IP Library Granted Patent US 10,587,586
Granted Patent B2
US 10,587,586 · App. 15/429,455 · Granted Mar 10, 2020

System and method for a multi system trust chain

Inventors: Srinivas Kumar (Cupertino, CA); Gopal Raman (San Jose, CA); Atul Gupta (Sunnyvale, CA); Shashank Jaywant Pandhare (Kothrud Pune, IN)
Assignee: MOCANA CORPORATION
H04L63/0428H04L9/0838H04L9/3268H04L63/0281H04L63/0823H04L63/126H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,587,586
App. No.
15/429,455
Granted
Mar 10, 2020
Kind
B2
Abstract

The method provides a multi system trust chain between a client system and a remote system in a secure connection, wherein an intermediary system associated with the network flow path serves as a signing entity to establish an end to end transitive trust. The intermediate system is a corroborative entity in the operations technology (OT) realm of the client system. The remote system serves as the host for a plurality of services in the information technology (IT) realm. A two way handshake during the initial secure exchange protocol between a local client application and a remote service is extended to a three way handshake that includes a nonce issued by the remote service on the remote system and a digital signature for the nonce issued by a signature service on an associated intermediate system. The nonce signature is verified authoritatively at the remote system based on the signing certificate of the intermediate system for explicit proof of association.

Claims (34)

1. A method of establishing a trust chain between a client application on a client system, a signature service on an intermediate system, and a remote service on a remote system, the method comprising:

transmitting, by the client application to the remote service, a signing certificate of the intermediate system in a session request message;

verifying, by the remote service, status of the signing certificate of the intermediate system;

generating, by the remote service, a nonce for the client application;

transmitting, from the remote service to the client application, the nonce in a session negotiate message of a two-way handshake sequence;

establishing, by the client application and the signature service, a trusted session based on application identification and attestation by the client system;

transmitting, from the client application to the signature service, the nonce for issuance of a digital signature for the nonce by the intermediate system;

transmitting, from the client application to the remote service, in a session setup message the digital signature for the nonce in a session setup message;

validating, by the remote service, the trust chain by verifying the digital signature for the nonce using the verified signing certificate of the intermediate system; and

establishing, by the client application and the remote service, a secure transport for encrypted communications traversing the intermediate system,

wherein the client application and signature service exchange boot and execution trust measurements, attested to by a respective local root of trust anchor for application identification, prior to issuance of the digital signature for the nonce.

2. The method of claim 1 , wherein the signing certificate of the intermediate system is included by the client application as an optional attribute in the session request message.

3. The method of claim 1 , wherein the client application sends the digital signature for the nonce in the session setup message that includes an encrypted pre-master key to the remote service.

4. The method of claim 1 , wherein a secure connection is established between the client application and the signature service on the intermediate system with mutual certificate verification and application identification prior to transfer of the nonce and issuance of the digital signature for the nonce.

5. The method of claim 1 further comprising signing the nonce, performed by the signature service using a private key protected by a root of trust anchor on the intermediate system.

6. The method of claim 1 further comprising verifying the signed nonce, performed using a public key extracted from the signing certificate issued to the intermediate system.

7. A method of establishing a trust chain between a client application on a client system, a signature service on an intermediate system, and a remote service on a remote system, the method comprising:

transmitting, by the client application to the remote service, a signing certificate of the intermediate system in a session request message;

verifying, by the remote service, status of the received signing certificate of the intermediate system associated with a protected private key on the intermediate system;

generating, by the remote service, a nonce for signing by the intermediate system;

transmitting, by the remote service to the client application, the nonce in a session negotiate message of a two-way handshake sequence;

establishing, by the client application and the signature service, a trusted session based on application identification and attestation by the client system;

exchanging, by the client application and the signature service, boot and execution trust measurements for the client system and the intermediate system attested to by the respective local root of trust anchors;

verifying, by the signature service on the intermediate system, the received boot and execution trust measurements attested to by the root of trust on the client system;

transmitting, from the client application to the signature service, the nonce for issuance of a digital signature for the nonce by the intermediate system;

receiving, from the signature service on the intermediate system, the digital signature for the nonce generated using the protected private key associated with the signing certificate of the intermediate system;

transmitting, from the client application to the remote service, the received digital signature for the nonce in a session setup message;

validating, by the remote service, the trust chain by verifying the digital signature for the nonce using the verified signing certificate of the intermediate system; and

establishing, by the client application and the remote service, a secure transport for encrypted communications traversing the intermediate system.

8. The method of claim 7 , wherein the signing certificate of the intermediate system is included by the client application as an optional attribute in the session request message.

9. The method of claim 7 , wherein the client application sends the digital signature for the nonce signed by the signature service on the intermediate system in the session setup message to the remote service.

10. The method of claim 7 , wherein a secure connection is established between the client application and the signature service on the intermediate system with mutual certificate verification and application identification prior to transfer of the nonce and issuance of the digital signature for the nonce.

11. The method of claim 7 , further comprising signing the nonce, performed by the signature service using a private key protected by a root of trust anchor on the intermediate system.

12. The method of claim 7 , further comprising verifying the signed nonce, performed using a public key extracted from the signing certificate issued to the intermediate system.

Assignments (4)
FIRST LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Sep 24, 2025
From: DIGICERT, INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 072947/0203 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Jul 30, 2025
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 072295/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2022
From: MOCANA CORPORATION
To: DIGICERT, INC.
Reel/Frame 058946/0369 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2017
From: KUMAR, SRINIVAS; RAMAN, GOPAL; GUPTA, ATUL; PANDHARE, SHASHANK JAYWANT
To: MOCANA CORPORATION
Reel/Frame 041223/0515 →
Cited By (7)
US 12,261,838 US 12,301,563 US 12,309,262 US 12,368,580 US 12,463,802 US 12,470,372 US 12,476,793