IP Library Granted Patent US 12,292,994
Granted Patent B2
US 12,292,994 · App. 17/663,689 · Granted May 6, 2025

Encrypting data records and processing encrypted records without exposing plaintext

Inventors: Aviad Lahav (Tel-Aviv, IL); Lev Rosenblit (Shoam, IL)
Assignee: RingCentral, Inc.
G06F21/6227G06F16/901G06F16/90348G06F16/9038G06F21/602G06F21/64H04L9/0643H04L9/0822H04L9/0825H04L9/0891H04L9/0894H04L9/3239H04L2209/76
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,292,994
App. No.
17/663,689
Granted
May 6, 2025
Kind
B2
Abstract

A computer-implemented method of generating and distributing keys includes generating, based on a master key, a keyset, wherein the keyset comprises a re-encryption key, generating a key distribution request comprising the keyset, encrypting the keyset using an inbox key associated with a client device to generate an encrypted keyset, sending the re-encryption key to a key manager, and causing to distribute the encrypted keyset to the client device.

Claims (53)

1. A computer-implemented method of generating and distributing keys, comprising:

generating, based on a master key, a keyset, wherein the keyset comprises a re-encryption key;

generating a key distribution request comprising the keyset;

encrypting the keyset using an inbox key associated with a client device to generate an encrypted keyset;

sending the re-encryption key to a key manager; and

causing to distribute the encrypted keyset to the client device.

2. The computer-implemented method of claim 1 , wherein the keyset further comprises a decryption key or a search key.

3. The computer-implemented method of claim 1 , wherein generating the keyset further comprises generating the re-encryption key.

4. The computer-implemented method of claim 3 , wherein generating the re-encryption key comprises generating the re-encryption key in encrypted form.

5. The computer-implemented method of claim 1 , wherein generating the key distribution request further comprises including a user identify, a device identity, or a key identity in the key distribution request.

6. The computer-implemented method of claim 1 , further comprising:

generating a second master key and a rotation key based on the master key;

receiving a key management record; and

wherein generating the key distribution request comprises generating the key distribution request based on the key management record and the second master key.

7. The computer-implemented method of claim 6 , further comprising sending the rotation key to a record updater.

8. The computer-implemented method of claim 1 , further comprising:

receiving the inbox key from a key distributer, wherein the inbox key comprises an inbox public key generated using an asymmetric encryption scheme from the client device.

9. A non-transitory, computer-readable medium storing a set of instructions that, when executed by a processor, cause:

generating, based on a master key, a keyset, wherein the keyset comprises a re-encryption key;

generating a key distribution request comprising the keyset;

encrypting the keyset using an inbox key associated with a client device to generate an encrypted keyset;

sending the re-encryption key to a key manager; and

causing to distribute the encrypted keyset to the client device.

10. The non-transitory, computer-readable medium of claim 9 , wherein the keyset further comprises a decryption key or a search key.

11. The non-transitory, computer-readable medium of claim 9 , wherein generating the keyset further comprises generating the re-encryption key.

12. The non-transitory, computer-readable medium of claim 11 , wherein generating the re-encryption key comprises generating the re-encryption key in encrypted form.

13. The non-transitory, computer-readable medium of claim 9 , wherein generating the key distribution request further comprises including a user identify, a device identity, or a key identity in the key distribution request.

14. The non-transitory, computer-readable medium of claim 9 , storing further instructions that, when executed by the processor, cause:

generating a second master key and a rotation key based on the master key;

receiving a key management record; and

wherein generating the key distribution request comprises generating the key distribution request based on the key management record and the second master key.

15. The non-transitory, computer-readable medium of claim 9 , storing further instructions that, when executed by the processor, cause:

receiving the inbox key from a key distributer, wherein the inbox key comprises an inbox public key generated using an asymmetric encryption scheme from the client device.

16. A system of generating and distributing keys, the system comprising:

a processor;

a memory operatively connected to the processor and storing instructions that, when executed by the processor, cause:

generating, based on a master key, a keyset, wherein the keyset comprises a re-encryption key;

generating a key distribution request comprising the keyset;

encrypting the keyset using an inbox key associated with a client device to generate an encrypted keyset;

sending the re-encryption key to a key manager; and

causing to distribute the encrypted keyset to the client device.

17. The system of claim 16 , wherein the keyset further comprises a decryption key or a search key.

18. The system of claim 16 , wherein generating the keyset further comprises generating the re-encryption key.

19. The system of claim 18 , wherein generating the re-encryption key comprises generating the re-encryption key in encrypted form.

20. The system of claim 16 , wherein generating the key distribution request further comprises including a user identity, a device identity, or a key identity in the key distribution request.

21. The system of claim 16 , wherein the memory stories further instructions that, when executed by the processor, cause:

generating a second master key and a rotation key based on the master key;

receiving a key management record; and

wherein generating the key distribution request comprises generating the key distribution request based on the key management record and the second master key.

22. The system of claim 21 , wherein the memory stories further instructions that, when executed by the processor, cause sending the rotation key to a record updater.

23. The system of claim 16 , wherein the memory stories further instructions that, when executed by the processor, cause:

receiving the inbox key from a key distributer, wherein the inbox key comprises an inbox public key generated using an asymmetric encryption scheme from the client device; and

wherein encrypting the keyset using the inbox key comprises encrypting using the inbox public key to generate the encrypted keyset.

Assignments (3)
SECURITY INTEREST Recorded Feb 14, 2023
From: RINGCENTRAL, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062973/0194 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2022
From: LAHAV, AVIAD
To: KINDITE LTD.
Reel/Frame 059929/0885 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2022
From: KINDITE LTD.
To: RINGCENTRAL, INC.
Reel/Frame 059931/0724 →
Continuity (4)
Continuation 16547738 · Aug 22, 2019
Continuation PCTIL2018050210 · Feb 22, 2018
Provisional Application 62461808 · Feb 22, 2017
Related Publication 20220277099A1 · Sep 1, 2022
References Cited (41)
US 8769705B2 · Zhang et al. · 2014 [cited by applicant]
US 9374373B1 · Chan · 2016 [cited by examiner]
US 10007809B1 · Douglis et al. · 2018 [cited by applicant]
US 10313119B2 · Koike · 2019 [cited by examiner]
US 10657275B2 · Itamar · 2020 [cited by examiner]
US 20050147246A1 · Agrawal et al. · 2005 [cited by applicant]
US 20070074047A1 · Metzger et al. · 2007 [cited by applicant]
US 20070244865A1 · Gordon et al. · 2007 [cited by applicant]
US 20080059787A1 · Hohenberger · 2008 [cited by examiner]
US 20080170701A1 · Matsuo · 2008 [cited by examiner]
US 20090097648A1 · Jung et al. · 2009 [cited by applicant]
US 20090210697A1 · Chen · 2009 [cited by examiner]
US 20120161936A1 · Yoon et al. · 2012 [cited by applicant]
US 20120317655A1 · Zhang · 2012 [cited by examiner]
US 20130080771A1 · Brickell et al. · 2013 [cited by applicant]
US 20130238646A1 · Maro · 2013 [cited by applicant]
US 20130339726A1 · Yoshida · 2013 [cited by examiner]
US 20140025948A1 · Bestler et al. · 2014 [cited by applicant]
US 20140161251A1 · Yoshida · 2014 [cited by examiner]
US 20140281589A1 · Bain · 2014 [cited by applicant]
US 20150019879A1 · Haerterich et al. · 2015 [cited by applicant]
US 20160055347A1 · Park et al. · 2016 [cited by applicant]
US 20160085960A1 · Priev · 2016 [cited by examiner]
US 20160330022A1 · Ito · 2016 [cited by examiner]
US 20160352705A1 · Lockhart et al. · 2016 [cited by applicant]
US 20160380767A1 · Hayashi · 2016 [cited by examiner]
US 20170155628A1 · Rohloff · 2017 [cited by examiner]
US 20170366519A1 · Rao · 2017 [cited by examiner]
US 20180025172A1 · Mori · 2018 [cited by examiner]
US 20180026785A1 · Mori et al. · 2018 [cited by applicant]
CN 105787387A · 2016 [cited by applicant]
WO WO2016171271A1 · 2016 [cited by applicant]
25. Canetti R, Hohenberger S. Chosen-ciphertext secure proxy re-encryption. In Proceedings of the 14th ACM conference on Computer and communications security Oct. 28, 2007 (pp. 185-194). (Year: 2007). [cited by examiner]
Bjorkqvist et al., “Scalable Key Management for Distributed Cloud Storage,” 2018 IEEE International Conference on Cloud Engineering (IC2E), Orlando, FL, USA, 2018, pp. 250-256, doi: 10.1109/IC2E.2018.00051. (Year: 2018). [cited by examiner]
Wang et al., “Key Management Scheme based on Traditional Symmetrical Cryptogram System,” 2006 1ST IEEE Conference on Industrial Electronics and Applications, Singapore, 2006, pp. 1-5, doi: 10.1109/ICIEA.2006.257267. (Ye… [cited by examiner]
Song et al., “Favored Encryption Techniques for Cloud Storage,” 2015 IEEE First International Conference on Big Data Computing Service and Applications, Redwood City, CA, USA, 2015, pp. 267-274, doi: 10.1109/BigDataServ… [cited by examiner]
Lei Xu et al., CL-PRE: a Certificateless Proxy Re-Encryption Scheme for Secure Data Sharing with Public Cloud, ACM, 2012, 10 pages (Year 2012). [cited by applicant]
Elmer Lastdrager: “Securing Patient Information in Medical Databases”, Jan. 1, 2011 (Jan. 1, 2011), XP055665977, URL:https://essay.utwente.nl/61035/1/MSc_ELastdrager DIES CTIT.pdf [retrieved on Feb. 6, 2020]*abstract*“3… [cited by applicant]
Luan Ibraimi et al: A Type-and-Identity-Based Proxy Re-encryption Scheme and Its Application in Healthcare 11, Aug. 24, 2008 (Aug. 24, 2008), Secure Data Management; [Lecture Notes in Computer Science], Springer Berlin … [cited by applicant]
“Encryption techniques for secure database outsourcing.” In European Symposium on Research in Computer Security, pp. 327-342, Springer, Berlin, Heidelberg, 2007. (retrieved on Jun. 7, 2018). Retrieved from the Internet:… [cited by applicant]
“Modeling and assessing inference exposure in encrypted databases.” ACM Transactions on Information and System Secuiry (TISSEC) 8, No. 1 (2005): 119-152. (retrieved on Jun. 7, 2018). Retrieved from the Internet: http://… [cited by applicant]