IP Library › Granted Patent US 12,236,002
Granted Patent B2
US 12,236,002 · App. 17/454,565 · Granted Feb 25, 2025

System for secure multi-protocol processing of cryptographic data

Inventor: Karl J. Kreder, III (Austin, TX)
Assignee: GRIDPLUS, INC.
G06F21/79G06F21/602G06F21/72G06F21/83
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,236,002
App. No.
17/454,565
Granted
Feb 25, 2025
Kind
B2
Abstract

A general computing environment (GCE) determines request data comprising payload data and instruction data to use cryptographic functions in a secure computing environment (SCE). The SCE provides secure input and output devices, allowing secure presentation to a user and acquisition of user input. The SCE receives the request data and processes the payload data using the instructions in the instruction data to produce cryptographic output data. The request data may be determined using schemas that specify the formatting, grammar, and other attributes of data associated with a transaction that utilizes cryptographic functions. By using schemas and the request data, the SCE may support any protocol that uses the cryptographic functions supported by that SCE to compose cryptographic output. To enhance user comprehensibility and security, the SCE may securely replace some data with human readable text or images and present this as abstracted request data.

Claims (119)

1. A system comprising:

a first device comprising:

a first general computing environment (GCE) comprising:

a first network interface;

a first memory storing first computer-executable instructions; and

a first processor in communication with the first network interface and the first memory, the first processor executing the first computer-executable instructions to:

determine transaction input data indicative of a transaction using one or more cryptographic functions;

determine schema data associated with the transaction input data;

determine, based on the transaction input data and the schema data, request data comprising payload data and instruction data;

send the request data to a first secure computing environment (SCE);

receive, from the first SCE, cryptographic output data;

determine, based on the schema data and the cryptographic output data, formatted output data; and

send, using the first network interface, the formatted output data; and

the first SCE comprising:

a first secure output device;

a first secure input device;

a first secure encrypted memory;

a first cryptoprocessor; and

a second processor in communication with: the first processor, the first secure output device, the first secure input device, the first secure encrypted memory, and the first cryptoprocessor, and the second processor executing second computer-executable instructions to:

receive the request data;

process the payload data, according to the instruction data, using the first cryptoprocessor to determine cryptographic output data; and

send the cryptographic output data to the first GCE.

2. The system of claim 1 , wherein the first SCE utilizes one or more static buffers to process the request data.

3. The system of claim 1 , the second processor further executing the second computer-executable instructions to:

determine abstraction data associated with the request data;

determine, based on the abstraction data and the request data, abstracted request data;

present, using the first secure output device, at least a portion of the abstracted request data;

determine, using the first secure input device, first secure user input;

determine the first secure user input is valid input; and

wherein the instructions to process the payload data using the first cryptoprocessor are responsive to the valid input.

4. The system of claim 1 , wherein the schema data is indicative of one or more of:

grammar associated with a transaction using a first blockchain,

syntax associated with the transaction using the first blockchain,

number base and precision associated with one or more values of the transaction using the first blockchain, or

a message format.

5. The system of claim 1 , wherein the request data is formatted as a concise binary object representation (CBOR).

6. The system of claim 1 , the second processor further executing the second computer-executable instructions to:

receive signed abstraction data comprising abstraction data, wherein the abstraction data specifies a relationship between first data in the request data and second data;

determine, using the first cryptoprocessor, that the signed abstraction data is validly signed; and

store the abstraction data in the first secure encrypted memory.

7. The system of claim 1 , the second processor further executing the second computer-executable instructions to:

determine, using the first secure input device, first secure user input;

determine the first secure user input is valid input;

determine, based at least in part on the valid input, abstraction data, wherein the abstraction data specifies a relationship between first data in the request data and second data; and

store the abstraction data in the first secure encrypted memory.

8. The system of claim 1 , the first processor further executing the first computer-executable instructions to:

receive, using the first network interface, the transaction input data from a second device; and

the second processor further executing the second computer-executable instructions to:

determine, using the first secure input device, first secure user input; and

determine, based on the first secure user input, one or more values of the request data.

9. A computer-implemented method comprising:

determining transaction input data, wherein the transaction input data is indicative of a transaction using one or more cryptographic functions;

determining schema data associated with the transaction input data;

determining, based on the transaction input data and the schema data, request data comprising payload data and instruction data;

sending the request data to a secure computing environment (SCE);

receiving, from the SCE, cryptographic output data;

determining, based on the schema data and the cryptographic output data, formatted output data; and

sending the formatted output data.

10. The computer-implemented method of claim 9 , further comprising:

processing the request data within the SCE to determine the cryptographic output data, the processing comprising:

determining, based on the payload data, a first input;

accessing secret data stored in secure encrypted memory of the SCE; and

operating at least one processor within the SCE based on an instruction of the instruction data, wherein the instruction is indicative of a cryptographic function, the first input, and the secret data.

11. The computer-implemented method of claim 9 , further comprising:

storing abstraction data within the SCE;

determining at least a portion of the abstraction data is associated with the request data;

determining within the SCE, based on the abstraction data and the request data, abstracted request data;

presenting, using a secure output device associated with the SCE, at least a portion of the abstracted request data;

determining, using a secure input device associated with the SCE, secure user input;

determining the secure user input is valid input; and

processing the request data, using the SCE, responsive to the valid input.

12. The computer-implemented method of claim 9 , wherein the schema data is indicative of one or more:

grammar associated with a transaction,

syntax associated with the transaction,

number base and precision associated with one or more values of the transaction, or

a message format.

13. The computer-implemented method of claim 9 , wherein at least a portion of the request data is formatted as a concise binary object representation (CBOR).

14. The computer-implemented method of claim 9 , further comprising:

receiving signed abstraction data comprising abstraction data;

determining, using the SCE, that the signed abstraction data is validly signed; and

storing the abstraction data within the SCE.

15. The computer-implemented method of claim 9 , further comprising:

determining, using a secure input device associated with the SCE, secure user input;

determining the secure user input is valid input;

determining, based at least in part on the valid input, abstraction data, wherein the abstraction data specifies a relationship between first data in the request data and second data; and

storing the abstraction data in the SCE.

16. A system comprising:

a first secure computing environment (SCE) comprising:

a communication interface;

a secure output device;

a secure input device;

a secure encrypted memory; and

one or more processors in communication with: the communication interface, the secure output device, the secure input device, and the secure encrypted memory, and the one or more processors executing first computer-executable instructions to:

receive request data comprising payload data and instruction data, wherein the instruction data comprises one or more instructions;

receive, using the communication interface, signed abstraction data;

determine that the signed abstraction data is validly signed;

store at least a portion of the signed abstraction data in the secure encrypted memory;

determine the at least a portion of the signed abstraction data is associated with the request data;

determine, based on the at least a portion of the signed abstraction data and the request data, abstracted request data;

present, using the secure output device, data that is based at least in part on the request data, wherein the abstracted request data is the data that is based at least in part on the request data;

determine, using the secure input device, first secure user input;

based at least in part on the first secure user input, execute the one or more instructions of the instruction data to process the payload data and determine cryptographic output data; and

send, using the communication interface, the cryptographic output data.

17. The system of claim 16 , further comprising:

a general computing environment (GCE) comprising:

a second communication interface;

a second memory storing second computer-executable instructions; and

a second processor in communication with the second communication interface and the second memory, the second processor executing the second computer-executable instructions to:

determine transaction input data indicative of a transaction using one or more cryptographic functions;

determine schema data associated with the transaction input data, wherein the schema data is indicative of one or more:

grammar associated with a transaction,

syntax associated with the transaction,

number base and precision associated with one or more values of the transaction, or

a message format;

determine, based on the transaction input data and the schema data, the request data;

send the request data to the SCE;

receive, from the SCE, the cryptographic output data;

determine, based on the schema data and the cryptographic output data, formatted output data; and

send, using the second communication interface, the formatted output data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2021
From: KREDER, KARL J., III
To: GRIDPLUS, INC.
Reel/Frame 058090/0905 →
Continuity (1)
Related Publication 20230144774A1 · May 11, 2023
References Cited (58)
US 7051212B2 · Ginter et al. · 2006 [cited by applicant]
US 9785926B2 · Sanford et al. · 2017 [cited by applicant]
US 10733176B2 · Cochrane et al. · 2020 [cited by applicant]
US 20110307703A1 · Ogg et al. · 2011 [cited by applicant]
US 20140196107A1 · Lindberg et al. · 2014 [cited by applicant]
US 20140258736A1 · Merchan et al. · 2014 [cited by applicant]
US 20160149710A1 · Huxham · 2016 [cited by examiner]
US 20160275461A1 · Sprague et al. · 2016 [cited by applicant]
US 20160294564A1 · Mock · 2016 [cited by applicant]
US 20160306953A1 · Cambou · 2016 [cited by applicant]
US 20170221288A1 · Johnson et al. · 2017 [cited by applicant]
US 20180041345A1 · Maim · 2018 [cited by applicant]
US 20180183802A1 · Choyi · 2018 [cited by examiner]
US 20180254898A1 · Sprague · 2018 [cited by examiner]
US 20190013943A1 · Maim · 2019 [cited by applicant]
US 20190180273A1 · Cummings et al. · 2019 [cited by applicant]
US 20190268332A1 · Wang · 2019 [cited by applicant]
US 20190280864A1 · Cheng et al. · 2019 [cited by applicant]
US 20190325408A1 · Goroff · 2019 [cited by examiner]
US 20190378119A1 · Hyuga et al. · 2019 [cited by applicant]
US 20190394025A1 · Maim · 2019 [cited by applicant]
US 20200021446A1 · Roennow et al. · 2020 [cited by applicant]
US 20200036519A1 · Bitauld et al. · 2020 [cited by applicant]
US 20200099518A1 · Jacobs et al. · 2020 [cited by applicant]
US 20200143466A1 · Wu et al. · 2020 [cited by applicant]
US 20200280855A1 · Avetisov et al. · 2020 [cited by applicant]
US 20200349546A1 · Bedier · 2020 [cited by examiner]
US 20200387893A1 · Maim · 2020 [cited by applicant]
US 20210097528A1 · Wang · 2021 [cited by applicant]
US 20220051240A1 · Shamai · 2022 [cited by examiner]
AU 2009239396A1 · 2009 [cited by applicant]
CA 2850250C · 2020 [cited by applicant]
WO 2016120826A2 · 2016 [cited by applicant]
WO 2017122187A2 · 2017 [cited by applicant]
WO 2018211382A1 · 2018 [cited by applicant]
WO 2020234824A1 · 2020 [cited by applicant]
Erdene-Ochir, O., “Patent Cooperation Treaty International Search Report and Written Opinion dated Mar. 14, 2023”, Patent Cooperation Treaty Application Number PCT/US22/79645, Patent Cooperation Treaty, Mar. 14, 2023. [cited by applicant]
“A First Look at the Grid+Lattice1 Hardware Wallet 11”, 1 page, Oct. 18, 2018. Retrieved from the Internet: URL: https://www.youtube.com/watch?v=aypJYpWmxuk. [cited by applicant]
“DevCon4 Lattice Demo”, 1 page, Nov. 28, 2018. Retrieved from the Internet: URL: https://www.youtube.com/watch?v=YkJpQ19hYYU. [cited by applicant]
“Filament Security Overview Networking Devices at the Edge of Risk”, Apr. 1, 2017, 12 pages. Retrieved from the Internet: URL:https://filamet.com/assets/downloads/Filament%20Security.pdf. [cited by applicant]
“Gemalto and Ledger Join Forces to Provide Security Infrastructure for Cryptocurrency Based Activities”, Oct. 14, 2017, 3 pages, Thales Group 2021. Retrieved from the Internet: URL: https://www.thalesgroup.com/en/market… [cited by applicant]
“How to DeFi on Polkadot Series”, 23 pages, Polkaswap Community Collective, Medium.com. Retrieved from the Internet: URL: https://medium.com/@polkaswapcommunitycollective/how-to-defi-on-polkadot-series-b7c34733d5f5. [cited by applicant]
“Lattice1 Safe Cards”, 1 page, Oct. 29, 2018. Retrieved from the Internet: URL: https://www.youtube.com/watch?v=ZIKOhYWIGyE. [cited by applicant]
“Ledger”, Ledger SAS, 13 pages. Retrieved from the Internet: URL: https://www.ledger.com/. [cited by applicant]
“OpenPGP card”, Wikipedia, 3 pages. Retrieved from the Internet on Sep. 29, 2021. URL: https://en.wikipedia.org/wiki/OpenPGP_card. [cited by applicant]
“PKCS #11 Cryptographic Token Interface Base Specification Version 2.40”, OASIS, OASIS Standard, Apr. 14, 2015, pp. 1-149. Retrieved from the Internet: URL: http://docs.oasis-open.org/pkcs11/pkcs11-base/v2.40/os/pkcs11-… [cited by applicant]
“SafePal Crypto Hardware Wallet (Official)”, SafePal, 4 pages. Retrieved from the Internet: URL: https://www.safepal.io/. [cited by applicant]
“Specifys That Certs Must Be Checked to Receive Payment” Jun. 12, 2019. Retrieved from the Internet: URL: https://github.com/GridPlus/phonon-network/commit/77fe11a7d398268ad061029465a63bf66e653147. [cited by applicant]
“Supported Cryptocurrencies”, SafePal, 2 pages. Retrieved from the Internet: URL: https://safepalsupport.zendesk.com/hc/en-us/articles/360057304752-Supported-Cryptocurrencies. [cited by applicant]
“Thales Luna HSMs”, Thales 2021, 2 pages. Retrieved from the Internet: URL: https://cpl.thalesgroup.com/encryption/hardware-security-modules/network-hsms. [cited by applicant]
“Trezor Hardware Wallet (Official)”, 50 pages. SatoshiLabs s.r.o 2012-2021. Retrieved from the Internet: URL: https://trezor.io/coins/. [cited by applicant]
“YubiKey”, Wikipedia, 3 pages. Retrieved from the Internet on Sep. 29, 2021. URL: https://en.wikipedia.org/wiki/YubiKey. [cited by applicant]
Karst, et al., “Connecting Multiple Devices with Blockchain in the Internet of Things”, Jan. 5, 2017, 23 pages. Retrieved from the internet: URL:https://courses.cs.ut.ee/MTAT.03.323/2016_fall/uploads/Main/002.pdf. [cited by applicant]
Lind, et al., “Teechan: Payment Channels Using Trusted Execution Environments”, ARXIV.org, Cornell University Library, Ithaca, NY, Dec. 22, 2016, 15 pages. [cited by applicant]
Miller, et al., “Phonon Network Specification”, GitHub, 10 pages. Retrieved from the Internet on Jun. 10, 2019: URL: https://github.com/GridPlus/phonon-network. [cited by applicant]
Poon, et al., “The Bitcoin Lightning Network: Scalable Off-Chain Instant Payments”, Jan. 14, 2016. Retrieved from the Internet: URL: https://lightning.network/lightning-network-paper.pdf. [cited by applicant]
Veenstra, et al., “Phonon Network Specification”, GitHub, 8 pages. Retrieved from the Internet on Sep. 16, 2020: URL: https://github.com/GridPlus/phonon-network. [cited by applicant]
Erdene-Ochir, O., “Patent Cooperation Treaty International Preliminary Report on Patentability dated May 23, 2024”, Patent Cooperation Treaty Application No. PCT/US22/79645, Patent Cooperation Treaty, May 23, 2024. [cited by applicant]