Patent · US Expired

Method and apparatus for controlling access to encrypted data files in a computer system

US5787169A · kind A · utility

132Cited by
14References
28Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 28, 1995
Grant dateJul 28, 1998
Priority date
Expiry dateDec 28, 2015

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/2107
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

In a system in which encrypted information can be protected and maintained by multiple users using passwords in concert, a file with secure data contains both an unencrypted header and an encrypted data portion. The data portion contains both the secured data and a list of hashed passwords and is encrypted with a single file key. The unencrypted file header contains two tables. The first table is a list passwords, where each password is cryptographically hashed using a second, different hashing technique than the hashed passwords in the data portion of the file. The second table is a list of cryptographically hashed combinations of cryptographically hashed passwords, where the combinations correspond to authorized user quorums and the passwords are hashed using the same technique as the passwords stored in the data portion of the file. Each hashed combination on the list is also used as a password key to encrypt the file key. During use of the system, an authorized user must enter a password which, when hashed, can be found in the first table. If the entered password is found in the first table, a check is made to determine if enough authorized users have entered passwords to form …

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.