US20170142082A1

System and method for secure deposit and recovery of secret data

Claim Score by NHIP

Read claim 35, the broadest

Abstract

A system and method are disclosed for providing secure deposit and recovery of secret data based on a secret of a user, such as a password, a shared secret from a recovery server, and a secret from a recovery peer. The secret data is encrypted with these three secrets and stored remote from the user device to only allow the user to recover the secret data without compromising the secrecy of the secret data. Systems and methods for decoupling a password from the secret data the password protects is also provided to allow resetting the password or recovering the secret data to be separate operations that can be carried out independently. Another aspect provides for a user account to be securely recovered using a recovery peer to verify ownership of the user account.

US20170142082A1, drawing sheet 1
Sheet 1 of 10

Term

Projected expiry 10 March 2035.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

35 claims: 5 independent, 30 dependent

  1. 1
    A social-based cryptographic system that provides secure deposit of a secret data associated with a user account, the system comprising:a user device, the user device having a memory for storing instructions and a processor for executing the instructions to: derive an encryption key based on a secret provided to the user device to generate a derived encryption key, encrypt the secret data using the derived encryption key to generate a once-encrypted secret data, designate a recovery peer and obtaining a recovery-peer key associated with the recovery peer, and encrypting the once-encrypted secret data using the recovery-peer key to generate a twice-encrypted secret data;a recovery server to store the twice-encrypted secret data and associate the twice-encrypted secret data with the user account and the recovery peer;a recovery peer device associated with the recovery peer, the recovery peer device having a memory for storing instructions and a processor for executing the instructions to: generate the recovery-peer key and provide the recovery-peer key to the user device.
  2. 3
    A method for depositing a secret data of a user account in a cryptographic system to allow for secure recovery of the secret data, the method comprising:deriving an encryption key based on a secret provided to a user device to generate a derived encryption key at the user device;designating a recovery peer and obtaining a recovery-peer key associated with the recovery peer;encrypting the secret data using the derived encryption key and the recovery-peer key to generate an encrypted secret data;andstoring the encrypted secret data at a location remote from the user device.
  3. 17
    A method for securely recovering a secret data of a user account in a cryptographic system, the method comprising:obtaining an encrypted secret data at a recovery peer device, the encrypted secret data encrypted using a derived encryption key based on a secret and a recovery-peer key of a recovery peer device;deriving an encryption key based on a secret provided to the user device to generate the derived encryption key at the user device;anddecrypting the encrypted secret data using the recovery-peer key and the derived encryption at the user device to recover the secret data.
  4. 30
    A method of securely recovering a user account without a password using peer-based authentication of ownership of the user account, the method comprising:generating a random value at a user device associated with the user account and cryptographically signing the random value with a user private key associated with the user account to generate a first signature;designating a recovery peer and obtaining a recovery key associated with the recovery peer;encrypting the first signature with the recovery key associated with the recovery peer to generate an encrypted first signature;storing the random value and the encrypted first signature at a recovery server;retrieving the encrypted first signature from the recovery server at recovery peer device of the recovery peer;decrypting the encrypted first signature using the recovery key at a recovery peer device of the recovery peer to generate decrypted first signature;providing the decrypted first signature to the recovery server;andverifying the decrypted first signature using a user public key corresponding to the user private key and the random value at the recovery server.
  5. 35
    Broadest claimClaim Score 88, very broad(NHIP)A method of decoupling a password from secret data secured with the password, the method comprising:encrypting the secret data with a server key stored at a recovery server;andpermitting access to the server key by a user device by authenticated access using the password.