US2023275750A1PendingUtilityA1

System and method for secure storage and distribution of encryption keys

Assignee: Wildfi Pty LtdPriority: Nov 16, 2019Filed: Apr 28, 2023Published: Aug 31, 2023
Est. expiryNov 16, 2039(~13.3 yrs left)· nominal 20-yr term from priority
H04L 9/083H04L 9/14H04L 9/3247H04L 9/088H04L 9/0894H04L 9/16H04L 9/0819H04L 9/50H04L 9/0891H04L 63/062
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A computer system and a method are provided for storage and distribution of encryption keys in sequence. Encryption keys, such as public keys, are provided key pointers as properties, the key pointer indicating another key, to thereby form a sequence. A current key is designated, and the sequence is advanced to a successor key indicated by the key pointer of the current key upon a predetermined succession event. The current key is transmitted upon receipt of a key request. In various embodiments, succession events can include occurrence of an expiration date, or the addition of a new key to the sequence.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for storage and distribution of encryption keys in sequence, the method comprising:
 storing a plurality of encryption keys in a data storage of a first computer, at least one of the encryption keys having key properties including a key pointer, the key pointer indicating another of the encryption keys in said first computer, each of the plurality of encryption keys stored in the data storage of said first computer is a public key key having a corresponding private key;   defining a sequence of encryption keys in said first computer by:
 designating one of the encryption keys in said first computer as a current first computer key, and 
 designating the encryption key in said first computer indicated by the key pointer of the first computer current key as a successor key; 
   responsive to a predetermined succession event, advancing the sequence of encryption keys in said first computer by:
 designating the successor key in said first computer as a new current key, and 
 designating the encryption key indicated by the key pointer of the new current key as a new successor key; 
   wherein the predetermined succession event is receipt by the data storage of an additional key using the private key corresponding to a next key;   
       transmitting the current key to a remote second computer system responsive to receipt of a key request indicating the remote second computer; and
 adding an additional key in the remote second computer to the sequence of encryption keys by:
 receiving by said remote second computer, the additional key from said first computer; and 
 setting the key pointer in the second computer of a presently stored key to indicate the additional key. 
 
 
     
     
         2 . The method of  claim 1 , wherein the key properties further include expiry data indicating an expiry date, and wherein the predetermined succession event is occurrence of the expiry date indicated by the expiry data of the current key. 
     
     
         3 . The method of  claim 1 , wherein the predetermined succession event is receipt by the data storage of an expiry signal which has been digitally signed using the private key corresponding to the successor key. 
     
     
         4 . The method of  claim 1 , wherein the data storage is a blockchain database. 
     
     
         5 . The method of  claim 1 , wherein the key properties further include a key identifier, each key pointer being the key identifier of another encryption key to thereby indicate the another encryption key. 
     
     
         6 . A non-transitory computer readable medium encoded with instructions to perform a method comprising:
 storing a plurality of encryption keys in a data storage of a first computer, at least one of the encryption keys having key properties including a key pointer, the key pointer indicating another of the encryption keys, each of the plurality of encryption keys stored in the data storage is a public key having a corresponding private key;   defining a sequence of encryption keys in said first computer by:
 designating one of the first computer encryption keys as a current key, and 
 designating the first computer encryption key indicated by the key pointer of the current key as a successor key; 
   responsive to a predetermined succession event, advancing the sequence of encryption keys by:
 designating the successor key in said first computer as a new current key, and 
 designating the encryption key indicated by the key pointer of the new current key as a new successor key; 
   wherein the predetermined succession event is receipt by the data storage of an additional key using the private key corresponding to a next key;   transmitting the current key to a remote second computer system responsive to receipt of a key request indicating the remote computer system; and   adding an additional key in the remote second computer to the sequence of encryption keys by:
 receiving by said remote second computer the additional key from said first computer using the private key corresponding to an encryption key presently stored in the data storage, and 
 setting the key pointer in the second computer of a presently stored key to indicate the additional key. 
   
     
     
         7 . A computer system for storage and distribution of encryption keys in sequence, the computer system comprising a non-transitory computer readable memory and a processor, the computer system coupled to a data storage, software instructions being stored in the computer readable memory and executable to perform operations including:
 storing a plurality of encryption keys in a data storage of a first computer, at least one of the encryption keys having key properties including a key pointer, the key pointer indicating another of the encryption keys, each of the plurality of encryption keys stored in the data storage is a public key having a corresponding private key;   defining a sequence of encryption keys by:
 designating one of the encryption keys in said first computer as a current first computer key, and 
 designating the encryption key in said first computer indicated by the key pointer of the first computer current key as a successor key; 
   responsive to a predetermined succession event, advancing the sequence of encryption keys in said first computer by:
 designating the successor key in said first computer as a new current key, and 
 designating the encryption key indicated by the key pointer of the new current key as a new successor key; 
   wherein the predetermined succession event is receipt by the data storage of an additional key using the private key corresponding to a next key;   transmitting the current key to a remote second computer system responsive to receipt of a key request indicating the remote second computer system; and   adding an additional key in the remote second computer to the sequence of encryption keys by:
 receiving by said remote second, the additional key from said first computer; and 
 setting the key pointer in the remote second computer of the presently-stored key to indicate the additional key. 
   
     
     
         8 . The computer system of  claim 7 , wherein the key properties further include expiry data indicating an expiry date, and wherein the predetermined succession event is occurrence of the expiry date indicated by the expiry data of the current key. 
     
     
         9 . The computer system of  claim 7 , wherein the predetermined succession event is receipt by the data storage of an expiry signal which has been digitally signed using the private key corresponding to the successor key. 
     
     
         10 . The computer system of  claim 7 , wherein the data storage is a blockchain database. 
     
     
         11 . The computer system of  claim 7 , wherein the key properties further include a key identifier, each key pointer being the key identifier of another encryption key to thereby indicate the another encryption key.

Join the waitlist — get patent alerts

Track US2023275750A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.