IP Library Granted Patent US 11,743,057
Granted Patent B2
US 11,743,057 · App. 17/896,992 · Granted Aug 29, 2023

Using PKI for security and authentication of control devices and their data

Inventors: David William Kravitz (San Jose, CA); Donald Houston Graham, III (Pasadena, CA); Josselyn Lee Boudett (Clearwater, FL); Russell S. Dietz (San Jose, CA); James Jones (Tempe, AZ); Jamie Lynn Juarez (Glendora, CA)
Assignee: T-CENTRAL, INC.
H04L9/3268H04L9/0819H04L9/3255H04L63/0823H04L63/0876H04L63/10H04W12/06H04W12/08H04L2209/84H04W12/71H04W12/76
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,743,057
App. No.
17/896,992
Granted
Aug 29, 2023
Kind
B2
Abstract

Method for authenticating a first and a second electronic devices associated through a communication line includes: creating a unique ID, by a third electronic device; transmitting the unique ID to the first electronic device; signing the transmitted unique ID by the first electronic device; transmitting the signed unique ID to the second electronic device, by the first electronic device; signing the transmitted signed unique ID by the second electronic device; transmitting the unique ID signed by the first and second electronic devices to the third electronic device; verifying and accepting the unique ID signed by the first device and the second device, by the third device; issuing a certificate for a secure communication line between the first electronic device and the second electronic device; and transmitting the certificate to the first electronic device and the second electronic device.

Claims (40)

1. A method for establishing secure communication between a plurality of devices coupled to a communication network, each device including a hardware processor, associated memory, a unique identification and a cryptographic key, the method comprising:

transmitting, over the communication network, an invitation by a first device of the plurality of devices to a second device of the plurality of devices wherein the invitation comprises an invitation to securely communicate with the first device;

receiving by the first device a digital identity token associated with the second device;

authenticating a communication line between the first device and the second device, wherein the authenticating comprises one or more signed nonces;

issuing a communication line certificate to establish a secure communication line between the first device and the second device.

2. The method of claim 1 , further comprising at least one of:

preventing a third device for which a secure communication line between the first device and the third device has not been established from communicating with the first device such that the first device accepts the communication; and

preventing the third device for which a secure communication line between the second device and the third device has not been established from communicating with the second device such that the second device accepts the communication.

3. A method for utilizing a communication line certificate corresponding to a first device and a second device for a communication line, each of the first and second devices including a hardware processor and associated memory, the method comprising:

generating a digitally signed request by the first device, wherein the digitally signed request comprises a first proof of an association of the first device to the communication line;

transmitting the digitally signed request to the second device;

verifying the first proof by the second device to produce a first verification of the association of the first device to the communication line;

generating a digitally signed acceptance by the second device, wherein the digitally signed acceptance comprises a second proof of an association of the second device to the communication line; and

verifying the second proof by the first device to produce a second verification of the association of the second device to the communication line.

4. The method of claim 3 , wherein the first proof is generated using, at least in part, a first private key corresponding to a first public key that is contained within or referenced by the communication line certificate, wherein

the second proof is generated using, at least in part, a second private key corresponding to a second public key that is contained within or referenced by the communication line certificate, and wherein

the first verification uses the first public key, and the second verification uses the second public key.

5. The method of claim 3 , wherein the first verification comprises a precondition of use by the second device of a first public key that is contained within or referenced by the communication line certificate in establishment of a session key, and wherein the second verification comprises a precondition of use by the first device of a second public key that is contained within or referenced by the communication line certificate in establishment of the session key.

6. The method of claim 3 wherein a record layer of a standard communication protocol is executed using a session key that is established using at least one of: a first public key that is contained within or referenced by the communication line certificate, and a second public key that is contained within or referenced by the communication line certificate.

7. The method of claim 3 , wherein the first device's association to the communication line comprises a precondition of the first device receiving a batch of one or more one-time-use key agreement certificates owned by the second device.

8. The method of claim 3 , wherein a transaction generated by the first device comprises: a first one-time-use key agreement certificate included within a batch of one or more one-time-use key agreement certificates owned by the second device; and a one-time-use signature certificate owned by the first device.

9. The method of claim 8 , wherein one or more attributes of the first device as associated with the one-time-use signature certificate are accessed via the transaction by the second device using its knowledge of a private key corresponding to a public key contained within or referenced by the first one-time-use key agreement certificate, and wherein at least one of the one or more of the attributes is used as proof-of-fitness of the first device to participate in a task.

10. The method of claim 8 , wherein a public key contained within or referenced by the one-time-use signature certificate owned by the first device is used to authenticate entering into a communication protocol session with a third device that may be the same as or different than the second device, wherein the communication protocol session comprises at least one element of fulfilling a task.

11. A system for establishing secure communication between a plurality of devices coupled to a communication network, each device including a hardware processor and associated memory comprising:

a first device for inviting, via an invitation transmitted over the communication network, a second device to securely communicate with the first device;

a second device for receiving the invitation via the communication network, and transmitting a digital identity token over the communication network, wherein the first device receives the digital identity token via the communication network;

a third-party device for authenticating a communication line between the first device and the second device and issuing a communication line certificate to establish a secure communication line between the first device and the second device, wherein the authenticating comprises one or more signed nonces.

12. The system of claim 11 , wherein the third-party device prevents a new device for which a secure communication line between the first device and the new device has not been established from communicating with the first device such that the first device accepts the communication; and prevents the new device for which a secure communication line between the second device and the new device has not been established from communicating with the second device such that the second device accepts the communication.

13. A system for utilizing a communication line certificate over a computer network comprising:

a first device for generating a digitally signed request and transmitting the digitally signed request over the computer network, wherein the digitally signed request comprises a first proof of an association of the first device to the communication line; and

a second device for receiving the digitally signed request from the first device and verifying the first proof to produce a first verification of the association of the first device to the communication line, and for generating a digitally signed acceptance comprising a second proof of an association of the second device to the communication line, wherein the first device verifies the second proof to produce a second verification of the association of the second device to the communication line.

14. The system of claim 13 , wherein the first proof is generated using, at least in part, a first private key corresponding to a first public key that is contained within or referenced by the communication line certificate, wherein

the second proof is generated using, at least in part, a second private key corresponding to a second public key that is contained within or referenced by the communication line certificate, and wherein

the first verification uses the first public key, and the second verification uses the second public key.

15. The system of claim 13 , wherein the first verification comprises a precondition of use by the second device of a first public key that is contained within or referenced by the communication line certificate in establishment of a session key, and wherein the second verification comprises a precondition of use by the first device of a second public key that is contained within or referenced by the communication line certificate in establishment of the session key.

16. The system of claim 13 , wherein a record layer of a standard communication protocol is executed using a session key that is established using at least one of: a first public key that is contained within or referenced by the communication line certificate, and a second public key that is contained within or referenced by the communication line certificate.

17. The system of claim 13 , wherein the first device's association to the communication line comprises a precondition of the first device receiving a batch of one or more one-time-use key agreement certificates owned by the second device.

18. The system of claim 13 , wherein a transaction generated by the first device comprises: a first one-time-use key agreement certificate included within a batch of one or more one-time-use key agreement certificates owned by the second device; and a one-time-use signature certificate owned by the first device.

19. The system of claim 18 , wherein one or more attributes of the first device as associated with the one-time-use signature certificate are accessed via the transaction by the second device using its knowledge of a private key corresponding to a public key contained within or referenced by the first one-time-use key agreement certificate, and wherein at least one of the one or more of the attributes is used as proof-of-fitness of the first device to participate in a task.

20. The system of claim 18 , wherein a public key contained within or referenced by the one-time-use signature certificate owned by the first device is used to authenticate entering into a communication protocol session with a third device that may be the same as or different than the second device, wherein the communication protocol session comprises at least one element of fulfilling a task.

Continuity (51)
Continuation 16872112 · May 11, 2020
Continuation In Part 16236124 · Dec 28, 2018
Continuation In Part 15890140 · Feb 6, 2018
Division 15686076 · Aug 24, 2017
Continuation In Part 15621982 · Jun 13, 2017
Continuation 15469244 · Mar 24, 2017
Continuation In Part 15269832 · Sep 19, 2016
Continuation 15002225 · Jan 20, 2016
Continuation 14218897 · Mar 18, 2014
Continuation In Part 13481553 · May 25, 2012
Continuation In Part 13096764 · Apr 28, 2011
Continuation In Part 15409427 · Jan 18, 2017
Continuation 15154861 · May 13, 2016
Continuation 14715588 · May 18, 2015
Continuation In Part 14218897 · Mar 18, 2014
Continuation In Part 13481553 · May 25, 2012
Continuation In Part 13096764 · Apr 28, 2011
Provisional Application 62846737 · May 12, 2019
Provisional Application 62956456 · Jan 2, 2020
Provisional Application 62994801 · Mar 25, 2020
Provisional Application 63010547 · Apr 15, 2020
Provisional Application 62611527 · Dec 28, 2017
Provisional Application 62644470 · Mar 17, 2018
Provisional Application 62648945 · Mar 28, 2018
Provisional Application 62718724 · Aug 14, 2018
Provisional Application 62741409 · Oct 4, 2018
Provisional Application 62777104 · Dec 8, 2018
Provisional Application 62536884 · Jul 25, 2017
Provisional Application 62313124 · Mar 25, 2016
Provisional Application 62326812 · Apr 24, 2016
Provisional Application 62330839 · May 2, 2016
Provisional Application 62347822 · Jun 9, 2016
Provisional Application 62373769 · Aug 11, 2016
Provisional Application 62401150 · Sep 28, 2016
Provisional Application 61792927 · Mar 15, 2013
Provisional Application 61650866 · May 23, 2012
Provisional Application 61490952 · May 27, 2011
Provisional Application 61416629 · Nov 23, 2010
Provisional Application 61367576 · Jul 26, 2010
Provisional Application 61367574 · Jul 26, 2010
Provisional Application 61330226 · Apr 30, 2010
Provisional Application 62133371 · Mar 15, 2015
Provisional Application 61994885 · May 17, 2014
Provisional Application 61367576 · Jul 26, 2010
Provisional Application 61792927 · Mar 15, 2013
Provisional Application 61650866 · May 23, 2012
Provisional Application 61490952 · May 27, 2011
Provisional Application 61416629 · Nov 23, 2010
Provisional Application 61367574 · Jul 26, 2010
Provisional Application 61330226 · Apr 30, 2010
Related Publication 20220417038A1 · Dec 29, 2022