IP Library Granted Patent US 11,924,339
Granted Patent B2
US 11,924,339 · App. 17/382,282 · Granted Mar 5, 2024

System and method for secure end-to-end electronic communication using a privately shared table of entropy

Inventors: Douglass A. Hill (Marco Island, FL); Henry R. Tumblin (Castine, ME)
Assignee: Real Random IP, LLC
H04L9/0869G06F21/602G06F21/6245H04L9/0894H04L63/0428H04L63/0435
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,924,339
App. No.
17/382,282
Granted
Mar 5, 2024
Kind
B2
Abstract

A method performed at a first electronic device includes: (i) storing a privacy table that comprises random numbers at the first electronic device, (ii) transmitting the privacy table to a second electronic device over an encrypted channel, (iii) receiving a first message for transmission to the second electronic device, (iv) generating a map based on the privacy table, (v) generating a primary key based on the map and the privacy table, and (vi) encrypting the first message using the primary key to form an encrypted first message. The method also includes (vii) transmitting the map and the encrypted first message to the second electronic device, thereby enabling the second electronic device to decrypt the encrypted first message by recreating the primary key based on the map and the privacy table and decrypting the encrypted first message using the recreated primary key.

Claims (123)

1. A method performed at a first electronic device, the method comprising:

storing a privacy table at the first electronic device, the privacy table comprising random numbers;

transmitting the privacy table to a second electronic device over an encrypted channel, wherein the second electronic device is distinct from the first electronic device;

receiving a first message for transmission to the second electronic device;

generating a map based on the privacy table, the map including instructions on how to use the privacy table to generate a primary key;

generating the primary key based on the map and the privacy table;

encrypting the first message using the primary key to form an encrypted first message;

transmitting the map and the encrypted first message to the second electronic device, enabling the second electronic device to decrypt the encrypted first message by:

recreating the primary key based on the map and the privacy table; and

decrypting the encrypted first message using the recreated primary key;

receiving a second message for transmission to the second electronic device;

generating a new map, which is distinct from the map;

generating a new primary key based on the new map and the privacy table, wherein the new primary key is distinct from the primary key;

encrypting the second message using the new primary key to form an encrypted second message; and

transmitting the new map and the encrypted second message to the second electronic device, enabling the second electronic device to decrypt the encrypted second message by:

recreating the new primary key based on the new map and the privacy table; and

decrypting the encrypted second message using the recreated new primary key.

2. The method of claim 1 , wherein:

the encrypted first message and the encrypted second message are included in a live stream;

encrypting the first message includes using the primary key to form the encrypted first message;

encrypting the second message includes using the new primary key to form the encrypted second message; and

the method further comprises:

transmitting the map and the encrypted first message to the second electronic device; and

transmitting the new map and the encrypted second message to the second electronic device.

3. The method of claim 1 , wherein the encrypted second message comprises a new privacy table generated to replace the privacy table, the method further comprising, after transmitting the new map and the encrypted second message to the second electronic device:

replacing the privacy table with the new privacy table.

4. The method of claim 1 , wherein generating the map includes:

selecting a location in the privacy table;

selecting a read direction; and

generating the map based on values stored in the privacy table starting at the selected location and reading values stored in the privacy table in accordance with the selected read direction.

5. The method of claim 1 , wherein:

the privacy table is transmitted at a first time; and

the map and encrypted first message are transmitted at a second time subsequent to the first time.

6. The method of claim 1 , wherein:

the first electronic device is a remote sensing station;

the second electronic device is a medical device; and

the encrypted first message includes medical data.

7. The method of claim 1 , wherein transmitting the map and the encrypted first message to the second electronic device includes prepending the map to the encrypted first message to generate a payload that is transmitted from the first electronic device to the second electronic device.

8. The method of claim 1 , wherein the map includes two or more of:

a value corresponding to a starting point within the privacy table;

a value corresponding to a horizontal offset from the starting point within the privacy table;

a value corresponding to a horizontal read direction from the starting point within the privacy table;

a value corresponding to a vertical offset from the starting point within the privacy table;

a value corresponding to a vertical read direction from the starting point within the privacy table;

a value corresponding to a permutation of a size of the privacy table in a horizontal direction;

a value corresponding to a permutation of a size of the privacy table in a vertical direction;

a value corresponding to a starting point within the permutation; and

a length of a challenge string that is used to generate the primary key.

9. The method of claim 1 , wherein generating the primary key based on the map and the privacy table includes:

generating a challenge string based on the map; and

applying a digest function to the challenge string to form the primary key.

10. A computing device, comprising:

one or more processors; and

memory coupled to the one or more processors, the memory storing one or more programs configured to be executed by the one or more processors, the one or more programs including instructions for:

storing a privacy table at the computing device, the privacy table comprising random numbers;

transmitting the privacy table to an electronic device over an encrypted channel, wherein the electronic device is distinct from the computing device;

receiving a first message for transmission to the electronic device;

generating a map based on the privacy table, the map including instructions on how to use the privacy table to generate a primary key;

generating the primary key based on the map and the privacy table;

encrypting the first message using the primary key to form an encrypted first message;

transmitting the map and the encrypted first message to the electronic device, enabling the electronic device to decrypt the encrypted first message by:

recreating the primary key based on the map and the privacy table; and

decrypting the encrypted first message using the recreated primary keys;

receiving a second message for transmission to the electronic device;

generating a new map, which is distinct from the map;

generating a new primary key based on the new map and the privacy table, wherein the new primary key is distinct from the primary key;

encrypting the second message using the new primary key to form an encrypted second message; and

transmitting the new map and the encrypted second message to the electronic device, enabling the electronic device to decrypt the encrypted second message by:

recreating the new primary key based on the new map and the privacy table; and

decrypting the encrypted second message using the recreated new primary key.

11. The computing device of claim 10 , wherein generating the map includes:

selecting a location in the privacy table;

selecting a read direction; and

generating the map based on values stored in the privacy table starting at the selected location and reading values stored in the privacy table in accordance with the selected read direction.

12. The computing device of claim 10 , wherein:

the privacy table is transmitted at a first time; and

the map and encrypted first message are transmitted at a second time subsequent to the first time.

13. The computing device of claim 10 , wherein transmitting the map and the encrypted first message to the electronic device includes prepending the map to the encrypted first message to generate a payload that is transmitted from the computing device to the electronic device.

14. The computing device of claim 10 , wherein the map includes two or more of:

a value corresponding to a starting point within the privacy table;

a value corresponding to a horizontal offset from the starting point within the privacy table;

a value corresponding to a horizontal read direction from the starting point within the privacy table;

a value corresponding to a vertical offset from the starting point within the privacy table;

a value corresponding to a vertical read direction from the starting point within the privacy table;

a value corresponding to a permutation of a size of the privacy table in a horizontal direction;

a value corresponding to a permutation of a size of the privacy table in a vertical direction;

a value corresponding to a starting point within the permutation; and

a length of a challenge string that is used to generate the primary key.

15. A non-transitory computer-readable storage medium storing one or more programs configured for execution by a computing device having one or more processors and memory, the one or more programs comprising instructions for:

storing a privacy table at the computing device, the privacy table comprising random numbers;

transmitting the privacy table to an electronic device over an encrypted channel, wherein the electronic device is distinct from the computing device;

receiving a first message for transmission to the electronic device;

generating a map based on the privacy table, the map including instructions on how to use the privacy table to generate a primary key;

generating the primary key based on the map and the privacy table;

encrypting the first message using the primary key to form an encrypted first message;

transmitting the map and the encrypted first message to the electronic device, enabling the electronic device to decrypt the encrypted first message by:

recreating the primary key based on the map and the privacy table; and

decrypting the encrypted first message using the recreated primary keys;

receiving a second message for transmission to the electronic device;

generating a new map, which is distinct from the map;

generating a new primary key based on the new map and the privacy table, wherein the new primary key is distinct from the primary key;

encrypting the second message using the new primary key to form an encrypted second message; and

transmitting the new map and the encrypted second message to the electronic device, enabling the electronic device to decrypt the encrypted second message by:

recreating the new primary key based on the new map and the privacy table; and

decrypting the encrypted second message using the recreated new primary key.

16. The non-transitory computer-readable storage medium of claim 15 , wherein generating the map includes:

selecting a location in the privacy table;

selecting a read direction; and

generating the map based on values stored in the privacy table starting at the selected location and reading values stored in the privacy table in accordance with the selected read direction.

17. The non-transitory computer-readable storage medium of claim 15 , wherein:

the privacy table is transmitted at a first time; and

the map and encrypted first message are transmitted at a second time subsequent to the first time.

18. The non-transitory computer-readable storage medium of claim 15 , wherein transmitting the map and the encrypted first message to the electronic device includes prepending the map to the encrypted first message to generate a payload that is transmitted from the computing device to the electronic device.

19. The non-transitory computer-readable storage medium of claim 15 , wherein the map includes two or more of:

a value corresponding to a starting point within the privacy table;

a value corresponding to a horizontal offset from the starting point within the privacy table;

a value corresponding to a horizontal read direction from the starting point within the privacy table;

a value corresponding to a vertical offset from the starting point within the privacy table;

a value corresponding to a vertical read direction from the starting point within the privacy table;

a value corresponding to a permutation of a size of the privacy table in a horizontal direction;

a value corresponding to a permutation of a size of the privacy table in a vertical direction;

a value corresponding to a starting point within the permutation; and

a length of a challenge string that is used to generate the primary key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2021
From: HILL, DOUGLASS A.; TUMBLIN, HENRY R.
To: REAL RANDOM IP, LLC
Reel/Frame 056939/0734 →
Continuity (2)
Provisional Application 63175548 · Apr 15, 2021
Related Publication 20220337407A1 · Oct 20, 2022