IP Library Granted Patent US 11,463,423
Granted Patent B2
US 11,463,423 · App. 16/786,884 · Granted Oct 4, 2022

System and method to enable PKI- and PMI-based distributed locking of content and distributed unlocking of protected content and/or scoring of users and/or scoring of end-entity access means—added

Inventors: David W. Kravitz (San Jose, CA); Donald Houston Graham, III (Pasadena, CA); Josselyn L. Boudett (Clearwater, FL); Russell S. Dietz (San Ramon, CA)
Assignee: T-CENTRAL, INC.
H04L63/061H04L9/006H04L9/0825H04L9/0894H04L9/3247H04L63/0435H04L63/08H04L67/10H04L67/125H04L67/53
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,463,423
App. No.
16/786,884
Granted
Oct 4, 2022
Kind
B2
Abstract

A central server configured with an Attribute Authority (“AA”) acting as a Trusted Third Party mediating service provider and using X.509-compatible PKI and PMI, VPN technology, device-side thin client applications, security hardware (HSM, Network), cloud hosting, authentication, Active Directory and other solutions. This ecosystem results in real time management of credentials, identity profiles, communication lines, and keys. It is not centrally managed, rather distributes rights to users. Using its Inviter-Invitee protocol suite, Inviters vouch for the identity of Invitees who successfully complete the protocol establishing communication lines. Users establish and respond to authorization requests and other real-time verifications pertaining to accessing each communication line (not end point) and sharing encrypted digital files. These are auditable, brokered, trusted-relationships where such relationships/digital agreements can each stand-alone (for privacy) or can leverage build-up of identity confidence levels across relationships. The service is agnostic to how encrypted user content is transported or stored.

Claims (12)

1. A method executed on a distributed computer network for establishing secure electronic delivery agreements related to digital transactions between a plurality of devices, each device including a hardware processor and associated memory, the method comprising:

receiving a first unique identification and a first cryptographic key by a first device, and a second unique identification and a second cryptographic key by a second device;

generating a digital certificate using the first and second unique identifications and the first and second cryptographic keys;

authenticating an electronic delivery agreement related to a digital transaction between the first device and the second device by issuing the digital certificate to the first device and the second device; and

after the electronic delivery agreement is established, processing the digital transaction according to parameters of the electronic delivery agreement using a unique identification or a cryptographic key of one of the plurality of devices, wherein the electronic delivery agreement includes terms of use and rules of said each secure communication between respective devices, and wherein the digital transaction is validated without being privy to data exchanged in said digital transaction such that said rules allow exchange of encrypted data accordingly.

2. The method of claim 1 , further comprising including a group membership for a group of the plurality of devices in an attribute certificate indicating group characterization.

3. The method of claim 2 , wherein the attribute certificate is owned by one of the plurality of devices and references a public key or a public key certificate for said one of the plurality of devices.

4. The method of claim 2 , further comprising preventing a device for which a secure communication to any one of the plurality of devices has not been established, or which is not a member of a group with an approved attribute certificate, from communicating with said any one of the plurality of devices.

5. The method of claim 2 , wherein the group of the plurality of devices includes sub-groups.

6. The method of claim 2 , wherein the group of the plurality of devices includes associated rules of the group.

7. The method of claim 1 , wherein at least one of the plurality of devices assumes different identities to represent itself to external devices or endpoints.

8. The method of claim 1 , further comprising preventing an endpoint which is not a member of a group of the plurality of devices or is not authenticated with an approved attribute certificate, from communicating with the plurality of devices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2022
From: KRAVITZ, DAVID W.; GRAHAM, DONALD HOUSTON, III; BOUDETT, JOSSELYN L.; DIETZ, RUSSELL S.
To: T-CENTRAL, INC.
Reel/Frame 060805/0368 →
Continuity (15)
Continuation 16045646 · Jul 25, 2018
Continuation 15642304 · Jul 5, 2017
Continuation 15269832 · Sep 19, 2016
Continuation 15002225 · Jan 20, 2016
Continuation 14218897 · Mar 18, 2014
Continuation In Part 13481553 · May 25, 2012
Continuation In Part 13096764 · Apr 28, 2011
Provisional Application 61792927 · Mar 15, 2013
Provisional Application 61650866 · May 23, 2012
Provisional Application 61490952 · May 27, 2011
Provisional Application 61416629 · Nov 23, 2010
Provisional Application 61367574 · Jul 26, 2010
Provisional Application 61367576 · Jul 26, 2010
Provisional Application 61330226 · Apr 30, 2010
Related Publication 20200236095A1 · Jul 23, 2020