IP Library Granted Patent US 12,348,641
Granted Patent B2
US 12,348,641 · App. 18/770,587 · Granted Jul 1, 2025

Authentication and key regeneration using a regenerated secret

Inventors: Mark D. Hetherington (Crystal Lake, IL); Jorn Lyseggen (London, GB); Edgardo M. Cruz-Zeno (Round Lake, IL); Nai Sum Wong (Palatine, IL); Ming Dai (Buffalo Grove, IL)
Assignee: BKey, Inc.
H04L9/3236H04L9/0825H04L9/0869
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,348,641
App. No.
18/770,587
Granted
Jul 1, 2025
Kind
B2
Abstract

Disclosed herein is a method including identifying a first instance of a first secret; receiving and hashing a first instance of first data from a first source to generate a first instance of first hashed data, wherein the first instance of the first data from the first source is discarded; computing a first mapping function between the first instance of the first hashed data and the first instance of the first secret, wherein the first mapping function is stored and the first instance of the first hashed data and the first instance of the first secret are discarded; receiving and hashing a second instance of the first data from the first source to generate a second instance of the first hashed data; and applying the first mapping function to the second instance of the first hashed data to generate a second instance of the first secret.

Claims (76)

1. A method, comprising:

identifying a first instance of a first secret;

receiving and hashing a first instance of first data from a first source to generate a first hashed instance of the first data, wherein the first instance of the first data from the first source is discarded;

computing a first mapping function between the first hashed instance of the first data and the first instance of the first secret, wherein the first mapping function is stored and the first hashed instance of the first data and the first instance of the first secret are discarded;

receiving and hashing a second instance of the first data from the first source to generate a second hashed instance of the first data;

applying the first mapping function to the second hashed instance of the first data to generate a second instance of the first secret;

identifying a first instance of a second secret;

generating a first instance of a first codeword based on the first instance of the second secret;

receiving a first instance of second data from a second source;

computing a second mapping function between the first instance of second data from the second source and the first instance of the first codeword, wherein the second mapping function is stored and the first instance of second data from the second source and the first instance of the first codeword are discarded;

receiving a second instance of second data from the second source;

applying the second mapping function to the second instance of second data from the second source to generate a second instance of the first codeword;

generating a second instance of the second secret based on the second instance of the first codeword; and

generating a key using the second instance of the first secret and the second instance of the second secret.

2. The method of claim 1 , wherein the first source is an error-free source.

3. The method of claim 1 , further comprising:

updating the first source by binding an updated first source to the first secret; or

adding a first owner by binding the first owner to the first secret.

4. The method of claim 1 , further comprising computing a recovery mapping function.

5. The method of claim 1 , further comprising receiving one or more of the first instance of first data from the first source or the second instance of first data from the first source from a central entity.

6. The method of claim 1 , wherein the key is generated using the first instance of the first secret.

7. The method of claim 1 , further comprising revoking a first public key and creating a second public key.

8. A method, comprising:

identifying a first instance of a first secret;

generating a first instance of a first codeword based on the first instance of the first secret;

receiving a first instance of first data from a first source;

computing a mapping function between the first instance of first data from the first source and the first instance of the first codeword, wherein the mapping function is stored and the first instance of first data from the first source and the first instance of the first codeword are discarded;

receiving a second instance of first data from the first source;

applying the mapping function to the second instance of first data from the first source to generate a second instance of the first codeword;

generating a second instance of the first secret based on the second instance of the first codeword;

identifying a first instance of a second secret;

generating a first instance of a second codeword based on the first instance of the second secret;

receiving a first instance of second data from a second source; and

computing a second mapping function between the first instance of second data from the second source and the first instance of the second codeword, wherein the second mapping function is stored and the first instance of second data from the second source and the first instance of the second codeword are discarded;

receiving a second instance of second data from the second source;

applying the second mapping function to the second instance of second data from the second source to generate a second instance of the second codeword;

generating a second instance of the second secret based on the second instance of the second codeword; and

generating a key using the second instance of the first secret and the second instance of the second secret.

9. The method of claim 8 , wherein the first source is an error-containing source.

10. The method of claim 8 , further comprising generating the first instance of the first codeword using an error correction code encoder.

11. The method of claim 8 , further comprising generating the second instance of the second secret using an error-correction code decoder.

12. The method of claim 8 , further comprising one or more of:

updating the first source by binding an updated first source to the first secret; or

adding a first owner by binding the first owner to the first secret.

13. The method of claim 8 , further comprising computing a recovery mapping function.

14. The method of claim 8 , further comprising

receiving one or more of the first instance of first data from the first source or the second instance of first data from the first source from a central entity.

15. The method of claim 8 , further comprising generating the key using a first instance of the first secret.

16. The method of claim 8 , further comprising revoking a first public key and creating a second public key.

17. A method, comprising:

identifying a first instance of a first secret and a first instance of a second secret;

generating a first instance of a first codeword based on the first instance of the second secret;

receiving and hashing a first instance of first data from a first source to generate a first hashed instance of first data, wherein the first instance of the first data from the first source is discarded;

receiving a first instance of second data from a second source;

computing a first mapping function between the first hashed instance of the first data and the first instance of the first secret, wherein the first mapping function is stored and the first hashed instance of the first data and the first instance of the first secret are discarded, the first mapping function for generation of a second instance of the first secret;

computing a second mapping function between the first instance of second data from the second source and the first instance of the first codeword, wherein the second mapping function is stored and the first instance of second data from the second source and the first instance of the first codeword are discarded, the second mapping function for generation of a second instance of the second secret;

receiving and hashing a second instance of first data from the first source to generate a second hashed instance of the first data;

applying the first mapping function to the second hashed instance of the first data to generate the second instance of the first secret;

receiving a second instance of second data from the second source;

applying the second mapping function to the second instance of second data from the second source to generate a second instance of the first codeword;

generating the second instance of the second secret based on the second instance of the first codeword; and

generating a key using the second instance of the first secret and the second instance of the second secret.

18. The method of claim 17 , wherein the first source is an error-free source and the second source is an error-containing source.

19. The method of claim 1 , wherein the second source is an error containing source.

20. The method of claim 8 , wherein the first source is an error-free source and the second source is an error-containing source.

21. The method of claim 8 , wherein the first source and the second source are both error-containing sources.

22. The method of claim 1 , further comprising generating the first instance of the first codeword using an error correction code encoder.

23. The method of claim 1 , further comprising generating the second instance of the second secret using an error-correction code decoder.

24. The method of claim 3 , further comprising:

updating the second source by binding an updated second source to the second secret; or

binding the first owner to the second secret.

25. The method of claim 12 , further comprising one or more of:

updating the second source by binding an updated second source to the second secret; or

binding the first owner to the second secret.

26. The method of claim 6 , wherein the key is generated using the first instance of the second secret.

27. The method of claim 17 , wherein the key is generated using at least one of the first instance of the second or the first instance of the second secret.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2024
From: HETHERINGTON, MARK D.; LYSEGGEN, JORN; CRUZ-ZENO, EDGARDO M.; WONG, NAI SUM; DAI, MING
To: BKEY, INC.
Reel/Frame 068185/0871 →
Continuity (2)
Provisional Application 63513114 · Jul 11, 2023
Related Publication 20250023737A1 · Jan 16, 2025
References Cited (30)
US 7999863B2 · Nakamura · 2011 [cited by applicant]
US 8959364B2 · Kevenaar et al. · 2015 [cited by applicant]
US 9160532B2 · Pizano · 2015 [cited by examiner]
US 10764054B2 · Herder, III et al. · 2020 [cited by applicant]
US 11115203B2 · Herder, III et al. · 2021 [cited by applicant]
US 11343099B2 · Herder, III et al. · 2022 [cited by applicant]
US 11451385B2 · Herder, III et al. · 2022 [cited by applicant]
US 20080013721A1 · Hwang · 2008 [cited by applicant]
US 20100017618A1 · Golic · 2010 [cited by examiner]
US 20100202609A1 · Sandhu et al. · 2010 [cited by applicant]
US 20120237024A1 · Liu et al. · 2012 [cited by applicant]
US 20160119138A1 · Pizano et al. · 2016 [cited by applicant]
US 20170185761A1 · Stanwood et al. · 2017 [cited by applicant]
US 20190005470A1 · Uhr et al. · 2019 [cited by applicant]
US 20200065463A1 · Ryu · 2020 [cited by examiner]
US 20200252203A1 · Benini · 2020 [cited by examiner]
US 20200252217A1 · Mathieu · 2020 [cited by examiner]
US 20210019450A1 · Li · 2021 [cited by examiner]
US 20210110061A1 · Sharma et al. · 2021 [cited by applicant]
US 20210165794A1 · Armour et al. · 2021 [cited by applicant]
US 20220182216A1 · Hamburg et al. · 2022 [cited by applicant]
US 20230318820A1 · Fooksman et al. · 2023 [cited by applicant]
US 20230403144A1 · Rhodin · 2023 [cited by applicant]
WO 2022043850A1 · 2022 [cited by applicant]
International Search Report and Written Opinion of PCT Patent Application No. PCT/US2024/037675 mailed Oct. 21, 2024, 9 pgs. [cited by applicant]
“What is BIP39?”, Coinplate, Jan. 4, 2022, Retried from the URL: https://getcoinplate.com/blog/what-is-bip39/?v=7516fd43adaa, retrieved on Sep. 10, 2024, 15 Pages. [cited by applicant]
International Search Report and Written Opinion of PCT Application No. PCT/US2024/037674 mailed Oct. 1, 2024, 9 pgs. [cited by applicant]
Office Action of U.S. Appl. No. 18/770,578 mailed Sep. 12, 2024, 16 pgs. [cited by applicant]
Tuyls et al., “Practical Biometric Authentication with Template Protection”, Audio- and Video-Based Biometric Person Authentication, Lecture Notes in Computer Science, vol. 3546, Jul. 2005, pp. 436-446. [cited by applicant]
Final Office Action for U.S. Appl. No. 18/770,578, dated Jan. 2, 2025, 18 pages. [cited by applicant]