US2012002805A1PendingUtilityA1

Cryptographic Key Spilt Combiner Including a Biometric Input

Individually held — no corporate assignee on recordPriority: Feb 13, 1997Filed: Jul 1, 2011Published: Jan 5, 2012
Est. expiryFeb 13, 2017(expired)· nominal 20-yr term from priority
H04L 9/0869H04L 9/0866H04L 9/085H04L 9/0861
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A cryptographic key split combiner, which includes a number of key split generators for generating cryptographic key splits and a key split randomizer for randomizing the cryptographic key splits to produce a cryptographic key, and a process for forming cryptographic keys. Each of the key split generators generates key splits from seed data. The key split generators may include a random split generator for generating a random key split based on reference data. Other key split generators may include a token split generator for generating a token key split based on label data, a console split generator for generating a console key split based on maintenance data, and a biometric split generator for generating a biometric key split based on biometric data. All splits may further be based on static data, which may be updated, for example by modifying a prime number divisor of the static data. The label data may be read from a storage medium, and may include user authorization data. The resulting cryptographic key may be, for example, a stream of symbols, at least one symbol block, or a key matrix.

Claims

exact text as granted — not AI-modified
1 - 69 . (canceled) 
     
     
         70 . In a cryptographic system associated with an organization, a method of encrypting an object by a user, comprising:
 generating a cryptographic key by combining an organization split corresponding to the organization, a maintenance split, a random split, and at least one label split;   initializing a cryptographic algorithm with the cryptographic key;   encrypting the object according to the initialized cryptographic algorithm;   adding combiner data to the encrypted object, wherein the combiner data includes
 reference data corresponding to at least one of the at least one label split and the cryptographic algorithm, 
 name data associated with the organization, 
 at least one of the maintenance split and a maintenance level associated with the maintenance split, and 
 the random split; and 
   storing the encrypted object with the added combiner data.   
     
     
         71 . The method of  claim 70 , further comprising selecting the at least one label split from at least one credential. 
     
     
         72 . The method of  claim 71 , wherein the selected at least one label split is encrypted, the cryptographic key is a first cryptographic key, and the method further comprises:
 deriving a second cryptographic key from a user ID associated with the user, a password associated with the user, and at least one of a unique data instance and a random value, and   decrypting the selected at least one label split with the second cryptographic key.   
     
     
         73 . The method of  claim 71 , wherein the at least one credential is retrieved from a memory. 
     
     
         74 . The method of  claim 73 , wherein the memory is disposed on a smart card. 
     
     
         75 . The method of  claim 71 , further comprising generating a time stamp corresponding to a time at which the object was encrypted, wherein the combiner data further includes the time stamp. 
     
     
         76 . The method of  claim 71 , wherein the combiner data further includes a user ID associated with the user. 
     
     
         77 . The method of  claim 70 , further comprising generating a time stamp representing a time at which the object was encrypted, wherein the combiner data further includes the time stamp. 
     
     
         78 . The method of  claim 70 , wherein the combiner data is a header record. 
     
     
         79 . The method of  claim 70 , wherein the combiner data further includes one of a digital signature and a digital certificate. 
     
     
         80 . The method of  claim 70 , wherein the combiner data further includes a digital signature and a digital certificate. 
     
     
         81 . The method of  claim 70 , wherein the cryptographic key is a first cryptographic key, the method further comprising:
 generating a second cryptographic key based at least in part on the at least one label split; and   encrypting the random split with the second cryptographic key, prior to adding the combiner data to the encrypted object;   wherein the random split included the combiner data is the encrypted random split.   
     
     
         82 . The method of  claim 70 , further comprising
 before adding the combiner data to the encrypted object, encrypting at least a portion of the combiner data with a header split.   
     
     
         83 . The method of  claim 82 , wherein the header split is constant. 
     
     
         84 . The method of  claim 70 , wherein combining the organization split, the maintenance split, the random split, and the at least one label split includes applying a non-linear function to the splits 
     
     
         85 . The method of  claim 84 , wherein the cryptographic key is a single-integer cryptographic key. 
     
     
         86 . The method of  claim 70 , wherein the organization split, the maintenance split, the random split, and the at least one label split are provided by at least one of a policy manager and a credentials manager. 
     
     
         87 . The method of  claim 70 , wherein the cryptographic algorithm is a symmetrical algorithm. 
     
     
         88 . The method of  claim 70 , wherein the cryptographic key is a session key.

Join the waitlist — get patent alerts

Track US2012002805A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.