IP Library › Granted Patent US 12,081,659
Granted Patent B2
US 12,081,659 · App. 17/932,947 · Granted Sep 3, 2024

System and method to randomize distribution of cryptographic keys across multiple secure key storage devices

Inventors: Malini Raman (Chennai, IN); Namitha Jeremiah (Chennai, IN); Rohit Trivedi (Thane West, IN); Ashok Seshadri (Thane West, IN)
Assignee: TATA CONSULTANCY SERVICES LIMITED
H04L9/0869H04L9/0643H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,081,659
App. No.
17/932,947
Granted
Sep 3, 2024
Kind
B2
Abstract

Existing systems enable secure storage of encryption keys in the form of digital wallets, however, since the keys are preconfigured, they can be prone to malicious attacks. The embodiments herein provide a method and system for randomizing distribution of cryptographic keys across multiple secure key storage devices. The system generates random storage identities (RSIDs) for secure key storage devices by selecting a random storage device from a device portfolio, assigns the RSIDs randomly to create crypto addresses based on random access and partition the devices by deriving crypto addresses. Further, the system generates a user hash function and maps the user hash function to find an associated RSID hash function. The system identifies a device ID, a partition ID and a business date from a device mapper associated with the RSIDs to regenerate new RSIDs and recommends the regenerated new RSIDs randomly to each of the plurality of devices.

Claims (38)

1. A processor-implemented method comprising:

receiving, via an input/output interface, a public key, a network ID, and a key creation date from a user identity (ID) to randomize distribution of cryptographic keys across a plurality of secure key storage devices, wherein each the plurality of secure key storage devices is identified with a respective device ID;

generating, via one or more hardware processors, random storage identities (RSIDs) corresponding to each of the plurality of secure key storage devices by selecting a random storage device from a device portfolio;

assigning, via the one or more hardware processors, the generated RSIDs randomly to create crypto addresses based on random access to each of the plurality of secure key storage devices;

partitioning, via the one or more hardware processors, each of the plurality of secure key storage devices by deriving the created crypto addresses to generate a user hash function based on the user ID, the public key, the network ID, and the key creation date;

mapping, via the one or more hardware processors, the generated user hash function with a predefined key device hash mapper to find an associated RSID hash function;

identifying, via the one or more hardware processors, the device ID, the partition ID, and the business date from a device mapper associated with the RSIDs to regenerate new RSIDs for the plurality of secure key storage devices; and

recommending, via the input/output interface, the regenerated new RSIDs randomly to each of the plurality of secure key storage devices.

2. The processor-implemented method of claim 1 , wherein a randomness quotient is calculated for selecting at least one of the plurality of secure key storage devices secured in an ecosystem which is opaque to external adversaries.

3. The processor-implemented method of claim 1 , wherein crypto addresses create the SHA-256 hash function of the device mapper record by concatenating the device ID, the partition ID, and the business date.

4. The processor-implemented method of claim 3 , wherein a last character of the created SHA-256 hash function is picked if the last character is a digit and the RSID is set a concatenated string of the device ID, the partition ID, and the digit.

5. The processor-implemented method of claim 1 , wherein a uniform distribution of the generated RSIDs is based on a harmonic mean among the generated RSIDs.

6. The processor-implemented method of claim 1 , wherein the hash function of the newly generated RSIDs only resides in-memory for computation.

7. The processor-implemented method of claim 1 , wherein the derived crypto addresses, and a public key reside on-chain and a private key resides in the plurality of secure key storage devices.

8. A system comprising:

an input/output interface to receive a public key, a network ID, and a key creation date from a user identity (ID) to randomize distribution of cryptographic keys across a plurality of secure key storage devices, wherein each the plurality of secure key storage devices is identified with a respective device ID;

one or more hardware processors;

a memory in communication with the one or more hardware processors, wherein the one or more hardware processors are configured to execute programmed instructions stored in the memory, to:

generate random storage identities (RSIDs) corresponding to each of the plurality of secure key storage devices by selecting a random storage device from a device portfolio;

assign the generated RSIDs randomly to create crypto addresses based on random access to each of the plurality of secure key storage devices;

partition each of the plurality of secure key storage devices by deriving the created crypto addresses to generate a user hash function based on the user ID, the public key, the network ID, and the key creation date;

mapping the generated user hash function with a predefined key device hash mapper to find an associated RSID hash function;

identify the device ID, the partition ID, and the business date from a device mapper associated with the RSIDs to regenerate new RSIDs for the plurality of secure key storage devices; and

recommend the regenerated new RSIDs randomly to each of the plurality of secure key storage devices.

9. The system of claim 8 , wherein a randomness quotient is calculated for selecting at least one of the plurality of secure key storage devices secured in an ecosystem which is opaque to external adversaries.

10. The system of claim 8 , wherein crypto addresses create the SHA-256 hash function of the device mapper record by concatenating the device ID, the partition ID, and the business date.

11. The system of claim 10 , wherein a last character of the created SHA-256 hash function is picked if the last character is a digit and the RSID is set a concatenated string of the device ID, the partition ID, and the digit.

12. A non-transitory computer readable medium storing one or more instructions which when executed by one or more processors on a system, cause the one or more processors to perform method comprising:

receiving, via an input/output interface, a public key, a network ID, and a key creation date from a user identity (ID) to randomize distribution of cryptographic keys across a plurality of secure key storage devices, wherein each the plurality of secure key storage devices is identified with a respective device ID;

generating, via one or more hardware processors, random storage identities (RSIDs) corresponding to each of the plurality of secure key storage devices by selecting a random storage device from a device portfolio;

assigning, via the one or more hardware processors, the generated RSIDs randomly to create crypto addresses based on random access to each of the plurality of secure key storage devices;

partitioning, via the one or more hardware processors, each of the plurality of secure key storage devices by deriving the created crypto addresses to generate a user hash function based on the user ID, the public key, the network ID, and the key creation date;

mapping, via the one or more hardware processors, the generated user hash function with a predefined key device hash mapper to find an associated RSID hash function;

identifying, via the one or more hardware processors, the device ID, the partition ID, and the business date from a device mapper associated with the RSIDs to regenerate new RSIDs for the plurality of secure key storage devices; and

recommending, via the input/output interface, the regenerated new RSIDs randomly to each of the plurality of secure key storage devices.

13. The non-transitory computer readable medium of claim 12 , wherein a randomness quotient is calculated for selecting at least one of the plurality of secure key storage devices secured in an ecosystem which is opaque to external adversaries.

14. The non-transitory computer readable medium of claim 12 , wherein crypto addresses create the SHA-256 hash function of the device mapper record by concatenating the device ID, the partition ID, and the business date.

15. The non-transitory computer readable medium of claim 14 , wherein a last character of the created SHA-256 hash function is picked if the last character is a digit and the RSID is set a concatenated string of the device ID, the partition ID, and the digit.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2022
From: RAMAN, MALINI; JEREMIAH, NAMITHA; TRIVEDI, ROHIT; SESHADRI, ASHOK
To: TATA CONSULTANCY SERVICES LIMITED
Reel/Frame 061124/0954 →
Priority Claims (1)
IN 202121044405 · Sep 30, 2021 · national
Continuity (1)
Related Publication 20230103259A1 · Mar 30, 2023