IP Library Granted Patent US 12665760
Granted Patent B2
US 12665760 · App. 18/865,507 · Granted Jun 23, 2026

Methods and arrangements for enabling secure digital communications among a group

Inventor: Tuomas Kärkkäinen (Turku, FI)
Assignee: Gurulogic Microsystems Oy
H04L9/30H04L9/0825
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12665760
App. No.
18/865,507
Granted
Jun 23, 2026
Kind
B2
Abstract

An arrangement for establishing a digital crypto group includes a cryptographic engine configured to produce cryptoproducts from given input data. The cryptographic engine responds to receiving, through a secure transport mechanism, requests containing user identifiers by producing a cryptoproduct. It also responds to receiving, through the secure transport mechanism, a subsequent second request containing one of the plurality of user identifiers by transmitting the cryptoproduct through the secure transport mechanism. The cryptoproduct is a digital crypto group that contains the plurality of user identifiers and a common cryptographic key for use in symmetric cryptography between users identified by the plurality of user identifiers and/or user-specific and user-identifier-related public keys for use in asymmetric cryptography in communications between users identified by the plurality of user identifiers.

Claims (53)

1 . An arrangement for establishing a digital crypto group, the arrangement comprising:

a hardware-based cryptographic engine configured to produce cryptoproducts from given input data, and

a secure transport mechanism with a receiving end and a transmitting end, the receiving end and the transmitting end of the secure transport mechanism coupled to said hardware-based cryptographic engine;

wherein, in response to receiving through the secure transport mechanism, a first request containing a plurality of user identifiers, said hardware-based cryptographic engine is configured to generate and store a cryptoproduct; and

wherein, in response to receiving through the secure transport mechanism a subsequent second request containing one of said plurality of user identifiers, the hardware-based cryptographic engine is configured to retrieve and transmit the stored cryptoproduct as generated, through the secure transport mechanism;

wherein said cryptoproduct comprises a digital crypto group data structure containing:

the plurality of user identifiers:

a common cryptographic key for use in symmetric cryptography between users identified by said plurality of user identifiers; and

for each of the plurality of user identifiers, a corresponding user-specific public key for use in asymmetric cryptography in communications between users identified by said plurality of user identifiers; and

wherein the arrangement is configured to check, whether said first request contained a respective user-specific public key for each of said plurality of user identifiers; and

the arrangement is configured to respond to a finding that said first request did not contain a respective user-specific public key for each of said plurality of user identifiers by augmenting data received in said first request to contain a respective user-specific public key for each of said plurality of user identifiers.

2 . The arrangement according to claim 1 , wherein the arrangement is configured to perform said augmenting by requesting and receiving respective user-specific public keys from sources external to the arrangement.

3 . The arrangement according to claim 1 , wherein the arrangement is configured to check a piece of user-related information received in the first request against a corresponding piece of user-related information from another source, to find out whether the piece of user-related information received in the first request matches the corresponding piece of user-related information from another source.

4 . The arrangement according to claim 3 , wherein the arrangement is configured to respond to a finding that the piece of user-related information received in the first request and the corresponding piece of user-related information from another source do not match by making a decision about whether the establishing of the digital crypto group is allowed to continue.

5 . The arrangement according to claim 1 , wherein the arrangement is configured to use a signing key to digitally sign information elements it includes in said digital crypto group.

6 . The arrangement according to claim 1 , wherein the arrangement is configured to check from said subsequent second request whether the subsequent second request is destined to itself or to a further recipient, and respond to a finding that the subsequent second request is destined to a further recipient by forwarding said subsequent second request towards said further recipient.

7 . The arrangement according to claim 6 , wherein the arrangement is configured to, prior to said forwarding, replace an original authentication of said subsequent second request with an authentication of the arrangement itself.

8 . A method for establishing a digital crypto group, the method comprising:

receiving, through a secure transport mechanism, a first request containing a plurality of user identifiers,

in response to receiving said first request, generating, by a hardware-based cryptographic engine, a cryptoproduct and storing the cryptoproduct,

receiving, through said secure transport mechanism, a subsequent second request containing one of said plurality of user identifiers, and

in response to receiving said subsequent second request, retrieving and transmitting said stored cryptoproduct as generated through said secure transport mechanism;

wherein said cryptoproduct comprises a digital crypto group data structure that includes:

said plurality of user identifiers;

a common cryptographic key for use in symmetric cryptography between users identified by said plurality of user identifiers; and

for each of the plurality of user identifiers, a corresponding user-specific public key for use in asymmetric cryptography in communications between users identified by said plurality of user identifiers; and

wherein the arrangement is configured to check, whether said first request contained a respective user-specific public key for each of said plurality of user identifiers; and

the arrangement is configured to respond to a finding that said first request did not contain a respective user-specific public key for each of said plurality of user identifiers by augmenting data received in said first request to contain a respective user-specific public key for each of said plurality of user identifiers.

9 . The method according to claim 8 , comprising:

in producing said digital crypto group, using a signing key to digitally sign information elements included in said digital crypto group.

10 . The method according to claim 8 , comprising:

checking from said subsequent second request whether the subsequent second request is destined to the arrangement executing the method or to a further recipient, and

responding to a finding that the subsequent second request is destined to a further recipient by forwarding said subsequent second request towards said further recipient.

11 . The method according to claim 10 , comprising:

prior to said forwarding, replacing an original authentication of said subsequent second request with an authentication of the arrangement executing the method.

12 . A computer program product comprising a non-transitory medium for storing one or more sets of one or more machine-executable instructions that are configured to, when executed by one or more processors, make said one or more processors execute a method comprising:

receiving, through a secure transport mechanism, a first request containing a plurality of user identifiers,

in response to receiving said first request, generating, by a hardware-based cryptographic engine, a cryptoproduct and storing the cryptoproduct;

receiving, through said secure transport mechanism, a subsequent second request containing one of said plurality of user identifiers, and

in response to receiving said subsequent second request, retrieving and transmitting said stored cryptoproduct as generated through said secure transport mechanism;

wherein said cryptoproduct is a digital crypto group data structure that includes:

said plurality of user identifiers;

a common cryptographic key for use in symmetric cryptography between users identified by said plurality of user identifiers,

for each of the plurality of user identifiers, a corresponding user-specific public key for use in asymmetric cryptography in communications between users identified by said plurality of user identifiers; and

wherein the arrangement is configured to check, whether said first request contained a respective user-specific public key for each of said plurality of user identifiers; and

the arrangement is configured to respond to a finding that said first request did not contain a respective user-specific public key for each of said plurality of user identifiers by augmenting data received in said first request to contain a respective user-specific public key for each of said plurality of user identifiers.

13 . The arrangement according to claim 1 , wherein the arrangement comprises an electronic device including means for processing and communications and the hardware-based cryptographic engine is implemented by the means for processing.

14 . The arrangement according to claim 1 , wherein the arrangement comprises an electronic device implementing a vault or trusted party module comprising processing means for performing cryptographic operations and communications means for interfacing with a secure transport mechanism.

15 . The arrangement according to claim 1 , wherein the secure transport mechanism comprises a hardware-assisted communication interface configured to securely transmit and receive data between the cryptographic engine and one or more external entities.

16 . The arrangement according to claim 1 , wherein the apparatus comprises a non-transitory computer-readable medium storing a computer program product comprising machine-executable instructions that, when executed by one or more processors of the apparatus, cause the cryptographic engine to:

generate the cryptoproduct in response to the first request comprising the plurality of user identifiers; and

transmit the cryptoproduct in response to the subsequent second request comprising one of the plurality of user identifiers.

17 . The arrangement of claim 1 , wherein said cryptoproduct comprises a data structure dynamically generated by the hardware-based cryptographic engine in response to said first request, the data structure including the plurality of user identifiers and, for each user identifier, a corresponding user-specific public key, the cryptoproduct being stored for subsequent retrieval and transmission through said secure transport mechanism responsive to said subsequent second request.