypted private key of an asymmetrical key pair from a network storage;

obtaining, by the customer device, a customer secret;

decrypting, by a secure execution environment of the customer device, the encrypted private key using the customer secret to obtain a private key;

temporarily storing, by the secure execution environment, the private key for use in a cryptographic operation;

performing, by the secure execution environment, the cryptographic operation using the private key;

after performing the cryptographic operation using the private key, deleting the private key from a memory of the secure execution environment; and

providing a result of the cryptographic operation.

15. The method according to claim 14 , further comprising:

configuring a first secure link between a secure execution environment of the customer device and an application executing on the customer device;

obtaining the customer secret via the first secure link in the secure execution environment; and

providing the result of the cryptographic operation to the application via the first secure link.

16. The method according to claim 14 , further comprising:

creating the asymmetrical key pair comprising the private key in the secure execution environment;

temporarily storing the private key in the secure execution environment until stored in the network storage;

encrypting the private key in the secure execution environment using the customer secret before transmission to the network storage; and

transmit the encrypted private key from the customer device to the network storage.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2023
From: NAGRA FRANCE SAS
To: NAGRAVISION SARL
Reel/Frame 064398/0093 →
ASSIGNMENT - EMPLOYMENT CONTRACT Recorded Jul 27, 2023
From: RETAUREAU, HERVÉ
To: NAGRA FRANCE SAS
Reel/Frame 064398/0412 →
CHANGE OF NAME Recorded Jun 27, 2022
From: NAGRAVISION S.A.
To: NAGRAVISION SÀRL
Reel/Frame 060442/0238 →
Priority Claims (1)
EP 18208108 · Nov 23, 2018 · regional
Continuity (1)
Related Publication 20220014358A1 · Jan 13, 2022
References Cited (8)
US 9350536B2 · Sabin · 2016 [cited by applicant]
US 10157290B1 · Sinha · 2018 [cited by examiner]
US 10938560B2 · Thom · 2021 [cited by examiner]
US 20120173885A1 · Acar et al. · 2012 [cited by applicant]
US 20180212769A1 · Novak · 2018 [cited by examiner]
US 20180341937A1 · Kim · 2018 [cited by examiner]
“Trusted Execution Environment (TEE) 101: A Primer”, Version 1.0 (C) Apr. 2018 Secure Technology Alliance (pp. 1-24) https://www.securetechalliance.org/wp-content/uploads/TEE-101-White-Paper-FINAL2-April-2018.pdf (Year:… [cited by examiner]
M. Sabt, M. Achemlal and A. Bouabdallah, “Trusted Execution Environment: What It is, and What It is Not,” 2015 IEEE Trustcom/BigDataSE/ISPA, Helsinki, Finland, 2015, pp. 57-64 (Year: 2015). [cited by examiner]