×

Method and system for decoupling user authentication and data encryption on mobile devices

  • US 9,137,659 B2
  • Filed: 07/16/2013
  • Issued: 09/15/2015
  • Est. Priority Date: 04/25/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method for decoupling user authentication and data encryption on mobile devices, the method comprising:

  • (a) generating an encryption key (“

    EK”

    ) for encrypting data and a key encryption key (“

    KEK”

    ) for encrypting the EK, wherein neither the EK nor the KEK are generated using a user authentication secret as a seed;

    (b) obtaining an encrypted EK by encrypting the EK using the KEK;

    (c) storing the encrypted EK on a data container device (“

    DCD”

    );

    (d) storing the KEK on a key vault device (“

    KVD”

    ) that is distinct from the DCD;

    (e) generating a KEK identifier (“

    KEK_ID”

    ) that identifies the KEK; and

    (f) storing the KEK ID in memory accessible to an application resident on the DCD that accesses the data and on the KVD.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×