IP Library Granted Patent US 12,445,265
Granted Patent B2
US 12,445,265 · App. 18/591,861 · Granted Oct 14, 2025

Systems and methods for secure key management using distributed ledger technology

Inventor: Satyender Goel (Chicago, IL)
Assignee: Collibra Belgium BV
H04L9/0631H04L9/0891H04L9/14H04L9/3213H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,265
App. No.
18/591,861
Granted
Oct 14, 2025
Kind
B2
Abstract

The present disclosure is directed to systems and methods for securely managing and administering an encryption/decryption key using distributed ledger technology (DLT). In some examples, a client may possess a data attribute (or a dataset of data attributes). The client may receive tokenization parameters to apply to the data attribute to encrypt the data attribute. After tokenizing the data attribute, the client may then request the creation of an encryption key to be applied to the token. A third-party key management system (KMS) may create an encryption key and a salt. The salt may be applied to the token, and the salted token may then be encrypted. Additionally, a decryption key may be created and stored securely at the third-party KMS. The client may transmit the encrypted token to a third-party consolidation platform, wherein the consolidation platform requests access to the decryption key to unveil the underlying token.

Claims (57)

1. A system comprising:

at least one processor; and

memory coupled to the at least one processor, the memory comprising computer executable instructions that, when executed by the at least one processor, performs a method comprising:

receiving at least one encrypted token, wherein the at least one encrypted token comprises at least one encrypted data attribute, at least one encrypted token salt, and at least one encrypted object identification (ID) encryption key;

requesting at least one decryption key associated with the at least one encrypted token, wherein the at least one decryption key is configured to decrypt the at least one encrypted token salt and the at least one encrypted object ID encryption key;

analyzing at least one smart contract on a blockchain, wherein the at least one smart contract governs access to the at least one decryption key;

based on analyzing the at least one smart contract on the blockchain, determining that the access to the at least one decryption key is granted; and

transmitting results from the determination that the access to the at least one decryption key is granted to at least one owner of the at least one encrypted token.

2. The system of claim 1 , wherein requesting the at least one decryption key includes transmitting a request for the at least one decryption key to a third-party key management system (KMS) provider configured to store the at least one decryption key.

3. The system of claim 2 , further comprising:

providing the at least one decryption key to the KMS provider from the at least one owner of the at least one encrypted token.

4. The system of claim 2 , further comprising:

generating the at least one decryption key by the KMS provider.

5. The system of claim 1 , further comprising:

receiving an encryption request for at least one data attribute;

producing the at least one encrypted data attribute by applying the at least one encrypted token salt to the at least one data attribute in response to the encryption request;

generating the at least one encrypted object ID encryption key in response to the encryption request; and

creating the at least one encrypted token by integrating the at least one encrypted object ID encryption key with the at least one encrypted data attribute and the at least one encrypted token salt.

6. The system of claim 5 , wherein creating the at least one encrypted token is performed by a KMS provider.

7. The system of claim 5 , wherein creating the at least one encrypted token is performed by one or more owners of the at least one data attribute.

8. A method for securely managing a key in a distributed ledger technology (DLT) environment comprising:

receiving a request to create at least one encrypted token, wherein the at least one encrypted token comprises at least one encrypted data attribute, at least one encrypted token salt, and at least one encrypted object ID encryption key;

generating a decryption key associated with the at least one encrypted token, wherein the decryption key is configured to decrypt the at least one encrypted token salt and the at least one encrypted object ID encryption key;

generating a smart contract that governs access to the decryption key;

storing the decryption key and the smart contract governing the access to the decryption key on a permissioned blockchain;

requesting the decryption key associated with the at least one encrypted token;

based on the smart contract, determining that the access to the decryption key is granted; and

transmitting results from determining that the access to the decryption key is granted to at least one owner of the at least one encrypted token.

9. The method of claim 8 , wherein requesting the decryption key is made to a third-party key management system (KMS) provider configured to host the decryption key.

10. The method of claim 9 , further comprising:

providing the decryption key to the KMS provider from the at least one owner of the at least one encrypted token.

11. The method of claim 9 , further comprising:

generating the decryption key by the KMS provider.

12. The method of claim 8 , further comprising:

producing the at least one encrypted data attribute by applying the at least one encrypted token salt to at least one data attribute in response to the request to create the at least one encrypted token;

generating the at least one encrypted object ID encryption key in response to the request to create the at least one encrypted token; and

creating the at least one encrypted token by integrating the at least one encrypted object ID encryption key with the at least one encrypted data attribute and the at least one encrypted token salt.

13. The method of claim 12 , wherein creating the at least one encrypted token is performed by a KMS provider.

14. The method of claim 12 , wherein creating the at least one encrypted token is performed by an owner of the at least one data attribute.

15. A computer-readable media storing non-transitory computer executable instructions that when executed cause a computing system to perform a method for securely managing a key in a DLT environment comprising:

receiving a request to create at least one encrypted token, wherein the at least one encrypted token comprises at least one encrypted data attribute, at least one encrypted token salt, and at least one encrypted object ID encryption key;

generating a decryption key associated with the at least one encrypted token, wherein the decryption key is configured to decrypt the at least one encrypted token salt and the at least one encrypted object ID encryption key;

generating a smart contract that governs access to the decryption key;

storing the decryption key and the smart contract governing the access to the decryption key on a permissioned blockchain;

requesting the decryption key associated with the at least one encrypted token;

based on the smart contract, determining that the access to the decryption key is granted; and

transmitting results from the determination that the access to the decryption key is granted to at least one owner of the at least one encrypted token.

16. The computer-readable media of claim 15 , wherein requesting the decryption key is made to a third-party key management system (KMS) provider configured to host the decryption key.

17. The computer-readable media of claim 16 , further comprising:

providing the decryption key to the KMS provider from the at least one owner of the at least one encrypted token.

18. The computer-readable media of claim 16 , further comprising:

generating the decryption key by the KMS provider.

19. The computer-readable media of claim 15 , further comprising:

producing the at least one encrypted data attribute by applying the at least one encrypted token salt to at least one data attribute in response to the request to create the at least one encrypted token;

generating the at least one encrypted object ID encryption key in response to the request to create the at least one encrypted token; and

creating the at least one encrypted token by integrating the at least one encrypted object ID encryption key with the at least one encrypted data attribute and the at least one encrypted token salt.

20. The computer-readable media of claim 19 , wherein creating the at least one encrypted token is performed by a KMS provider.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2024
From: COLLIBRA NV; CNV NEWCO B.V.; COLLIBRA B.V.
To: COLLIBRA BELGIUM BV
Reel/Frame 066634/0534 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2024
From: GOEL, SATYENDER
To: COLLIBRA NV
Reel/Frame 066614/0222 →
Continuity (2)
Continuation 17215567 · Mar 29, 2021
Related Publication 20240348424A1 · Oct 17, 2024
References Cited (33)
US 9697371B1 · Willden et al. · 2017 [cited by applicant]
US 10411886B1 · Vermeulen · 2019 [cited by examiner]
US 10783190B2 · Qiu · 2020 [cited by examiner]
US 10833846B1 · Zhuo · 2020 [cited by applicant]
US 11153087B1 · Vermeulen · 2021 [cited by examiner]
US 11196561B2 · Tang · 2021 [cited by examiner]
US 11233655B2 · Yang et al. · 2022 [cited by applicant]
US 11315110B2 · Jayachandran et al. · 2022 [cited by applicant]
US 11600125B1 · Hapgood · 2023 [cited by examiner]
US 11949773B2 · Goel · 2024 [cited by examiner]
US 20020165971A1 · Baron · 2002 [cited by examiner]
US 20050278259A1 · Gunaseelan · 2005 [cited by examiner]
US 20140281535A1 · Kane · 2014 [cited by examiner]
US 20190065764A1 · Wood · 2019 [cited by examiner]
US 20190294817A1 · Hennebert · 2019 [cited by examiner]
US 20200036533A1 · Soundararajan et al. · 2020 [cited by applicant]
US 20200169407A1 · Wei et al. · 2020 [cited by applicant]
US 20200177579A1 · Allen · 2020 [cited by applicant]
US 20200177604A1 · Wei et al. · 2020 [cited by applicant]
US 20200204876A1 · Thompson · 2020 [cited by applicant]
US 20200387623A1 · Bayon · 2020 [cited by examiner]
US 20210099573A1 · van Rensburg et al. · 2021 [cited by applicant]
US 20210224418A1 · Nakajima · 2021 [cited by applicant]
US 20210273785A1 · Higashikado et al. · 2021 [cited by applicant]
US 20210279365A1 · Apsingekar et al. · 2021 [cited by applicant]
US 20210377002A1 · Guillama et al. · 2021 [cited by applicant]
US 20220078170A1 · Kravitz et al. · 2022 [cited by applicant]
US 20220311597A1 · Goel · 2022 [cited by applicant]
US 20230114924A1 · Breu · 2023 [cited by applicant]
US 20230161907A1 · Kumar · 2023 [cited by examiner]
CN 104885093A · 2015 [cited by applicant]
CN 111914269A · 2020 [cited by applicant]
PCT/EP2022/057751, International Search Report and Written Opinion mailed Jul. 22, 2022, 13 pgs. [cited by applicant]