IP Library Granted Patent US 11,743,257
Granted Patent B2
US 11,743,257 · App. 17/155,089 · Granted Aug 29, 2023

Automated authentication and authorization in a communication system

Inventors: Peter Martin Goldstein (San Francisco, CA); Seth Joshua Blank (San Francisco, CA); Ashley Duane Wilson (San Francisco, CA); Jack William Abbott (Parker, CO); Robert Benjamin Barclay (Thornton, CO)
Assignee: ValiMail Inc.
H04L63/0884H04L9/3247H04L63/101H04L63/107H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,743,257
App. No.
17/155,089
Granted
Aug 29, 2023
Kind
B2
Abstract

An application-operating organization may delegate a third-party server to serve as an automated contextual authentication responder and an authorization responder. The third-party server may manage a delegated section of the organization's namespace that includes the public identities of various devices controlled by the organization. The third-party server may also dynamically generate interaction control list that is tailored to a requesting device's context based on the interaction control policies set forth by the organization. The interaction control list may include information that determines the authorization of the requesting device to interact with another device. The third-party server may also automatically determine the role of a new device to which existing policies are inapplicable and provide guided workflow for the organization to set up new interaction control policies in governing the new device. The determination of the roles of devices may be based on an iterative process using external data sources.

Claims (16)

1. A computer-implemented method comprising:

receiving, by a third-party server from an organization, one or more rules governing authentication of messages transmitted from a named entity device that is associated with the organization, the named entity device being an Internet-of-Things (IoT) device, the organization having a namespace, the third-party server delegated by the organization for managing a delegated namespace of the organization, the delegated namespace being a section of the namespace, a geographical restriction rule of the one or more rules governing an authorized geographical location of the named entity device serving as a message transmitter;

storing, in the delegated namespace, an identity record of the named entity device, the identity record comprising (i) a unique device identifier of the named entity device, the unique device identifier being distinct from IP address and having a format that is under the namespace of the organization, (ii) one or more contextual conditions of the named entity device, the one or more contextual conditions comprising the authorized geographical location of the named entity device, and (iii) a public key of the named entity device, the public key being associated with the unique device identifier in the identity record, the public key corresponding to a private key of the named entity device that is secretly kept by the named entity device;

receiving, by the third-party server, an authentication query from a recipient IoT device that attempts to authenticate a message transmitted from a transmitter IoT device purportedly associated with the unique device identifier belonging to the named entity device, the message comprising a digital signature signed by the private key of the named entity device, the digital signature comprising the unique device identifier and a timestamp at which the message was transmitted, the authentication query from the recipient IoT device including the digital signature in the message and a current geographical location of the recipient IoT device, wherein the authentication query that includes the current geographical information of the recipient IoT device and the digital signature is directed at the delegated namespace of the organization;

verifying, by the third-party server, the unique device identifier of the named entity device to confirm that the unique device identifier is under the namespace of the organization;

examining, by the third-party server, the current geographical location of the recipient IoT device and the digital signature using the geographical restriction rule provided by the organization for authenticating the message, wherein the examining comprises using the unique device identifier to retrieve the public key stored in the identity record to verify the digital signature and the timestamp and comparing the current geographical location of the recipient IoT device against the authorized geographical location of the named entity device serving as a message transmitter;

determine, by the third-party server and based on the unique device identifier and the geographical restriction rule, a response to the authentication query; and

transmitting, by the third-party server, the response to the message recipient, the response allowing the recipient IoT device to verify the message.

2. The computer-implemented method of claim 1 , wherein the public key of the named entity device is part of credential of the named entity device, the public key capable of authenticating the digital signature signed by the named entity device.

3. The computer-implemented method of claim 2 , wherein determining the response to the authentication query comprises:

retrieving the credential of the named entity device from a domain name system (DNS) address specified in the unique device identifier of the named entity device;

using the credential to verify attested metadata of the named entity device that is included in the message;

responsive to a successful verification, determining that the message is authenticated, wherein the response comprises an indication that the third-party server has determined that the message is authenticated.

4. The computer-implemented method of claim 1 , wherein the namespace is a domain name system (DNS).

5. The computer-implemented method of claim 4 , wherein the unique device identifier is an address in the DNS and the response to the authentication query comprises the public key of the named entity device, the public key being stored at the address.

6. The computer-implemented method of claim 4 , wherein the transmitter IoT device is an IoT sensor whose public key is stored in the DNS.

Assignments (3)
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 9, 2026
From: VALIMAIL INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 074281/0239 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 10, 2025
From: VALIMAIL INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 073910/0374 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2023
From: GOLDSTEIN, PETER MARTIN; BLANK, SETH JOSHUA; WILSON, ASHLEY DUANE; ABBOTT, JACK WILLIAM; BARCLAY, ROBERT BENJAMIN
To: VALIMAIL INC.
Reel/Frame 063209/0308 →
Continuity (5)
Provisional Application 63120049 · Dec 1, 2020
Provisional Application 63093723 · Oct 19, 2020
Provisional Application 63057814 · Jul 28, 2020
Provisional Application 62964624 · Jan 22, 2020
Related Publication 20210226951A1 · Jul 22, 2021
Cited By (3)
US 12,238,101 US 12,407,638 US 12,609,812