IP Library Granted Patent US 12,267,437
Granted Patent B2
US 12,267,437 · App. 17/669,302 · Granted Apr 1, 2025

Enabling internal and external verification of hash-based signature computations by signing server

Inventors: Panagiotis Theodorou Kampanakis (Apex, NC); Dimitrios Sikeridis (San Diego, CA)
Assignee: Cisco Technology, Inc.
H04L9/3247H04L9/3239
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,437
App. No.
17/669,302
Granted
Apr 1, 2025
Kind
B2
Abstract

Methods and systems enable internal and external verification of computations performed by a code signing server according to hash-based signature techniques using unique state, and further for a code signing server to expose parts of a hash-based signature log without negating the security of the one-time signature key pairs generated by the code signing server. A signing module of a code signing server receives a signing request from a client computing system. The signing module configures the code signing server to generate a one-time signature key pair based on a Merkle tree state. The signing module configures the code signing server to issue a hash-based signature to the client computing system. The code signing server is configured to record the Merkle tree state and the issued HBS in an immutably ordered log at a logging server.

Claims (8)

1. A computing system comprising:

one or more processing units; and one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processing units, cause the one or more processing units to:

record a Merkle tree state used to generate a one-time signature (“OTS”) key pair and record an issued hash-based signature (“HBS”) in an immutably ordered log; and

autonomously report non-reuse or reuse of a Merkle tree state recorded in the immutably ordered log, such that the reporting verifies that a Merkle tree had a particular state when used to generate an OTS key pair of a particular issued OTS, or verifies that a current Merkle tree state was not previously used to generate any OTS key pair before a signing module generates an OTS key pair in response to a signing request.

2. The computing system of claim 1 , wherein the instructions further cause the one or more processing units to receive an internal state query including an internally queried Merkle state.

3. The computing system of claim 2 , wherein the instructions further cause the one or more processing units to look up the internally queried state in the immutably ordered log, returning if either no HBS or only one HBS is associated with the internally queried state.

4. The computing system of claim 3 , wherein the instructions further cause the one or more processing units to compare the internally queried HBS with the returned HBS.

5. The computing system of claim 1 , wherein the recorded Merkle tree state is a state of a Merkle tree used to generate an OTS key pair of the HBS, and the Merkle tree state and the HBS are recorded separately in association in an entry of the log.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2022
From: KAMPANAKIS, PANAGIOTIS THEODOROU; SIKERIDIS, DIMITRIOS
To: CISCO TECHNOLOGY, INC.
Reel/Frame 059007/0159 →
Continuity (1)
Related Publication 20230254154A1 · Aug 10, 2023
References Cited (20)
US 11159326B1 · Nelson · 2021 [cited by examiner]
US 20160085955A1 · Lerner · 2016 [cited by examiner]
US 20170272250A1 · Kaliski, Jr. · 2017 [cited by examiner]
US 20170364700A1 · Goldfarb · 2017 [cited by examiner]
US 20180183602A1 · Campagna · 2018 [cited by examiner]
US 20180183771A1 · Campagna · 2018 [cited by examiner]
US 20180183774A1 · Campagna · 2018 [cited by examiner]
US 20190364042A1 · Liu · 2019 [cited by examiner]
US 20200052886A1 · Buldas · 2020 [cited by examiner]
US 20200090188A1 · Wince · 2020 [cited by examiner]
US 20200193025A1 · Jacquin et al. · 2020 [cited by applicant]
US 20200259663A1 · Firsov · 2020 [cited by examiner]
US 20200302065A1 · Lawson · 2020 [cited by examiner]
US 20200351074A1 · Wood · 2020 [cited by examiner]
US 20200382301A1 · Saket · 2020 [cited by examiner]
US 20200389521A1 · Brock · 2020 [cited by examiner]
US 20210192346A1 · Taylor · 2021 [cited by examiner]
US 20210326442A1 · Campagna · 2021 [cited by examiner]
US 20220368533A1 · Irazábal · 2022 [cited by examiner]
Hülsing et al., “Hash-Based Signatures: An Outline for a New Standard,” https://csrc.nist.gov/csrc/media/events/workshop-on-cybersecurity-in-a-post-quantum-world/documents/papers/session5-hulsing-paper.pdf. [cited by applicant]
Cited By (2)
US 12,572,630 US 12,603,784