US2018026953A1PendingUtilityA1

Encryption on computing device

Assignee: DATA GUARD SOLUTIONS INCPriority: May 7, 2014Filed: Sep 20, 2017Published: Jan 25, 2018
Est. expiryMay 7, 2034(~7.8 yrs left)· nominal 20-yr term from priority
G06F 21/6218H04L 67/306H04L 63/0492H04L 63/061H04L 9/0861H04W 12/04G06F 2221/2117G06F 2221/2153G09C 1/00
40
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A first component of a cryptographic key is received from a user via a user interface of a user computing device. A second component of the cryptographic key is received via a short-range communication interface that communicatively couples the user computing device to a physically separate storage device. The cryptographic key is generated based at least on the first component and the second component. The cryptographic key is then used to encrypt and/or decrypt data.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for generating cryptographic keys for encrypting and decrypting data, the method comprising:
 receiving, by one or more processors, a first component of a cryptographic key from a user via a user interface of a user computing device;   receiving, by the one or more processors, a second component of the cryptographic key via a short-range communication interface that communicatively couples the user computing device to a physically separate storage device;   generating, by the one or more processors, the cryptographic key based at least on the first component and the second component; and   using the cryptographic key to encrypt and/or decrypt data, by the one or more processors.   
     
     
         2 . The method of  claim 1 , wherein using the cryptographic key to encrypt and/or decrypt the data includes:
 storing the generated cryptographic key in a volatile memory of the user computing device during an active session,   automatically encrypting and/or decrypting data accessed by the user during the active session, by the one or more processors, and   deleting the cryptographic key from the volatile memory when the active session completes.   
     
     
         3 . The method of  claim 2 , further comprising:
 verifying the cryptographic key using control data stored on the storage device, wherein the generated cryptographic key is stored in the volatile memory only in response to the cryptographic key having been successfully verified.   
     
     
         4 . The method of  claim 3 , wherein the control data includes first control data and second control data, and wherein verifying the cryptographic key includes:
 retrieving the first control data from the storage device,   applying the cryptographic key to the first control data to generate an encryption/decryption result, and   comparing the encryption/decryption result to the second control data, wherein the cryptographic key is successfully verified when the encryption/decryption result matches the second control data.   
     
     
         5 . The method of  claim 2 , further comprising completing the active session in response to detecting that the storage device has been removed. 
     
     
         6 . The method of  claim 2 , further comprising completing the active session in response to detecting that the user logged off. 
     
     
         7 . The method of  claim 1 , wherein using the cryptographic key to encrypt and/or decrypt the data includes automatically applying, by the one or more processors, the cryptographic key to files stored in a persistent memory of the user computing device, which the user accesses during an active session, without prompting the user. 
     
     
         8 . The method of  claim 7 , wherein applying the cryptographic key to the files stored in a persistent memory of the user computing device including executing a task in a kernel mode on the user computing device. 
     
     
         9 . The method of  claim 1 , further comprising, prior to receiving the second component via the short-range communication interface:
 receiving, by the one or more processors, the second component of the cryptographic key via a long-range communication interface from a network server;   causing, by the one or more processors, the second component of the cryptographic key to be stored in the storage device.   
     
     
         10 . The method of  claim 8 , further comprising:
 providing, by the one or more processors, an interactive menu for receiving registration data from a user; and   sending the registration data to the network server via the long-range communication interface, wherein the second component of the cryptographic key is received from the network server in response to the registration data.   
     
     
         11 . The method of  claim 1 , wherein the user computing device has a port to removeably couple the user computing device to a peripheral storage device, wherein the second component of the cryptographic key is received via the port from the peripheral storage device. 
     
     
         12 . The method of  claim 1 , wherein generating the cryptographic key includes appending, by the one or more processors, one of the first and the second component of the cryptographic key to the other one of the first and the second component of the cryptographic key. 
     
     
         13 . A network server comprising:
 a communication interface to communicatively couple the network server to a user computing device via a communication network; and   processing hardware configured to:
 receive a request for a cryptographic key from the user computing device, wherein the request includes a first component of the cryptographic key, the first component having been specified by a user of the user computing device, 
   in response to the request, automatically generate a second component of the cryptographic key, and   provide the second component of the cryptographic key to the user device for storage on a storage device physically separate from the user computing device,   wherein the user computing device is configured to (i) generate the cryptographic key based at least on the first component and the second component of the cryptographic key and (ii) encrypt and/or decrypt user-selected data using the cryptographic key.   
     
     
         14 . The network server of  claim 13 , further comprising:
 a computer-readable storage in which a database is implemented;   wherein the processing hardware is further configured to:   receive registration data for the user from the user computing device, and   store the registration data, the first component of the cryptographic key, and the second component of the cryptographic key in the database.   
     
     
         15 . The network server of  claim 14 , wherein the processing hardware is further configured to reset the cryptographic key in response to a user request, including generate a new second component of the cryptographic key. 
     
     
         16 . The network server of  claim 13 , wherein the processing hardware is further configured to:
 generate the cryptographic key based on the first component and the second component,   generate first control data,   apply the cryptographic key to the first control data to generate second control data, and   provide the first control data and the second control data to the user device for storage on the storage device,   wherein the user computing device is configured to verify user input of the first component of the cryptographic key using the first control data, the second control data, and the second component of the cryptographic key.   
     
     
         17 . The network server of  claim 16 , wherein the processing hardware is configured to generate the first control data randomly. 
     
     
         18 . A method in a user computing device for efficiently encrypting and/or decrypting data, the method comprising:
 receiving, by one or more processors, an indication that a storage device physically separate from the user computing device is now communicatively coupled to the user computing device via a short-range communication interface;   receiving, by the one or more processors, a first component of a cryptographic key from a user via a user interface;   retrieving, from the storage device, (i) a second component of the cryptographic key, (ii) first control data, and (iii) second control data corresponding to the first control data encrypted using a correct version of the cryptographic key;   generating the cryptographic key based at least on the first component and the second component; and   determining whether the generated cryptographic key is correct using the first control data and the second control data.   
     
     
         19 . The method of  claim 18 , further comprising:
 receiving, by the one or more processors, the second component of the cryptographic key, the first control data, and second control data from a network server via a communication network; and   storing the second component of the cryptographic key, the first control data, and second control data in the storage device.   
     
     
         20 . The method of  claim 19 , wherein receiving the second component of the cryptographic key, the first control data, and second control data from the network server includes is in response to a user requesting that a new cryptographic key be generated.

Join the waitlist — get patent alerts

Track US2018026953A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.