Volume cryptographic key management
US-10078754-B1 · Sep 18, 2018 · US
US10467429B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10467429-B2 |
| Application number | US-201715703968-A |
| Country | US |
| Kind code | B2 |
| Filing date | Sep 13, 2017 |
| Priority date | Sep 14, 2016 |
| Publication date | Nov 5, 2019 |
| Grant date | Nov 5, 2019 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Systems and methods for secure user profiles are disclosed. One example method includes the steps of receiving a user profile, the user profile comprising a plurality of domains, at least one of the domains having an associated encryption key and at least one associated data record, wherein the encryption key is encrypted according to a first encryption technique and wherein the at least one data record is encrypted according to a second encryption technique using the encryption key; transmitting a request for a decryption key to a first device, the decryption key usable by the first encryption technique to decrypt the encryption key; receiving the decryption key from the first device; decrypting the encryption key using the first encryption technique and the decryption key; decrypting the at least one data record using the second encryption technique and the encryption key.
Opening claim text (preview).
The invention claimed is: 1. A method comprising: receiving a user profile, the user profile comprising a plurality of domains including a first and second domain, the first domain having an associated encryption key and at least one associated data record, wherein the first encryption key is encrypted according to a first encryption technique and wherein the at least one data record is encrypted according to a second encryption technique using the first encryption key; receiving a selection of the at least one associated data record; receiving a selection of the second domain; and subsequent to receiving the selection of the at least one data record and the second domain, associate the at least one data record with the second domain, and de-associate the at least one data record from the first domain; wherein associating the at least one data record with the second domain comprises: transmitting a request for a decryption key to a first device, the decryption key usable by the first encryption technique to decrypt the first encryption key; receiving the decryption key from the first device; decrypting the first encryption key using the first encryption technique and the decryption key; and decrypting the at least one data record using the second encryption technique and the first encryption key. 2. The method of claim 1 , further comprising: receiving a request for authentication information from the first device; and in response to the request and prior to receiving the decryption key, providing the authentication information to the first device. 3. The method of claim 1 , wherein the at least one data record comprises biometric information about a person, and further comprising: capturing a biometric sample of the person; comparing the biometric sample to the biometric information; and responsive to the biometric sample matching the biometric information, authenticating the person. 4. A method comprising: receiving a user profile, the user profile comprising a first domain and a second domain, the first domain having an associated encryption key, the second domain having an associated first data record; receiving a selection of the first data record; receiving a selection of the first domain; subsequent to receiving the selection of the first data record and the first domain, associating the first data record with the first domain, and de associating the first data record from the second domain; and subsequently encrypting the first data record using a first encryption technique and the encryption key. 5. The method of claim 4 , wherein the second domain has an associated second encryption key, and wherein associating the first data record with the first domain comprises decrypting the first data record using a second encryption technique and the second encryption key. 6. The method of claim 4 , further comprising, prior to associating the first data record with the first domain and de-associating the first data record from the second domain, authenticating a data owner of the user profile. 7. A system comprising: a hardware processor configured to: receive a user profile, the user profile comprising a plurality of domains including a first and second domain, the first domain having an associated encryption key and at least one associated data record, wherein the first encryption key is encrypted according to a first encryption technique, and wherein the at least one data record is encrypted according to a second encryption technique using the first encryption key; receive a selection of the at least one data record; receive a selection of the second domain; and subsequent to receiving the selection of the at least one data record and the second domain, associate the at least one data record with the second domain, and de-associate the at least one data record from the first domain; wherein, in associating the at least one data record with the second domain, the processor is further configured to: transmit a request for a decryption key to a first device, the decryption key usable by the first encryption technique to decrypt the first encryption key; receive the decryption key from the first device; decrypt the first encryption key using the first encryption technique and the decryption key; and decrypt the at least one data record using the second encryption technique and the first encryption key. 8. The system of claim 7 , wherein the hardware processor is further configured to receive a request for authentication information from the first device; and in response to the request and prior to receiving the decryption key, provide the authentication information to the first device. 9. The system of claim 7 , wherein the at least one data record comprises biometric information about a person, and wherein the hardware processor is further configured to: capture a biometric sample of the person; compare the biometric sample to the biometric information; and responsive to the biometric sample matching the biometric information, authenticate the person. 10. A vehicle incorporating the system of claim 7 .
using biometric data, e.g. fingerprints, iris scans or voiceprints · CPC title
User profiles · CPC title
specially adapted for terminals or networks with limited capabilities; specially adapted for terminal portability · CPC title
specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks · CPC title
Protecting personal data, e.g. for financial or medical purposes · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.