IP Library Granted Patent US 12,425,191
Granted Patent B1
US 12,425,191 · App. 18/482,650 · Granted Sep 23, 2025

System and method for providing multiple key encryption

Inventors: James Pecoraro (New York, NY); Scott Ryan James (New York, NY); Jakub Guzikowski (Wroclaw, PL); Cezary Siewierski (Dublin, IE); Jason Niggel (New York, NY)
Assignee: THE BANK OF NEW YORK MELLON
H04L9/0822H04L9/0877H04L9/0891H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,191
App. No.
18/482,650
Granted
Sep 23, 2025
Kind
B1
Abstract

Systems and methods for providing multiple key encryption may generate a private key encryption key (KEK) and a corresponding public KEK in a trusted execution environment (TEE); provide the public KEK to a key generator; generate, by the key generator, a data encryption key (DEK) and encrypt the DEK with the public KEK; obtain, by a key processor, an ephemeral public key and the encrypted DEK, and send the ephemeral public key and the encrypted DEK to the TEE; decrypt, by the TEE, the encrypted DEK using the private KEK, and re-encrypt the decrypted DEK with the ephemeral public key; obtain, by the key processor, the re-encrypted DEK from the TEE and pass the re-encrypted DEK to a signing service; decrypt, by the signing service, the re-encrypted DEK using a corresponding ephemeral private key; and encrypt, by the signing service, data using the DEK.

Claims (59)

1. A method for providing multiple key encryption, comprising:

generating, a private key encryption key (KEK) and a corresponding public KEK in a trusted execution environment (TEE);

providing the public KEK to a key generator;

generating, by the key generator, a data encryption key (DEK) and encrypting the DEK with the public KEK;

obtaining, by a key processor, an ephemeral public key and the encrypted DEK, and sending the ephemeral public key and the encrypted DEK to the TEE;

decrypting, by the TEE, the encrypted DEK using the private KEK, and re-encrypting the decrypted DEK with the ephemeral public key;

obtaining, by the key processor, the re-encrypted DEK from the TEE and passing the re-encrypted DEK to a signing service;

decrypting, by the signing service the re-encrypted DEK using a corresponding ephemeral private key; and

encrypting, by the signing service, data using the DEK.

2. The method of claim 1 , wherein the TEE, is a hardware security module (HSM).

3. The method of claim 1 , wherein the encrypted DEK is stored in a secret management system (SMS).

4. The method of claim 3 , wherein the ephemeral public key is obtained from the signing service, and the encrypted DEK is obtained from the SMS.

5. The method of claim 1 , wherein the signing service resides in a secure enclave.

6. The method of claim 1 , further comprising:

obtaining the encrypted data; and

decrypting the encrypted data using the DEK.

7. The method of claim 1 , further comprising:

sharding, by the key processor, the DEK, into multiple shards, and

distributing, the DEK shards to multiple actors.

8. The method of claim 7 , wherein the multiple actors comprise at least two actors, each having different credentials.

9. The method of claim 1 , wherein the data is a transaction request; and

wherein, the transaction request is broadcast to a blockchain network.

10. A system for providing multiple key encryption, comprising:

one or more processors; and

at least one memory storing one or more code sets in the at least one memory and executed by the one or more processors, which, when executed, configure the one or more processors to:

generate a private key encryption key (KEK) and a corresponding public KEK in a trusted execution environment (TEE);

provide the public KEK to a key generator;

generate, by the key generator, a data encryption key (DEK) and encrypt the DEK with the public KEK;

obtain, by a key processor, an ephemeral public key and the encrypted DEK, and send the ephemeral public key and the encrypted DEK to the TEE;

decrypt, by the TEE, the encrypted DEK using the private KEK, and re-encrypt the decrypted DEK with the ephemeral public key;

obtain, by the key processor, the re-encrypted DEK from the TEE and pass the re-encrypted DEK to a signing service;

decrypt, by the signing service the re-encrypted DEK using a corresponding ephemeral private key; and

encrypt, by the signing service, data using the DEK.

11. The system of claim 10 , wherein the TEE, is a hardware security module (HSM).

12. The system of claim 10 , wherein the encrypted DEK is stored in a secret management system (SMS).

13. The system of claim 12 , wherein the ephemeral public key is obtained from the signing service, and the encrypted DEK is obtained from the SMS.

14. The system of claim 10 , wherein the signing service resides in a secure enclave.

15. The system of claim 10 , further configured to:

obtain the encrypted data; and

decrypt the encrypted data using the DEK.

16. The system of claim 10 , further configured to:

shard, by the key processor, the DEK, into multiple shards, and

distribute, the DEK shards to multiple actors.

17. The system of claim 16 , wherein the multiple actors comprise at least two actors, each having different credentials.

18. The system of claim 10 , wherein the data is a transaction request; and

wherein, the transaction request is broadcast to a blockchain network.

19. A non-transitory computer-readable medium storing computer-program instructions that, when executed by one or more processors, cause the one or more processors to effectuate operations comprising:

generating, a private key encryption key (KEK) and a corresponding public KEK in a trusted execution environment (TEE);

providing the public KEK to a key generator;

generating, by the key generator, a data encryption key (DEK) and encrypting the DEK with the public KEK;

obtaining, by a key processor, an ephemeral public key and the encrypted DEK, and sending the ephemeral public key and the encrypted DEK to the TEE;

decrypting, by the TEE, the encrypted DEK using the private KEK, and re-encrypting the decrypted DEK with the ephemeral public key;

obtaining, by the key processor, the re-encrypted DEK from the TEE and passing the re-encrypted DEK to a signing service;

decrypting, by the signing service the re-encrypted DEK using a corresponding ephemeral private key; and

encrypting, by the signing service, data using the DEK.

20. The non-transitory computer-readable medium of claim 19 , further comprising:

sharding, by the key processor, the DEK, into multiple shards, and

distributing, the DEK shards to multiple actors;

wherein the multiple actors comprise at least two actors, each having different credentials.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2023
From: PECORARO, JAMES; JAMES, SCOTT RYAN; GUZIKOWSKI, JAKUB; SIEWIERSKI, CEZARY; NIGGEL, JASON
To: THE BANK OF NEW YORK MELLON
Reel/Frame 065299/0498 →
References Cited (27)
US 5799086A · Sudia · 1998 [cited by applicant]
US 10903991B1 · Craige et al. · 2021 [cited by applicant]
US 11201743B2 · Le Saint et al. · 2021 [cited by applicant]
US 11611431B2 · Bursell et al. · 2023 [cited by applicant]
US 11671412B2 · Bursell et al. · 2023 [cited by applicant]
US 20010050990A1 · Sudia · 2001 [cited by applicant]
US 20150278531A1 · Smith · 2015 [cited by examiner]
US 20160036826A1 · Pogorelik · 2016 [cited by examiner]
US 20190042706A1 · Dewan · 2019 [cited by examiner]
US 20190318356A1 · Martin et al. · 2019 [cited by applicant]
US 20190340393A1 · Mo · 2019 [cited by examiner]
US 20200067907A1 · Avetisov · 2020 [cited by examiner]
US 20200111080A1 · Metcalfe et al. · 2020 [cited by applicant]
US 20210064741A1 · Fujiwara · 2021 [cited by examiner]
US 20210173950A1 · Kwak · 2021 [cited by examiner]
US 20210234678A1 · Armleder · 2021 [cited by applicant]
US 20220029801A1 · Velagapalli et al. · 2022 [cited by applicant]
US 20220078028A1 · Pettit · 2022 [cited by applicant]
US 20230121852A1 · Yan · 2023 [cited by examiner]
US 20230126356A1 · Peddada et al. · 2023 [cited by applicant]
US 20240388453A1 · Zheng · 2024 [cited by examiner]
CN 115001669A · 2022 [cited by applicant]
CN 115865349A · 2023 [cited by applicant]
CN 115865460A · 2023 [cited by applicant]
JP 3992491B2 · 2007 [cited by applicant]
WO 2020051710A1 · 2020 [cited by applicant]
WO 2023080355A1 · 2023 [cited by applicant]
Cited By (1)
US 12,609,927