Method and system for secure data collection and distribution
Abstract
A data provider generates a data encryption key and an identifier, uses the data encryption key to encrypt data, sends the encrypted data and the identifier to a data requester, and sends the data encryption key and the identifier to a crypto information server. The data requestor sends the identifier to the crypto information server to request the encryption key. The crypto information server authenticates the data requestor and, contingent on that authentication, sends the data encryption key to the data requestor. If a plurality of data instances are captured, then for each instance, a respective data encryption key and identifier are generated.
Claims
exact text as granted — not AI-modified1 . A method of distributing data, comprising the steps of:
(a) encrypting the data, using a data encryption key, thereby providing encrypted data; (b) requesting the data, by a data requestor; (c) in response to said request, sending said encrypted data to said data requester; (d) authenticating said data requester, by a crypto information server; and (e) contingent on said authenticating, sending said data encryption key to said data requester, by said crypto information server.
2 . The method of claim 1 , wherein said data encryption key is a symmetric key.
3 . The method of claim 1 , wherein said data encryption key is sent to said data requestor in encrypted form.
4 . The method of claim 1 , further comprising the step of:
(f) requesting said data encryption key, by said data requester, said authenticating being in response to said requesting of said data encryption key.
5 . The method of claim 1 , further comprising the steps of:
(f) generating said data encryption key; and (g) associating said data encryption key with a respective identifier.
6 . The method of claim 5 , wherein said data encryption key is generated according to a predefined key granularity.
7 . The method of claim 5 , wherein said identifier is sent to said data requestor along with said encrypted data, the method further comprising the step of:
(h) sending said identifier to said crypto information server, by said data requestor, to request said data encryption key, said authenticating being in response to receipt of said identifier from said data requestor by said crypto information server.
8 . The method of claim 5 , further comprising the step of:
(h) storing said data encryption key and said identifier in a database, by said crypto information server.
9 . The method of claim 8 , wherein said data encryption key is stored in said database in encrypted form.
10 . The method of claim 1 , wherein the data are encrypted by a data provider, the method further comprising the step of:
(f) storing said encrypted data in an archive separate from said data provider, said encrypted data being sent to said data requestor from said archive.
11 . The method of claim 1 , further comprising the steps of:
(f) attaching a message authentication code to the data prior to said encrypting; and (g) contingent on said authenticating, sending a message authentication code key of said message authentication code to said data requester, by said crypto information server.
12 . The method of claim 11 , further comprising the steps of:
(h) generating said data encryption key and said message authentication code key; and (i) associating said data encryption key and said message authentication code key with a common respective identifier.
13 . The method of claim 12 , wherein said data encryption key and said message authentication code key are generated according to a predefined key granularity.
14 . The method of claim 12 , wherein said identifier is sent to said data requestor along with said encrypted data, the method further comprising the step of:
(j) sending said identifier to said crypto information server, by said data requestor, to request said data encryption key and said message authentication code key, said authenticating being in response to receipt of said identifier from said data requester by said crypto information server.
15 . The method of claim 12 , further comprising the step of:
(j) storing said data encryption key and said message authentication code key in a database, by said crypto information server.
16 . The method of claim 15 , wherein said data encryption key and said message authentication code key are stored in said database in encrypted form.
17 . A system for secure distribution of data, comprising:
(a) a data requester; (b) a data provider operative:
(i) to encrypt the data using a data encryption key, thereby providing encrypted data, and
(ii) to send said encrypted data to said data requestor; and
(c) a crypto information server operative:
(i) to authenticate said data requester, and
(ii) contingent on said authentication, to send said data encryption key to said data requestor.
18 . The system of claim 17 , wherein said crypto information server is operative to send said data encryption key to said data requester in encrypted form.
19 . The system of claim 17 , wherein said data provider also is operative:
(iii) to generate said data encryption key; and (iv) to associate said data encryption key with a respective identifier.
20 . The system of claim 19 , wherein said data provider is operative to generate said data encryption key according to a predefined key granularity.
21 . The system of claim 19 , wherein said data provider also is operative:
(v) to send said identifier to said data requestor along with said encrypted data; and (vi) to send said data encryption key and said identifier to said crypto information server;
wherein said data requestor is operative to request said data encryption key from said crypto information server by steps including sending said identifier to said crypto information server, said authenticating being in response to receipt of said identifier from said data requestor by said crypto information server.
22 . The system of claim 21 , wherein each of said data provider and said data requestor includes a respective instance of a crypto information client that is operative:
(i) to generate said data encryption key; (ii) to generate said respective identifier; (iii) to send said data encryption key and said identifier to said crypto information server; and (iv) to request said data encryption key from said crypto information server by steps including sending said identifier to said crypto information server.
23 . The system of claim 21 , further comprising:
(d) a database wherein said crypto information server stores said data encryption key and said identifier.
24 . The system of claim 23 , wherein said crypto information server stores said data encryption key in said database in encrypted form.
25 . The system of claim 17 , further comprising:
(d) an archive, separate from said data provider, for storing said encrypted data.
26 . The system of claim 25 , wherein said archive is operative to send said encrypted data to said data requester.
27 . The system of claim 17 , wherein said data provider also is operative:
(iii) to attach a message authentication code to the data prior to encrypting the data;
and wherein said crypto information server also is operative:
(iii) contingent on said authenticating, to send a message authentication code key of said message authentication code to said data requester.
28 . The system of claim 27 , wherein said data provider also is operative:
(iv) to generate said data encryption key and said message authentication code key; and (v) to associate said data encryption key and said message authentication code key with a common respective identifier.
29 . The system of claim 28 , wherein said data provider is operative to generate said data encryption key and said message authentication key according to a predefined key granularity.
30 . The system of claim 28 , wherein said data provider also is operative:
(vi) to send said identifier to said data requestor along with said encrypted data; and (vii) to send said data encryption key, said message authentication code key and said identifier to said crypto information server;
wherein said data requestor is operative to request said data encryption key and said message authentication code key from said crypto information server by steps including sending said identifier to said crypto information server, said authenticating being in response to receipt of said identifier from said data requester by said crypto information server.
31 . The system of claim 30 , wherein each of said data provider and said data requestor includes a respective instance of a crypto information client that is operative:
(i) to generate said data encryption key; (ii) to generate said message authentication code key; (iii) to generate said respective common identifier; (iv) to send said data encryption key, said message authentication code key and said identifier to said crypto information server; and (v) to request said data encryption key and said message authentication code key from said crypto information server by steps including sending said identifier to said crypto information server.
32 . The system of claim 30 , further comprising:
(d) a database wherein said crypto information server stores said data encryption key, said message authentication code key and said identifier.
33 . The system of claim 32 , wherein said crypto information server stores said data encryption key and said message authentication code key in said database in encrypted form.
34 . A method of collecting and distributing a plurality of instances of data, comprising the steps of:
(a) for each instance:
(i) generating a respective data encryption key, and
(ii) encrypting said each instance, using said respective data encryption key, thereby providing respective encrypted data;
(b) requesting at least a portion of one of the instances, by a data requestor; and (c) in response to said request, sending a corresponding portion of said respective encrypted data of said one instance to said data requestor.
35 . The method of claim 34 , wherein said one instance includes voice data.
36 . The method of claim 34 , wherein said one instance includes VoIP data.
37 . The method of claim 34 , wherein said one instance includes video data.
38 . The method of claim 34 , wherein said one instance includes screen capture data.
39 . The method of claim 34 , wherein said data encryption keys are symmetric keys.
40 . The method of claim 34 , wherein said data encryption keys are generated according to a predefined key granularity.
41 . The method of claim 34 , further comprising the step of:
(d) for each instance: capturing said instance, by a respective data provider, said generating of said respective data encryption key and said encrypting of said each instance being effected by said respective data provider.
42 . The method of claim 41 , further comprising the step of:
(e) for each instance, storing said encrypted data in an archive separate from said respective data provider, said respective encrypted data being sent to said data requestor from said archive.
43 . The method of claim 34 , further comprising the step of:
(d) for said one instance:
(i) authenticating said data requestor, by a crypto information server; and
(ii) contingent on said authenticating, sending said respective data encryption key of said one instance to said data requester, by said crypto information server.
44 . The method of claim 43 , wherein said respective data encryption key of said one instance is sent to said data requestor in encrypted form.
45 . The method of claim 43 , further comprising the step of:
(e) for said one instance: requesting said respective data encryption key, by said data requestor, said authenticating being in response to said requesting of said respective data encryption key.
46 . The method of claim 45 , further comprising the step of:
(f) for each instance, associating said respective data encryption key with a respective identifier.
47 . The method of claim 46 , further comprising the step of:
(g) for said one instance: sending said respective identifier of said one instance to said data requestor along with said respective encrypted data of said one instance, said requesting of said respective data encryption key by said data requester then including sending said respective identifier of said one instance to said crypto information server.
48 . The method of claim 46 , further comprising the step of:
(g) for each instance, storing said respective data encryption key and said respective identifier in a database, by said crypto information server.
49 . The method of claim 48 , wherein said data encryption keys are stored in said database in encrypted form.
50 . The method of claim 43 , further comprising the steps of:
(d) for each instance, attaching a respective message authentication code to said each instance prior to said encrypting; and (e) for said one instance:
(i) authenticating said data requestor by a crypto information server; and
(ii) contingent on said authenticating, sending said respective data encryption key of said one instance and a message authentication code key of said respective message authentication code of said one instance to said data requester, by said crypto information server.
51 . The method of claim 50 , further comprising the step of:
(f) for each instance:
(i) generating a respective message authentication code key; and
(ii) generating said respective message authentication code, using said respective message authentication code key.
52 . The method of claim 51 , wherein said message authentication code keys are generated according to a predefined key granularity.
53 . The method of claim 50 , wherein said respective data encryption key and said respective message authentication code key of said one instance are sent to said data requestor in encrypted form.
54 . The method of claim 50 , further comprising the step of:
(f) for said one instance: requesting said respective data encryption key and said respective message authentication code key, by said data requestor, said authenticating being in response to said requesting of said respective data encryption key and said respective message authentication code key.
55 . The method of claim 54 , further comprising the step of:
(g) for each instance, associating said respective data encryption key and said respective message authentication code key with a common respective identifier.
56 . The method of claim 55 , further comprising the step of:
(h) for said one instance: sending said respective identifier of said one instance to said data requestor along with said respective encrypted data of said one instance, said requesting of said respective data encryption key and said respective message authentication code key by said data requester then including sending said respective identifier of said one instance to said crypto information server.
57 . The method of claim 55 , further comprising the step of:
(h) for each instance, storing said respective data encryption key, said respective message authentication code key and said respective identifier in a database, by said crypto information server.
58 . The method of claim 57 , wherein said data encryption keys and said message authentication code keys are stored in said database in encrypted form.
59 . A system for secure collection and distribution of a plurality of instances of data, comprising:
(a) a set, of at least one data provider, operative:
(i) to capture said instances, and
(ii) for each instance:
(A) to generate a respective data encryption key, and
(B) to encrypt said each instance, using said respective data encryption key, thereby providing respective encrypted data;
(b) a data requestor operative:
(i) to request at least a portion of one of the instances; and
(c) an archive operative:
(i) to store said encrypted data; and
(ii) in response to said request of said at least portion of said one instance by said data requester: to send a corresponding portion of said respective encrypted data of said one instance to said data requestor.
60 . The system of claim 59 , wherein said archive is separate from said set of at least one data provider.
61 . The system of claim 59 , wherein said set of said at least one data provider is operative to generate said data encryption keys according to a predefined key granularity.
62 . The system of claim 59 , further comprising:
(d) a crypto information server, operative:
(i) to authenticate said data requestor; and
(ii) contingent on said authentication, to send said respective data encryption key of said one instance to said data requestor.
63 . The system of claim 62 , wherein said crypto information server is operative to send said data encryption key to said data requestor in encrypted form.
64 . The system of claim 62 , wherein said data requestor also is operative:
(ii) to request said respective data encryption key of said one instance from said crypto information server, said authenticating being in response to said requesting of said respective data encryption key.
65 . The system of claim 64 , wherein said set of said at least one data provider also is operative, for each instance:
(C) to associate said respective data encryption key with a respective identifier;
wherein said archive also is operative:
(iii) in response to said request of said at least portion of said one instance by said data requester: to send said respective identifier of said one instance to said data requester;
and wherein said data requestor requests said respective data encryption key of said one instance from said crypto information server by steps including sending said respective identifier of said one instance to said crypto information server.
66 . The system of claim 65 , wherein each of said at least one data provider and said data requestor includes a respective instance of a crypto information client that is operative:
(i) to generate said data encryption keys and said identifiers; (ii) to send said data encryption keys and said identifiers to said crypto information server; and (iii) to request said data encryption keys from said crypto information server by steps including, for each requested said data encryption key, sending said identifier thereof to said crypto information server.
67 . The system of claim 65 , further comprising:
(e) a database, wherein said crypto information server stores said data encryption keys and said identifiers.
68 . The system of claim 67 , wherein said crypto information server stores said data encryption keys and said identifiers in said database in encrypted form.
69 . The system of claim 59 , wherein said set of said at least one data provider also is operative, for each instance:
(C) to generate a respective message authentication code key; (D) to generate a respective message authentication code, using said respective message authentication code key; and (E) to attach said respective message authentication code to said each instance prior to encrypting said each instance;
and wherein the system further comprises:
(d) a crypto information server, operative:
(i) to authenticate said data requestor; and
(ii) contingent on said authentication, to send said respective data encryption key and said respective message authentication code key of said one instance to said data requester.
70 . The system of claim 69 , wherein said set of said at least one data provider is operative to generate said message authentication code keys according to a predefined key granularity.
71 . The system of claim 69 , wherein said crypto information server is operative to send said respective data encryption key and said respective message authentication code key of said one instance to said data requestor in encrypted form.
72 . The system of claim 69 , wherein said set of said at least one data provider also is operative, for each instance:
(F) to associate said respective data encryption key and said respective message authentication code key with a common respective identifier;
wherein said archive also is operative:
(iii) in response to said request of said at least portion of said one instance by said data requester: to send said respective identifier of said one instance to said data requester;
and wherein said data requestor requests said respective data encryption key and said respective message authentication code key of said one instance from said crypto information server by steps including sending said respective identifier of said one instance to said crypto information server.
73 . The system of claim 72 , wherein each of said at least one data provider and said data requestor includes a respective instance of a crypto information client that is operative:
(i) to generate said data encryption keys, said message authentication code keys and said identifiers; (ii) to send said data encryption keys, said message authentication code keys and said identifiers to said crypto information server; and (iii) to request said data encryption keys and said message authentication code keys from said crypto information server by steps including, for each requested said data encryption key and for each requested said message authentication code key, sending said identifier thereof to said crypto information server.
74 . The system of claim 72 , further comprising:
(e) a database, wherein said crypto information server stores said data encryption keys, said message authentication code keys and said identifiers.
75 . The system of claim 74 , wherein said crypto information server stores said data encryption keys, said message authentication code keys and said identifiers in said database in encrypted form.Join the waitlist — get patent alerts
Track US2008066184A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.