IP Library › Granted Patent US 12,206,769
Granted Patent B2
US 12,206,769 · App. 18/457,265 · Granted Jan 21, 2025

Distributed anonymized compliant encryption management system

Inventor: Tommaso Gagliardoni (Lausanne, CH)
Assignee: Nagravision Sàrl
H04L9/085H04L9/3268H04L63/0421H04L63/0428H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,206,769
App. No.
18/457,265
Filed
Aug 28, 2023
Granted
Jan 21, 2025
Kind
B2
Art Unit
2495
USPC
713/158
Abstract

A method for data security implemented as an application on a device includes generating a request for one or more secret shares needed to reconstruct a key. The device stores a first secret share in its memory. The method also includes signing the request with a certificate that identifies the request as valid without identifying the device, and sending the request, signed with the certificate, to at least one other device. The method further includes receiving, from the at least one other device, the one or more secret shares, determining whether the one or more secret shares received from the at least one other device is sufficient to reconstruct the key, and reconstructing the key using the first secret share and the one or more secret shares upon determining that the one or more secret shares are sufficient to reconstruct the key.

Claims (42)

1. A method performed by an apparatus, comprising:

performing, with circuitry, a validation process for a request to validate a device based on identity information corresponding to the device, the identity information being included in the request and being for a clearance level of the device;

upon successful validation of the device, generating, with the circuitry, a certificate for the device, the certificate including a pseudonym of the device and a security clearance of an owner of the device; and

distributing, with the circuitry, the certificate to the device of a blockchain network.

2. The method according to claim 1 , wherein the identity information corresponding to the device includes financial information of the owner of the device.

3. The method according to claim 1 , wherein the identity information corresponding to the device includes residency information of the owner of the device.

4. The method according to claim 1 , further comprising:

maintaining regional information corresponding to the device; and

inserting the regional information into the certificate before distributing the certificate to the device.

5. The method according to claim 4 , further comprising uploading the regional information to a distributed ledger stored in devices distributed throughout the blockchain network and accessible to the device.

6. The method according to claim 1 , further comprising:

maintaining a certificate revocation list indicating a revocation status of the certificate distributed to the device; and

providing the certificate revocation list to the device.

7. The method according to claim 6 , wherein the providing of the certificate revocation list to the device includes uploading the certificate revocation list to a distributed ledger stored in devices distributed throughout the blockchain network and accessible to the device.

8. A non-transitory computer-readable storage medium including computer executable instructions, wherein the instructions, when executed by a computer, cause the computer to perform a method, the method comprising:

performing a validation process for a request to validate a device based on identity information corresponding to the device, the identity information being included in the request and being for a clearance level of the device;

upon successful validation of the device, generating a certificate for the device, the certificate including a pseudonym of the device and a security clearance of an owner of the device; and

distributing the certificate to the device of a blockchain network.

9. The non-transitory computer-readable storage medium according to claim 8 , wherein the identity information corresponding to the device includes financial information of the owner of the device.

10. The non-transitory computer-readable storage medium according to claim 8 , wherein the identity information corresponding to the device includes residency information of the owner of the device.

11. The non-transitory computer-readable storage medium according to claim 8 , further comprising:

maintaining regional information corresponding to the device; and

inserting the regional information into the certificate before distributing the certificate to the device.

12. The non-transitory computer-readable storage medium according to claim 11 , further comprising uploading the regional information to a distributed ledger stored in devices distributed throughout the blockchain network and accessible to the device.

13. The non-transitory computer-readable storage medium according to claim 8 , further comprising:

maintaining a certificate revocation list indicating a revocation status of the certificate distributed to the device; and

providing the certificate revocation list to the device.

14. The non-transitory computer-readable storage medium according to claim 13 , wherein the providing of the certificate revocation list to the device includes uploading the certificate revocation list to a distributed ledger stored in devices distributed throughout the blockchain network and accessible to the device.

15. An apparatus comprising:

processing circuitry configured to

perform a validation process for a request to validate a device based on identity information corresponding to the device, the identity information being included in the request and being for a clearance level of the device,

upon successful validation of the device, generate a certificate for the device, the certificate including a pseudonym of the device and a security clearance of an owner of the device, and

distribute the certificate to the device of a blockchain network.

16. The apparatus according to claim 15 , wherein the identity information corresponding to the device includes financial information of the owner of the device.

17. The apparatus according to claim 15 , wherein the identity information corresponding to the device includes residency information of the owner of the device.

18. The apparatus according to claim 15 , wherein the processing circuitry is configured to

maintain regional information corresponding to the device, and

insert the regional information into the certificate before distributing the certificate to the device.

19. The apparatus according to claim 18 , wherein the processing circuitry is configured to upload the regional information to a distributed ledger stored in devices distributed throughout the blockchain network and accessible to the device.

20. The apparatus according to claim 15 , wherein the processing circuitry is configured to

maintain a certificate revocation list indicating a revocation status of the certificate distributed to the device; and

provide the certificate revocation list to the device.

Continuity (3)
Continuation 17447990 · Sep 17, 2021
Division 16900391 · Jun 12, 2020
Related Publication 20240064009A1 · Feb 22, 2024
References Cited (29)
US 5675649A · Brennan et al. · 1997 [cited by applicant]
US 5764767A · Beimel et al. · 1998 [cited by applicant]
US 8850187B2 · Hoggan · 2014 [cited by applicant]
US 8978118B2 · Aichroth · 2015 [cited by applicant]
US 9774578B1 · Ateniese et al. · 2017 [cited by applicant]
US 10397005B2 · Brickell · 2019 [cited by examiner]
US 10505741B1 · Conley · 2019 [cited by applicant]
US 10873470B2 · Fynaardt · 2020 [cited by applicant]
US 11133942B1 · Griffin · 2021 [cited by applicant]
US 11582221B1 · Raj · 2023 [cited by applicant]
US 20030037233A1 · Pearson · 2003 [cited by examiner]
US 20070143608A1 · Zeng et al. · 2007 [cited by applicant]
US 20100325441A1 · Laurie · 2010 [cited by examiner]
US 20110179269A1 · Furukawa · 2011 [cited by examiner]
US 20130042298A1 · Plaza Fonseca · 2013 [cited by examiner]
US 20170132630A1 · Castinado · 2017 [cited by applicant]
US 20170346639A1 · Muftic · 2017 [cited by applicant]
US 20180232526A1 · Reid · 2018 [cited by applicant]
US 20190116048A1 · Chen · 2019 [cited by examiner]
US 20190149342A1 · Fynaardt · 2019 [cited by examiner]
US 20190215165A1 · Simplicio, Jr. et al. · 2019 [cited by applicant]
US 20190238311A1 · Zheng · 2019 [cited by applicant]
US 20190333054A1 · Cona · 2019 [cited by examiner]
US 20190334884A1 · Ross · 2019 [cited by examiner]
US 20200036537A1 · Fynaardt · 2020 [cited by examiner]
US 20200153627A1 · Went · 2020 [cited by applicant]
EP 3556045A1 · 2019 [cited by applicant]
WO WO2019229257A1 · 2019 [cited by applicant]
International Search Report and Written Opinion of the International Searching Authority issued Sep. 21, 2021 in PCT/IB2021/000367, 14 pages. [cited by applicant]