IP Library Granted Patent US 12,034,709
Granted Patent B1
US 12,034,709 · App. 18/133,419 · Granted Jul 9, 2024

Centralized secure distribution of messages and device updates

Inventor: Ashley Duane Wilson (San Francisco, CA)
Assignee: ValiMail Inc.
H04L63/0435H04L9/0825
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,034,709
App. No.
18/133,419
Granted
Jul 9, 2024
Kind
B1
Abstract

Embodiments relate to systems for the distribution of payload in a secure manner. A server may receive a query from a device that includes a subscriber identifier. The server may determine, from confidential information stored, an association between the subscriber identifier and a public key of the device. The server may retrieve the public key of the device. The server may generate a data payload as a response to the query. The server may encrypt the data payload by a symmetric key that is generated randomly. The server may encrypt the symmetric key by the public key of the device. The server may transmit the data payload and the symmetric key that are encrypted to the device for the device to use a private key corresponding to the public key to decrypt the symmetric key and use the symmetric key to decrypt the data payload.

Claims (43)

1. A system, comprising:

at least one processor; and

memory configured to store computer code comprising instructions, the instructions, when executed by the at least one processor, cause the at least one processor to:

receive, by a server, an application programming interface (API) query from a device, the API query including a device identifier, the device having a private key that is secretly kept by the device, the private key corresponding to a public key that is included in a namespace record stored at a location of a public namespace, the location associated with the device;

generate, based on the device identifier, a query directed at the location of the public namespace to retrieve namespace record;

extract the public key of the device from the namespace record;

generate a data payload as a response to the API query;

encrypt the data payload by a symmetric key;

encrypt the symmetric key by the public key of the device that is extracted from the namespace record; and

transmit, as the response to the API query, the data payload and the symmetric key that are encrypted to the device for the device to use the private key corresponding to the public key to decrypt the symmetric key and use the symmetric key to decrypt the data payload.

2. The system of claim 1 , wherein the symmetric key is generated specific to the API query.

3. The system of claim 1 , wherein the symmetric key is a string of random bits that are generated independent of bits in the data payload.

4. The system of claim 1 , wherein the server is a third-party server that is delegated to respond to the API query on behalf of an organization, and wherein the data payload is generated based on information provided by the organization or is provided by the organization.

5. The system of claim 1 , wherein the public key is part of a public identity record of the device.

6. The system of claim 1 , wherein the location of the public namespace is a DNS address that is assigned to the device.

7. The system of claim 1 , wherein the data payload includes a message that is generated based on a policy.

8. The system of claim 1 , wherein the data payload and the symmetric key that are encrypted are transmitted with a certificate of the server for the device to authenticate the data payload.

9. The system of claim 1 , wherein the data payload and the symmetric key that are encrypted are authenticatable by the device using a DNS associated with the server.

10. The system of claim 1 , wherein the data payload is to be transmitted to multiple devices and the server is configured to generate a different symmetric key for each of the multiple devices for encrypting the data payload.

11. A computer-implemented method, comprising:

receiving, by a server, an application programming interface (API) query from a device, the API query including a device identifier, the device having a private key that is secretly kept by the device, the private key corresponding to a public key that is included in a namespace record stored at a location of a public namespace, the location associated with the device;

generating, based on the device identifier, a query directed at the location of the public namespace to retrieve namespace record;

extracting the public key of the device from the namespace record;

generating a data payload as a response to the API query;

encrypting the data payload by a symmetric key;

encrypting the symmetric key by the public key of the device that is extracted from the namespace record; and

transmitting, as the response to the API query, the data payload and the symmetric key that are encrypted to the device for the device to use the private key corresponding to the public key to decrypt the symmetric key and use the symmetric key to decrypt the data payload.

12. The computer-implemented method of claim 11 , wherein the symmetric key is generated specific to the API query.

13. The computer-implemented method of claim 11 , wherein the symmetric key is a string of random bits that are generated independent of bits in the data payload.

14. The computer-implemented method of claim 11 , wherein the server is a third-party server that is delegated to respond to the API query on behalf of an organization, and wherein the data payload is generated based on information provided by the organization or is provided by the organization.

15. The computer-implemented method of claim 11 , wherein the public key is part of a public identity record of the device.

16. The computer-implemented method of claim 11 , wherein the location of the public namespace is a DNS address that is assigned to the device.

17. The computer-implemented method of claim 11 , wherein the data payload includes a message that is generated based on a policy.

18. The computer-implemented method of claim 11 , wherein the data payload and the symmetric key that are encrypted are transmitted with a certificate of the server for the device to authenticate the data payload.

19. The computer-implemented method of claim 11 , wherein the data payload and the symmetric key that are encrypted are authenticatable by the device using a DNS associated with the server.

20. A non-transitory computer-readable medium configured to store computer code comprising instructions, the instructions, when executed by at least one processor, cause the at least one processor to:

receive, by a server, an application programming interface (API) query from a device, the API query including a device identifier, the device having a private key that is secretly kept by the device, the private key corresponding to a public key that is included in a namespace record stored at a location of a public namespace, the location associated with the device;

generate, based on the device identifier, a query directed at the location of the public namespace to retrieve namespace record;

extract the public key of the device from the namespace record;

generate a data payload as a response to the API query;

encrypt the data payload by a symmetric key;

encrypt the symmetric key by the public key of the device that is extracted from the namespace record; and

transmit, as the response to the API query, the data payload and the symmetric key that are encrypted to the device for the device to use the private key corresponding to the public key to decrypt the symmetric key and use the symmetric key to decrypt the data payload.

Assignments (4)
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 9, 2026
From: VALIMAIL INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 074281/0239 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 10, 2025
From: VALIMAIL INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 073910/0374 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2023
From: WILSON, ASHLEY DUANE
To: VALIMAIL INC.
Reel/Frame 063498/0795 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2023
From: WILSON, ASHLEY DUANE
To: BARCLAY, ROBERT B, BARC
Reel/Frame 063294/0234 →
Continuity (2)
Continuation 17087620 · Nov 3, 2020
Provisional Application 62929889 · Nov 3, 2019