IP Library Granted Patent US 8,068,612
Granted Patent B2
US 8,068,612 · App. 12/107,043 · Granted Nov 29, 2011

Security device for cryptographic communications

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,068,612
App. No.
12/107,043
Granted
Nov 29, 2011
Kind
B2
Abstract

Cryptographic systems and methods are provided in which authentication operations, digital signature operations, and encryption operations may be performed. Authentication operations may be performed using authentication information. The authentication information may be constructed using a symmetric authentication key or a public/private pair of authentication keys. Users may digitally sign data using private signing keys. Corresponding public signing keys may be used to verify user signatures. Identity-based-encryption (IBE) arrangements may be used for encrypting messages using the identity of a recipient. IBE-encrypted messages may be decrypted using appropriate IBE private keys. A smart card, universal serial bus key, or other security device having a tamper-proof enclosure may use the authentication information to obtain secret key information. Information such as IBE private key information, private signature key information, and authentication information may be stored in the tamper-proof enclosure.

Claims (28)

1. A method for supporting identity-based-encryption (IBE) operations in a system in which an IBE private key is provided from an IBE private key server over a communications network to a security device of a user having storage and processing circuitry in a tamper-proof enclosure, comprising:

storing authentication information in the circuitry on the security device in the tamper-proof enclosure;

using the security device and stored authentication information to request the IBE private key from the IBE private key server over the communications network, wherein using the security device and stored authentication information to request the IBE private key comprises:

digitally signing at least an identity (ID) of the user at the security device, and

sending the digitally-signed ID to the IBE private key server as part of the IBE private key request;

verifying the authentication information to determine whether to satisfy the IBE private key request;

if the authentication information is valid, sending the IBE private key to the security device from the IBE private key server over the communications network;

at the security device, storing the IBE private key in the circuitry in the tamper-proof enclosure; and

at the IBE private key server, using a public key of the user to encrypt the IBE private key before sending the IBE private key to the security device over the communications network.

2. The method defined in claim 1 wherein digitally signing the ID of the user comprises using a symmetric key to digitally sign the ID of the user.

3. The method defined in claim 2 wherein verifying the authentication information comprises verifying the digitally-signed ID using a verification service that compares the symmetric key used to digitally sign the ID to a copy of the symmetric key that is stored at the verification service.

4. The method defined in claim 1 further comprising:

at the security device, receiving the IBE private key that has been encrypted using the public key; and

using a private key of the user to decrypt the encrypted IBE private key.

5. The method defined in claim 1 wherein the security device is a portable device installed in a personal computer, comprising:

using the personal computer and the portable device to receive an IBE-encrypted message; and

using the IBE private key stored in the tamper-proof enclosure and an IBE decryption engine to decrypt the IBE-encrypted message.

6. The method defined in claim 1 wherein the security device is a universal serial bus (USB) key installed in a personal computer, comprising:

using the personal computer and USB key to receive an IBE-encrypted message; and

using the IBE private key stored in the tamper-proof enclosure and an IBE decryption engine to decrypt the IBE-encrypted message.

7. A method for supporting identity-based-encryption (IBE) operations in a system in which an IBE private key is provided from an IBE private key server over a communications network to a security device of a user having storage and processing circuitry in a tamper-proof enclosure, comprising:

storing authentication information in the circuitry on the security device in the tamper-proof enclosure;

using the security device and stored authentication information to request the IBE private key from the IBE private key server over the communications network, wherein using the security device and stored authentication information to request the IBE private key comprises:

digitally signing at least an identity (ID) of the user at the security device, and

sending the digitally-signed ID to the IBE private key server as part of the IBE private key request;

verifying the authentication information to determine whether to satisfy the IBE private key request;

if the authentication information is valid, sending the IBE private key to the security device from the IBE private key server over the communications network; and

at the security device, storing the IBE private key in the circuitry in the tamper-proof enclosure, wherein digitally signing the ID of the user comprises using a private authentication key Auth-Ks of the user to digitally sign the ID of the user and wherein verifying the authentication information comprises using an authentication public key Auth-Kp of the user to verify the digitally-signed ID.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Dec 17, 2018
From: VOLTAGE SECURITY, INC.
To: VOLTAGE SECURITY, LLC
Reel/Frame 051198/0611 →
MERGER AND CHANGE OF NAME Recorded Dec 17, 2018
From: VOLTAGE SECURITY, LLC; ENTIT SOFTWARE LLC
To: ENTIT SOFTWARE LLC
Reel/Frame 051199/0074 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
RELEASE OF SECURITY INTEREST Recorded Feb 27, 2015
From: VENTURE LENDING & LEASING VI, INC.; VENTURE LENDING & LEASING VII, INC.
To: VOLTAGE SECURITY, INC.
Reel/Frame 035110/0726 →
SECURITY AGREEMENT Recorded Feb 7, 2014
From: VOLTAGE SECURITY, INC.
To: VENTURE LENDING & LEASING VI, INC.; VENTURE LENDING & LEASING VII, INC.
Reel/Frame 032170/0273 →