IP Library Granted Patent US 12711266
Granted Patent B2
US 12711266 · App. 18/085,477 · Granted Aug 18, 2026

Multi-platform use case implementations to securely provision a secure data asset to a target device

Inventors: Matthew Evan Orzen (San Francisco, CA); Denis Alexandrovich Pochuev (Lafayette, CA)
Assignee: Cryptography Research, Inc.
G06F21/6245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12711266
App. No.
18/085,477
Filed
Dec 20, 2022
Granted
Aug 18, 2026
Kind
B2
Examiner
YU, XIANG
Art Unit
2455
USPC
726/26
Abstract

An application executing at a first platform receives, from a tester device, a first request to generate a secure data asset to be securely provisioned to a target device. Responsive to receiving the first request, the application performs one or more operations related to the generation of the secure data asset. Subsequent to performing the one or more operations related to the generation of the secure data asset, the application sends, to a second secure platform, a second request to generate the secure data asset. The application receives, from the second secure platform, the generated secure data asset.

Claims (40)

1 . A method comprising:

receiving, by an application executing at a first unsecured platform and from a tester device, a first request to generate a secure data asset to be securely provisioned to a target device;

responsive to receiving the first request, performing, by the application executing at the first unsecured platform, one or more operations related to the generation of the secure data asset, wherein the one or more operations comprise identifying first information that is used at least in part to generate the secure data asset;

subsequent to performing the one or more operations related to the generation of the secure data asset, sending, by the first unsecured platform to a second secure platform comprising a hardware security module (HSM), a second request to generate the secure data asset based on the first information and second information associated with the second secure platform; and

receiving, by the application and from the second secure platform, the generated secure data asset that is cryptographically bound to the first information, the application and the second information such that the secure data asset is generated responsive to cryptographic validation that only a combination of elements comprising the application, the first information, and the second information are cryptographically authorized to operate together.

2 . The method of claim 1 , wherein performing the one or more operations related to the first request to generate the secure data asset comprises:

identifying the first information comprising context data that is used at least in part to generate the secure data asset, and wherein the context data is identified in the second request to the second secure platform.

3 . The method of claim 2 , wherein the context data comprises one or more private cryptographic keys.

4 . The method of claim 2 , wherein performing the one or more operations related to the first request to generate the secure data asset comprises:

identifying the first information comprising one or more of pre-computed data (PCD) or arguments, wherein one or more of the PCD or arguments are used at least in part to generate the secure data asset, wherein one or more of the PCD or the arguments are identified in the second request to the second secure platform.

5 . The method of claim 1 , further comprising:

sending, by the application, the generated secure data asset to the tester device in response to the first request to generate the secure data asset.

6 . The method of claim 5 , further comprising:

modifying, by the application, the generated secure data asset, wherein the modified data asset is sent to the tester device by the application in response to the first request.

7 . The method of claim 1 , wherein the secure data asset comprises one or more of encrypted data, authenticated data, or a certificate.

8 . The method of claim 1 , wherein performing the one or more operations related to the first request to generate the secure data asset comprises:

performing a pre-module operation to retrieve additional information related to the first request to generate the secure data asset.

9 . The method of claim 8 , wherein performing the pre-module operation comprises sending a Hypertext Transfer Protocol (HTTP) request to an unsecured server to obtain additional data or to perform a service related to the generation of the secure data asset.

10 . A method comprising:

receiving, by a library component of a first secure platform comprising a hardware security module (HSM) and from an application executing at a second unsecured platform, a first request to generate a secure data asset to be securely provisioned to a target device, the first request indicating first information identified by the second unsecured platform;

responsive to receiving the first request, executing the library component of the first secure platform to perform one or more operations related to the first request to generate the secure data asset;

sending, by the library component to a cryptographic management (CM) module of the first secure platform, a second request to generate the secure data asset;

generating, by the CM module, the secure data asset based on the first information identified by the second unsecured platform and second information associated with the CM module, wherein the secure data asset is cryptographically bound to the first information, the application and the second information such that the secure data asset is generated responsive to cryptographic validation that only a combination of elements comprising the application, the first information, and the second information are cryptographically authorized to operate together; and

sending, by the first secure platform, the generated secure data asset to the application executing on the second unsecured platform responsive to the first request.

11 . The method of claim 10 , wherein the first request is responsive to a previous request by a tester device for requesting a generation of the secure data asset.

12 . The method of claim 10 , wherein the first request identifies the first information comprising context data.

13 . The method of claim 12 , wherein the second request to generate the secure data asset identifies the context data, and wherein the secure data asset is generated based on the context data.

14 . The method of claim 13 , wherein the first request identifies the first information comprising one or more of pre-computed data (PCD) or arguments, wherein the secure data asset is generated based on one or more of the PCD or the arguments.

15 . The method of claim 12 , wherein the executing the library component of the first secure platform to perform the one or more operations related to the first request to generate the secure data asset comprises:

decrypting the context data, wherein the decrypted context data is identified in the second request.

16 . The method of claim 15 , wherein the context data comprises one or more private cryptographic keys.

17 . The method of claim 10 , wherein the secure data asset comprises one or more of encrypted data, authenticated data, or a certificate.

18 . The method of claim 10 , wherein the library component provides an interface between the application executing at the second unsecured platform and the CM module of the first secure platform.

19 . A cryptographic management (CM) system, comprising:

a memory device; and

a processing device, coupled to the memory device, configured to perform operations comprising:

receiving, by an application executing at the processing device of a first unsecured platform and from a tester device, a first request to generate a secure data asset to be securely provisioned to a target device;

responsive to receiving the first request, performing, by the application executing at the first unsecured platform, one or more operations related to the generation of the secure data asset, wherein the one or more operations comprise identifying first information that is used at least in part to generate the secure data asset;

subsequent to performing the one or more operations related to the generation of the secure data asset, sending, by the first unsecured platform to a second secure platform comprising a hardware security module (HSM), a second request to generate the secure data asset based on the first information and second information associated with the second secure platform; and

receiving, by the application and from the second secure platform, the generated secure data asset that is cryptographically bound to the first information, the application and the second information such that the secure data asset is generated responsive to cryptographic validation that only a combination of elements comprising the application, the first information, and the second information are cryptographically authorized to operate together.