IP Library › Granted Patent US 11,831,759
Granted Patent B1
US 11,831,759 · App. 17/887,442 · Granted Nov 28, 2023

Optimized authentication system for a multiuser device

Inventor: Mindaugas Valkaitis (Vilnius, LT)
Assignee: UAB 360 IT
H04L9/0825H04L9/0866H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,831,759
App. No.
17/887,442
Granted
Nov 28, 2023
Kind
B1
Abstract

A method including encrypting, by a multiuser device, a first folder based on utilizing a first symmetric key and a second folder based on utilizing a second symmetric key, the first folder and the second folder being stored on the multiuser device; encrypting, by the multiuser device, the first symmetric key based on utilizing a first assigned public key and the second symmetric key based on utilizing a second assigned public key; and providing access, by the multiuser device, to the encrypted first folder by decrypting the encrypted first symmetric key based on verifying first biometric information and to the encrypted second folder by decrypting the encrypted second symmetric key based on verifying second biometric information, the first biometric information being different from the second biometric information is disclosed. Various other aspects and techniques are contemplated.

Claims (65)

1. A method, comprising:

encrypting, by a multiuser device, a first folder based at least in part on utilizing a first symmetric key and a second folder based at least in part on utilizing a second symmetric key, the first folder and the second folder being stored on the multiuser device;

encrypting, by the multiuser device, the first symmetric key, to determine an encrypted first symmetric key, based at least in part on utilizing a first assigned public key specific to the first folder, and the second symmetric key, to determine an encrypted second symmetric key, based at least in part on utilizing a second assigned public key specific to the second folder;

decrypting the encrypted first symmetric key based at least in part on verifying first biometric information specific to the first folder, the decrypting the encrypted first symmetric key including transmitting a first request to a trusted device located on the multiuser device, the first request including a first identifier identifying a first trusted key to indicate that an encrypted first assigned private key, associated with the first assigned public key, is to be decrypted based at least in part on utilizing the first trusted key to determine a decrypted first assigned private key, which is utilized to decrypt the encrypted first symmetric key to determine a decrypted first symmetric key;

decrypting the encrypted second symmetric key based at least in part on verifying second biometric information specific to the second folder, the decrypting the encrypted second symmetric key including transmitting a second request to the trusted device, the second request including a second identifier identifying a second trusted key to indicate that an encrypted second assigned private key, associated with the second assigned public key, is to be decrypted based at least in part on utilizing the second trusted key to determine a decrypted second assigned private key, which is utilized to decrypt the encrypted second symmetric key to determine a decrypted second symmetric key, the first biometric information being different from the second biometric information,

decrypting, by the multiuser device, the encrypted first folder based at least in part on utilizing the decrypted first symmetric key; and

decrypting, by the multiuser device, the encrypted second folder based at least in part on utilizing the decrypted second symmetric key.

2. The method of claim 1 , wherein

decrypting the encrypted first symmetric key includes causing a biometric unit, associated with the multiuser device, to receive the first biometric information, and

decrypting the encrypted second symmetric key includes causing the biometric unit to receive the second biometric information.

3. The method of claim 1 , wherein

decrypting the encrypted first symmetric key includes comparing the first biometric information with authorized first biometric information, and

decrypting the encrypted second symmetric key includes comparing the second biometric information with authorized second biometric information.

4. The method of claim 1 , wherein

the first trusted key is different from the second trusted key.

5. The method of claim 1 , wherein

the first request indicates successful verification of the first biometric information, and

the second request indicates successful verification of the second biometric information.

6. The method of claim 1 , further comprising:

receiving, from the trusted device, the first identifier that identifies the first trusted key and the second identifier that identifies the second trusted key.

7. The method of claim 1 , further comprising:

associating decrypting of the encrypted first symmetric key with verification of the first biometric information, and

associating decrypting of the encrypted second symmetric key with verification of the second biometric information.

8. A multiuser device, comprising:

a memory; and

a processor communicatively coupled to the memory, the memory and the processor being configured to:

encrypt a first folder based at least in part on utilizing a first symmetric key and a second folder based at least in part on utilizing a second symmetric key, the first folder and the second folder being stored on the multiuser device;

encrypt the first symmetric key, to determine an encrypted first symmetric key, based at least in part on utilizing a first assigned public key specific to the first folder, and the second symmetric key, to determine an encrypted second symmetric key, based at least in part on utilizing a second assigned public key specific to the second folder;

decrypt the encrypted first symmetric key based at least in part on verifying first biometric information specific to the first folder, wherein, to decrypt the encrypted first symmetric key, the memory and the processor are configured to transmit a first request to a trusted device located on the multiuser device, the first request including a first identifier identifying a first trusted key to indicate that an encrypted first assigned private key, associated with the first assigned public key, is to be decrypted based at least in part on utilizing the first trusted key to determine a decrypted first assigned private key, which is utilized to decrypt the encrypted first symmetric key to determine a decrypted first symmetric key;

decrypt the encrypted second symmetric key based at least in part on verifying second biometric information specific to the second folder, wherein, to decrypt the encrypted second symmetric key, the memory and the processor are configured to transmit a second request to the trusted device, the second request including a second identifier identifying a second trusted key to indicate that an encrypted second assigned private key, associated with the second assigned public key, is to be decrypted based at least in part on utilizing the second trusted key to determine a decrypted second assigned private key, which is utilized to decrypt the encrypted second symmetric key to determine a decrypted second symmetric key, the first biometric information being different from the second biometric information;

decrypt the encrypted first folder based at least in part on utilizing the decrypted first symmetric key; and

decrypt the encrypted second folder based at least in part on utilizing the decrypted second symmetric key.

9. The multiuser device of claim 8 , wherein

to decrypt the encrypted first symmetric key, the memory and the processor are configured to cause a biometric unit, associated with the multiuser device, to receive the first biometric information, and

to decrypt the encrypted second symmetric key, the memory and the processor are configured to cause the biometric unit to receive the second biometric information.

10. The multiuser device of claim 8 , wherein

to decrypt the encrypted first symmetric key, the memory and the processor are configured to compare the first biometric information with authorized first biometric information, and

to decrypt the encrypted second symmetric key, the memory and the processor are configured to compare the second biometric information with authorized second biometric information.

11. The multiuser device of claim 8 , wherein

the first trusted key is different from the second trusted key.

12. The multiuser device of claim 8 , wherein

the first request indicates successful verification of the first biometric information, and

the second request indicates successful verification of the second biometric information.

13. The multiuser device of claim 8 , wherein the memory and the processor are configured to receive, from the trusted device, the first identifier that identifies the first trusted key and the second identifier that identifies the second trusted key.

14. The multiuser device of claim 8 , wherein the memory and the processor are configured to:

associate decrypting of the encrypted first symmetric key with verification of the first biometric information, and

associate decrypting of the encrypted second symmetric key with verification of the second biometric information.

15. A non-transitory computer-readable medium configured to store instructions, which when executed by a processor associated with a multiuser device, configure the processor to:

encrypt a first folder based at least in part on utilizing a first symmetric key and a second folder based at least in part on utilizing a second symmetric key, the first folder and the second folder being stored on the multiuser device;

encrypt the first symmetric key, to determine an encrypted first symmetric key, based at least in part on utilizing a first assigned public key specific to the first folder, and the second symmetric key, to determine an encrypted second symmetric key, based at least in part on utilizing a second assigned public key specific to the second folder;

decrypt the encrypted first symmetric key based at least in part on verifying first biometric information specific to the first folder, wherein, to decrypt the encrypted first symmetric key, the processor is configured to transmit a first request to a trusted device located on the multiuser device, the first request including a first identifier identifying a first trusted key to indicate that an encrypted first assigned private key, associated with the first assigned public key, is to be decrypted based at least in part on utilizing the first trusted key to determine a decrypted first assigned private key, which is utilized to decrypt the encrypted first symmetric key to determine a decrypted first symmetric key;

decrypt the encrypted second symmetric key based at least in part on verifying second biometric information specific to the second folder, wherein, to decrypt the encrypted second symmetric key, the processor is configured to transmit a second request to the trusted device, the second request including a second identifier identifying a second trusted key to indicate that an encrypted second assigned private key, associated with the second assigned public key, is to be decrypted based at least in part on utilizing the second trusted key to determine a decrypted second assigned private key, which is utilized to decrypt the encrypted second symmetric key to determine a decrypted second symmetric key, the first biometric information being different from the second biometric information;

decrypt the encrypted first folder based at least in part on utilizing the decrypted first symmetric key; and

decrypt the encrypted second folder based at least in part on utilizing the decrypted second symmetric key.

16. The non-transitory computer-readable medium of claim 15 , wherein

to decrypt the encrypted first symmetric key, the processor is configured to cause a biometric unit, associated with the multiuser device, to receive the first biometric information, and

to decrypt the encrypted second symmetric key, the processor is configured to cause the biometric unit to receive the second biometric information.

17. The non-transitory computer-readable medium of claim 15 , wherein

to decrypt the encrypted first symmetric key, the processor is configured to compare the first biometric information with authorized first biometric information, and

to decrypt the encrypted second symmetric key, the processor is configured to compare the second biometric information with authorized second biometric information.

18. The non-transitory computer-readable medium of claim 15 , wherein the first trusted key is different from the second trusted key.

19. The non-transitory computer-readable medium of claim 15 , wherein

the first request indicates successful verification of the first biometric information, and

the second request indicates successful verification of the second biometric information.

20. The non-transitory computer-readable medium of claim 15 , wherein the processor is configured to receive, from the trusted device, the first identifier that identifies the first trusted key and the second identifier that identifies the second trusted key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2022
From: VALKAITIS, MINDAUGAS
To: UAB 360 IT
Reel/Frame 060811/0049 →
Continuity (1)
Continuation 17884511 · Aug 9, 2022
Cited By (1)
US 12,621,145