IP Library › Granted Patent US 12,212,671
Granted Patent B2
US 12,212,671 · App. 18/485,165 · Granted Jan 28, 2025

Systems and methods for blocking decryption capabilities in symmetric key encryption

Inventors: Margarita Vald (Tel Aviv, IL); Julia Zarubinsky (Tel Aviv, IL); Yaron Sheffer (Tel Aviv, IL); Sergey Banshats (Tel Aviv, IL)
Assignee: INTUIT INC.
H04L9/0866H04L9/0825H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,212,671
App. No.
18/485,165
Granted
Jan 28, 2025
Kind
B2
Abstract

Systems and methods that may be used to provide policies and protocols for blocking decryption capabilities in symmetric key encryption using a unique protocol in which key derivation may include injecting a random string into each key derivation. For example, a policy may be assigned to each client device indicating whether the client device has been assigned encryption only permission or full access permission to both encrypt and decrypt data. The disclosed protocol prevents client devices with encryption only permission from obtaining keys for decryption.

Claims (35)

1. A computer implemented method comprising:

receiving an encryption derive request from a client device;

generating a random string according to one or more predefined rules;

generating a digest parameter based on the random string and a masked secret key;

generating a blinded partial derived key based on the digest parameter; and

transmitting the blinded partial derived key to the client device, the blinded partial derived key being configured to generate a derived key for encrypting data.

2. The computer implemented method of claim 1 , assigning an encryption only policy to the client device, wherein the encryption only policy defines access permissions associated with a protocol for blocking decryption.

3. The computer implemented method of claim 1 , wherein the encryption derive request further includes a key name and derivation data.

4. The computer implemented method of claim 3 , wherein the derivation data is blinded, such that a server receiving the derivation data will not have access to clear text included with the derivation data.

5. The computer implemented method of claim 1 , wherein the random string is one or more of a timestamp, a random phrase, a predictable phrase, a series of numbers, and/or a series of random alphanumeric characters.

6. The computer implemented method of claim 1 , wherein the random string is generated according to one or more predefined rules, including at least generating the random string at predetermined time intervals.

7. The computer implemented method of claim 1 , wherein the digest parameter is further configured to be stored with the derived key in a ciphertext.

8. A system including one or more processors and a memory device configured to implement a method comprising:

receiving an encryption derive request from a client device;

generating a random string according to one or more predefined rules;

generating a digest parameter based on the random string and a masked secret key;

generating a blinded partial derived key based on the digest parameter; and

transmitting the blinded partial derived key to the client device, wherein the blinded partial derived key is configured to generate a derived key for encrypting data.

9. The system of claim 8 , further comprising: assigning an encryption only policy to a client device, wherein the encryption only policy defines access permissions associated with a protocol for blocking decryption.

10. The system of claim 8 , wherein the encryption derive request further includes a key name and derivation data.

11. The system of claim 10 , wherein the derivation data is blinded, such that a server receiving the derivation data will not have access to clear text included with the derivation data.

12. The system of claim 8 , wherein the random string is one or more of a timestamp, a random phrase, a predictable phrase, a series of numbers, and/or a series of random alphanumeric characters.

13. The system of claim 8 , wherein the random string is generated according to one or more predefined rules including at generating the random string at predetermined time intervals.

14. The system of claim 8 , wherein the digest parameter is further configured to be stored with the derived key in a ciphertext.

15. A computer implemented method comprising:

receiving a decryption derive request from a client device, the decryption request including a digest data;

verifying policy permissions associated with the client device;

determining that the policy permissions grant the client device both encryption permission and decryption permission;

processing the decryption derive request based on the policy permission determination; and

generating a derive key based on the digest data in the decryption derive request.

16. The computer implemented method of claim 15 , further comprises extracting a digest from a ciphertext associated with the client device.

17. The computer implemented method of claim 15 , wherein the decryption derive request further includes a key name and derivation data.

18. The computer implemented method of claim 17 , wherein the derivation data is blinded, such that a server receiving the derivation data will not have access to clear text included with the derivation data.

19. The computer implemented method of claim 15 , further comprises generating a random string, wherein the random string is one or more of a timestamp, a random phrase, a predictable phrase, a series of numbers, and/or a series of random alphanumeric characters.

20. The computer implemented method of claim 19 , wherein the random string is generated according to one or more predefined rules, including at least generating the random string at predetermined time intervals.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 29, 2024
From: VALD, MARGARITA; ZARUBINSKY, JULIA; SHEFFER, YARON; BANSHATS, SERGEY
To: INTUIT INC.
Reel/Frame 066758/0565 →
Continuity (2)
Continuation 18066868 · Dec 15, 2022
Related Publication 20240205001A1 · Jun 20, 2024
References Cited (14)
US 8005227B1 · Linnell · 2011 [cited by examiner]
US 11233647B1 · Fontaine · 2022 [cited by examiner]
US 20140164773A1 · Kotla · 2014 [cited by examiner]
US 20140229739A1 · Roth · 2014 [cited by examiner]
US 20150026465A1 · Cucinotta · 2015 [cited by examiner]
US 20150143111A1 · Parann-Nissany · 2015 [cited by examiner]
US 20180248689A1 · Hu · 2018 [cited by examiner]
US 20190207769A1 · Donohoe · 2019 [cited by examiner]
US 20190222424A1 · Lindemann · 2019 [cited by examiner]
US 20200112429A1 · Keselman · 2020 [cited by examiner]
US 20210250163A1 · Vald · 2021 [cited by examiner]
US 20220191039A1 · Kisley · 2022 [cited by examiner]
US 20220311620A1 · Saha · 2022 [cited by examiner]
US 20220400006A1 · Hunsberger · 2022 [cited by examiner]