Secure message passing using semi-trusted intermediaries
Abstract
Techniques are provided for secure message passing. A sender process has a clear (non-encrypted) text message to pass to a recipient process as an encrypted message. The sender generates a message encryption key (MEK) for encrypting the message and sends the MEK to a first intermediary process, which encrypts the MEK. The sender uses the MEK to encrypt the message and passes both the encrypted message and the encrypted MEK to a second intermediary process. The second intermediary verifies that the sender is authorized to send messages and retains the encrypted message and the encrypted MEK. The second intermediary passes the encrypted message and the encrypted MEK to the recipient, which requests decryption of the encrypted MEK from the first intermediary. The first intermediary then decrypts the MEK and returns it to the recipient. Finally, the recipient decrypts the message using the MEK.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method comprising:
receiving, by a first intermediary device, a first key generated by a sender device; encrypting, by the first intermediary device, the first key using a second key; and sending, by the first intermediary device, the encrypted first key to the sender device, the encrypted first key and a message encrypted using the first key being transferrable between the sender device and a recipient device via a second intermediary device, the recipient device being different from the first intermediary device.
22 . The method of claim 21 , further comprising:
receiving, by the first intermediary device, the encrypted first key from the recipient device; decrypting, by the first intermediary device, the encrypted first key using the second key; and sending, by the first intermediary device, the decrypted first key to the recipient device to decrypt the encrypted message.
23 . The method of claim 22 , further comprising verifying that the recipient device is authorized to request decryption of the encrypted first key based on a recipient identifier (“RID”) associated with the recipient device.
24 . The method of claim 21 , further comprising digitally signing, by the first intermediary device, the encrypted first key.
25 . The method of claim 21 , further comprising:
receiving, by the second intermediary device and from the sender device, the encrypted first key and the encrypted message; receiving, by the second intermediary device, a request to pass the encrypted first key and the encrypted message to the recipient device; and passing, by the second intermediary device and to the recipient device, the encrypted first key and the encrypted message.
26 . The method of claim 21 , further comprising verifying, by the first intermediary device, that the sender device is authorized to request encryption of the first key in response to receiving the first key from the sender device.
27 . The method of claim 21 , wherein the first key is encrypted using a symmetric encryption process.
28 . The method of claim 21 , wherein the first key is encrypted using an asymmetric encryption process.
29 . A method comprising:
receiving, by a second intermediary device, an encrypted message encrypted by a sender device using a first key and an encrypted first key encrypted by a first intermediary using a second key, the first intermediary device being different from the second intermediary device; and passing, by the second intermediary device, the encrypted message and the encrypted first key to the recipient device.
30 . The method of claim 29 , further comprising verifying, by the second intermediary device, that the recipient device is authorized to request sending of the encrypted message to the recipient device based on an identifier associated with the recipient device prior to sending the encrypted message to the recipient device.
31 . The method of claim 30 , further comprising:
receiving, by the first intermediary device, the first key; encrypting, by the first intermediary device, the first key using the second key; and sending, by the first intermediary device, the encrypted first key to the sender device for inclusion with the encrypted message.
32 . The method of claim 31 , further comprising:
receiving, by the first intermediary device, the encrypted first key from the recipient device subsequent to receipt of the encrypted message from the sender device; decrypting, by the first intermediary device, the encrypted first key using the second key; and sending, by the first intermediary device, the decrypted first key to the recipient device to decrypt the encrypted message.
33 . The method of claim 31 , further comprising receiving, by the first intermediary device, the encrypted first key from the recipient device, and verifying that the recipient device is authorized to request decryption of the encrypted first key based on a recipient identifier (RID) associated with the recipient device prior to decrypting the encrypted first key.
34 . A system for secure message passing, the system comprising:
a first intermediary including a first memory and at least one first processor coupled to the first memory, wherein the first intermediary is configured to receive a message encryption key (“MEK”) generated by a sender device;
encrypt the MEK using a guard key; and
send the encrypted MEK to the sender device, the encrypted MEK and a message a message encrypted using the MEK being transferrable between the sender device and a recipient device; and
a second intermediary including a second memory and at least one second processor coupled to the second memory, wherein the second intermediary different from the first intermediary and configured to
receive, from the sender device, the encrypted MEK and the encrypted message; and
send, to the recipient device, the encrypted MEK and the encrypted message.
35 . The system of claim 34 , wherein the first intermediary is further configured to verify that the sender device is authorized to request the first intermediary to encrypt the MEK in response to receiving the MEK from the sender device.
36 . The system of claim 34 , wherein the first intermediary is further configured to receive the encrypted MEK from the recipient device;
decrypt the encrypted MEK using the guard key; and send the decrypted MEK to the recipient device to decrypt the encrypted message.
37 . The system of claim 36 , wherein the first intermediary is further configured to verify that the recipient device is authorized to request decryption of the encrypted MEK based on a recipient identifier (“RID”) associated with the recipient device prior to decrypting the encrypted MEK.
38 . The system of claim 36 , wherein the sender device is configured to encrypt the message using the MEK, and wherein the recipient device is configured to decrypt the encrypted message using the decrypted MEK.
39 . The system of claim 34 , wherein the first intermediary is further configured to digitally sign a recipient identifier (“RID”) associated with the recipient device.
40 . The system of claim 34 , wherein the MEK is encrypted using a symmetric encryption process.Join the waitlist — get patent alerts
Track US2022006795A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.