IP Library › Granted Patent US 12,494,905
Granted Patent B2
US 12,494,905 · App. 18/624,805 · Granted Dec 9, 2025

Multiple encryption data storage and retrieval system

Inventors: Richard L Przonek (Glen Head, NY); Lance D Reich (Albany, NY)
Assignee: Verai System, LLC
H04L9/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,494,905
App. No.
18/624,805
Granted
Dec 9, 2025
Kind
B2
Abstract

A computer system and method for storage and retrieval of multiple encrypted data. The system and method allow a user to first encryption data with a first key only held by the user such that the user solely possesses one of the necessary keys for later decryption of the stored and encrypted data. The firstly encrypted data is then doubly encrypted and stores the data in such a secure manner that the data can be stored on a public blockchain architecture, if desired. Full decryption of the original user data can only be performed with access to the user's initial key.

Claims (95)

1 . A system for storage and retrieval of encrypted data, comprising:

a data intake device configured to selectively intake data from a user, the data intake device selectively communicably connected to a network, the data network device sending and receiving data across the network; and

a data management system connected to the network and in selective communication with the data intake device, the data management system in further communication with at least one data storage for the selective storage and retrieval of encrypted data,

wherein the data management system is selectively configured to transmit a first encryption key to the data intake device for original user data intake;

wherein the data intake device receives the first encryption key from the data management system and is further configured to:

receive a user key from a user;

create a second encryption key from the first encryption key and the user key;

intake original user data from the user;

encrypt the original user data with the second encryption key to create a first encrypted user data;

transmit the first encrypted user data to the data management system;

store the second encryption key at a device of the user; and

delete the second encryption key from the data intake device;

wherein the data management system is further configured to:

generate a third encryption key;

further encrypt the first encrypted user data with the third encryption key to create a second encrypted user data; and

store the second encrypted user data at a data storage.

2 . The system of claim 1 , wherein the data management system further configured to:

create a verification token;

embed the verification token with the first encrypted user data prior to encrypting the encrypted user data with the third encryption key to become second encrypted user data; and

store the second encrypted user data with the verification token embedded therein.

3 . The system of claim 2 , wherein the data management system further configured to:

receive a user request for the original user data, the user request including the second encryption key;

retrieve the second encrypted user data from the data storage;

decrypt the second encrypted user biometrics data with the third key such that the data becomes first unencrypted user data and the verification token;

verify the integrity of the verification token; and

decrypt the first encrypted user data with the second encryption key to become the original user data.

4 . The system of claim 3 , wherein the data management system further configured to transmit the original user data to a third-party comparison device across the network.

5 . The system of claim 3 , wherein the data management system further configured to:

retrieve new user data from a point-of-sale device across the network;

compare the new user data against the unencrypted original user data to determine a matching status; and

transmit the matching status to the point-of-sale device across the network.

6 . The system of claim 1 , wherein the data management system is further configured to store the second encrypted user data at a data storage across the network.

7 . The system of claim 1 , wherein the data management system is further configured to store the second encrypted user data in Hyperledger fabric.

8 . The system of claim 7 , wherein the data management system is further configured to store the second encrypted user data in a public blockchain.

9 . A method of storing and retrieving encrypted data, comprising the steps of:

communicating an original data intake request from a data intake device to a biometrics data management system, the data intake device selectively communicably connected to a network, and the data intake device sending and receiving data across the network;

transmitting a first encryption key from the data management system to the data intake device, the data management system connected to the network and in selective communication with the data intake device;

the data intake device further:

receiving the first encryption key from the data management system;

receiving a user key from a user;

creating a second encryption key from the first encryption key and the user key;

intaking at the data intake device original user data from the user;

encrypting the original user data with the second encryption key to create a first encrypted user data;

transmitting the first encrypted user data to the data management system;

storing the second encryption key at a device of the user; and

deleting the second encryption key from the data intake device; and

the data management system further:

generating a third encryption key;

encrypting the first encrypted user data with the third encryption key to create a second encrypted user data; and

storing the second encrypted user data at a data storage.

10 . The method of claim 9 , wherein, at the data management system, further:

creating a verification token;

embedding the verification token with the first encrypted user data prior to encrypting the encrypted user data with the third encryption key to become second encrypted user data; and

storing the second encrypted user data with the verification token embedded therein.

11 . The method of claim 10 , wherein, at the data management system, further:

receiving a user request for the original user data, the user request including the second encryption key;

retrieving the second encrypted user data from the data storage;

decrypting the second encrypted user biometrics data with the third key such that the data becomes first unencrypted user data and the verification token;

verifying the integrity of the verification token; and

decrypting the first encrypted user data with the second encryption key to become the original user data.

12 . The method of claim 11 , wherein, at the data management system, further transmitting the original data to a third-party comparison device across the network.

13 . The method of claim 11 , wherein, at the data management system, further:

retrieving new user data from a point-of-sale device across the network;

comparing the new user data against the unencrypted original user data to determine a matching status; and

transmitting the matching status to the point-of-sale device across the network.

14 . The method of claim 9 , wherein, at the data management system, further storing the second encrypted user data at a data storage across the network.

15 . The method of claim 9 , wherein, at the data management system, further storing the second encrypted user data in Hyperledger fabric.

16 . The method of claim 15 , wherein, at the data system, further storing the second encrypted user data in a public blockchain.

17 . A system for storage and retrieval of encrypted data, comprising:

a data intake means for selectively intaking original data from a user, the data intake means selectively communicably connected to a network, and the data intake means sending and receiving data across the network;

a data management means for managing the storage and retrieval of encrypted data, the data management means connected to a network and in selective communication with the data intake means, the data management means in further communication with at least one data storage means for the selective storage and retrieval of encrypted data, wherein the data management means is further configured for transmitting a first encryption key to the data intake means for original user data intake;

wherein the data intake means is further configured for:

receiving the first encryption key from the data management means

receiving a user key from a user;

creating a second encryption key from the first encryption key and the user key;

intaking original user data from the user;

encrypting the original user data with the second encryption key to create a first encrypted user data;

transmitting the first encrypted user data to the data management means;

storing the second encryption key at a device of the user; and

deleting the second encryption key from the data intake device; and

wherein the data management means is further configured for:

generating a third encryption key;

encrypting the first encrypted user data with the third encryption key to create a second encrypted user data; and

storing the second encrypted user data at a data storage means for storing data.

18 . The system of claim 17 , wherein the data management means is further configured for:

creating a verification token;

embedding the verification token with the first encrypted user data prior to encrypting the encrypted user data with the third encryption key to become second encrypted user data; and

storing the second encrypted user data with the verification token embedded therein.

19 . The system of claim 17 , wherein the data management means is further configured for:

receiving a user request for the original user data, the user request including the second encryption key;

retrieving the second encrypted user data from the data storage means;

decrypting the second encrypted user biometrics data with the third key such that the data becomes first unencrypted user data and the verification token;

verifying the integrity of the verification token; and

decrypting the first encrypted user data with the second encryption key to become the original user data.

20 . The system of claim 19 , wherein the data management means is further configured for transmitting the original user data to a third-party comparison means for comparing new user data with original user data.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2025
From: PRZONEK, RICHARD L.; REICH, LANCE D.
To: VERAI SYSTEMS, INC.
Reel/Frame 072816/0882 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2025
From: VERAI SYSTEMS, INC.
To: VERAI SYSTEMS, LLC
Reel/Frame 072816/0916 →
Continuity (2)
Provisional Application 63456709 · Apr 3, 2023
Related Publication 20240333489A1 · Oct 3, 2024
References Cited (24)
US 8150036B2 · Paykin · 2012 [cited by examiner]
US 8295490B1 · McCoy · 2012 [cited by examiner]
US 11630912B2 · In · 2023 [cited by examiner]
US 20140049653A1 · Leonard et al. · 2014 [cited by applicant]
US 20150347999A1 · Lau et al. · 2015 [cited by applicant]
US 20170005803A1 · Brownewell · 2017 [cited by examiner]
US 20180139188A1 · Iyer et al. · 2018 [cited by applicant]
US 20180373464A1 · Schoenberger · 2018 [cited by examiner]
US 20200252457A1 · Zakrzewski · 2020 [cited by examiner]
US 20210167955A1 · Rameez · 2021 [cited by examiner]
US 20220052988A1 · Gadnis · 2022 [cited by examiner]
US 20220284112A1 · Seader · 2022 [cited by examiner]
US 20220284113A1 · Nelson · 2022 [cited by examiner]
US 20220335147A1 · Yedluri et al. · 2022 [cited by applicant]
US 20220368685A1 · Pollack · 2022 [cited by examiner]
US 20250247240A1 · Przonek · 2025 [cited by examiner]
CN 116032475A · 2023 [cited by examiner]
CN 118509262A · 2024 [cited by examiner]
CN 119129001A · 2024 [cited by examiner]
EP 2680566A1 · 2014 [cited by examiner]
EP 4235473A2 · 2023 [cited by examiner]
JP 2006196010A · 2006 [cited by examiner]
WO 2019207101A1 · 2019 [cited by applicant]
WO WO2024211294A1 · 2024 [cited by examiner]