IP Library Granted Patent US 12,418,396
Granted Patent B2
US 12,418,396 · App. 17/176,575 · Granted Sep 16, 2025

Hash-based digital signatures for hierarchical internet public key infrastructure

Inventor: Burton S. Kaliski, Jr. (McLean, VA)
Assignee: VeriSign, Inc.
H04L9/006H04L9/007H04L9/3239H04L9/3247H04L9/3265H04L61/4511H04L63/123G06F16/2255
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,396
App. No.
17/176,575
Granted
Sep 16, 2025
Kind
B2
Abstract

Techniques for signing internet data are disclosed. The techniques include accessing a plurality of internet data records. The techniques also include generating, using at least one electronic processor, leaf nodes from the plurality of internet data records, and constructing a recursive hash tree from the plurality of leaf nodes. The techniques also include deriving information sufficient to validate the root node, and publishing, in an internet public key infrastructure (PKI) as a synthesized public key, the information sufficient to validate the root node. The techniques also include providing, through the internet and as a signature on at least one of the plurality of internet data records, validation data including sibling path data from the recursive hash tree, such that an internet client validates the at least one of the internet data records using at least the validation data and the synthesized public key.

Claims (86)

1. A method of electronically signing at least one internet record, the method comprising:

accessing the at least one internet record;

generating a plurality of leaf nodes, wherein at least one leaf node of the plurality of leaf nodes is generated from the at least one internet record;

constructing a hash tree from the plurality of leaf nodes, wherein the hash tree comprises a first node from the plurality of leaf nodes, a second node derived from a child node, and a root node;

providing, as a public key, data derived from the root node; and

providing, with the at least one internet record, validation data derived from the hash tree,

wherein the at least one internet record is validatable by:

using the validation data to construct at least a portion of the hash tree to obtain an accumulated hash value, and

confirming that the accumulated hash value is consistent with the public key.

2. The method of claim 1 , wherein the at least one internet record comprises the at least one Domain Name System (DNS) resource record.

3. The method of claim 2 , wherein the DNS resource record comprises one of an A resource record, an AAAA resource record, or a Delegation Signer (DS) resource record.

4. The method of claim 1 , further comprising publishing the public key with a Domain Name System Security Extensions (DNSSEC) key record.

5. The method of claim 4 , wherein the publishing comprises publishing the public key as a Zone Signing Key (ZSK).

6. The method of claim 1 , wherein the validation data comprises a signature, and wherein providing the validation data comprises providing the signature with the at least one internet record.

7. The method of claim 6 , further comprising publishing the signature with a Domain Name System Security Extensions (DNSSEC) signature record.

8. The method of claim 1 , further comprising obtaining a hash-based signature on the public key using a second hash tree.

9. The method of claim 8 , further comprising publishing the hash-based signature in a Domain Name System Security Extensions (DNSSEC) signature record.

10. The method of claim 8 , further comprising publishing data derived from a root node of the second hash tree as a Key Signing Key (KSK) in a Domain Name System Security Extensions (DNSSEC) key record.

11. The method of claim 1 , wherein the data derived from the root node comprises the root node.

12. The method of claim 1 , wherein the first node comprises a first subset of nodes of a plurality of nodes, wherein the second node comprises a second subset of nodes from the plurality of nodes, wherein the child node comprises at least one child node from the plurality of nodes.

13. The method of claim 1 , wherein the public key is a public key of an internet Public Key Infrastructure (PKI).

14. The method of claim 1 , wherein constructing at least the portion of the hash tree using the validation data to confirm consistency with the public key comprises:

constructing at least the portion of the hash tree using the validation to obtain an accumulated value; and

confirming the accumulated value is consistent with the public key.

15. The method of claim 1 , further comprising obtaining a non-hash-based signature on the public key using a non-hash-based signature scheme involving a non-hash-based public key.

16. The method of claim 15 , further comprising publishing the non-hash-based signature in a Domain Name System Security Extensions (DNSSEC) signature record.

17. The method of claim 15 , further comprising publishing data derived from the public key of the non-hash-based signature scheme as a Key Signing Key (KSK) in a Domain Name System Security Extensions (DNSSEC) key record.

18. The method of claim 15 , wherein the non-hash-based signature scheme is a post-quantum signature scheme.

19. The method of claim 15 , wherein the non-hash-based signature scheme is a conventional signature scheme.

20. The method of claim 1 , wherein the public key is a public key of an internet Public Key Infrastructure (PKI),

wherein the providing, as a public key, data derived from the root node is performed by a certification authority,

wherein the providing, with the at least one internet record, validation data derived from the hash tree is performed by the certification authority,

wherein the at least one internet record comprises the at least one digital certificate content,

wherein the plurality of leaf nodes comprises cryptographic hashes of the at least one digital certificate content,

wherein the public key is published as an intermediate-level certification authority public key, and

further comprising publishing a second public key for validating a signature of the public key, wherein the second public key is published as a higher-level certification authority public key.

21. The method of claim 20 , further comprising:

accessing a plurality of electronically stored Online Certificate Status Protocol (OCSP) certificate status data records;

generating a second plurality of leaf nodes from the plurality of OCSP certificate status data records;

constructing a second hash tree, wherein the second hash tree comprises the second plurality of leaf nodes, a second root node, and at least one node comprising a hash of data comprising child nodes;

deriving information sufficient to validate the second root node;

publishing, in the internet PKI and as the at least one synthesized OCSP responder public key, the information sufficient to validate the second root node; and

providing, as a signature on at least one OCSP certificate status data record of the plurality of OCSP certificate status data records, second validation data comprising sibling path data from the second hash tree, wherein the second validation data is validatable by using at least the second validation data and the synthesized OCSP responder public key,

wherein the at least one internet data record comprises the synthesized OCSP responder public key.

22. The method of claim 1 , wherein the public key is a public key of an internet Public Key Infrastructure (PKI),

wherein the providing, as a public key, data derived from the root node is performed by an Online Certificate Status Protocol (OCSP) responder,

wherein the providing, with the at least one internet record, validation data derived from the hash tree is performed by the Online Certificate Status Protocol (OCSP) responder,

wherein the at least one internet record comprises the at least one OCSP certificate status data record,

wherein the plurality of leaf nodes comprises cryptographic hashes of the at least one OCSP certificate status data record,

wherein the public key is published as an OCSP responder public key, and

further comprising publishing a second public key for validating a signature of the public key, wherein the second public key is published as a certification authority public key.

23. The method of claim 22 , wherein the at least one OCSP certificate status data record comprises at least one multiple inconsistent status indicator.

24. The method of claim 1 , wherein the public key is a public key of an internet Public Key Infrastructure (PKI),

wherein the providing, as a public key, data derived from the root node is performed by an identity provider,

wherein the providing, with the at least one internet record, validation data derived from the hash tree is performed by the identity provider,

wherein the at least one internet record comprises the at least one authentication assertion content,

wherein the plurality of leaf nodes comprises cryptographic hashes of the at least one authentication assertion content,

wherein the public key is published as an identity provider public key, and

further comprising publishing a second public key for validating a signature of the public key, wherein the second public key is published as an identity provider key validating key.

25. The method of claim 1 , wherein the public key is a public key of an internet Public Key Infrastructure (PKI),

wherein the providing, as a public key, data derived from the root node is performed by a code signer,

wherein the providing, with the at least one internet record, validation data derived from the hash tree is performed by the code signer,

wherein the at least one internet record comprises the at least one software image,

wherein the plurality of leaf nodes comprises cryptographic hashes of the at least one software image,

wherein the public key is published as a code signing public key, and

further comprising publishing a second public key for validating a signature of the public key, wherein the second public key is published as a code signing key validating key.

26. The method of claim 1 , wherein the public key is a public key of an internet Public Key Infrastructure (PKI),

wherein the providing, as a public key, data derived from the root node is performed by a payment authority,

wherein the providing, with the at least one internet record, validation data derived from the hash tree is performed by the payment authority,

wherein the at least one internet record comprises the at least one payment transaction data,

wherein the plurality of leaf nodes comprises cryptographic hashes of the at least one payment transaction data,

wherein the public key is published as a payment authority public key, and

further comprising publishing a second public key for validating a signature of the public key, wherein the second public key is published as a payment authority key validating key.

27. The method of claim 1 , wherein the at least one internet record comprises at least one computer-interpretable object.

28. The method of claim 27 , wherein the at least one computer-interpretable object comprises at least one of: at least one digital certificate content, at least one synthesized Online Certificate Status Protocol (OCSP) responder public key, at least one OCSP certificate status data record, at least one authentication assertion content, at least one software image, at least one payment transaction data, and/or at least one Domain Name System (DNS) resource record.

29. The method of claim 28 , wherein the at least one software image comprises software code or a hash of software code.

30. A system for electronically signing at least one internet record, the system comprising:

at least one electronic processor programmed to perform:

accessing the at least one internet record;

generating a plurality of leaf nodes, wherein at least one leaf node of the plurality of leaf nodes is generated from the at least one internet record;

constructing a hash tree from the plurality of leaf nodes, wherein the hash tree comprises a first node from the plurality of leaf nodes, a second node derived from a child node, and a root node;

providing, as a public key, data derived from the root node; and

providing, with the at least one internet record, validation data derived from the hash tree,

wherein the at least one internet record is validatable by:

using the validation data to construct at least a portion of the hash tree to obtain an accumulated hash value, and

confirming that the accumulated hash value is consistent with the public key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2021
From: KALISKI, BURTON S., JR.
To: VERISIGN, INC.
Reel/Frame 055272/0862 →
Continuity (3)
Continuation 15612561 · Jun 2, 2017
Continuation In Part 14959281 · Dec 4, 2015
Related Publication 20210273779A1 · Sep 2, 2021
References Cited (53)
US 5016274A · Micali et al. · 1991 [cited by applicant]
US 6085320A · Kaliski, Jr. · 2000 [cited by examiner]
US 6097811A · Micali · 2000 [cited by applicant]
US 6301659B1 · Micali · 2001 [cited by applicant]
US 6411966B1 · Kwan · 2002 [cited by examiner]
US 10153905B2 · Kaliski, Jr. · 2018 [cited by applicant]
US 20020194209A1 · Bolosky · 2002 [cited by examiner]
US 20050114666A1 · Sudia · 2005 [cited by examiner]
US 20050289060A1 · Abumehdi · 2005 [cited by examiner]
US 20070033419A1 · Kocher · 2007 [cited by examiner]
US 20080137859A1 · Jagadeesan · 2008 [cited by examiner]
US 20080260160A1 · Moreau · 2008 [cited by applicant]
US 20100042842A1 · Huang · 2010 [cited by examiner]
US 20100251351A1 · Teranishi · 2010 [cited by examiner]
US 20120117621A1 · Kondamuru · 2012 [cited by examiner]
US 20120278626A1 · Smith · 2012 [cited by examiner]
US 20120284505A1 · Smith et al. · 2012 [cited by applicant]
US 20120290870A1 · Shah · 2012 [cited by examiner]
US 20130083926A1 · Hughes · 2013 [cited by examiner]
US 20140149740A1 · Sato · 2014 [cited by examiner]
US 20140244998A1 · Amenedo · 2014 [cited by examiner]
US 20140282887A1 · Kaminsky et al. · 2014 [cited by applicant]
US 20140344925A1 · Muthiah · 2014 [cited by examiner]
US 20160197898A1 · Hozza · 2016 [cited by examiner]
US 20160226664A1 · Tang · 2016 [cited by examiner]
US 20170163425A1 · Kaliski, Jr. · 2017 [cited by applicant]
US 20170272250A1 · Kaliski, Jr. · 2017 [cited by applicant]
Bernstein et al., “SPHINCS: practical stateless hash-based signatures,” In Annual International Conference on the Theory and Applications of Cryptographic Techniques. Springer, 2015, 33 pages. [cited by applicant]
Bindel et al., “Transitioning to a Quantum-Resistant Public Key Infrastructure,” May 24, 2017. http://eprint.iacr.org/2017/460, pp. 1-27. [cited by applicant]
Buchmann et al., “XMSS—A Practical Forward Secure Signature Scheme based on Minimal Security Assumptions,” In International Workshop on Post-Quantum Cryptography. Springer, 2011, pp. 1-26. [cited by applicant]
Cooper et al., “Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile,” May 2008, pp. 1-151. [cited by applicant]
Ducas et al., “Lattice Signatures and Bimodal Gaussians,” In Advances in Cryptology: CRYPTO 2013, ResearchGate, pp. 40-56, Springer, 2013. [cited by applicant]
Laurie et al., “IETF RFC 6962: Certificate Transparency,” Jun. 2013, 27 pages. [cited by applicant]
McGrew et al., “Hash-Based Signatures, Internet-Draft draft-mcgrew-hash-sigs-06,” Mar. 5, 2017, pp. 1-44. [cited by applicant]
Merkle, “Secrecy, Authentication and Public Key Systems,” Standford University Technical Report No. 1979-1, Jun. 1979, pp. 1-182. [cited by applicant]
Nakamoto, “Bitcoin: A Peer-to-Peer Electronic Cash System,” 2008, pp. 1-9. [cited by applicant]
Oasis, Security Assertion Markup Language (SAML) 2.0, Mar. 15, 2005, 66 pages. [cited by applicant]
Pavlovski et al., “Efficient Batch Signature Generation Using Tree Structures,” International Workshop on Cryptographic Techniques and E-Commerce, CrypTEC. vol. 99. 1999, 8 pages. [cited by applicant]
Santesson et al., “IETF RFC 6960: X.509 Internet Public Key Infrastructure Online Certificate Status Protocol—OCSP Abstract,” Jun. 2013, pp. 1-41. [cited by applicant]
Even et al., “On-line/off-line digital signatures.” In Advances in Cryptology: Crypto' 89, pp. 263-277. Springer, 1990. [cited by applicant]
Kocher, “On certificate revocation and validation.” In Financial Cryptography. Springer, 1998. [cited by applicant]
Extended European Search Report dated Apr. 18, 2017, European Application No. 16202042.4, pp. 1-7. [cited by applicant]
Burton S. Kaliski, Jr., “Rethinking Adoption of Hash Signatures”, ETSI 2nd Quantum-Safe Cryptography Workshop, Oct. 6, 2014, pp. 1-18. [cited by applicant]
R. Arends et al., “Resource Records for the DNS Security Extensions”, Network Working Group RFC 1717, Internet Society, 2005, pp. 1-29. [cited by applicant]
Michael Szydlo, “Recent Improvements in the Efficient Use of Merkle Trees: Additional Options for the Long Term”, RSA Laboratories, Mar. 10, 2004, Retrieved from the Internet: http://www.emc.com/emc-plus/rsa-labs/histor… [cited by applicant]
Non-Final Office Action issued in corresponding U.S. Appl. No. 14/959,281 on Sep. 13, 2017, (13 pages). [cited by applicant]
Final Office Action issued in corresponding U.S. Appl. No. 14/959,281 on Mar. 30, 2018, (16 pages). [cited by applicant]
Notice of Allowance issued in corresponding U.S. Appl. No. 14/959,281 on Aug. 24, 2018, (14 pages). [cited by applicant]
Non-Final Office Action issued in corresponding U.S. Appl. No. 15/612,561 on Nov. 26, 2018, (25 pages). [cited by applicant]
Final Office Action issued in corresponding U.S. Appl. No. 15/612,561 on May 28, 2019, (26 pages). [cited by applicant]
Non-Final Office Action issued in corresponding U.S. Appl. No. 15/612,561 on Nov. 15, 2019, (24 pages). [cited by applicant]
Final Office Action issued in corresponding U.S. Appl. No. 15/612,561 on Apr. 17, 2020, (26 pages). [cited by applicant]
Notice of Allowance issued in corresponding U.S. Appl. No. 15/612,561 on Nov. 4, 2020, (24 pages). [cited by applicant]