IP Library › Granted Patent US 11,997,191
Granted Patent B2
US 11,997,191 · App. 17/701,792 · Granted May 28, 2024

System and method for protecting secret data items using multiple tiers of encryption and secure element

Inventor: Wei Li (Guangzhou, CN)
Assignee: Blue Space Information Technology Co., Ltd.
H04L9/0822H04L9/0863H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,997,191
App. No.
17/701,792
Granted
May 28, 2024
Kind
B2
Abstract

A system and method for protecting secret data items using multiple layers of encryption with multiple encryption keys, a Secure Element, and a sandbox on an electronic device includes a secret data item manager. The secret data item manager encrypts secret data items using a hardware encryption key and the Secure Element. It encrypts the transient secret cipher data with an account encryption key to generate and store repository account cipher data. It further encrypts the account encryption key to generate and store the repository account key cipher data with a root encryption key. The manager also derives a secondary encryption key from a user account password, encrypts the root encryption key with the secondary key to generate the transient root encryption key, encrypts the transient root encryption key using the hardware key to generate the repository root encryption key cipher data, and stores repository root encryption key cipher data.

Claims (33)

1. A method for protecting secret data items using multiple layers of encryption, multiple encryption keys and a secure microprocessor, said method performed by a secret data item manager running on an electronic device and comprising:

1) Causing a hardware encryption key generated by said secure microprocessor of said electronic device, said electronic device including:

a) processing unit;

b) some amount of memory operatively coupled to said processing unit;

c) a network interface operatively coupled to said processing unit;

d) a power module operatively coupled to said processing unit for providing electrical power to said electronic device;

e) said secure microprocessor operatively coupled to said processing unit;

f) an operating system running on said processing unit, and

g) said secret data item manager adapted to be managed by said operating system and be executed by said processing unit;

2) Generating a root encryption key;

3) Retrieving a set of secret data items;

4) Retrieving a collection of general account data items;

5) Creating an account encryption key for a user account;

6) Using said hardware encryption key, encrypting said set of secret data items to generate transient secret cipher data;

7) Using said account encryption key, encrypting said transient secret cipher data and said collection of general account data items together to generate repository account cipher data;

8) Storing said repository account cipher data;

9) Using said root encryption key, encrypting said account encryption key to generate repository account key cipher data;

10) Storing repository account key cipher data;

11) Using a key derivation function, deriving a secondary encryption key from a master password for said user account;

12) Using said secondary encryption key, encrypting said root encryption key to generate transient root encryption key cipher data;

13) Using said hardware encryption key, encrypting said transient root encryption key cipher data to generate repository root encryption key cipher data; and

14) storing repository root encryption key cipher data.

2. The method of claim 1 wherein said secure microprocessor is a Secure Element of said electronic device.

3. The method of claim 2 wherein at least one of said hardware encryption key, said root encryption key, said account encryption key, and said secondary encryption key is a symmetric encryption key or an asymmetric encryption key pair.

4. The method of claim 2 wherein said transient secret cipher data is not stored.

5. The method of claim 2 wherein said transient root encryption key cipher data is not stored.

6. The method of claim 2 wherein said key derivation function is a Password-Based Key Derivation Function 2 function or an Argon 2 function.

7. The method of claim 2 wherein said operating system is an Android operating system or an iOS operating system.

8. The method of claim 2 wherein said set of secret data items includes at least one of a password, a passcode, a time-based one-time password, and a recovery key.

9. The method of claim 1 wherein at least one of said hardware encryption key, said root encryption key, said account encryption key, and said secondary encryption key is a symmetric encryption key or an asymmetric encryption key pair.

10. The method of claim 1 wherein said transient secret cipher data is not stored.

11. The method of claim 1 wherein said transient root encryption key cipher data is not stored.

12. The method of claim 1 wherein said set of secret data items includes at least one of a password, a passcode, a time-based one-time password, and a recovery key.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2024
From: BLUE SPACE INFORMATION TECHNOLOGY CO., LTD.
To: LI, WEI
Reel/Frame 067177/0478 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2022
From: LI, WEI
To: BLUE SPACE INFORMATION TECHNOLOGY CO., LTD.
Reel/Frame 059371/0648 →
Continuity (1)
Related Publication 20230327855A1 · Oct 12, 2023