US2019245837A1PendingUtilityA1

Systems and methods for secure storage and management of credentials and encryption keys

Assignee: FHOOSH INCPriority: Jan 20, 2016Filed: Apr 16, 2019Published: Aug 8, 2019
Est. expiryJan 20, 2036(~9.5 yrs left)· nominal 20-yr term from priority
H04L 63/107H04L 9/3234H04L 63/083H04L 63/061H04L 63/0876
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system for storing and managing credentials and encryption keys includes a first data store, a second data store, a client device, and a secure key platform. The client device is configured to transmit a request to retrieve user data stored in the first data store. The secure key platform configured to: store user credentials and data store credentials in the second data store separate from the user data stored in the first data store; receive a request to retrieve user data; retrieve, from the second data store, user credentials of a user of the client device and data store credentials of the first data store in response to the request; use the user credentials of the user of the client device and data store credentials of the first data store to retrieve user data from the first data store; and provide the user data to the client device.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system for storing and managing credentials and encryption keys, comprising:
 a first data store configured to store user data;   a second data store configured to user credentials and data store credentials in the second data store separate from the user data stored in the first data store; and   one or more processors configured to execute instructions to:
 establish a secure session based on one or more user credentials of a user of a client device, wherein the one or more user credentials are received from the client device; 
 retrieve, from the second data store, data store credentials of the first data store based on the established secure session; 
 use at least the data store credentials of the first data store to retrieve user data from the first data store; and 
 transmit the user data to the client device. 
   
     
     
         2 . The system of  claim 1 , wherein the one or more processors are further configured to receive, from the client device, a request to retrieve user data stored in the first data store. 
     
     
         3 . The system of  claim 2 , wherein the one or more processors are further configured to retrieve the data store credentials in response to receiving the request from the client device. 
     
     
         4 . The system of  claim 1 , wherein the one or more processors are further configured to generate a session token based on the one or more user credentials and store the session token in the second database. 
     
     
         5 . The system of  claim 4 , wherein the one or more processors are further configured to retrieve the database credentials using the session token. 
     
     
         6 . The system of  claim 1 , wherein the one or more processors are further configured to verify the received one or more user credential against user credentials stored in the second data store, wherein the secure session is established based on successful verification of the received one or more user credential. 
     
     
         7 . The system of  claim 1 , wherein the one or more processors are further configured to register the client device including by validating and recording one or more of a device signature, browser type, plugins, hardware settings, and geolocation. 
     
     
         8 . The system of  claim 7 , wherein the one or more processors are further configured to register the client device by posing one or more challenge questions, and storing responses to the one or more challenge questions. 
     
     
         9 . The system of  claim 1 , wherein the one or more processors are further configured to authenticate the client device prior to establishing the secure session. 
     
     
         10 . The system of  claim 9 , wherein the one or more processors are configured to automatically retrieve the user credentials in response to successfully authenticating the client device. 
     
     
         11 . The system of  claim 9 , wherein the one or more processors are configured to authenticate the client device based on one or more of a username provided by the user, a password provided by the user, a response to at least one challenge question provided by the user, a browser type of the client device, plugins of the client device, hardware settings of the client device, a geolocation of the client device, and an internet protocol (IP) address from which the client device is attempting the login. 
     
     
         12 . The system of  claim 1 , wherein the user credentials comprise a first passphrase. 
     
     
         13 . The system of  claim 12 , wherein the user data stored in the first data store is encrypted based on the first passphrase. 
     
     
         14 . The system of  claim 12 , wherein the first passphrase controls access to a second passphrase, and wherein the user data stored in the first data store is encrypted using the second passphrase. 
     
     
         15 . The system of  claim 1 , wherein the user credentials correspond to a plurality of users, each user credential associated with at least one data credential in the second data store, wherein the one or more processors are further configured to retrieve only those data store credentials associated with the user credentials used establish the secure session. 
     
     
         16 . The system of  claim 1 , wherein the first data store comprises a plurality of data stores, and the system further comprising a secure object platform configured to:
 decompose the user data into a plurality of segments; and   store the plurality of segments of the decomposed user data across the plurality of data stores of the first data store.   
     
     
         17 . The system of  claim 1 , wherein the second data store comprises a plurality of data stores, and wherein the one or more processors are further configured to:
 decompose the user credentials into a plurality of segments; and   store the plurality of segments of the decomposed user credentials across the plurality of data stores of the second data store.   
     
     
         18 . The system of  claim 1 , wherein the second data store comprises a plurality of data stores, and wherein the one or more processors are further configured to:
 decompose the data store credentials into a plurality of segments; and   store the plurality of segments of the decomposed data credentials across the plurality of data stores of the second data store.   
     
     
         19 . The system of  claim 1 , wherein the one or more processors are further configured to retrieve the user data from the first data store using the data store credentials and the user credentials. 
     
     
         20 . A method for storing and managing credentials and encryption keys, comprising:
 establishing a secure session based on one or more user credentials of a user of a client device, wherein the one or more user credentials are received from the client device and stored in a first data store;   retrieving, from the first data store, data store credentials of a second data store based on the established secure session, the second data store storing user data separate from the user credentials and data store credentials;   using at least the data store credentials of the second data store to retrieve user data from the second data store; and   transmitting the user data to the client device.

Join the waitlist — get patent alerts

Track US2019245837A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.