IP Library Granted Patent US 10,187,200
Granted Patent B1
US 10,187,200 · App. 15/881,648 · Granted Jan 22, 2019

System and method for generating a multi-stage key for use in cryptographic operations

Inventors: Adam C. Firestone (Alexandria, VA); Hilary L. MacMillan (Ashburn, VA)
Assignee: SECURE CHANNELS INC.
H04L9/0618H04L9/0869H04L63/0435
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,187,200
App. No.
15/881,648
Granted
Jan 22, 2019
Kind
B1
Abstract

A computerized method that encrypts each of a plurality of segments of a binary value using a selected block cipher of a plurality of block ciphers and a unique symmetric key of a first plurality of unique, symmetric keys to produce a first ciphertext. The method further encrypts each of a plurality of segments of the first ciphertext using a selected block cipher of the plurality of block ciphers and a unique symmetric key of a second plurality of unique, symmetric keys to produce a second ciphertext. The selected block cipher used to encrypt a first segment of the binary value to produce a first segment of the plurality of segments of the first ciphertext is different than the selected block cipher used to encrypt the first segment of the ciphertext to produce a first encrypted segment of the second ciphertext.

Claims (33)

1. A computerized method comprising:

encrypting each of a plurality of segments of a binary value using a selected block cipher of a plurality of block ciphers and a unique symmetric key of a first plurality of unique, symmetric keys to produce a first ciphertext;

encrypting each of a plurality of segments of the first ciphertext using a selected block cipher of the plurality of block ciphers and a unique symmetric key of a second plurality of unique, symmetric keys to produce a second ciphertext, wherein the selected block cipher used to encrypt a first segment of the binary value to produce a first segment of the plurality of segments of the first ciphertext is different than the selected block cipher used to encrypt the first segment of the first ciphertext to produce a first segment of the second ciphertext and the encrypting of each of the plurality of segments of the first ciphertext comprises aligning the plurality of segments of the first ciphertext with a plurality of segments of the second ciphertext where the first segment of the plurality of segments of the first ciphertext corresponds to the first segment of the second ciphertext, a second segment of the plurality of segments of the first ciphertext corresponds to a second segment of the plurality of segments of the second ciphertext and continuing to associate remaining segments of the plurality of segments of the first ciphertext with remaining segments of the plurality of segments of the second ciphertext;

concatenating a pattern key to a prescribed segment of the plurality of segments of the second ciphertext to produce a composite ciphertext, the pattern key including identifiers of the block ciphers and symmetric keys used to encrypt each of the plurality of segments of the binary value and each of the plurality of segments of the first ciphertext; and

encrypting the composite ciphertext using a symmetric key cipher and a selected symmetric key to produce a multi-layered, multi-segmented ciphertext for secure storage within a memory device.

2. The computerized method of claim 1 , wherein the encrypting of each of the plurality of segments of the binary value comprises

generating a first plurality of unique nonces by a random number generator; and

generating each of a first plurality of unique, symmetric keys based on a corresponding nonce of the first plurality of nonces.

3. The computerized method of claim 2 , wherein the encrypting of each of the plurality of segments of the binary value further comprises

generating a second plurality of unique nonces by the random number generator; and

selecting a block cipher of the plurality of block ciphers for each of the plurality of segments of the binary data based on a corresponding nonce of the second plurality of nonces.

4. The computerized method of claim 3 , wherein the encrypting of each of the plurality of segments of the first ciphertext comprises

generating a third plurality of unique nonces by the random number generator; and

generating each of the second plurality of unique, symmetric keys based on a corresponding nonce of the third plurality of nonces.

5. The computerized method of claim 4 , wherein the encrypting of each of the plurality of segments of the first ciphertext further comprises

generating a fourth plurality of unique nonces by the random number generator; and

selecting block ciphers for each of the plurality of segments of the first ciphertext based on a corresponding nonce of the fourth plurality of nonces.

6. The computerized method of claim 1 , wherein the

encrypting the composite ciphertext further comprises

encrypting the selected symmetric key to produce the multi-layered, multi-segmented ciphertext including the encrypted composite ciphertext and the encrypted symmetric key.

7. A system comprising:

a processor; and

a memory communicatively coupled to the processor, the memory including one or more software module that, upon execution by the processor, perform operations, including

encrypting each of a plurality of segments of a binary value using a selected block cipher of a plurality of block ciphers and a unique symmetric key of a first plurality of unique, symmetric keys to produce a first ciphertext,

encrypting each of a plurality of segments of the first ciphertext using a selected block cipher of the plurality of block ciphers and a unique symmetric key of a second plurality of unique, symmetric keys to produce a second ciphertext, wherein the selected block cipher used to encrypt a first segment of the binary value to produce a first segment of the plurality of segments of the first ciphertext is different than the selected block cipher used to encrypt the first segment of the first ciphertext to produce a first segment of the second ciphertext and the second ciphertext being produced by at least aligning the plurality of segments of the first ciphertext with a plurality of segments of the second ciphertext, wherein the first segment of the plurality of segments of the first ciphertext corresponds to the first segment of the second ciphertext, a second segment of the plurality of segments of the first ciphertext corresponds to a second segment of the second ciphertext and remaining segments of the plurality of segments of the first ciphertext corresponding to remaining segments of the plurality of segments of the second ciphertext,

concatenating a pattern key to a prescribed segment of the plurality of segments of the second ciphertext to produce a composite ciphertext, the pattern key including identifiers of the block ciphers and symmetric keys used to encrypt each of the plurality of segments of the binary value and each of the plurality of segments of the first ciphertext; and

encrypting the composite ciphertext using a symmetric key cipher and a selected symmetric key to produce a multi-layered, multi-segmented ciphertext.

8. The system of claim 7 , wherein a software module of the one or more software modules, upon execution by the processor, encrypts each of the plurality of segments of the binary value by at least (i) generating a first plurality of unique nonces by a random number generator, and (ii) generating each of a first plurality of unique, symmetric keys based on a corresponding nonce of the first plurality of nonces.

9. The system of claim 8 , wherein a software module of the one or more software modules, upon execution by the processor, encrypts each of the plurality of segments of the binary value by at least (i) generating a second plurality of unique nonces by the random number generator, and (ii) selecting a block cipher of the plurality of block ciphers for each of the plurality of segments of the binary data based on a corresponding nonce of the second plurality of nonces.

10. The system of claim 9 , wherein a software module of the one or more software modules, upon execution by the processor, encrypts each of the plurality of segments of the first ciphertext by at least (i) generating a third plurality of unique nonces by the random number generator, and (ii) generating each of the second plurality of unique, symmetric keys based on a corresponding nonce of the third plurality of nonces.

11. The system of claim 10 , wherein a software module of the one or more software modules, upon execution by the processor, encrypts each of the plurality of segments of the first ciphertext by at least (i) generating a fourth plurality of unique nonces by the random number generator, and (ii) selecting block ciphers for each of the plurality of segments of the first ciphertext based on a corresponding nonce of the fourth plurality of nonces.

12. The system of claim 7 , wherein the memory further comprises one or more software module that, upon execution by the processor, further perform operations, comprising:

generating an output ciphertext for transmission over a network, the output ciphertext including the encrypted composite ciphertext and an encrypted version of the selected symmetric key to form the multi-layered, multi-segmented ciphertext.

Assignments (5)
SECURITY INTEREST Recorded Mar 26, 2021
From: SECURE CHANNELS, INC.
To: PETNEDA HOLDINGS LIMITED
Reel/Frame 055733/0610 →
FIRST AMENDMENT TO ASSIGNMENT AND ASSUMPTION OF CONTRACTS Recorded Mar 26, 2021
From: PETNEDA HOLDINGS LIMITED
To: CHOL, INC.
Reel/Frame 055820/0148 →
ASSIGNMENT AND ASSUMPTION OF CONTRACTS Recorded Mar 24, 2020
From: PETNEDA HOLDINGS LIMITED
To: CHOL INC.
Reel/Frame 052208/0990 →
SECURITY INTEREST Recorded Feb 28, 2020
From: SECURE CHANNELS INC.
To: PETNEDA HOLDINGS LIMITED
Reel/Frame 051965/0323 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2018
From: FIRESTONE, ADAM C.; MACMILLAN, HILARY L.
To: SECURE CHANNELS INC.
Reel/Frame 044745/0460 →
Continuity (1)
Provisional Application 62607263 · Dec 18, 2017
Cited By (2)
US 12,254,116 US 12,587,377