US20060010324A1

Secure messaging system with derived keys

Claim Score by NHIP

Read claim 15, the broadest

Abstract

Secure messages may be sent between senders and recipients using symmetric message keys. The symmetric message keys may be derived from a master key using a key generator at an organization. A gateway may encrypt outgoing message using the derived keys. Senders in the organization can send messages to recipients who are customers of the organization. The recipients can authenticate to a decryption server in the organization using preestablished credentials. The recipients can be provided with copies of the derived keys for decrypting the encrypted messages. A hierarchical architecture may be used in which a super master key generator at the organization derives master keys for delegated key generators in different units of the organization. An organization may have a policy server that generates non-customer symmetric message keys. The non-customer symmetric message keys may be used to encrypt messages sent by a non-customer sender to a recipient at the organization.

US20060010324A1, drawing sheet 1
Sheet 1 of 11

Term

Projected expiry 17 June 2028.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

20 claims: 4 independent, 16 dependent

  1. 1
    A method for a sender at an organization to send a message to a recipient who is a customer of the organization over a communications network, wherein the recipient has a recipient identity (ID), comprising:at the organization, deriving a symmetric key for encrypting the message from a master key using a one-way function whose inputs include the master key and the recipient ID;at the organization, encrypting the message using the derived symmetric key and sending the message to the recipient over the communications network;at the recipient, receiving the encrypted message;at the recipient, submitting a derived symmetric key request to the organization over the communications network, wherein the derived symmetric key request includes the recipient ID;authenticating the recipient to the organization and establishing a secure communications channel between the organization and the recipient over the communications network;and in response to the derived symmetric key request of the recipient, generating the derived symmetric key for the recipient to use in decrypting the message and providing the derived symmetric key to the recipient over the secure communications channel.
  2. 8
    A method for a sender at an organization to send a message to a recipient, wherein the organization has a gateway, a key generator, a server, and an intranet to which the sender, gateway, key generator, and server are connected and wherein the recipient is outside of the organization, wherein the recipient is a customer of the organization, and wherein the recipient has a recipient identity (ID), the method comprising:using the key generator to derive a symmetric key for encrypting the message from a master key using an HMAC function whose inputs include the master key and the recipient ID;providing the derived symmetric key from the key generator to the gateway over the intranet;encrypting the message at the gateway using the derived symmetric key to produce an encrypted message;providing the encrypted message from the gateway to the recipient outside of the organization over the Internet;at the recipient, receiving the encrypted message;authenticating the recipient to the server and establishing a secure sockets layer (SSL) link between the server and the recipient;providing a derived symmetric key request to the sever from the recipient, wherein the derived symmetric key request includes the recipient ID;using the server to obtain the derived symmetric key from the key generator over the intranet using the recipient ID and to provide the derived symmetric key obtained from the key generator to the recipient over the SSL link;and at the recipient, using the derived symmetric key provided by the server over the SSL link to decrypt the encrypted message.
  3. 10
    A method for using a hierarchical key generator architecture to support secure communications for an organization having multiple units, wherein the organization has a super key generator and a plurality of delegated key generators, the method comprising:using the super key generator to generate a plurality of derived sub-master keys from a super master key, each derived sub-master key being provided to a respective one of the delegated key generators in a respective one of the multiple units;at a given one of the units, allowing a sender in the given unit to create a message to be communicated securely to a recipient outside of the organization who is a customer of the given unit, wherein the recipient has a recipient identity (ID);at the given unit, using the delegated key generator of that given unit to derive a symmetric key for encrypting the message from the sub-master key provided to that delegated key generator using a one-way function whose inputs include that sub-master key and the recipient ID;at the given unit, encrypting the message using the derived symmetric key and sending the message to the recipient over a communications network;at the recipient, receiving the encrypted message;at the recipient, submitting a derived symmetric key request to the given unit over the communications network, wherein the derived symmetric key request includes the recipient ID;authenticating the recipient to the given unit and establishing a secure communications channel between the given unit and the recipient over the communications network;and using the delegated key generator of the given unit to generate the derived symmetric key for the recipient to use in decrypting the message and providing the derived symmetric key from the given unit to the recipient over the secure communications channel.
  4. 15
    Broadest claimClaim Score 65, broad(NHIP)A method for supporting secure communications between a sender who is outside an organization and a recipient who is inside an organization or who is a customer of the organization using symmetric key cryptography, comprising:establishing a secure communications channel between the sender and the organization;deriving a symmetric key from a master key at the organization;generating a random number N at the organization;at the organization, producing a non-customer symmetric message key based on the derived symmetric key and the random number N;providing the non-customer symmetric message key and the random number N to the sender over the secure communications channel;and at sender, using the non-customer symmetric message key to encrypt a message for the recipient.