IP Library Granted Patent US 9,954,832
Granted Patent B2
US 9,954,832 · App. 15/136,142 · Granted Apr 24, 2018

System and method for enhanced data protection

Inventors: Cody Pollet (Austin, TX); Charles Burgess (Cedar Park, TX); Courtney Roach (Frisco, TX); Brandon Hart (Dallas, TX)
Assignee: Encryptics, LLC
H04L63/0435H04L63/0442H04L63/08H04L2463/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,954,832
App. No.
15/136,142
Granted
Apr 24, 2018
Kind
B2
Abstract

In one embodiment, a method of secure network transmission is performed by a computer system. The method includes encrypting a payload via a first symmetric key and encrypting the first symmetric key via a second symmetric key. The method further includes encrypting an author header comprising the encrypted first symmetric key and a recipient list via a third symmetric key, wherein the recipient list comprises at least one recipient. The method also includes encrypting the third symmetric key via a public asymmetric key associated with an authentication server. Furthermore, the method includes transmitting the encrypted author header and the encrypted third symmetric key to the authentication server for use in recipient-initiated pre-access authentication. In addition, the method includes transmitting the encrypted payload and the second symmetric key over a computer network to the at least one recipient.

Claims (48)

1. A method comprising, by an authentication server:

receiving, from a recipient computer system, a recipient header in relation to an encrypted payload received by the recipient computer system from a sender computer system, wherein the recipient header comprises metadata and recipient authentication information;

causing the metadata of the recipient header to be correlated to a particular authentication header of a plurality of stored authentication headers;

wherein the particular authentication header comprises:

an encrypted data subportion that includes an authorized recipient list and an encrypted first symmetric key, wherein the encrypted first symmetric key is encrypted via a second symmetric key; and

an encrypted third symmetric key that is distinct from the encrypted first symmetric key and the second symmetric key, wherein the encrypted data subportion is encrypted via the encrypted third symmetric key, wherein the encrypted third symmetric key is encrypted via a public key associated with the authentication server;

decrypting the encrypted third symmetric key via a private asymmetric key associated with the authentication server;

decrypting the encrypted data subportion via the decrypted encrypted third symmetric key;

authenticating the recipient computer system as an authorized recipient of the encrypted payload based, at least in part, on a determined match between the recipient authentication information and the authorized recipient list of the decrypted encrypted data subportion;

responsive to the authenticating, encrypting the encrypted first symmetric key via a public asymmetric key associated with the recipient computer system to yield a doubly-encrypted first symmetric key; and

transmitting the doubly-encrypted first symmetric key to the recipient computer system so that the encrypted payload can be decrypted by the recipient computer system.

2. The method of claim 1 , wherein the plurality of stored authentication headers are maintained in a data store that is physically separate from the authentication server.

3. The method of claim 1 , wherein the plurality of stored authentication headers are maintained in a data store resident on the authentication server.

4. The method of claim 1 , wherein the particular authentication header comprises metadata sufficient to identify the particular authentication header.

5. The method of claim 1 , wherein the recipient header comprises credentials associated with a user of the recipient computer system.

6. The method of claim 1 , wherein the recipient header comprises the public asymmetric key associated with the recipient computer system.

7. An authentication system comprising a processor and memory, wherein the processor and memory in combination are operable to perform a method comprising:

receiving, from a recipient computer system, a recipient header in relation to an encrypted payload received by the recipient computer system from a sender computer system, wherein the recipient header comprises metadata and recipient authentication information;

causing the metadata of the recipient header to be correlated to a particular authentication header of a plurality of stored authentication headers;

wherein the particular authentication header comprises:

an encrypted data subportion that includes an authorized recipient list and an encrypted first symmetric key, wherein the encrypted first symmetric key is encrypted via a second symmetric key; and

an encrypted third symmetric key that is distinct from the encrypted first symmetric key and the second symmetric key, wherein the encrypted data subportion is encrypted via the encrypted third symmetric key, wherein the encrypted third symmetric key is encrypted via a public key associated with the authentication system;

decrypting the encrypted third symmetric key via a private asymmetric key associated with the authentication system;

decrypting the encrypted data subportion via the decrypted encrypted third symmetric key;

authenticating the recipient computer system as an authorized recipient of the encrypted payload based, at least in part, on a determined match between the recipient authentication information and the authorized recipient list of the decrypted encrypted data subportion;

responsive to the authenticating, encrypting the encrypted first symmetric key via a public asymmetric key associated with the recipient computer system to yield a doubly-encrypted first symmetric key; and

transmitting the doubly-encrypted first symmetric key to the recipient computer system so that the encrypted payload can be decrypted by the recipient computer system.

8. The authentication system of claim 7 , wherein the plurality of stored authentication headers are maintained in a data store that is physically separate from the authentication system.

9. The authentication system of claim 7 , wherein the plurality of stored authentication headers are maintained in a data store resident on the authentication system.

10. The method of claim 1 , wherein the particular authentication header comprises metadata sufficient to identify the particular authentication header.

11. The authentication system of claim 7 , wherein the recipient header comprises credentials associated with a user of the recipient computer system.

12. The authentication system of claim 7 , wherein the recipient header comprises the public asymmetric key associated with the recipient computer system.

13. A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method comprising:

receiving, from a recipient computer system, a recipient header in relation to an encrypted payload received by the recipient computer system from a sender computer system, wherein the recipient header comprises metadata and recipient authentication information;

causing the metadata of the recipient header to be correlated to a particular authentication header of a plurality of stored authentication headers;

wherein the particular authentication header comprises:

an encrypted data subportion that includes an authorized recipient list and an encrypted first symmetric key, wherein the encrypted first symmetric key is encrypted via a second symmetric key; and

an encrypted third symmetric key that is distinct from the encrypted first symmetric key and the second symmetric key, wherein the encrypted data subportion is encrypted via the encrypted third symmetric key, wherein the encrypted third symmetric key is encrypted via a public key associated with an authentication server;

decrypting the encrypted third symmetric key via a private asymmetric key associated with the authentication server;

decrypting the encrypted data subportion via the decrypted encrypted third symmetric key;

authenticating the recipient computer system as an authorized recipient of the encrypted payload based, at least in part, on a determined match between the recipient authentication information and the authorized recipient list of the decrypted encrypted data subportion;

responsive to the authenticating, encrypting the encrypted first symmetric key via a public asymmetric key associated with the recipient computer system to yield a doubly-encrypted first symmetric key; and

transmitting the doubly-encrypted first symmetric key to the recipient computer system so that the encrypted payload can be decrypted by the recipient computer system.

14. The computer-program product of claim 13 , wherein the plurality of stored authentication headers are maintained in a data store that is physically separate from the authentication server.

15. The computer-program product of claim 13 , wherein the plurality of stored authentication headers are maintained in a data store resident on the authentication server.

16. The computer-program product of claim 13 , wherein the particular authentication header comprises metadata sufficient to identify the particular authentication header.

17. The computer-program product of claim 13 , wherein the recipient header comprises credentials associated with a user of the recipient computer system.

18. The computer-program product of claim 13 , wherein the recipient header comprises the public asymmetric key associated with the recipient computer system.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2020
From: ENCRYPTICS, LLC
To: KEYAVI DATA CORP
Reel/Frame 053771/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2016
From: POLLET, CODY; BURGESS, CHARLES; ROACH, COURTNEY; HART, BRANDON
To: ENCRYPTICS, LLC
Reel/Frame 040690/0518 →
Continuity (2)
Provisional Application 62152178 · Apr 24, 2015
Related Publication 20160315918A1 · Oct 27, 2016