IP Library Granted Patent US 11,909,880
Granted Patent B2
US 11,909,880 · App. 17/353,392 · Granted Feb 20, 2024

Centralized credential issuance and rotation

Inventors: Ashley Duane Wilson (San Francisco, CA); Peter Martin Goldstein (San Francisco, CA)
Assignee: ValiMail Inc.
H04L9/3213H04L9/0825H04L61/4511H04L67/133
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,909,880
App. No.
17/353,392
Granted
Feb 20, 2024
Kind
B2
Abstract

Embodiments relate to a system that may include a third-party server and a domain name system (DNS). The third-party server may be configured to receive a request for a credential from a named entity device for the named entity device to communicate with an application programming interface (API). The API may be associated with a domain. The third-party server may obtain the credential from the API. The third-party server may encrypt the credential with a public key corresponding to the named entity device to generate an encrypted credential. The DNS may be configured to receive the encrypted credential and publish a DNS record at a namespace of the DNS, the DNS record containing the encrypted credential for the named entity device to retrieve the credential. The named entity device may decrypt the encrypted credential by the private key stored at the device.

Claims (47)

1. A system comprising:

a third-party server comprising one or more processors and memory, the memory storing computer code comprising instructions, the instructions, when executed by the one or more processors, cause the one or more processors to at least:

receive, by the third-party server from a named entity device, a request for a credential for the named entity device to communicate with an application programming interface (API), the API associated with a domain;

obtain, by the third-party server, the credential from the API; and

encrypt, by the third-party server, the credential with a public key corresponding to the named entity device to generate an encrypted credential; and

a domain name system (DNS) associated with the domain, the DNS configured to receive the encrypted credential and publish a DNS record at a namespace of the DNS, the DNS record containing the encrypted credential for the named entity device to retrieve the credential.

2. The system of claim 1 , wherein the credential includes a session token, and wherein the instruction to obtain the credential from the API comprises instructions, when executed, cause the one or more processors to at least:

retrieve an API username and password corresponding to the named entity device, the API username and password stored at the third-party server;

transmit the API username and password to the API for the API to generate the session token; and

receive the session token.

3. The system of claim 1 , wherein the instruction to obtain the credential from the API comprises instructions, when executed, cause the one or more processors to at least:

receive the credential from the API that periodically pushes refreshed credentials to the third-party server.

4. The system of claim 1 , wherein the request from the named entity device for the credential corresponds to a query to the DNS.

5. The system of claim 1 , wherein the namespace is a delegated sub-namespace managed by the third-party server, the domain delegating the sub-namespace to the third-party server.

6. The system of claim 1 , wherein the credential is a first session token, and the instructions, when executed by the one or more processors, further cause the one or more processors to at least:

obtain, by the third-party server and responsive to the first session token being expired or close to expiration, a second session token from the API;

encrypt, by the third-party server, the second session token with the public key corresponding to the named entity device; and

publish, by the third-party server, the second session token encrypted by the public key at the namespace of the DNS for the named entity device to retrieve the second session token at the DNS.

7. The system of claim 1 , wherein the public key is obtained from a DNS record associated with the named entity device.

8. The system of claim 1 , wherein credential includes one or more of elements selected from the following: a key identifier, a secret key, a username, a password, and a session token.

9. The system of claim 1 , wherein the DNS record includes a time to live entry that corresponds to a lifetime of the credential.

10. The system of claim 1 , wherein the named entity device is an Internet-of-Thing (IoT) device that stores a private key corresponding to the public key at a hardware secure element.

11. A computer-implemented method comprising:

receiving, by a third-party server from a named entity device, a request for a credential for the named entity device to communicate with an application programming interface (API), the API associated with a domain;

obtaining, by the third-party server, the credential from the API;

encrypting, by the third-party server, the credential with a public key corresponding to the named entity device to generate an encrypted credential; and

publishing, by the third-party server, a domain name system (DNS) record at a namespace of a DNS associated with the domain, the DNS record containing the encrypted credential for the named entity device to retrieve the credential at the DNS.

12. The computer-implemented method of claim 11 , wherein the credential includes a session token, and wherein obtaining the credential from the API comprises:

retrieving an API username and password corresponding to the named entity device, the API username and password stored at the third-party server;

transmitting the API username and password to the API for the API to generate the session token; and

receiving the session token.

13. The computer-implemented method of claim 11 , wherein obtaining the credential from the API comprises:

receiving the credential from the API that periodically pushes refreshed credentials to the third-party server.

14. The computer-implemented method of claim 11 , wherein the request from the named entity device for the credential corresponds to a query to the DNS.

15. The computer-implemented method of claim 11 , wherein the namespace is a delegated sub-namespace managed by the third-party server, the domain delegating the sub-namespace to the third-party server.

16. The computer-implemented method of claim 11 , wherein the credential is a first session token, and the computer-implemented method further comprises:

obtaining, by the third-party server and responsive to the first session token being expired or close to expiration, a second session token from the API;

encrypting, by the third-party server, the second session token with the public key corresponding to the named entity device; and

publishing, by the third-party server, the second session token encrypted by the public key at the namespace of the DNS for the named entity device to retrieve the second session token at the DNS.

17. The computer-implemented method of claim 11 , wherein the public key is obtained from a DNS record associated with the named entity device.

18. The computer-implemented method of claim 11 , wherein credential includes one or more of elements selected from the following: a key identifier, a secret key, a username, a password, and a session token.

19. The computer-implemented method of claim 11 , wherein the DNS record includes a time to live entry that corresponds to a lifetime of the credential.

20. A non-transitory computer-readable medium configured to store computer code comprising instructions, the instructions, when executed by one or more processors, cause the one or more processors to at least:

receive, by a third-party server from a named entity device, a request for a credential for the named entity device to communicate with an application programming interface (API), the API associated with a domain;

obtain, by the third-party server, the credential from the API; and

encrypt, by the third-party server, the credential with a public key corresponding to the named entity device to generate an encrypted credential; and

publish a domain name system (DNS) record at a namespace of a DNS associated with the domain, the DNS record containing the encrypted credential for the named entity device to retrieve the credential.

Assignments (3)
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 9, 2026
From: VALIMAIL INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 074281/0239 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 10, 2025
From: VALIMAIL INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 073910/0374 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2021
From: WILSON, ASHLEY DUANE; GOLDSTEIN, PETER MARTIN
To: VALIMAIL INC.
Reel/Frame 056640/0107 →
Continuity (3)
Continuation 17030866 · Sep 24, 2020
Provisional Application 62906015 · Sep 25, 2019
Related Publication 20210314157A1 · Oct 7, 2021