PL176458B1

Method of and system for encoding with deposition of encoding keys

Abstract

The invention provides a cryptographic system and method with a key escrow feature that uses a method for verifiably splitting users' private encryption keys into components and for sending those components to trusted agents chosen by the particular users, and provides a system that uses modern public key certificate management, enforced by a chip device that also self-certifies. In a preferred embodiment of this invention, the chip encrypts or decrypts only if certain conditions are met, namely, (1) if a valid "sender certificate" and a valid "recipient certificate" are input, where "valid" means that the particular user's private decryption key is provably escrowed with a specified number of escrow agents and that the master escrow center is registered and certified by the chip manufacturer, and (2) if a valid Message Control Header is generated by the sender and validated by the recipient, thereby giving authorized investigators sufficient information with which to request and obtain the escrowed keys. A further preferred embodiment of this invention provides a method for generating verifiably trusted communications among a plurality of users, comprising the steps of escrowing at a trusted escrow center a plurality of asymmetric cryptographic keys to be used by a plurality of users; verifying each of said plurality of keys at the escrow center; certifying the authorization of each of said plurality of keys upon verification; and initiating a communication from each of said plurality of users using a respective one of said plurality of keys contingent upon said certification.

PL176458B1, drawing sheet 1
Sheet 1 of 57

Term

Term ended

Expired 13 January 2015, 11.7 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

14 claims: 14 independent, 0 dependent

  1. 1
    Patent claims Zastrzeżenia patentowe 1. The method of encrypting the communication system, during which secret, asymmetrical encryption keys are deposited in a reliable deposit center for use by many users, characterized in that each of the many keys in the deposit center is verified, each of the many keys is confirmed after verification and transmission is initiated from each of the many users using one of the many keys, conditioned by confirmation. 1. Sposób szyfrowania systemu komunikacyjnego, podczas którego deponuje się w wiarygodnym centrum depozytowym tajne, asymetryczne klucze szyfrowe do użycia przez wielu użytkowników, znamienny tym, że weryfikuje się każdy z wielu kluczy w centrum depozytowym, potwierdza się każdy z wielu kluczy po weryfikacji i inicjuje się transmisję od każdego z wielu użytkowników, używających jednego z wielu kluczy, uwarunkowaną potwierdzeniem.
  2. 2
    A method of encrypting the communication system, during which secret, asymmetric encryption keys are deposited in a reliable deposit center for use by many users;characterized in that each of the keys in the depository center is verified, each of the keys is verified after verification and a secure transmission is initiated from the initiating user to the receiving user, subject to confirmation of the keys of both the initiating user and the receiving user. 2. Sposób szyfrowania systemu komunikacyjnego, podczas którego deponuje się w wiarygodnym centrum depozytowym tajne, asymetryczne klucze szyfrowe do użycia przez wielu użytkowników;znamienny tym, że weryfikuje się każdy z kluczy w centrum depozytowym, potwierdza się każdy z kluczy po weryfikacji i inicjuje się bezpieczną transmisję od użytkownika inicjującego do użytkownika odbierającego, uwarunkowaną potwierdzeniem kluczy zarówno użytkownika inicjującego, jak i użytkownika odbierającego.
  3. 3
    The method of encrypting the communication system, during which secret, asymmetric encryption keys are deposited in a reliable escrow center for use by many users, characterized in that at least the first selected unit, which is not a communication party, is made available for user communications, the keys are verified in the deposit center . each key is confirmed after verification and a reliable transmission is initiated from the initiating to the receiving user in a way that allows access to the communication of the first entity that is not a communication party. 3. Sposób szyfrowania systemu komunikacyjnego, podczas którego deponuje się w wiarygodnym centrum depozytowym tajne, asymetryczne klucze szyfrowe do użycia przez wielu użytkowników, znamienny tym, że co najmniej pierwszą wybranąjednostkę, nie będącą stroną łączności, udostępnia się do łączności użytkowników, weryfikuje się klucze w centrum depozytowym, potwierdza się każdy z kluczy po weryfikacji i inicjuje się wiarygodnątransmisję od użytkownika inicjującego do odbierającego w sposób umożliwiający dostęp do łączności pierwszej jednostce nie będącej stroną łączności.
  4. 4
    The method of encrypting the communication system, during which secret, asymmetrical encryption keys are deposited in a reliable deposit center for use by many users, characterized in that when each user is equipped with a computer device, the computer devices in the center are registered in accordance with the control information specified by the device owner, who is not a device user, computer devices are confirmed, whereby each confirmation creates a certificate related to the center, user and computer device and initiates secure transmission from the initiating user to the recipient using the message key in a way that allows the owner to access the transmission. 4. Sposób szyfrowania systemu komunikacyjnego, podczas którego deponuje się w wiarygodnym centrum depozytowym tajne, asymetryczne klucze szyfrowe do użycia przez wielu użytkowników, znamienny tym, że przy wyposażeniu każdego użytkownika w urządzenie komputerowe, rejestruje się urządzenia komputerowe w centrum zgodnie z informacją kontrolną określonąprzez właściciela urządzenia, który nie jest użytkownikiem urządzenia, potwierdza się urządzenia komputerowe, przy czym przez każde potwierdzenie tworzy się certyfikat związany z centrum, użytkownikiem i urządzeniem komputerowym i inicjuje się bezpieczną transmisję od użytkownika inicjującego do odbiorcy, wykorzystując klucz komunikatu w sposób umożliwiający właścicielowi dostęp do transmisji.
  5. 5
    The method of encrypting the communication system, during which secret, asymmetric encryption keys are deposited in a reliable escrow center for use by many users, characterized in that the keys are verified in the escrow center, each key is confirmed after verification, and reliable transmission is initiated from the sending user to the receiving user using a verified key, the information is included in the transmission to obtain the initiating user key and the receiving user key. 5. Sposób szyfrowania systemu komunikacyjnego, podczas którego deponuje się w wiarygodnym centrum depozytowym tajne, asymetryczne klucze szyfrowe do użycia przez wielu użytkowników, znamienny tym, że weryfikuje się klucze w centrum depozytowym, potwierdza się każdy z kluczy po weryfikacji i inicjuje się wiarygodną transmisję od użytkownika nadającego do użytkownika odbierającego, stosując zweryfikowany klucz, przy czym do transmisji włącza się informację dla uzyskania klucza użytkownika inicjującego i klucza użytkownika odbierającego.
  6. 6
    The method of encrypting the communication system, during which secret, asymmetrical encryption keys are deposited in a reliable deposit center for use by many users, characterized in that when using electronic computer devices controlled by a tamper-proof logic system, a secure transmission is initiated from the initiating device to receiving, wherein the access information signed by the initiating device is included in the transmission and external access to the transmission is enabled. 6. Sposób szyfrowania systemu komunikacyjnego, podczas którego deponuje się w wiarygodnym centrum depozytowym tajne, asymetryczne klucze szyfrowe do użycia przez wielu użytkowników, znamienny tym, że przy zastosowaniu elektronicznych urządzeń komputerowych, kontrolowanych przez odporny na manipulacje układ logiczny, inicjuje się bezpieczną transmisję od urządzenia inicjującego do odbierającego, przy czym do transmisji włącza się informacje dostępu podpisane przez urządzenie inicjujące i umożliwia się dostęp do transmisji przez stronę zewnętrzną.
  7. 7
    The method of encrypting the communication system, during which secret, asymmetrical encryption keys are deposited in a reliable escrow center for use by many users, characterized in that the keys are verified in the escrow center, each key is confirmed after verification, and transmission from the initiating user to receiving user, conditional on confirmation of the keys of the initiating user and the receiving user by a reliable device of the initiating user. 7. Sposób szyfrowania systemu komunikacyjnego, podczas którego deponuje się w wiarygodnym centrum depozytowym tajne, asymetryczne klucze szyfrowe do użycia przez wielu użytkowników, znamienny tym, że weryfikuje się klucze w centrum depozytowym, potwierdza się każdy z kluczy po weryfikacji i inicjuje się transmisję od użytkownika inicjującego do użytkownika odbierającego, uwarunkowaną potwierdzeniem kluczy użytkownika inicjującego i użytkownika odbierającego przez wiarygodne urządzenie użytkownika inicjującego. 176 458 176 458
  8. 8
    The method of encrypting the communication system, during which secret, asymmetrical encryption keys are deposited in a reliable escrow center for use by many users, characterized in that the keys are verified in the escrow center, each key is confirmed after verification, and transmission from the initiating user to the receiving user, subject to confirmation of the key used in the transmission, wherein access information is included in the transmission to allow access to the transmission via the external party. 8. Sposób szyfrowania systemu komunikacyjnego, podczas którego deponuje się w wiarygodnym centrum depozytowym tajne, asymetryczne klucze szyfrowe do użycia przez wielu użytkowników, znamienny tym, że weryfikuje się klucze w centrum depozytowym, potwierdza się każdy z kluczy po weryfikacji i inicjuje się transmisję od użytkownika inicjującego do użytkownika odbierającego, uwarunkowaną potwierdzeniem klucza używanego w transmisji, przy czym do transmisji włącza się informacje o dostępie dla umożliwienia dostępu do transmisji przez stronę zewnętrzną.
  9. 9
    The method of encrypting the communication system, during which secret, asymmetrical encryption keys are deposited in a reliable deposit center for use by many users, characterized in that the keys in the deposit center are verified, each of the keys is confirmed after verification and a reliable device associated with each user and transmission is initiated from the initiating user to the recipient after confirmation of the key used in the transmission and after confirmation of the parameters of the reliable device associated with the initiating user. 9. Sposób szyfrowania systemu komunikacyjnego, podczas którego deponuje się w wiarygodnym centrum depozytowym tajne, asymetryczne klucze szyfrowe do użycia przez wielu użytkowników, znamienny tym, że weryfikuje się klucze w centrum depozytowym, potwierdza się każdy z kluczy po weryfikacji i wiarygodne urządzenie związane z każdym użytkownikiem i inicjuje się transmisję od użytkownika inicjującego do odbiorcy po potwierdzeniu klucza używanego w transmisji i po potwierdzeniu parametrów wiarygodnego urządzenia związanego z użytkownikiem inicjującym.
  10. 10
    The method of encrypting the communication system, during which secret, asymmetrical encryption keys are deposited in a reliable deposit center for use by many users, characterized in that one of the deposit centers is assigned to the first group, the other of the deposit centers is assigned to the second group, the keys are verified deposit centers, each key is confirmed after verification and transmission between the first user and the second user is carried out, conditioned by groups to which the sender's and recipient's deposit centers are assigned. 10. Sposób szyfrowania systemu komunikacyjnego, podczas którego deponuje się w wiarygodnym centrum depozytowym tajne, asymetryczne klucze szyfrowe do użycia przez wielu użytkowników, znamienny tym, że jedne z centrów depozytowych przyporządkowuje się pierwszej grupie, drugie z centrów depozytowych przyporządkowuje się drugiej grupie, weryfikuje się klucze w centrach depozytowych, potwierdza się każdy z kluczy po weryfikacji i realizuje się transmisję pomiędzy pierwszym użytkownikiem i drugim użytkownikiem, uwarunkowaną grupami, do których przyporządkowane są centra depozytowe nadawcy i odbiorcy.
  11. 11
    The method of encrypting the communication system, during which secret, asymmetrical encryption keys are deposited in a reliable escrow center for use by many users, characterized in that each key in the deposit center is verified, each key is confirmed after verification, and an encrypted streaming stream is created from the initiating user to the receiving user using the initiating user's code key, a preliminary access information packet is included in the transmission, enabling the external party to decrypt the stream, and a stream of subsequent packets, each subsequent packet containing information identifying the next packet as associated with the stream, and at least one of the subsequent packets is deprived of access information. 11. Sposób szyfrowania systemu komunikacyjnego, podczas którego deponuje się w wiarygodnym centrum depozytowym tajne, asymetryczne klucze szyfrowe do użycia przez wielu użytkowników, znamienny tym, że weryfikuje się każdy z kluczy w centrum depozytowym, potwierdza się każdy z kluczy po weryfikacji i tworzy się zaszyfrowanątransmisję strumieniową od użytkownika inicjującego do użytkownika odbierającego, stosując klucz szyfrowy użytkownika inicjującego, do transmisji włącza się wstępny pakiet informacji o dostępie, umożliwiający stronie zewnętrznej deszyfrowanie strumienia, i strumień kolejnych pakietów, każdy kolejny pakiet, zawierający informację identyfikującą kolejny pakiet jako związany ze strumieniem i co najmniej jeden z kolejnych pakietów pozbawia się informacji o dostępie.
  12. 12
    The method of encrypting the communication system, during which secret, asymmetrical encryption keys are deposited in a reliable deposit center for use by many users, characterized in that a key associated with the source of the software is placed in a reliable device, the software is transmitted to a reliable device, wherein the transmission is modified by the software source in a manner confirmed using a placed key and the software is introduced into a reliable device, conditioned by the confirmation of transmission using a placed key. 12. Sposób szyfrowania systemu komunikacyjnego, podczas którego deponuje się w wiarygodnym centrum depozytowym tajne, asymetryczne klucze szyfrowe do użycia przez wielu użytkowników, znamienny tym, że umieszcza się w wiarygodnym urządzeniu klucz związany ze źródłem oprogramowania, transmituje się oprogramowanie do wiarygodnego urządzenia, przy czym transmisję modyfikuje się przez źródło oprogramowania w sposób potwierdzany przy użyciu umieszczonego klucza i wprowadza się oprogramowanie do wiarygodnego urządzenia, uwarunkowane potwierdzeniem transmisji przy użyciu umieszczonego klucza.
  13. 13
    The method of encrypting the communication system, during which secret, asymmetrical encryption keys are deposited in a reliable deposit center for use by many users, characterized in that when each user is equipped with a computer device having at least one device-related key, computer devices are registered in at least one center, selected from many centers, confirms the computer devices, whereby a certificate is created for the device by confirmation, a secure transmission is initiated from the initiating user to the recipient using a message key, the access part encrypted with the center key is included in the transmission to obtain the message key. 13. Sposób szyfrowania systemu komunikacyjnego, podczas którego deponuje się w wiarygodnym centrum depozytowym tajne, asymetryczne klucze szyfrowe do użycia przez wielu użytkowników, znamienny tym, że przy wyposażeniu każdego użytkownika w urządzenie komputerowe, mające co najmniej jeden klucz związany z urządzeniem, rejestruje się urządzenia komputerowe w co najmniej jednym centrum, wybranym z wielu centrów, potwierdza się urządzenia komputerowe, przy czym przez potwierdzenie tworzy się certyfikat dla urządzenia, inicjuje się bezpieczną transmisję od użytkownika inicjującego do odbiorcy, stosując klucz komunikatu, do transmisji włącza się część dostępu zaszyfrowaną kluczem centrum dla uzyskania klucza komunikatu.
  14. 14
    The method of encrypting the communication system, during which secret, asymmetrical encryption keys are deposited in a reliable escrow center for use by many users, characterized in that they are transmitted electronically via a reliable device to a third party, a request to authorize electronic operation, and the request is included identification of a reliable device is determined by a third party, that a reliable device should be authorized to perform the operation, at least 14. Sposób szyfrowania systemu komunikacyjnego, podczas którego deponuje się w wiarygodnym centrum depozytowym tajne, asymetryczne klucze szyfrowe do użycia przez wielu użytkowników, znamienny tym, że transmituje się elektronicznie przez, wiarygodne urządzenie do trzeciej strony, żądanie upoważnienia przeprowadzenia operacji elektronicznej, przy czym do żądania włącza się identyfikację wiarygodnego urządzenia, określa się przez trzecią stronę, że wiarygodne urządzenie powinno być upoważnione do przeprowadzenia operacji, przynajmniej 176 458 partly in accordance with the statement that a reliable device will operate in accordance with the rules, is transmitted electronically, by a third party to a credible device, authorization to carry out an electronic operation, where the authorization includes confirmation that the third party has given this authorization, is transmitted electronically , by a reliable device to the other party, confirmation as assurance, that a reliable device is authorized to carry out an electronic operation and will conduct it only in accordance with the rules and the data of the operation is electronically transmitted through a reliable device to the other party in accordance with the rules. 176 458 częściowo zgodnie z określeniem, że wiarygodne urządzenie będzie działać zgodnie z regułami, transmituje się elektronicznie, przez trzecią stronę do wiarygodnego urządzenia, upoważnienia na przeprowadzenie operacji elektronicznej, przy czym do upoważnienia włącza się potwierdzenie, że trzecia strona dała to upoważnienie, transmituje się elektronicznie, przez wiarygodne urządzenie do drugiej strony, potwierdzenie jako zapewnienie, że wiarygodne urządzenie jest upoważnione do przeprowadzenia operacji elektronicznej i będzie ją prowadzić tylko zgodnie z regułami i transmituje się elektronicznie dane operacji, przez wiarygodne urządzenie do drugiej strony, zgodnie z regułami.
Independent claims14