IP Library Granted Patent US 12,219,060
Granted Patent B2
US 12,219,060 · App. 17/730,817 · Granted Feb 4, 2025

Access policy token

Inventor: Anthony K. Dyer (Royston, GB)
Assignee: Ivanti, Inc.
H04L9/3213H04L9/0894H04L63/045H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,219,060
App. No.
17/730,817
Granted
Feb 4, 2025
Kind
B2
Abstract

A method may include accessing a key from a secure storage. A payload may be encrypted using the key. A policy token may be generated. The policy token may include a publicly-readable header including a header identifier of the key and the payload encrypted using the key. The policy token may be sent. The policy token may be received. The publicly-readable header may be read. The key may be identified using the header identifier of the key from the publicly-readable header. The key may be accessed from the secure storage. The payload may be decrypted using the key.

Claims (70)

1. A method of secured resource access using an encrypted token, the method comprising:

receiving a first access token configured to permit access to a resource on a storage server, the first access token including a first access token signature and a first host name for the storage server;

symmetrically encrypting a payload using an encryption key and an initialization vector, the encryption key being stored in a secure key storage of a host system that is associated with a user device, wherein the payload includes information used to reconstruct the first access token signature;

generating a policy token URI that includes:

a storage resource URI that identifies the host system instead of the first host name for the storage server;

a policy token that includes the encrypted payload and a publicly readable header, wherein the publicly readable header includes a key identifier of the encryption key; and the initialization vector;

replacing the first access token signature of the first access token with the policy token;

sending the policy token URI to a user device such that following receipt of the policy token URI, the host system accesses the encryption key at the secure key storage using the publicly readable header identifier and decrypts the payload using the encryption key and the initialization vector; and

based on the encrypted payload, providing the resource associated with the decrypted payload from the storage server to the user device.

2. The method of claim 1 , further comprising modifying the initialization vector prior to the symmetric encryption of the payload.

3. The method of claim 2 , wherein:

a user identifier is used to modify the initialization vector; and

the user identifier is unique to the user device or a user associated with the user device.

4. The method of claim 1 , wherein:

the publicly readable header further includes a fingerprint value;

the fingerprint value is configured to allow verification of the user device for which the policy token URI is intended to be used;

the fingerprint value is generated based on a user identifier; and

the user identifier is unique to the user device or a user associated with the user device.

5. The method of claim 1 , further comprising:

generating the fingerprint value using a one-way function;

receiving an indication of an attempt to access the policy token URI by a second user device;

responsive to the indication, comparing the first fingerprint value with a second fingerprint value that corresponds to the second user device; and

responsive to a determination that the fingerprint value and the second fingerprint value are not the same, verifying that the attempt to access the policy token by the second user device is an unauthorized access attempt.

6. The method of claim 1 , wherein:

the encrypted payload further includes a security access policy for the user device or the user; and

access to the encrypted payload is based on satisfaction of the security access policy.

7. The method of claim 6 , wherein the security access policy relates to one or more or a combination of: an internet protocol address of the user device, a geographic location of the user device, a type of the user device, and a time of access by the user device.

8. One or more non-transitory computer-readable storage media configured to store instructions that, in response to being executed, cause a system to perform operations, the operations comprising:

receiving a first access token configured to permit access to a resource on a storage server, the first access token including a first access token signature and a first host name for the storage server;

symmetrically encrypting a payload using an encryption key and an initialization vector, the encryption key being stored in a secure key storage of a host system that is associated with a user device, wherein the payload includes information used to reconstruct the first access token signature;

generating a policy token URI that includes:

a storage resource URI that identifies the host system instead of the first host name for the storage server;

a policy token that includes the encrypted payload and a publicly readable header, wherein the publicly readable header includes a key identifier of the encryption key; and the initialization vector;

replacing the first access token signature of the first access token with the policy token;

sending the policy token URI to a user device such that following receipt of the policy token URI, the host system accesses the encryption key at the secure key storage using the publicly readable header identifier and decrypts the payload using the encryption key and the initialization vector; and

based on the encrypted payload, providing the resource associated with the decrypted payload from the storage server to the user device.

9. The one or more non-transitory computer-readable storage media of claim 8 , wherein the operations further comprise modifying the initialization vector prior to the symmetric encryption of the payload.

10. The one or more non-transitory computer-readable storage media of claim 9 , wherein:

a user identifier is used to modify the initialization vector; and

the user identifier is unique to the user device or a user associated with the user device.

11. The one or more non-transitory computer-readable storage media of claim 9 , wherein:

the publicly readable header further includes a fingerprint value;

the fingerprint value is configured to allow verification of the user device for which the policy token URI is intended to be used;

the fingerprint value is generated based on a user identifier; and

the user identifier is unique to the user device or a user associated with the user device.

12. The one or more non-transitory computer-readable storage media of claim 11 , further comprising:

generating the fingerprint value using a one-way function;

receiving an indication of an attempt to access the policy token URI by a second user device;

responsive to the indication, comparing the first fingerprint value with a second fingerprint value that corresponds to the second user device; and

responsive to a determination that the fingerprint value and the second fingerprint value are not the same, verifying that the attempt to access the policy token URI by the second user device is an unauthorized access attempt.

13. The one or more non-transitory computer-readable storage media of claim 9 , wherein:

the encrypted payload further includes a security access policy for the user device or a user associated with the user device; and

access to the encrypted payload is based on satisfaction of the security access policy.

14. The one or more non-transitory computer-readable storage media of claim 13 , wherein the security access policy relates to one or more or a combination of: an internet protocol address of the user device, a geographic location of the user device, a type of the user device, and a time of access by the user device.

15. A system, comprising:

one or more processors; and

one or more non-transitory computer-readable storage media configured to store instructions that, in response to being executed, cause the system to perform operations, the operations comprising:

receiving a first access token configured to permit access to a resource on a storage server, the first access token including a first access token signature and a first host name for the storage server;

symmetrically encrypting a payload using an encryption key and an initialization vector, the encryption key being stored in a secure key storage of a host system that is associated with a user device, wherein the payload includes information used to reconstruct the first access token signature;

generating a policy token URI that includes:

a storage resource URI that identifies the host system instead of the first host name for the storage server;

a policy token that includes the encrypted payload and a publicly readable header, wherein the publicly readable header includes a key identifier of the encryption key; and the initialization vector;

replacing the first access token signature of the first access token with the policy token;

sending the policy token URI to a user device such that following receipt of the policy token URI, the host system accesses the encryption key at the secure key storage using the publicly readable header and decrypts the payload using the encryption key and the initialization vector; and

based on the encrypted payload, providing the resource associated with the decrypted payload from the storage server to the user device.

16. The system of claim 15 , further comprising:

generating a first fingerprint value using a one-way function, wherein the first fingerprint value corresponds to an identity of the user device for which the payload of is intended to be used, wherein the first fingerprint value is included in the publicly readable header;

receiving an indication of an attempt to access the policy token by a second user device;

responsive to the indication, comparing the first fingerprint value with a second fingerprint value that corresponds to the second user device; and

responsive to a determination that the first fingerprint value and the second fingerprint value are not the same, verifying that the attempt to access the policy token by the second user device is an unauthorized access attempt.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 064932/0425 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071124/0228 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2022
From: DYER, ANTHONY K.
To: IVANTI, INC.
Reel/Frame 059743/0178 →
Continuity (1)
Related Publication 20230353362A1 · Nov 2, 2023
References Cited (17)
US 7797751B1 · Hughes · 2010 [cited by examiner]
US 8621592B2 · Benaloh · 2013 [cited by examiner]
US 9002386B2 · Ngo · 2015 [cited by examiner]
US 9820078B2 · Ngo · 2017 [cited by examiner]
US 10659467B1 · Verma · 2020 [cited by examiner]
US 10944561B1 · Cahill · 2021 [cited by examiner]
US 11682072B2 · Kim · 2023 [cited by examiner]
US 11743048B2 · Haque · 2023 [cited by examiner]
US 20150350186A1 · Chan · 2015 [cited by examiner]
US 20160226840A1 · Buccella · 2016 [cited by examiner]
US 20160344635A1 · Lee · 2016 [cited by examiner]
US 20180300471A1 · Jain · 2018 [cited by examiner]
US 20210067341A1 · Haque · 2021 [cited by examiner]
US 20210273805A1 · Jain et al. · 2021 [cited by applicant]
US 20230224314A1 · Kolluru · 2023 [cited by examiner]
International Preliminary Report on Patentability and Written Opinion for Application No. PCT/US2023/066327, dated Jul. 7, 2023, 9 pages. [cited by applicant]
International Preliminary Report on Patentability and Written Opinion for Application No. PCT/US2023/066327, dated Oct. 29, 2024, 5 pages. [cited by applicant]