IP Library Granted Patent US 9,485,096
Granted Patent B2
US 9,485,096 · App. 14/173,794 · Granted Nov 1, 2016

Encryption / decryption of data with non-persistent, non-shared passkey

Inventors: Apurva Shrivastava (Duluth, GA); Aditya Shrivastava (Duluth, GA)
H04L9/14H04L9/0822H04L9/0863
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,485,096
App. No.
14/173,794
Granted
Nov 1, 2016
Kind
B2
Abstract

The method herein teaches encrypting a Private Key using a Passkey from an RSA generated private key/public key pair; the encrypted Private Key is split and then the portions are stored in two different databases. To encrypt data a new AES key is created that encrypts the data that is stored in another database. All users have their AES key encrypted using their associated public encryption keys such that the encrypted AES keys are stored in another database. To decrypt data the user enters his PassKey that is used to decrypt a rejoined split private key from portions that were retrieved from their respective databases. Next the encrypted AES key is retrieved and decrypted using the decrypted Private Key. Finally the AES encrypted data is retrieved from a database and decrypted using the decrypted AES key.

Claims (24)

1. A method of decrypting encoded data in a processor of a computer, wherein the processor is connected to a plurality of storage components including a first storage component and a second storage component, said method comprising the steps of:

receiving a user entered PassKey into the processor, wherein the PassKey was previously created by the user;

retrieving a first portion of a Split Private Key into the processor from a first storage component;

retrieving a second portion of a Split Private Key from a second storage component; and

decrypting the encoded data in the process of a computer using the first portion and second portion of the Split Private Key, to facilitate the secure receipt of information;

wherein the PassKey is not stored in a persistent state on any of the plurality of storage components connected to the processor.

2. The method of decrypting encoded data of claim 1 , further comprising the step of:

joining the first and second portion of a Split Private Key in the processor.

3. The method of decrypting encoded data of claim 2 , further comprising the step of:

decrypting the joined Private Key in the processor using the user PassKey resulting in a decrypted user Private Key.

4. The method of decrypting encoded data of claim 3 , further comprising the step of:

retrieving an associated public key encrypted random key in the processor.

5. The method of decrypting encoded data of claim 4 , further comprising the step of:

decrypting the associated public key encrypted random key in the processor using the decrypted user Private Key.

6. The method of decrypting encoded data of claim 5 , further comprising the step of:

retrieving encoded data from at least one of the plurality of storage components.

7. The method of decrypting encoded data of claim 6 , further comprising the step of:

decrypting the encoded data in the processor using the decrypted random key.

8. The method of decrypting encoded data of claim 1 , wherein the computer is a server that is remote from the user, wherein the PassKey is received across a network.

9. The method of decrypting encoded data of claim 1 , wherein the plurality of storage components are a plurality of databases.

10. The method of decrypting encoded data of claim 1 , wherein the processor generates the Private Key/Public Key Pair by using a Rivest-Shamir-Adlemen (“RSA”) algorithm, and wherein the PassKey is an input to the RSA algorithm and not an output of the RSA algorithm.

11. The method of decrypting encoded data of claim 1 , wherein the user does not share the PassKey with a second user.

12. The method of decrypting encoded data of claim 1 , wherein the encoded data was encrypted with an Advanced Encryption Standard (“AES”) Key.

13. The method of decrypting encoded data of claim 1 , wherein the PassKey is not stored permanently within the processor.

Continuity (2)
Provisional Application 61849939 · Feb 6, 2013
Related Publication 20140355757A1 · Dec 4, 2014