Cryptographic Key Spilt Combiner Including a Biometric Input
Abstract
A cryptographic key split combiner, which includes a number of key split generators for generating cryptographic key splits and a key split randomizer for randomizing the cryptographic key splits to produce a cryptographic key, and a process for forming cryptographic keys. Each of the key split generators generates key splits from seed data. The key split generators may include a random split generator for generating a random key split based on reference data. Other key split generators may include a token split generator for generating a token key split based on label data, a console split generator for generating a console key split based on maintenance data, and a biometric split generator for generating a biometric key split based on biometric data. All splits may further be based on static data, which may be updated, for example by modifying a prime number divisor of the static data. The label data may be read from a storage medium, and may include user authorization data. The resulting cryptographic key may be, for example, a stream of symbols, at least one symbol block, or a key matrix.
Claims
exact text as granted — not AI-modified1 - 69 . (canceled)
70 . In a cryptographic system associated with an organization, a method of encrypting an object by a user, comprising:
generating a cryptographic key by combining an organization split corresponding to the organization, a maintenance split, a random split, and at least one label split; initializing a cryptographic algorithm with the cryptographic key; encrypting the object according to the initialized cryptographic algorithm; adding combiner data to the encrypted object, wherein the combiner data includes
reference data corresponding to at least one of the at least one label split and the cryptographic algorithm,
name data associated with the organization,
at least one of the maintenance split and a maintenance level associated with the maintenance split, and
the random split; and
storing the encrypted object with the added combiner data.
71 . The method of claim 70 , further comprising selecting the at least one label split from at least one credential.
72 . The method of claim 71 , wherein the selected at least one label split is encrypted, the cryptographic key is a first cryptographic key, and the method further comprises:
deriving a second cryptographic key from a user ID associated with the user, a password associated with the user, and at least one of a unique data instance and a random value, and decrypting the selected at least one label split with the second cryptographic key.
73 . The method of claim 71 , wherein the at least one credential is retrieved from a memory.
74 . The method of claim 73 , wherein the memory is disposed on a smart card.
75 . The method of claim 71 , further comprising generating a time stamp corresponding to a time at which the object was encrypted, wherein the combiner data further includes the time stamp.
76 . The method of claim 71 , wherein the combiner data further includes a user ID associated with the user.
77 . The method of claim 70 , further comprising generating a time stamp representing a time at which the object was encrypted, wherein the combiner data further includes the time stamp.
78 . The method of claim 70 , wherein the combiner data is a header record.
79 . The method of claim 70 , wherein the combiner data further includes one of a digital signature and a digital certificate.
80 . The method of claim 70 , wherein the combiner data further includes a digital signature and a digital certificate.
81 . The method of claim 70 , wherein the cryptographic key is a first cryptographic key, the method further comprising:
generating a second cryptographic key based at least in part on the at least one label split; and encrypting the random split with the second cryptographic key, prior to adding the combiner data to the encrypted object; wherein the random split included the combiner data is the encrypted random split.
82 . The method of claim 70 , further comprising
before adding the combiner data to the encrypted object, encrypting at least a portion of the combiner data with a header split.
83 . The method of claim 82 , wherein the header split is constant.
84 . The method of claim 70 , wherein combining the organization split, the maintenance split, the random split, and the at least one label split includes applying a non-linear function to the splits
85 . The method of claim 84 , wherein the cryptographic key is a single-integer cryptographic key.
86 . The method of claim 70 , wherein the organization split, the maintenance split, the random split, and the at least one label split are provided by at least one of a policy manager and a credentials manager.
87 . The method of claim 70 , wherein the cryptographic algorithm is a symmetrical algorithm.
88 . The method of claim 70 , wherein the cryptographic key is a session key.Join the waitlist — get patent alerts
Track US2012002805A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.