IP Library Granted Patent US 11,044,239
Granted Patent B2
US 11,044,239 · App. 16/689,113 · Granted Jun 22, 2021

Methods and systems for distributing encrypted cryptographic data

Inventor: William R. Ackerly (Washington, DC)
Assignee: Virtru Corporation
H04L63/062H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,044,239
App. No.
16/689,113
Granted
Jun 22, 2021
Kind
B2
Abstract

A method for distributing encrypted cryptographic data includes receiving, by a key service, from a first client device, a request for a first public key. The method includes transmitting, by the key service, to the first client device, the first public key. The method includes receiving, by the key service, from an access control management system, an encryption key encrypted with the first public key and a request from a second client device for access to the encryption key. The method includes decrypting, by the key service, the encrypted encryption key, with a private key corresponding to the first public key. The method includes encrypting, by the key service, the decrypted encryption key, with a second public key received from the second computing device. The method includes transmitting, by the key service, to the second client device, the encryption key encrypted with the second public key.

Claims (19)

1. A method for distributing encrypted cryptographic data comprises:

receiving, by an access control management system maintained by a first entity, from a first client device, a request for transmission, to a second client device, of a message encryption key, the request including the message encryption key, wherein the message encryption key is generated by the first client device and encrypted with a public key of a key management system maintained by a second entity separate from the first entity, and wherein the second client device is identified by the first client device;

transmitting, by the access control management system, to the key management system, the message encryption key;

receiving, by the access control management system, from the key management system, the message encryption key decrypted with a private key of the key management system and encrypted with a public key of a message recipient associated with the second client device;

and transmitting, by the access control management system, to the second client device, the encryption key.

2. The method of claim 1 further comprising generating, by a key issue mechanism of the key service, the public key of the key management system.

3. The method of claim 1 further comprising receiving, by the key management system, from the access control management system, an indication that a user of the second client device has been authenticated by an identity provider.

4. The method of claim 1 further comprising receiving, by the key management system, from the access control management system, an indication that a user of the second client device has been authorized, by the first client device, to receive access to the encryption key.

5. A non-transitory, computer readable medium comprising computer program instructions tangibly stored on the computer readable medium, wherein the computer program instructions are executable by at least one computer processor to perform a method for distributing encrypted cryptographic data, the method comprising:

receiving, by an access control management system maintained by a first entity, from a first client device, a request for transmission, to a second client device, of a message encryption key, the request including the message encryption key, wherein the message encryption key is generated by the first client device and encrypted with a public key of a key management system maintained by a second entity separate from the first entity, and wherein the second client device is identified by the first client device;

transmitting, by the access control management system, to the key management system message, the encryption key;

receiving, by the access control management system, from the key management system, the message encryption key decrypted with a private key of the key management system and encrypted with a public key of a message recipient associated with the second client device;

and transmitting, by the access control management system, to the second client device, the encryption key.

6. A system comprising:

an access control management system maintained by a first entity and executing on a computer:

receiving, from a first client device, a request for transmission, to a second client device, of a message encryption key, the request including the message encryption key, wherein the message encryption key is generated by the first client device and encrypted with a public key of a key management system maintained by a second entity separate from the first entity, and wherein the second client device is identified by the first client device

transmitting, by the access control management system, to the key management system, the message encryption key;

receiving, by the access control management system, from the key management system, the message encryption key decrypted with a private key of the key management system and encrypted with a public key of a message recipient associated with the second client device;

and transmitting, by the access control management system, to the second client device, the encryption key.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Feb 7, 2024
From: FIRST-CITIZENS BANK & TRUST COMPANY
To: VIRTRU CORPORATION
Reel/Frame 066412/0348 →
SECURITY INTEREST Recorded Feb 6, 2024
From: VIRTRU CORPORATION
To: STIFEL BANK
Reel/Frame 066398/0565 →
SECURITY INTEREST Recorded Oct 6, 2021
From: VIRTRU CORPORATION
To: SILICON VALLEY BANK
Reel/Frame 057718/0099 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2019
From: ACKERLY, WILLIAM R.
To: VIRTRU CORPORATION
Reel/Frame 051173/0265 →
Continuity (4)
Continuation 15238752 · Aug 17, 2016
Provisional Application 62305704 · Mar 9, 2016
Provisional Application 62208839 · Aug 24, 2015
Related Publication 20200092270A1 · Mar 19, 2020
Cited By (1)
US 12,395,473