Method for preventing inadvertent betrayal by a trustee of...

Electrical computers and digital processing systems: support – System access control based on user identification by...

Reexamination Certificate

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

C713S183000, C713S152000, C380S277000, C380S286000

Reexamination Certificate

active

06216229

ABSTRACT:

FIELD OF THE INVENTION
The present invention relates generally to computer data security. More particularly, the invention relates to a method and apparatus for preventing a trustee holding escrowed security information from revealing the information to someone other than a party legitimately entitled to receive such information.
BACKGROUND AND SUMMARY OF THE INVENTION
In modern computer systems, especially those using a PC or laptop computer, it is common for the data stored in, for example, disk memory to be encrypted. This offers the user great protection against the stored data being discoverable by a thief—even when the computer is stolen.
Typically, such stored the information is encrypted with a key which is derived in some fashion from a password known only to the user. The password is converted via well known cryptographic processing techniques into a cryptographic key, which is used to decrypt (and thereby access) all information stored in the computer.
Particularly if sensitive data is being stored, most standard security practices urge users not to record passwords—lest they be discovered by an adversary. Since the data stored in the computer is present only in its encrypted form, without knowledge of the password, it is, for all practical purposes, inaccessible. Accordingly, a serious problem is created if the user forgets the password.
In practice, from time to time users do forget their passwords. The problem is compounded by the possibility that a disgruntled employee may refuse to supply or “forget” the password to a corporate computer which has previously been assigned to the employee.
One attempted solution to this problem is to “escrow” the password (or some other key information associated with the encryption) with a trustee, i.e., a trusted entity, such as, for example, a computer security software officer in the user's organization. The user may use the trustee's public key to encrypt the secret information and store the information in, for example, with the trustee, with a 3rd party or with the protected computer itself. In this fashion, the trustee could, in case of emergency, be given the resulting escrowed cipher text and use its private key to decrypt and retrieve the escrowed secret.
When the user is well know to the escrow agent, the process for retrieving the secret information is relatively straightforward. The known user presents the escrowed information (possibly including the entire computer) to the trustee, who then retrieves the escrowed information with the trustee's private key (the other half of the public/private key pair) associated with the trustee's encrypting public key) to decrypt the user's secret information. The user may be provided with a program to extract the escrowed information to be forwarded to the trustee. If only the trustee has access to the decrypting private key, the escrowed information is not compromised by the storage of the escrowed information in the user's computer.
The present invention addresses the danger that the trustee might be tricked into revealing escrowed information to someone other than the legitimate owner (or another party entitled to receive the escrowed information). For example, a thief could present a stolen computer to the trustee claiming that it is their own.
In practice, it is not unusual for vendors of computer data encryption products to be asked to help users who claim to have forgotten or otherwise lost their password. Contrary to whatever warnings are offered, users expect vendors to help recover their stored information. If a vendor cannot or will not assist a user due, for example, to fear of liability for revealing sensitive information to a thief, a bona fide user will typically become irate. The risk to the vendor is that the alleged user may not actually be the true owner of the sensitive data but rather an adversary of the true owner—e.g., someone to whom giving access to the computer could potentially severely harm the true owner. Accordingly, the vendor may be faced with the dilemma of whether or not to assist in “re-enabling” a lost key for an often frantic customer.
In accordance with the present invention, various alternative binary data strings may be escrowed. A password used to derive a symmetric DES key which is used to encrypt the user's secret may be escrowed. In its broadest sense, the present invention contemplates escrowing any secret digital information voluntarily placed in the hands of an escrow agent (e.g., a Swiss bank account number, safety deposit identifying indicia, vault combination, the formula for Coca Cola® or the like). The present invention permits a user to cryptographically secure such data and to securely permit a manufacturer, vendor, or other escrow agent's (trustee) to allow the user to access data under circumstances where the password is forgotten or lost.
The present invention is designed to reduce, if not eliminate, the risk of a trustee escrow agent's (e.g., vendor) possible inadvertent betrayal while balancing the escrow agent's goal of providing security, with optional recoverability—even when the true owner/customer was previously unknown to the vendor. The present invention provides significant assurance to both user and trustee that the trust delegated will not be betrayed if the trustee assists in re-enabling a lost key or password.
The present invention accomplishes these objectives utilizing methodology employing a voluntary identification/definition phase performed, for example, shortly after a computer is purchased, and a secret information retrieval phase. In the definition phase, the true owner/customer defines an escrow record which provides self-identification data together with encrypted password or other secret data. The present invention contemplates prompting a user to voluntarily escrow password or other secret information for later retrieval by entering a series of information uniquely describing himself or herself. The identification indicia is combined with the secret information (such as the user's encryption password) and is then encrypted under the control of the trustee's public key. There are many ways of doing this, and the examples herein are demonstrative and not exhaustive. For example, the combined information may be encrypted, for example, under a random symmetric key (such as DES) which is then encrypted under the trustee's public key.
In an embodiment of the invention, after unique identification data has been entered, the user is asked to select a password to protect the system. Thereafter, all the personal identifying data, together with the password, is encrypted with the manufacturer's (trustee's) public key and is stored, for example, in the user's computer as an escrow security record. The password is then used to encrypt all data on the user's disk.
If at some point in time in the future, the user forgets the password, the retrieval phase of the applicant's invention is performed. Under such circumstances, the user contacts the escrow agent, e.g., the vendor or manufacturer. In accordance with one embodiment of the invention, the user (applicant) must provide sufficient credentials to definitively establish his or her identification. This might take the form of an affidavit executed before a notary public. It might occur by using a digitally signed message verifiable with a well certified public key (or the public key indicated in the escrowed information itself). It might require production of a driver's license, independent investigation by the trustee; or the physical presence of the applicant to confirm identity. In accordance with one embodiment of the present invention, the user in initially establishing the escrow record is asked to define for the vendor what security measures are to be required if the key (or other secret information) must sometimes be retrieved, such as, by requiring identification performed before a notary, a personal appearance, production of a valid driver's license, et

LandOfFree

Say what you really think

Search LandOfFree.com for the USA inventors and patents. Rate them and share your experience with other people.

Rating

Method for preventing inadvertent betrayal by a trustee of... does not yet have a rating. At this time, there are no reviews or comments for this patent.

If you have personal experience with Method for preventing inadvertent betrayal by a trustee of..., we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Method for preventing inadvertent betrayal by a trustee of... will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFUS-PAI-O-2451722

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.