WO0122650A9

Server-side implementation of a cryptographic system

Abstract

The invention is a secure server, or trust engine, having server-centric keys, or in other words, storing cryptographic keys and user authentication data on a server. Users access cryptographic functionality through network access to the trust engine; however, the trust engine does not release actual cryptographic keys or other authentication data. Therefore, the system provides that the keys and data remain secure. The server-centric storage of keys and authentication data provides for user-independent security, portability, availability, and straightforwardness, along with a wide variety of implementation possibilities.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

69 claims: 12 independent, 57 dependent

  1. 1
    WHAT IS CLAIMED IS:1. A remotely accessible secure cryptographic system for storing a plurality of private cryptographic keys to be associated with a plurality of users, wherein the cryptographic system associates each of the plurality of users with one or more different keys from the plurality of private cryptographic keys and performs cryptographic functions for each user using the associated one or more different keys without releasing the plurality of private cryptographic keys to the users, the cryptographic system comprising: a depository system having at least one server which stores a plurality of private cryptographic keys and a plurality of enrollment authentication data, wherein each enrollment authentication data identifies one of multiple users and each of the multiple users is associated with one or more different keys from the plurality of private cryptographic keys;an authentication engine which compares authentication data received by one of the multiple users to enrollment authentication data corresponding to the one of multiple users and received from the depository system, thereby producing an authentication result;a cryptographic engine which, when the authentication result indicates proper identification of the one of the multiple users, performs cryptographic functions on behalf of the one of the multiple users using the associated one or more different keys received from the depository system;and a transaction engine connected to route data from the multiple users to the depository server system, the authentication engine, and the cryptographic engine.
  2. 2
    A remotely accessible secure cryptographic system, comprising:a depository system having at least one server which stores at least one private key and a plurality of enrollment authentication data, wherein each enrollment authentication data identifies one of multiple users;an authentication engine which compares authentication data received by one of the multiple users to enrollment authentication data corresponding to the one of multiple users and received from the depository system, thereby producing an authentication result;a cryptographic engine which, when the authentication result indicates proper identification of the one of the multiple users, performs cryptographic functions on behalf of the one of the multiple users using at least said private key received from the depository system;and a transaction engine connected to route data from the multiple users to the depository server system, the authentication engine, and the cryptographic engine.
  3. 10
    A method of facilitating cryptographic functions, the method comprising:associating a user from multiple users with one or more keys from a plurality of private cryptographic keys stored on a secure server;receiving authentication data from the user;comparing the authentication data to authentication data corresponding to the user, thereby verifying the identity of the user;and utilizing the one or more keys to perform cryptographic functions without releasing the one or more keys to the user.
  4. 14
    An authentication system for uniquely identifying a user through secure storage of the user's enrollment authentication data, the authentication system comprising:a plurality of data storage facilities, wherein each data storage facility includes a computer accessible storage medium which stores one of portions of enrollment authentication data;and an authentication engine which communicates with the plurality of data storage facilities and comprises a data splitting module which operates on the enrollment authentication data to create portions, a data assembling module which processes the portions from at least two of the data storage facilities to assemble the enrollment authentication data, and a data comparator module which receives current authentication data from a user and compares the current authentication data with the assembled enrollment authentication data to determine whether the user has been uniquely identified.
  5. 30
    A cryptographic system, comprising:a plurality of data storage facilities, wherein each data storage facility includes a computer accessible storage medium which stores one of portions of cryptographic keys;and a cryptographic engine which communicates with the plurality of data storage facilities and comprises a data splitting module which operate on the cryptographic keys to create portions, a data assembling module which processes the portions from at least two of the data storage facilities to assemble the cryptographic keys, and a cryptographic handling module which receives the assembled cryptographic keys and performs cryptographic functions therewith.
  6. 36
    A method of storing authentication data in geographically remote secure data storage facilities thereby protecting the authentication data against comprise of any individual data storage facility, the method comprising:receiving authentication data at a trust engine;combining at the trust engine the authentication data with a first substantially random value to form a first combined value;combining the authentication data with a second substantially random value to form a second combined value;creating a first pairing of the first substantially random value with the second combined value;creating a second pairing of the first substantially random value with the second substantially random value;storing the first pairing in a first secure data storage facility;and storing the second pairing in a second secure data storage facility remote from the first secure data storage facility.
  7. 37
    A method of storing authentication data comprising:receiving authentication data;combining the authentication data with a first set of bits to form a second set of bits;combining the authentication data with a third set of hits to form a fourth set of bits;creating a first pairing of the first set of bits with the third set of bits;creating a second pairing of the first set of bits with the fourth set of bits;storing one of the first and second pairings in a first computer accessible storage medium;and storing the other of the first and second pairings in a second computer accessible storage medium.
  8. 45
    A method of storing cryptographic data in geographically remote secure data storage facilities thereby protecting the cryptographic data against comprise of any individual data storage facility, the method comprising:receiving cryptographic data at a trust engine;combining at the trust engine the cryptographic data with a first substantially random value to form a first combined value;combining the cryptographic data with a second substantially random value to form a second combined value;creating a first pairing of the first substantially random value with the second combined value;creating a second pairing of the first substantially random value with the second substantially random value;storing the first pairing in a first secure data storage facility;and storing the second pairing in a secure second data storage facility remote from the first secure data storage facility.
  9. 46
    A method of storing cryptographic data comprising:receiving authentication data;combining the cryptographic data with a first set of bits to form a second set of bits;combining the cryptographic data with a third set of bits to form a fourth set of bits;creating a first pairing of the first set of bits with the third set of bits;creating a second pairing of the first set of bits with the fourth set of bits;storing one of the first and second pairings in a first computer accessible storage medium;and storing the other of the first and second pairings in a second computer accessible storage medium.
  10. 54
    A method of handling sensitive data in a cryptographic system, wherein the sensitive data exists in a useable form only during actions employing the sensitive data, the method comprising:receiving in a software module, substantially randomized sensitive data from a first computer accessible storage medium;receiving in the software module, substantially randomized data from a second computer accessible storage medium, processing the substantially randomized sensitive data and the substantially randomized data in the software module to assemble the sensitive data;and employing the sensitive data in a software engine to perform an action, wherein the action includes one of authenticating a user and performing a cryptographic function.
  11. 59
    A secure authentication system, comprising:a plurality of authentication engines, wherein each authentication engine receives enrollment authentication data designed to uniquely identify a user to a degree of certainty, each authentication engine receives current authentication data to compare to the enrollment authentication data, and wherein each authentication engine determines an authentication result;and a redundancy system which receives the authentication result of at least two of the authentication engines and determines whether the user has been uniquely identified.
  12. 65
    A trust engine system for facilitating authentication of a user, the trust engine system comprising:a first trust engine comprising a first depository, wherein the first depository includes a computer accessible storage medium which stores portions of enrollment authentication data;a second trust engine located at a different geographic location than the first trust engine and comprising a second depository having a computer accessible storage medium which stores portions of enrollment authentication data, an authentication engine communicating with the first and second depositories and which assembles at least two portions of enrollment authentication data into a usable form, and a transaction engine communicating with the first and second depositories and the authentication engine, wherein when the second trust engine is determined to be available to execute a transaction, the transaction engine receives authentication data from a user and forwards a request for the portions of enrollment authentication data to the first and second depositories, and wherein the authentication engine receives the authentication data from the transaction engine and the portions of the enrollment authentication data from the first and second depositories, and determines an authentication result.