IP Library Granted Patent US 9,578,035
Granted Patent B2
US 9,578,035 · App. 15/154,861 · Granted Feb 21, 2017

System and method to use a cloud-based platform supported by an API to authenticate remote users and to provide PKI- and PMI-based distributed locking of content and distributed unlocking of protected content

Inventors: David W. Kravitz (Fairfax, VA); Donald Houston Graham, III (Pasadena, CA); Josselyn L. Boudett (Clearwater, FL); Russell S. Dietz (Los Gatos, CA)
Assignee: T-Central, Inc.
H04L63/10H04L9/006H04L9/0822H04L9/0894H04L9/30H04L9/3247H04L9/3263H04L63/0435H04L63/0442H04L63/061H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,578,035
App. No.
15/154,861
Filed
May 13, 2016
Granted
Feb 21, 2017
Kind
B2
Art Unit
2497
USPC
713/171
Abstract

A security system for authenticating users and protecting content that provides an application program interface (API) with a Cloud Platform integration (Platform) to extend the security capabilities of Public Key Infrastructure and Privilege Management Infrastructure systems to authenticated external users and protected content.

Claims (28)

1. A method, comprising:

establishing a secure communications line between an entity device and a client device, the entity device need not have specific knowledge of cryptographic functions of a platform service;

receiving, at one client device from the entity device, an invitation to authenticate a secure communications line with the entity device using an inviter-invitee protocol, the invitation including an authentication parameter;

downloading, at the client device from a platform service, a client application based at least in part on the invitation, the platform service comprising a public key infrastructure, privilege management infrastructure, and at least one of certification authority, registration authority, attribute authority, or hardware security module, or a combination thereof;

authenticating an identity of a user of the client device based at least in part on the authentication parameter included in the invitation;

creating, at the client device, certain cryptographic keys, including at least one public-private key pair and a digital identity token upon receiving authentication approval from the platform service;

transmitting, from the client device to the platform service, a public key of the public-private key pair of the client device which is subsequently received by the entity device;

receiving, at the client device from the platform service, a public key corresponding to the inviting entity device with that device's digital identity token; and

transmitting, from the client device to the platform service, a request to create the digital identity token;

wherein the invitation includes a unique invitation code; and

wherein the downloading the client application occurs based at least in part on the unique invitation code.

2. The method of claim 1 , wherein the authentication parameter includes an answer to an authentication question; and wherein the identity of the user is authenticated based at least in part on transmitting the answer to the authentication question from the client device to the platform service.

3. The method of claim 1 , wherein the platform service is located in at least one server in a cloud computing environment within a network; and

wherein the platform service is accessible by an application programming interface.

4. A client device, comprising:

one or more memory devices to store instructions; and

one or more processing devices to execute the instructions to:

establish a secure communications line between an entity device and the client device, the entity device need not have specific knowledge of cryptographic functions of the client device to access security or cryptographic functions;

receive, from the entity device, an invitation to authenticate the secure communications line with the entity device using an inviter-invitee protocol, the invitation including an authentication parameter;

download, from a platform service, a client application based at least in part on the invitation, the platform service comprising a public key infrastructure, privilege management infrastructure, and at least one of certification authority, registration authority, attribute authority, or hardware security module, or a combination thereof;

authenticate an identity of a user of the client device based at least in part on the authentication parameter included in the invitation;

create, at the client device, certain cryptographic keys, including at least one public-private key pair and a digital identity token upon receiving approval from the platform service;

transmit, to the platform service, a client device public key of the public-private key pair;

receive, from the platform service, a public key corresponding to the entity device;

receive, at the client device, a public key corresponding to the entity device with its digital identity token; and

transmit, from the client device to the platform service, a request to create the digital identity token;

wherein the invitation includes a unique invitation code; and

wherein the downloading the client application occurs based at least in part on the unique invitation code.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 5, 2016
From: KRAVITZ, DAVID W.; GRAHAM, DONALD H., III; BOUDETT, JOSSELYN L.; DIETZ, RUSSELL S.
To: T-CENTRAL, INC.
Reel/Frame 040233/0343 →
Continuity (14)
Continuation 14715588 · May 18, 2015
Continuation In Part 14218897 · Mar 18, 2014
Continuation In Part 13481553 · May 25, 2012
Continuation In Part 13096764 · Apr 28, 2011
Provisional Application 62133371 · Mar 15, 2015
Provisional Application 61994885 · May 17, 2014
Provisional Application 61792927 · Mar 15, 2013
Provisional Application 61650866 · May 23, 2012
Provisional Application 61490952 · May 27, 2011
Provisional Application 61330226 · Apr 30, 2010
Provisional Application 61367574 · Jul 26, 2010
Provisional Application 61367576 · Jul 26, 2010
Provisional Application 61416629 · Nov 23, 2010
Related Publication 20160337361A1 · Nov 17, 2016