IP Library Granted Patent US 8,831,214
Granted Patent B2
US 8,831,214 · App. 12/402,786 · Granted Sep 9, 2014

Password self encryption method and system and encryption by keys generated from personal secret information

Inventor: Cheman Shaik (Riyadh, SA)
H04L9/302H04L9/002H04L2209/56H04L9/0844
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,831,214
App. No.
12/402,786
Granted
Sep 9, 2014
Kind
B2
Abstract

A public key cryptographic system and method is provided for a password or any other predefined personal secret information that defeats key factoring and spoofing attacks. The method adopts a new technique of encrypting a password or any predefined secret information by a numeric function of itself, replacing the fixed public key of the conventional RSA encryption. The whole process involving key generation, encryption, decryption and password handling is discussed in detail. Mathematical and cryptanalytical proofs of defeating factoring and spoofing attacks are furnished.

Claims (49)

1. A method comprising

using a server computer to select a first original text password of a first user from a plurality of original text passwords for a plurality of corresponding users stored in a web application's user table in a computer server database;

using the server computer to generate a first key based at least in part on the first original text password;

storing the first key against the first original text password in the web application's user table in the computer server database;

receiving at the server computer an identification of the first user; and

using the server computer to retrieve from the web application's user table the first key based on the identification of the first user;

sending the first key, from the server computer to a first client computer;

encrypting a first set of information by use of the first client computer by using the first key to form a first set of encrypted information; and

sending the first set of encrypted information from the first client computer to the server computer.

2. The method of claim 1 further comprising

using the first original text password as a digital certificate of the first user and digitally signing messages using a public key generated from the first original text password.

3. The method of claim 2 further comprising

verifying a digital signature of the first user by using a private key generated from the first original text password.

4. The method of claim 1 wherein

the step of encrypting information by using the first key is implemented using a layer underlying communication between the client computer which is used as the sender and the server computer.

5. The method of claim 4 wherein

the layer includes a web browser.

6. The method of claim 4 wherein

the layer includes a web page.

7. The method of claim 1 further comprising

decrypting messages from the server computer to the client computer using a public key generated from the first original text password in order to secure information communicated both from the server computer to the client computer and from the client computer to the server computer.

8. The method of claim 1 further comprising

encrypting a message digest by using a public key generated from the first original text password.

9. The method of claim 8 further comprising

decrypting the encrypted message digest by using a private key generated from the first original text password.

10. The method of claim 1 wherein

the server computer is comprised of a plurality of computers.

11. The method of claim 1 further wherein

the server computer retrieves from the web application's user table the first key based only on the identification of the first user.

12. The method of claim 1 further wherein

the server computer retrieves from the web application's user table the first key without using any password of the first user.

13. The method of claim 1 further comprising

using the server computer to select a second original text password of a second user from the plurality of original text passwords for the plurality of corresponding users stored in the web application's user table in the computer server database;

using the server computer to generate a second key based at least in part on the second original text password;

storing the second key against the second original text password in the web application's user table in the computer server database;

receiving at the server computer an identification of the second user; and

using the server computer to retrieve from the web application's user table the second key based on the identification of the second user;

sending the second key, from the server computer to a second client computer;

encrypting a second set of information by use of the second client computer by using the second key to form a second set of encrypted information; and

sending the second set of encrypted information from the second client computer to the server computer.

14. The method of claim 13 wherein

the server computer retrieves from the web application's user table the first key based only on the identification of the first user.

15. The method of claim 13 further wherein

the server computer retrieves from the web application's user table the first key without using any password of the first user.

16. The method of claim 13 further comprising

using the server computer to decrypt the first set of encrypted information by using the first key; and

using the server computer to decrypt the second set of encrypted information by using the second key.

17. The method of claim 1 further comprising

using the server computer to decrypt the first set of encrypted information by using the first key.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 4, 2020
From: UNIVERSAL CIPHER LLC
To: SHAIK, CHEMAN
Reel/Frame 054268/0179 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2018
From: CUMBERLAND SYSTEMS, LLC
To: UNIVERSAL CIPHER, LLC
Reel/Frame 047210/0628 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2017
From: SHAIK, CHEMAN; UNIVERSAL CIPHER LLC
To: UNIVERSAL CIPHER LLC; CUMBERLAND SYSTEMS, LLC
Reel/Frame 042148/0922 →
Continuity (3)
Division 12170506 · Jul 10, 2008
Provisional Application 61056991 · May 29, 2008
Related Publication 20090296927A1 · Dec 3, 2009