IP Library Granted Patent US 12,200,099
Granted Patent B2
US 12,200,099 · App. 18/386,214 · Granted Jan 14, 2025

Multi-party cryptographic systems and methods

Inventors: Stephen G. Mitchell (Ben Lomond, CA); Vanishree Rao (San Mateo, CA)
Assignee: Intertrust Technologies Corporation
H04L9/006H04L9/008H04L9/0825H04L9/0866H04L2209/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,200,099
App. No.
18/386,214
Granted
Jan 14, 2025
Kind
B2
Abstract

This disclosure relates to systems and methods for performing cryptographic operations in connection with the management of electronic content using multiple license services. In some circumstances, a content service may not wish to share unencrypted content keys with a single license service for a variety of security reasons. Embodiments of the disclosed systems and methods may use multi-party cryptographic methods in connection with the management of protected content keys and/or associated licenses and/or the distribution of content keys and/or licenses to authorized users and/or devices. In various embodiments, a content service may split a content key into a plurality of key shares and may transmit the key shares to a plurality of different license services. The license services may coordinate operations to generate a protected content key without revealing unencrypted content key to any of the participating license services.

Claims (25)

1. A method for managing electronic data performed by a first service system comprising a processor and a non-transitory computer-readable medium storing instructions that, when executed by the processor, cause the first service system to perform the method, the method comprising:

receiving a public key from a device;

receiving a first padded decryption key share of a decryption key and first key identification information associated with the first padded decryption key share from a data management service managing the electronic data, the first padded decryption key share comprising a first padding string, the first key identification information identifying that the first padded key share is associated with the decryption key;

receiving a protected second padded decryption key share of the decryption key and second key identification information associated with the protected second padded decryption key share from a second service, the protected second padded decryption key share comprising a second padded decryption key share of the decryption key encrypted by the second service using the public key, the second padded decryption key share comprising a second padding string, the second key identification information identifying that the second padded key share is associated with the decryption key;

generating a protected first padded decryption key share of the decryption key by encrypting the first padded decryption key share using the public key;

determining that both the first padded decryption key share and the second padded decryption key share are associated with the decryption key based on determining that the first key identification information and the second key identification information match;

generating, at least in part responsive to the determining, a protected decryption key by multiplying the protected first padded decryption key share and the protected second padded decryption key share, the generated protected decryption key comprising the decryption key encrypted with the public key, wherein the first padding string and the second padding string being configured to allow for generation of the protected decryption key by the first service system without decrypting the protected first padded decryption key share and the protected second padded decryption key share; and

transmitting the protected decryption key to the device for use in accessing the electronic data through the device decrypting the protected decryption key using a private key corresponding to the public key.

2. The method of claim 1 , wherein the method further comprises receiving a request from the device for a license to access the electronic data.

3. The method of claim 2 , wherein the method further comprises generating an electronic license for the electronic data, the electronic license comprising the protected decryption key.

4. The method of claim 3 , wherein transmitting the protected decryption key to the device comprises transmitting the electronic license to the device.

5. The method of claim 1 , wherein the first service is separate from the second service.

6. The method of claim 1 , wherein the decryption key is generated by the data management service.

7. The method of claim 1 , wherein the first padded decryption key share is generated by the data management service.

8. The method of claim 1 , wherein the second padded decryption key share is generated by the data management service.

9. The method of claim 1 , wherein the first service system is an untrusted system with respect to the data management service.

10. The method of claim 1 , wherein the second service system is an untrusted system with respect to the data management service.

11. The method of claim 1 , wherein the protected decryption key comprises the decryption key encrypted with the public key using a homomorphic encryption algorithm.

12. The method of claim 1 , wherein the protected second padded decryption key share comprises the second padded decryption key share encrypted with the public key using a homomorphic encryption algorithm by the second service system.

13. The method of claim 1 , wherein the protected first padded decryption key share comprises the first padded decryption key share encrypted with the public key using a homomorphic encryption algorithm.

14. The method of claim 1 , wherein the protected decryption key comprises a protected padded decryption key.

15. The method of claim 1 , wherein the public key is associated with the device.

16. The method of claim 1 , wherein the public key is associated with a user of the device.

17. The method of claim 1 , wherein the private key is associated with the device.

18. The method of claim 1 , wherein the private key is associated with a user of the device.

Assignments (2)
SECURITY INTEREST Recorded Mar 25, 2026
From: INTERTRUST TECHNOLOGIES CORPORATION
To: JAMSTER CAPITAL LLC
Reel/Frame 075228/0345 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 26, 2024
From: INTERTRUST TECHNOLOGIES CORPORATION
To: JERA CO., INC.
Reel/Frame 068173/0212 →
Continuity (3)
Continuation 17004610 · Aug 27, 2020
Provisional Application 62892357 · Aug 27, 2019
Related Publication 20240063999A1 · Feb 22, 2024
References Cited (25)
US 7257844B2 · Woodward · 2007 [cited by applicant]
US 9077539B2 · Kamara et al. · 2015 [cited by applicant]
US 9350539B2 · Veugen et al. · 2016 [cited by applicant]
US 9660805B2 · Parann-Nissany et al. · 2017 [cited by applicant]
US 9673975B1 · Machani · 2017 [cited by applicant]
US 9794232B2 · Shaw · 2017 [cited by applicant]
US 9954680B1 · Machani et al. · 2018 [cited by applicant]
US 10511436B1 · Machani · 2019 [cited by applicant]
US 10547444B2 · Harris et al. · 2020 [cited by applicant]
US 11238140B2 · Dean et al. · 2022 [cited by applicant]
US 20080056501A1 · McGough · 2008 [cited by examiner]
US 20100208889A1 · Humphrey · 2010 [cited by applicant]
US 20160140545A1 · Flurscheim et al. · 2016 [cited by examiner]
US 20200076594A1 · Audley · 2020 [cited by applicant]
US 20200112429A1 · Keselman · 2020 [cited by examiner]
EP 1372055 · 2003 [cited by applicant]
EP 3334083 · 2018 [cited by applicant]
Secure Multiparty Computation (MPC). Yehuda Lindell. IACR Cryptol. ePrint Arch. vol. 2020. Published May 11, 2020, (15 pgs). [cited by applicant]
From Keys to Databases—Real-World Applications of Secure Multi-Party Computation. Archer et al. The Computer Journal, vol. 61, Issue 12, pp. 1749-1771. Published Sep. 12, 2018 (32 pgs). [cited by applicant]
High-Throughput Semi-Honest Secure Three-Party Computation with an Honest Majority. Araki et al. CCS '16: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 805-817. Published Oct… [cited by applicant]
Fast Secure Multiparty ECDSA with Practical Distributed Key Generation and Applications to Cryptocurrency Custody. Lindell et al. IACR Cryptol. ePrint Arch. Vol. 2018. Published Oct. 14, 2018 (50 pgs). [cited by applicant]
Dec. 1, 2020 International Search Report, PCT/US2020/048199. (5 pgs). [cited by applicant]
Dec. 1, 2020 Written Opinion of the International Search Authority, PCT/US2020/048199. (8 pgs). [cited by applicant]
Official Communication Pursuant to Rules 161(1) and 162 EPC from the European Patent Office. EP Application No. 20775973.9-1218. [cited by applicant]
Communciation Pursuant to Article 94(3) EPC from the European Patent Office, EP Application No. 20775973.9—2018. [cited by applicant]