OA10456A

Cryptographic system and method with key escrow feature

Abstract

The invention provides a cryptographic system and method with a key escrow feature that uses a method for verifiably splitting users' private encryption keys into components and for sending those components to trusted agents chosen by the particular users, and provides a system that uses modern public key certificate management, enforced by a chip device that also self-certifies. In a preferred embodiment of this invention, the chip encrypts or decrypts only if certain conditions are met, namely, (1) if a valid "sender certificate" and a valid "recipient certificate" are input, where "valid" means that the particular user's private decryption key is provably escrowed with a specified number of escrow agents and that the master escrow center is registered and certified by the chip manufacturer, and (2) if a valid Message Control Header is generated by the sender and validated by the recipient, thereby giving authorized investigators sufficient information with which to request and obtain the escrowed keys. A further preferred embodiment of this invention provides a method for generating verifiably trusted communications among a plurality of users, comprising the steps of escrowing at a trusted escrow center a plurality of asymmetric cryptographic keys to be used by a plurality of users; verifying each of said plurality of keys at the escrow center; certifying the authorization of each of said plurality of keys upon verification; and initiating a communication from each of said plurality of users using a respective one of said plurality of keys contingent upon said certification.

OA10456A, drawing sheet 1
Sheet 1 of 28

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Granted
  4. Today

14 claims: 14 independent, 0 dependent

  1. 1
    What is claimed is:1. A method for generating verifiably trusted communication among a plurality of users, comprising the steps of: escrowing at a trusted escrow center a plurality of secret asymmetric cryptographie keys to be used by a plurality of users;verifying each of said plurality of keys at the escrow center;certifying [the authorization of] each of said plurality of keys upon vérification;and initiating a communication from each of said plurality of users using a respective one of said plurality of keys contingent upon said certification.
  2. 2
    A method for generating verifiably trusted communications among a plurality of users, comprising the steps of:escrowing at a trusted escrow center an asymmetric cryptographie key associated with each of a plurality of users;verifying each of the keys at the escrow center;certifying each of the keys upon vérification;and initiating a secure communication from an initiating user to a receiving user contingent upon certification of keys of both the initiating and receiving users.
  3. 3
    A method for generating verifiably trusted communications among a plurality of users with sélective non-party access, comprising the steps of:escrowing, at a trusted escrow center, asymmetric cryptographie keys associated with a plurality of users. 010456 each user associated with at least one key and at least a first selectable non-party to hâve access to the user's communications;verifying the keys at the escrow center;certifying each of the keys upon vérification;initiating a trusted communication from a sending user to a récipient in a manner that permits access to the communication by the first non-party.
  4. 4
    A method for secure communication in a system having at least one communicating party and a message key that is recoverable by one not a party to the communication, the method comprising steps of:providing each user with a computer hardware device;registering hardware devices with a center in accordance with control information determined by a device owner distinct from a device user;certifying hardware devices, each certification generating a certificate associating a center, a user, and a hardware device;initiating a secure communication from an initiating user to a récipient using a message key in a manner that permits the owner to access the communication.
  5. 5
    A method for generating verifiably trusted communications among a plurality of users with third party access, comprising the steps of:escrowing with at least one of a plurality of escrow centers an asymétrie cryptographie key associated with each of a plurality of users;verifying the keys at the escrow center;certifying each of the keys upon vérification;010456 initiating a trusted communication from a sending user to a receiving user using a verified key, said communication including information to recover a key of the initiating user and a key of the receiving user.
  6. 6
    A method for generating verifiably trusted communications among a plurality of users comprising steps of:manufacturing electronic hardware devices, each device controlled by tamper-proof logic;and initiating a secure communication from an initiating device to a récipient, said communication including access information signed by the initiating device and containing information to permit access to the communication by an outside party.
  7. 7
    A method for generating verifiably trusted communications among a plurality of users, comprising the steps of:escrowing at an escrow center an asymmetric cryptographie key associated with each of a plurality of users;verifying the keys at the escrow center;Â certifying each of the keys upon vérification;and initiating a communication from an initiating user to a receiving user contingent upon a trusted device of the initiating user confirming certification of keys of the sending and receiving users.
  8. 8
    A method for generating verifiably trusted communications among a plurality of users, comprising the steps of:010456
  9. 9
    9* escrowing at a trusted escrow center an asymétrie cryptographie key associated with each of a plurality of users; * Λ verifying the keys at the escrow center; certifying each of the keys upon vérification; and initiating a communication from an initiating user to a receiving user contingent upon certification ar a key used in the communication, said communication containing access information that permits access to the communication by an outside party. 9. A method for generating verifiably trusted communications among a plurality of users, comprising the steps of:escrowing at a trusted escrow center an asymmetric cryptographie key associated with each of a plurality of users;verifying the keys at the escrow center;certifying each of the keys upon vérification and a trusted device associated with each user;and initiating a communication from an initiating user to a récipient after certification of a key used fer the communication and after confirmation of attributes of a trusted device associated with the initiating user.
  10. 10
    A method for generating verifiably trusted communications among a plurality of users, comprising the steps of:escrowing, at trusted escrows centers, asymmetric cryptographie keys associated with a plurality of users, ones of said escrow centers belonging to a first group, others of said escrow centers belonging to a second group;010456 verifying the keys at the escrow centers;certifying each of the keys upon vérification;and communicating between a first user and a second user contingent upon the groups to which the escrow centers of 5 sending and receiving users belong.
  11. 11
    A method for generating verifiably trusted, stream oriented communications among a plurality of users, comprising the steps of:escrowing at a trusted escrow center an asymmetric 10 cryptographie key associated with each of a plurality of users;verifying each of the keys at the escrow center;certifying each of the keys upon vérification;and generating a stream oriented communication from an 15 initiating user to a receiving user, said communication comprising (a) an initial packet having access information to allow an outside party to hâve access to the stream, and (b) a stream of subséquent packets, each subséquent packet containing information identifying the 20 subséquent packet as associated with the stream.
  12. 12
    A method of upgrading firmware of a trusted device, comprising steps of:embedding within the trusted device a key associated with a firmware source;25 communicating firmware to the trusted device, said communication modified by the firmware source in a manner that can be confirmed using the embedded key;and incorporate the firmware into the trusted device contingent upon confirmation of the communication using 30 the embedded key. 9β 010456
  13. 13
    A method for encrypted communication in a system having communicating parties and a message key that is recoverable by one not a party to the communication, the method comprising steps of:providing each user with a computer hardware device having at least one device-associated key;registering hardware devices with at least a selected one of a plurality of centers;certifying the hardware devices, said certification generating a certificate for a device;initiating a secure communication from an initiating user to a récipient using a message key, said communication containing an access portion encrypted by a key of the center to recover the message key.
  14. 14
    A method of authorizing a trusted device to conduct an electronic transaction between a first user and a second party, and providing assurance that said trusted device will engage in said electronic transaction in accordance with predetermined rules which cannot be changed by said user, said method comprising:electronically transmitting from said trusted device to a third party a request for authorization to engage in said electronic transaction, said request including the identity of said trusted device;determining, by said third party, that said trusted device should be authorized to engage in said transaction at least in part in accordance with a détermination that said trusted device will operate only in accordance with said rules;electronically transmitting from said third party to said trusted device authorization to engage in said electronic transaction, said authorization including 010456 certification that said third party provided said authorization;electronically transmitting from said trusted device to said second party said certification as 5 assurance that said trusted device is authorized to engage in said electronic transaction and will do so only in accordance with said rules;electronically transmitting transaction data from said trusted device to said second party in 10 accordance with said rules.
Independent claims14