Method of and system for encryption and authentication
Abstract
The invention provides a method of and system for networked security, involving multiple clients and servers. Rather than relying on single server based authentication and/or single stream based data transmission, the invention breaks apart information before if leaves the User's computer so that intercepting any single electronic message does not provide the hacker with sufficient information to gain access. The invention splits the values (i.e. password, User name, card number for authorization; encrypted text for encryption, etc.) at the point of sender/external authorization client. These split values are encrypted with different keys and transmitted to multiple external authorization servers. The invention can be applied to any secure transmission, storage or authentication of data over a data network.
Claims
exact text as granted — not AI-modified1 .- 24 . (canceled)
25 . A method of secured communication over a networked system comprising:
a first party:
splitting a secure message into two or more separate messages, each separate message including at least some unique portion of said secure data message, said two or more separate messages collectively preserving information contained in said secure message; and
transmitting each of said two or more separate messages to a separate gatekeeper;
each of said separate gatekeepers:
receiving a respective one of said separate messages;
receiving a partial data set from a second party;
securely processing said separate message by comparing the one of said separate messages to the partial data set;
generating a pass code responsive to the comparison; and
transmitting said processed separate message and the pass code to the second party;
said second party:
receiving said processed separate messages and the pass code from each of said separate gatekeepers; and
re-assembling said processed, separate messages.
26 . The method of claim 25 wherein said secure message is split using a partitioning algorithm.
27 . The method of claim 26 wherein said partitioning algorithm comprises at least one of: a sliding algorithm or a non-sliding algorithm.
28 . The method of claim 26 wherein the contents of said two or more separate messages overlap.
29 . The method of claim 26 wherein the contents of said two or more separate messages do not overlap.
30 . The method of claim 25 wherein said secure message comprises a request for access to data held by said second party.
31 . The method of claim 30 wherein said request for access includes data selected from the group consisting of a Username, a User ID, a password, a passphrase and a User identifier.
32 . The method of claim 25 wherein said first party is selected from the group consisting of:
a personal computer;
a cellular telephone;
a personal digital assistant (PDA);
a portable music player;
a wireless email device;
a portable video player; and
other similar electronic communication device.
33 . The method of claim 25 wherein said secure message comprises an encrypted text message, each separate message being encrypted with a different key.
34 . The method of claim 25 wherein said secure message comprises an email message.
35 . The method of claim 25 wherein said transmitted separate messages further comprise decoy messages.
36 . The method of claim 25 wherein said second party comprises a secure server.
37 . The method of claim 25 wherein said second party comprises a firewalled server which will only communicate with said separate gatekeepers.
38 . The method of claim 25 wherein said secure message is of a type selected from the group consisting of:
high security documents;
digital media files, including movies and music files;
financial transaction data;
authentication codes;
any document needing absolute verifiable sources;
live video transmissions, including corporate digital conferences, CCTV, or subscription and fee based broadcasts;
electronic voting;
RFID tags; and
transmission of biometric authentication date.
39 . The method of claim 25 wherein said secured communication is applied to a system selected from the group consisting of:
unencrypted file transmission with enhanced error correction;
automatic protection against server level viruses via checksum matching;
use of multiple routing in protected server to counter DOS attacks;
network authentication for Financial transactions or Network logons;
wireless Data Transmission for Modified WEP encryption or Multiple broadcast point transmission;
secure networked storage and retrieval of data;
use of splitting via multiple processors in addition to multiple servers; and
splitting via multiple processors applied to a single computer rather than a network of computers or servers.
40 . The method of claim 25 wherein said secure message comprises a data message to be securely stored, and securely processing comprises separately protecting and storing each of said two or more separate messages.
41 . The method of claim 30 wherein said second party is an authentication server and said authentication server responds to a received request for access being accepted by:
generating an authentication code;
splitting up said authentication code into two or more parts;
separately encrypting said two or more parts; and
transmitting said two or more parts to separate gateways who may forward the encrypted parts to the User so that it may be re-assembled and decrypted.
42 . The method of claim 25 wherein said secure message comprises a data message being securely store at said first party, said first party being a storage server, and said second party being a User retrieving said stored message.
43 . A method of authentication comprising:
generating identification data for a User; dividing said identification data into two or more separate sets; protecting each of said two or more separate sets; and transmitting each of said two or more separate protected sets of data to two or more intermediate servers; said two or more intermediate servers:
receiving a partial set of data from an authentication server;
comparing the two or more separate protects sets of data to the partial set of data;
generating a pass code responsive to the comparison; and
forwarding said two or more separate protected sets of data and the pass code to the authentication server;
said authentication server re-assembling two or more separate protected sets of data and determining whether access should be granted to said User.
44 . A system for secured communication comprising:
a first device operable to:
split a secure message into two or more separate messages, each separate message including at least some unique portion of said secure data message, and said two or more separate messages collectively preserving information contained in said secure message; and
transmit each of said two or more separate messages to a separate gatekeeper;
each of said separate gatekeepers being operable to:
receive a respective one of said separate messages;
receive a partial data set from a second device;
securely process the one of said separate messages by comparing the one of said separate messages to the partial data set;
generate a pass code responsive to the comparison; and
transmit said processed separate message and the pass code to the second device;
said second device being operable to:
receive said processed separate messages and the pass code from each of said separate gatekeepers; and
re-assemble said processed, separate messages;
said first device, second device and separate gatekeepers being interconnected via a communication network.Join the waitlist — get patent alerts
Track US2015135301A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.