Implementing enhanced computer security standard for secure cryptographic key storage using a software-based keystore
US12261950B2 · kind B2 · utility
Inventors
Key dates
| Filing date | Feb 1, 2022 |
| Grant date | Mar 25, 2025 |
| Priority date | — |
| Expiry date | Oct 27, 2042 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L9/3231
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
A client device that is not originally compliant with a particular security standard (e.g., FIPS) is brought into compliance through the addition of a standard-compliant software-based cryptographic library. In order to adapt the cryptographic library to integrate with the hardware-backed keystore, a non-hardware-backed software keystore is used to store keys used by the cryptographic library. Additionally, in order to provide appropriate security for the software keystore, the software keystore (and/or the keypairs within the software keystore) is protected by a password, and the password is in turn protected by the hardware-backed keystore. Thus, to obtain the password needed to obtain a keypair from the software keystore that is in turn needed to use the cryptographic library, a user must authenticate with the operating system, e.g., by providing biometric credentials.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.