IP Library › Granted Patent US 12,335,241
Granted Patent B2
US 12,335,241 · App. 17/990,544 · Granted Jun 17, 2025

Cryptographic communication binding system and method

Inventors: C. Jay Wack (Clarksville, MD); Roger Butler (Centreville, VA)
Assignee: Safe Harbor Digital Asset Security LLC
H04L63/0428H04L9/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,335,241
App. No.
17/990,544
Granted
Jun 17, 2025
Kind
B2
Abstract

A method of cryptographically binding communication parties includes assigning attributes to parties, and performing a combine operation including creating communication keys. Data is encrypted using a session key. A recombine operation includes receiving output parameters, along with the session key if the parameters are validated. A cryptographic communication binder includes an attribute mixer configured to assign attributes to the parties, and a combiner configured to create communication keys. A communication key generator is configured to combine attributes to create the session key. A first cryptographic engine is configured to encrypt data using the session key and create output parameters. A recombiner is configured to receive the output parameters and identity attribute, validate the parameters, and identify and validate the originator. A second cryptographic engine is configured to receive the encrypted data and session key, if validating and identifying were successful, and to decrypt the encrypted data using the session key.

Claims (64)

1. A method of cryptographically binding communication parties, comprising:

assigning respective attributes to a sending party and to a receiving party; and

performing a combine operation;

wherein the combine operation includes creating, by the sending party, communication keys;

wherein the attributes include an identity attribute, and input parameters;

wherein the input parameters include an originator attribute and a list of contacts; and

wherein creating the communication keys includes:

combining values from the attributes to create an ephemeral key wrapping key;

using the ephemeral key wrapping key to protect an ephemeral key generating key; and

mixing at least the ephemeral key generating key and a static key generating key to create the session key.

2. The method of claim 1 , wherein the identity attribute includes at least one of:

an origination encryption key pair;

a pairing key pair;

an origination signing key pair;

an attribute symmetric key;

a static key generating key;

an identity ID; and

an identity name.

3. The method of claim 1 , further comprising performing a key-rolling operation, comprising utilizing rolling key values to re-key at least one of the attributes.

4. The method of claim 1 , further comprising encrypting communication data using the session key; and

sending the encrypted communication data to the receiving party.

5. The method of claim 4 , further comprising creating output parameters, wherein the output parameters include at least some of the input parameters, and ephemeral data.

6. The method of claim 5 , further comprising performing a recombine operation;

wherein the recombine operation includes:

receiving, by the receiving party, the output parameters and the sending party identity attribute;

validating the output parameters; and

identifying and validating the originator.

7. The method of claim 6 , further comprising:

receiving, by the receiving party, the encrypted communication data;

receiving, by the receiving party, the session key, if validating the output parameters and identifying and validating the originator were successful; and

decrypting the encrypted communication data by the receiving party, using the session key.

8. The method of claim 6 , further comprising zeroing at least some of the output parameters if at least one of

validating the output parameters, and

identifying and validating the originator,

was unsuccessful.

9. A cryptographic communication binder, comprising:

an attribute mixer configured to assign respective attributes to a sending party and to a receiving party; and

a combiner configured to create, by the sending party, communication keys;

wherein the attributes include an identity attribute, and input parameters;

wherein the input parameters include an originator attribute and a list of contacts; and

wherein the combiner further includes a communication key generator configured to combine values from the attributes to create an ephemeral key wrapping key, use the ephemeral key wrapping key to protect an ephemeral key generating key, and mix at least the ephemeral key generating key and a static key generating key to create the session key.

10. The cryptographic communication binder of claim 9 , wherein the identity attribute includes at least one of:

an origination encryption key pair;

a pairing key pair;

an origination signing key pair;

an attribute symmetric key;

a static key generating key;

an identity ID; and

an identity name.

11. The cryptographic communication binder of claim 9 , further comprising a key roller configured to utilize rolling key values to re-key at least one of the attributes.

12. The cryptographic communication binder of claim 9 , further comprising a first cryptographic engine configured to encrypt communication data using the session key and send the encrypted communication data to the receiving party.

13. The cryptographic communication binder of claim 12 , wherein the first cryptographic engine is further configured to create output parameters, wherein the output parameters include at least some of the input parameters and ephemeral data.

14. The cryptographic communication binder of claim 13 , further comprising a recombiner configured to:

receive, by the receiving party, the output parameters and the sending party identity attribute;

validate the output parameters; and

identify and validate the originator.

15. The cryptographic communication binder of claim 14 , further comprising a second cryptographic engine configured to:

receive, by the receiving party, the encrypted communication data;

receive, by the receiving party, the session key, if validating the output parameters and identifying and validating the originator were successful; and

decrypt the encrypted communication data by the receiving party, using the session key.

16. The cryptographic communication binder of claim 14 , wherein the recombiner is further configured to zero at least some of the output parameters if at least one of

validating the output parameters, and

identifying and validating the originator,

was unsuccessful.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2025
From: WACK, C. JAY; BUTLER, ROGER
To: SAFE HARBOR DIGITAL ASSET SECURITY LLC
Reel/Frame 071185/0816 →
Continuity (2)
Provisional Application 63281169 · Nov 19, 2021
Related Publication 20250047648A1 · Feb 6, 2025
References Cited (13)
US 5812671A · Ross, Jr. · 1998 [cited by examiner]
US 7590238B2 · Kamijoh · 2009 [cited by examiner]
US 8555361B2 · Nakhjiri · 2013 [cited by examiner]
US 8667265B1 · Hamlet · 2014 [cited by examiner]
US 8751796B2 · Vogt · 2014 [cited by examiner]
US 8990569B2 · Haynes · 2015 [cited by examiner]
US 11880832B2 · Viola · 2024 [cited by examiner]
US 20010010724A1 · Murakami · 2001 [cited by examiner]
US 20070183600A1 · Smart · 2007 [cited by examiner]
US 20080301445A1 · Vasic · 2008 [cited by examiner]
US 20090028342A1 · Cerruti · 2009 [cited by examiner]
US 20180026950A1 · Wasiq · 2018 [cited by examiner]
US 20230155825A1 · Wu · 2023 [cited by examiner]