US2014310516A1PendingUtilityA1

Systems and methods for securing data in motion

Assignee: SECURITY FIRST CORPPriority: Nov 25, 2009Filed: Jun 27, 2014Published: Oct 16, 2014
Est. expiryNov 25, 2029(~3.3 yrs left)· nominal 20-yr term from priority
H04L 63/0823H04L 9/3263H04L 63/0428H04L 12/4641H04L 63/029H04L 9/0816H04L 9/085H04L 63/061H04L 9/00G06F 21/602H04L 63/08H04L 63/0272H04L 63/062
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Two approaches are provided for distributing trust among certificate authorities. Each approach may be used to secure data in motion. One approach provides methods and systems in which a secure data parser is used to distribute trust in a set of certificate authorities during initial negotiation (e.g., the key establishment phase) of a connection between two devices. Another approach of the present invention provides methods and systems in which the secure data parser is used to disperse packets of data into shares. A set of tunnels is established within a communication channel using a set of certificate authorities, keys developed during the establishment of the tunnels are used to encrypt shares of data for each of the tunnels, and the shares of data are transmitted through each of the tunnels. Accordingly, trust is distributed among a set of certificate authorities in the structure of the communication channel itself.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A method comprising:
 receiving secret information by a hardware processor;   dispersing the secret information into shares, wherein the shares are restorable from at least a threshold number of the shares, wherein the threshold number of shares includes fewer than all of the shares;   computing a first shared encryption key based on information associated with the secret information;   recombining the at least a threshold number of the shares; and   computing a second shared encryption key based on information associated with the recombined shares.   
     
     
         3 . The method of  claim 2 , wherein computing the first shared encryption key comprises computing the first shared encryption key based on a set of substantially random numbers, and wherein computing the second shared encryption key comprises computing the second shared encryption key based on the set of substantially random numbers. 
     
     
         4 . The method of  claim 2  further comprising determining whether the first shared encryption key matches the second shared encryption key. 
     
     
         5 . The method of  claim 2 , further comprising transmitting data based on the recombined shares. 
     
     
         6 . The method of  claim 2 , further comprising:
 comparing the first and second shared encryption key;   determining whether to transmit data based on the comparison; and   transmitting data based on the determination.   
     
     
         7 . The method of  claim 2 , further comprising encrypting each one of the shares based on a keywrap. 
     
     
         8 . The method of  claim 7 , wherein the keywrap is based on a workgroup key. 
     
     
         9 . The method of  claim 2 , further comprising:
 generating a certificate authority hierarchy, wherein the certificate authority hierarchy comprises root certificate authorities; and   encrypting each one of the shares based on a certificate issued by a unique root certificate authority of the certificate authority hierarchy.   
     
     
         10 . The method of  claim 2 , wherein the shares comprise a substantially random distribution of the secret information. 
     
     
         11 . The method of  claim 2 , wherein the shares comprise data units from the secret information that have been shuffled. 
     
     
         12 . The method of  claim 2 , wherein the step of dispersing the secret information into the shares comprises using a deterministic technique. 
     
     
         13 . A system comprising a hardware processor configured to:
 receive secret information;   disperse the secret information into shares, wherein the shares are restorable from at least a threshold number of the shares, wherein the threshold number of shares includes fewer than all of the shares;   compute a first shared encryption key based on information associated with the secret information;   recombine the at least a threshold number of the shares; and   compute a second shared encryption key based on information associated with the recombined shares.   
     
     
         14 . The system of  claim 13 , wherein the hardware processor is configured to compute the first shared encryption key by computing the first shared encryption key based on a set of substantially random numbers, and wherein the hardware processor is configured to compute the second shared encryption key by computing the second shared encryption key based on the set of substantially random numbers. 
     
     
         15 . The system of  claim 13 , wherein the hardware processor is further configured to determine whether the first shared encryption key matches the second shared encryption key. 
     
     
         16 . The system of  claim 13 , wherein the hardware processor is further configured to transmit data based on the recombined shares. 
     
     
         17 . The system of  claim 13 , wherein the hardware processor is further configured to:
 compare the first and second shared encryption key;   determine whether to transmit data based on the comparison; and   transmit data based on the determination.   
     
     
         18 . The system of  claim 13 , wherein the hardware processor is further configured to encrypt each one of the shares based on a keywrap. 
     
     
         19 . The system of  claim 18 , wherein the keywrap is based on a workgroup key. 
     
     
         20 . The system of  claim 13 , wherein the hardware processor is further configured to:
 generate a certificate authority hierarchy, wherein the certificate authority hierarchy comprises root certificate authorities; and   encrypt each one of the shares based on a certificate issued by a unique root certificate authority of the certificate authority hierarchy.   
     
     
         21 . The system of  claim 13 , wherein the shares comprise a substantially random distribution of the secret information. 
     
     
         22 . The system of  claim 13 , wherein the shares comprise data units from the secret information that have been shuffled. 
     
     
         23 . The system of  claim 13 , wherein the hardware processor is configured to disperse the secret information into the shares using a deterministic technique. 
     
     
         24 . A non-transitory computer-readable medium comprising instructions that, when executed by processing circuitry, cause a computer system to carry out a method for secure workgroup communication, the method comprising:
 receiving secret information by a hardware processor;   dispersing the secret information into shares, wherein the shares are restorable from at least a threshold number of the shares, wherein the threshold number of shares includes fewer than all of the shares;   computing a first shared encryption key based on information associated with the secret information;   recombining the at least a threshold number of the shares; and   computing a second shared encryption key based on information associated with the recombined shares.

Join the waitlist — get patent alerts

Track US2014310516A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.