US20170230179A1

Password triggered trusted encrytpion key deletion

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A method of evaluating secrets in a computer system's trusted execution environment, wherein after evaluation of secrets, a securely stored encryption key is either retrieved or deleted upon entering corresponding secret (password, graphical password, biometric information, data sequence, security token, etc.) or secrets. Deletion of the encryption key can happen in a verifiable manner or in a non-verifiable manner. If a storage is encrypted with the encryption key, deletion of the encryption key makes the encrypted storage irreversibly undecryptable, while retrieval of the key permits decryption of the storage. Two encryption keys can be used to encrypt two separate storages, and then securely stored and processed in the trusted execution environment. Each of the two encryption keys can be retrieved using one or more associated secrets (passwords, etc.), and one or more other secrets would delete the encryption key associated with a preselected storage. During sleep-wake event a computer system's memory can be encrypted with a symmetric key, and the symmetric key can be secured by encrypting with a public encryption key. Corresponding private key is retrieved to decrypt the symmetric key upon evaluation of associated password (secret) in trusted execution environment, while the private key is deleted upon evaluation of one or many preselected deletion password (secret) leaving the encrypted memory undecryptable.

US20170230179A1, drawing sheet 1
Sheet 1 of 4

Term

11.2 yearsto projected expiry

Projected expiry 27 November 2037, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

32 claims: 3 independent, 29 dependent

  1. 1
    Broadest claimClaim Score 77, broad(NHIP)A method of evaluating secrets in a computer system's trusted execution environment, wherein after evaluation of secrets, a securely stored encryption key is either unlocked upon entering a secret associated with encryption key retrieval or deleted in a verifiable manner or in a non-verifiable manner upon entering a secret associated with encryption key deletion.
  2. 19
    A computer subsystem comprising of:a hidden system forming part of a computer system storing encrypted data with a first encryption key, KH;and a decoy system forming part of the computer system storing encrypted other data with a second encryption key, KN;with a first password, PH, for retrieving KH in order to either retrieve secured data or store additional data within the hidden system;a second password, PN, for retrieving KN in order to either retrieve other data or store additional data within the decoy system;and a third password, PD, with performing a secure deletion of KH;whereas receiving PD results in secure deletion of KH.
  3. 31
    A computer subsystem comprising of:a symmetric encryption key (SK) stored within the memory of the computer system associated with the encryption of the memory of the computer system upon the initiation of a sleep mode of the computer system;encrypted memory of the computer system encrypted with SK during entry into the sleep mode of the computer system;a public key, HGPUB, for encrypting SK during entry into the sleep mode of the computer system;storing the encrypted SK within the memory of the computer system;receiving a correct secret (PW) during initiation of a wake mode of the computer system after the sleep mode has been entered;retrieving a private key HGPRIV corresponding to HGPUB from secure storage of the computer system upon receipt of PW;decrypting SK when HGPRIV is retrieved allowing subsequent decryption of the encrypted active system memory encrypted with SK during entry into the sleep mode;wherein receipt of a special deletion password (PD) instead of PW, during initiation of the wake mode of the computer system after the sleep mode has been entered results in deletion of HGPRIV or receipt of multiple incorrect passwords during initiation of the wake mode of the computer system after the sleep mode has been entered results in the deletion of HGPRIV.