IP Library › Granted Patent US 11,153,098
Granted Patent B2
US 11,153,098 · App. 16/597,405 · Granted Oct 19, 2021

Systems, devices, and methods for recording a digitally signed assertion using an authorization token

Inventor: Christian T Wentz (Providence, RI)
Assignee: Ares Technologies, Inc.
H04L9/3247H04L9/0825H04L9/3213H04L9/3278H04L9/3297
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,098
App. No.
16/597,405
Granted
Oct 19, 2021
Kind
B2
Abstract

A system for recording a digitally signed assertion using an authorization token, includes a cryptographic evaluator designed and configured to receive a dataset and an authorization token. The authorization token includes a verification datum of a device-specific secret possessed by the cryptographic evaluator, a digital signature of a certificate authority generating the authorization token, and a secure temporal attribute. The cryptographic evaluator is configured to produce a secure proof using the device-specific secret. The cryptographic evaluator is configured to generate a first digitally signed assertion as a function of the dataset, the secure proof, and the authorization token. The cryptographic evaluator is configured to enter the first digitally signed assertion in at least an instance of a first temporally sequential listing.

Claims (42)

1. A system for recording a digitally signed assertion using an authorization token, the system comprising a cryptographic evaluator, the cryptographic evaluator comprising a computing device designed and configured to:

receive a dataset and an authorization token, wherein the authorization token further comprises:

a verification datum of a device-specific secret possessed by the cryptographic evaluator;

a digital signature of a certificate authority generating the authorization token; and

a secure temporal attribute;

produce a secure proof using the device-specific secret;

generate a first digitally signed assertion as a function of the dataset, the secure proof, and the authorization token; and

enter the first digitally signed assertion in at least an instance of a first temporally sequential listing.

2. The system of claim 1 , wherein the dataset further comprises a reference to a second digitally signed assertion.

3. The system of claim 2 , wherein the second digitally signed assertion is entered in the first temporally sequential listing.

4. The system of claim 2 , wherein the second digitally signed assertion is entered in at least an instance of a second temporally sequential listing.

5. The system of claim 1 , wherein the authorization token is contained in a second digitally signed assertion.

6. The system of claim 1 , wherein the cryptographic evaluator is configured to receive the authorization token by:

generating the verification datum using the device-specific secret;

providing the verification datum to the certificate authority; and

receiving the authorization token from the certificate authority containing the generated verification datum.

7. The system of claim 1 , wherein the digitally signed assertion further includes a secure timestamp.

8. The system of claim 1 , wherein the cryptographic evaluator is further configured to generate the proof of authenticity using a physically unclonable function.

9. The system of claim 1 , wherein the cryptographic evaluator is further configured to generate the proof of authenticity using a hardware private key generator.

10. The system of claim 1 , wherein the cryptographic evaluator is further configured to generate the proof of authenticity using an attested computing protocol.

11. A method of recording a digitally signed assertion using authorization token, the method comprising:

receiving, at a cryptographic evaluator, wherein the cryptographic evaluator comprises a computing device, a dataset and an authorization token, wherein the authorization token further comprises:

a verification datum of a device-specific secret possessed by the cryptographic evaluator;

a digital signature of a certificate authority generating the authorization token; and

a secure temporal attribute;

producing, at the cryptographic evaluator, a secure proof using the device-specific secret;

generating, at the cryptographic evaluator, a first digitally signed assertion as a function of the dataset, the secure proof, and the authorization token; and

entering, by the cryptographic evaluator, the first digitally signed assertion in at least an instance of a first temporally sequential listing.

12. The method of claim 11 , wherein receiving the dataset further comprises receiving a reference to a second digitally signed assertion.

13. The method of claim 12 , wherein the second digitally signed assertion is entered in the first temporally sequential listing.

14. The method of claim 12 , wherein the second digitally signed assertion is entered in at least an instance of a second temporally sequential listing.

15. The method of claim 11 , wherein the authorization token is contained in a second digitally signed assertion.

16. The method of claim 11 , wherein receiving the authorization token further comprises:

generating the verification datum using the device-specific secret;

providing the verification datum to the certificate authority; and

receiving the authorization token from the certificate authority containing the generated verification datum.

17. The method of claim 11 , wherein generating the digitally signed assertion further comprises:

generating a secure timestamp; and

including the secure timestamp in the digitally signed assertion.

18. The method of claim 11 , wherein producing the proof of authenticity further comprises generating the proof of authenticity using a physically unclonable function.

19. The method of claim 11 , wherein producing the proof of authenticity further comprises generating the proof of authenticity using a hardware private key generator.

20. The method of claim 11 , wherein producing the proof of authenticity further comprises generating the proof of authenticity using an attested computing protocol.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2020
From: WENTZ, CHRISTIAN T
To: ARES TECHNOLOGIES, INC.
Reel/Frame 052556/0534 →
Continuity (2)
Provisional Application 62743132 · Oct 9, 2018
Related Publication 20200112442A1 · Apr 9, 2020
Cited By (3)
US 12,670,294 US 12,676,750 US 12,676,751