IP Library Granted Patent US 11,665,145
Granted Patent B1
US 11,665,145 · App. 14/702,713 · Granted May 30, 2023

Method of providing end to end encryption with auditability

Inventor: Navroop Mitter (Boyds, MD)
H04L63/0442H04L9/0894H04L63/0435
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,665,145
App. No.
14/702,713
Granted
May 30, 2023
Kind
B1
Abstract

A method of performing secure end to end communication between users, the method includes registering a plurality of devices corresponding to a first user having a first user profile stored within a repository, each device having a unique asymmetric public-private key pair, publishing the public key of each device of the first user on the first user profile, storing the private key of each device on corresponding device of the first user, using the published public keys, a second user encrypting and sending a secure message to the first user, and receiving and decrypting the encrypted secure message from the second user on all registered devices corresponding to the first user stored within the repository using the stored private key on each device.

Claims (35)

1. A method of performing and auditing secure end to end communication between users, the method comprising:

registering a plurality of separate devices corresponding to a first user having a first user profile and a second user having a second user profile stored within a repository, each device having a unique asymmetric public-private key pair;

publishing the public key of each separate device of the first user on the first user profile and the second user on the second user profile;

registering a separate auditor device corresponding to a first auditor having a first auditor profile stored within the repository, the auditor device having a unique auditor asymmetric public-private key pair;

publishing the public key of the separate auditor device corresponding to the first auditor on the first auditor profile;

linking the first auditor profile to the first user profile;

using the published public keys on the first user profile and the published public key on the first auditor profile linked to the first user profile and the published public keys on the second user profile, a second user encrypting and sending a secure message to the first user, the first auditor, and the remaining devices of the second user;

receiving and decrypting the encrypted secure message from the second user on all registered devices corresponding to the first user stored within the repository;

receiving and decrypting the encrypted secure message from the second user on the auditor device corresponding to the first auditor linked to the first user profile; and

receiving and decrypting the encrypted secure message from the second user on all remaining registered devices corresponding to the second user stored within the repository,

wherein an auditor device is registered corresponding to a second auditor having a second auditor profile stored within the repository, the auditor device having a unique auditor asymmetric public-private key pair, the method further comprising

publishing the public key of the auditor device corresponding to the second auditor on the second auditor profile;

linking the second auditor profile to the second user profile,

wherein using the published public keys on the second auditor profile linked to the second user profile, the published public keys on the first user profile and the published public key on the first auditor profile linked to the first user profile and the published public keys on the second user profile, a second user encrypts and sends a secure message to the first user, the first auditor whose profile is linked to the first user profile, the second auditor whose profile is linked to the second user profile, and the remaining devices of the second user;

receiving and decrypting the encrypted secure message from the second user on all registered devices corresponding to the first user stored within the repository;

receiving and decrypting the encrypted secure message from the second user on the auditor device corresponding to the first auditor linked to the first user profile;

receiving and decrypting the encrypted secure message from the second user on the auditor device corresponding to the second auditor linked to the second user profile; and

receiving and decrypting the encrypted secure message from the second user on all remaining registered devices corresponding to the second user stored within the repository.

2. A method of claim 1 , wherein the receiving and decrypting the encrypted secure message from the second user occurs on the auditor device corresponding to the auditor linked to the first user profile when the second user encrypted and sent the secure message.

3. A method of claim 1 , wherein the receiving and decrypting the encrypted secure message from the second user occurs on the auditor device corresponding to the first auditor linked to the first user profile and the auditor device corresponding to the second auditor linked to the second user profile when the second user encrypted and sent the secure message.

4. A computer based secure end to end communication system, the system comprising:

a secure messaging application server to register a plurality of separate devices corresponding to a first user having a first user profile a second user having a second user profile stored within a repository, each device having a unique asymmetric public-private key pair;

the secure messaging application server to publish the public key of each separate device of the first and second users on the first user profile and the second user profile respectively;

the secure messaging application server to store the private key of each separate device on corresponding device of the first or second user;

wherein the second user encrypts a message to the first user with a symmetric key, the system further comprising

encrypting the symmetric key with each of the published pubic keys on the first user profile;

encrypting the symmetric key with the published public key on an auditor profile linked to the first user profile;

encrypting the symmetric key with each of the published public keys on the second user profile;

sending the encrypted message and the encrypted symmetric keys to the first user, the auditor, and the remaining devices on the second user profile;

receiving and decrypting the encrypted symmetric key using the stored private key on each device of the first users;

receiving and decrypting the encrypted secure message using the decrypted symmetric key decrypted on all registered devices corresponding to the first user stored within the repository;

receiving and decrypting the encrypted symmetric key using the stored auditor private key on the auditor device;

receiving and decrypting the encrypted secure message using the decrypted symmetric key decrypted on the auditor device;

receiving and decrypting the encrypted symmetric key using the stored private key on each of the remaining devices of the second user; and

receiving and decrypting the encrypted secure message using the decrypted symmetric key decrypted on all of the remaining registered devices corresponding to the second user stored within the repository.

Continuity (1)
Provisional Application 61988009 · May 2, 2014
Cited By (1)
US 12,627,499