US2012159645A1PendingUtilityA1
Techniques for validating and sharing secrets
Est. expiryJun 18, 2028(~1.9 yrs left)· nominal 20-yr term from priority
H04L 9/085
30
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Techniques for validating and sharing secrets are presented. A secret is divided into a plurality of parts. Each part is represented by a unique value. Each value is distributed to a unique user that shares in the secret. The secret is recreated when each user presents each user's unique value. Each unique value is then used to recreate its corresponding part of the key and when all parts are present and validated, the secret is reproduced.
Claims
exact text as granted — not AI-modified1 . A machine-implemented method residing in a non-transitory computer-readable storage medium for execution on a processing device, comprising:
dividing, by the processor, a secret into shares, each share representing a different portion of the secret; assigning, by the processor, each share to a unique user associated with a group of users; calculating, by the processor, a share value for each share, each share value represented as a particular remainder obtained by dividing the secret by a particular pairwise co-prime number associated with a particular user; executing, by the processor, a Chinese Remainder Theorem (CRT) algorithm for each share value and its pairwise co-prime to produce a single value for each share that permits each share, via that share's single value to be independently verified; and sending, by the processor, each single value to the user associated with that single value.
2 . The method of claim 1 further comprising, receiving, by the processor, at different intervals each single value from each of the users.
3 . The method of claim 2 further comprising, validating, by the processor, each single value.
4 . The method of claim 3 further comprising, reproducing, by the processor, each share value from each received single value to re-assemble the secret.
5 . The method of claim 4 further comprising, acquiring, by the processor, a key from secure storage using the re-assembled secret.
6 . The method of claim 5 further comprising, delivering, by the processor, the key to a resource for use in accordance with evaluation of a policy.
7 . The method of claim 1 further comprising, requesting, by the processor, each user to deliver that user's single value for verification and for re-assembling of the secret.
8 . The method of claim 1 , wherein dividing further includes receiving an administrator instruction to divide the secret.
9 . The method of claim 1 , wherein assigning further includes identifying the group of user based on evaluation of a policy.
10 . A machine-implemented method residing in a non-transitory computer-readable storage medium for execution on a processing device, comprising:
acquiring, by the processor, numeric values from users, each use supplying a particular unique one of the numeric values; processing, by the processor, a Chinese Remainder Theorem (CRT) algorithm against each numeric value to produce a portion of a secret; validating, by the processor, each portion of the secret; assembling, by the processor, the portions into the secret; and using, by the processor, the secret to deliver a key to a resource.
11 . The method of claim 10 , wherein acquiring further includes requesting that each user deliver that user's numeric value based on evaluation of a policy.
12 . The method of claim 10 , wherein acquiring further includes requesting that each user deliver that user's numeric value based on an administrator instruction.
13 . The method of claim 10 , wherein acquiring further includes obtaining each user's numeric value based on actions of the users that are unsolicited.
14 . The method of claim 10 , wherein processing further includes using a specific pairwise co-prime number associated with a particular user and that particular user's numeric value as input to the CRT algorithm.
15 . The method of claim 10 , wherein using further includes accessing a secure storage with the secret to obtain the key.
16 . The method of claim 10 , wherein using further includes using, by the resource, the key to access another secure resource that requires the key for access.
17 . A machine-implemented system, comprising:
a machine having a key dividing service implemented in a non-transitory computer-readable storage medium, the key dividing service executing on the machine; and the machine having a key re-assembling service implemented in a non-transitory computer-readable storage medium, the key re-assembling service executing on the machine; wherein the key dividing service is configured to divide a key into portions and derive a single value representing each portion and then deliver each single value to a particular user from a group of users; the key re-assembling service is configured to reproduce each portion after validating each received single value from each user and re-produce the key.
18 . The system of claim 17 , wherein the key re-assembling service is also configured to evaluate policy to deliver the re-produced key to a particular resource.
19 . The system of claim 17 , wherein the key re-assembling service is also configured to use the re-produced key to access a secure storage for a different key accessible via the re-produced key and then deliver the different key to a particular resource in accordance with a policy.
20 . The system of claim 17 , wherein the key is divided and re-produced by processing a Chinese Remainder Theorem (CRT) algorithm.Join the waitlist — get patent alerts
Track US2012159645A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.