IP Library Granted Patent US 12,028,466
Granted Patent B2
US 12,028,466 · App. 18/224,022 · Granted Jul 2, 2024

Using PKI for security and authentication of control devices and their data

Inventors: David William Kravitz (San Jose, CA); Donald Houston Graham, III (Pasadena, CA); Josselyn Lee Boudett (Clearwater, FL); Russell S. Dietz (San Jose, CA); James Jones (Tempe, AZ); Jamie Lynn Juarez (Glendora, CA)
Assignee: T-CENTRAL, INC.
H04L9/3268H04L9/0819H04L9/3255H04L63/0823H04L63/0876H04L63/10H04W12/06H04W12/08H04L2209/84H04W12/71H04W12/76
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,028,466
App. No.
18/224,022
Granted
Jul 2, 2024
Kind
B2
Abstract

Method for utilizing a communication line certificate corresponding to a first device and a second device for a communication line, each of the first and second devices including a hardware processor and associated memory includes: creating a unique ID, by a third electronic device; transmitting the unique ID to the first generating a digitally signed request by the first device, wherein the digitally signed request comprises a first proof of an association of the first device to the communication line; transmitting the digitally signed request to the second device; verifying the first proof by the second device to produce a first verification of the association of the first device to the communication line; and generating a digitally signed acceptance by the second device, wherein the digitally signed acceptance comprises a second proof of an association of the second device to the communication line.

Claims (26)

1. A method for utilizing a communication line certificate corresponding to a first device and a second device for a communication line, each of the first and second devices including a hardware processor and associated memory, the method comprising:

generating a digitally signed request by the first device, wherein the digitally signed request comprises a first proof of an association of the first device to the communication line;

transmitting the digitally signed request to the second device;

verifying the first proof by the second device to produce a first verification of the association of the first device to the communication line; and

generating a digitally signed acceptance by the second device, wherein the digitally signed acceptance comprises a second proof of an association of the second device to the communication line.

2. The method of claim 1 , further comprising verifying the second proof by the first device to produce a second verification of the association of the second device to the communication line, wherein the first proof is generated using, at least in part, a first private key corresponding to a first public key that is contained within or referenced by the communication line certificate, wherein

the second proof is generated using, at least in part, a second private key corresponding to a second public key that is contained within or referenced by the communication line certificate, and wherein

the first verification uses the first public key, and the second verification uses the second public key.

3. The method of claim 1 , wherein the first verification comprises a precondition of use by the second device of a first public key that is contained within or referenced by the communication line certificate in establishment of a session key, and wherein the second verification comprises a precondition of use by the first device of a second public key that is contained within or referenced by the communication line certificate in establishment of the session key.

4. The method of claim 1 , wherein a record layer of a standard communication protocol is executed using a session key that is established using at least one of: a first public key that is contained within or referenced by the communication line certificate, and a second public key that is contained within or referenced by the communication line certificate.

5. The method of claim 1 , wherein the first device's association to the communication line comprises a precondition of the first device receiving a batch of one or more one-time-use key agreement certificates owned by the second device.

6. The method of claim 1 , wherein a transaction generated by the first device comprises: a first one-time-use key agreement certificate included within a batch of one or more one-time-use key agreement certificates owned by the second device; and a one-time-use signature certificate owned by the first device.

7. The method of claim 6 , wherein one or more attributes of the first device as associated with the one-time-use signature certificate are accessed via the transaction by the second device using its knowledge of a private key corresponding to a public key contained within or referenced by the first one-time-use key agreement certificate, and wherein at least one of the one or more of the attributes is used as proof-of-fitness of the first device to participate in a task.

8. The method of claim 6 , wherein a public key contained within or referenced by the one-time-use signature certificate owned by the first device is used to authenticate entering into a communication protocol session with a third device that may be the same as or different than the second device, wherein the communication protocol session comprises at least one element of fulfilling a task.

9. A system for establishing secure communication between a plurality of devices coupled to a communication network, each device including a hardware processor and associated memory comprising:

a first device for inviting, via an invitation transmitted over the communication network, a second device to securely communicate with the first device;

a second device for receiving the invitation via the communication network, and transmitting a digital identity token over the communication network, wherein the first device receives the digital identity token via the communication network;

a third-party device for authenticating a communication line between the first device and the second device and issuing a communication line certificate to establish a secure communication line between the first device and the second device.

10. The system of claim 9 , wherein the third-party device prevents a new device for which a secure communication line between the first device and the new device has not been established from communicating with the first device such that the first device accepts the communication; and prevents the new device for which a secure communication line between the second device and the new device has not been established from communicating with the second device such that the second device accepts the communication.

11. A system for utilizing a communication line certificate over a computer network comprising:

a first device for generating a digitally signed request and transmitting the digitally signed request over the computer network, wherein the digitally signed request comprises a first proof of an association of the first device to the communication line; and

a second device for receiving the digitally signed request from the first device and verifying the first proof to produce a first verification of the association of the first device to the communication line, and for generating a digitally signed acceptance comprising a second proof of an association of the second device to the communication line.

12. The system of claim 11 , wherein the first device verifies the second proof to produce a second verification of the association of the second device to the communication line, wherein the first proof is generated using, at least in part, a first private key corresponding to a first public key that is contained within or referenced by the communication line certificate, wherein

the second proof is generated using, at least in part, a second private key corresponding to a second public key that is contained within or referenced by the communication line certificate, and wherein

the first verification uses the first public key, and the second verification uses the second public key.

13. The system of claim 11 , wherein the first verification comprises a precondition of use by the second device of a first public key that is contained within or referenced by the communication line certificate in establishment of a session key, and wherein the second verification comprises a precondition of use by the first device of a second public key that is contained within or referenced by the communication line certificate in establishment of the session key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2023
From: KRAVITZ, DAVID WILLIAM; GRAHAM III, DONALD HOUSTON; BOUDETT, JOSSELYN LEE; DIETZ, RUSSELL S.; JONES, JAMES; JUAREZ, JAMIE LYNN
To: T-CENTRAL, INC.
Reel/Frame 064345/0166 →
Continuity (45)
Continuation 17896992 · Aug 26, 2022
Continuation 16872112 · May 11, 2020
Continuation In Part 16236124 · Dec 28, 2018
Continuation In Part 15890140 · Feb 6, 2018
Division 15686076 · Aug 24, 2017
Continuation In Part 15621982 · Jun 13, 2017
Continuation 15469244 · Mar 24, 2017
Continuation In Part 15409427 · Jan 18, 2017
Continuation In Part 15269832 · Sep 19, 2016
Continuation 15154861 · May 13, 2016
Continuation 15002225 · Jan 20, 2016
Continuation 14715588 · May 18, 2015
Continuation In Part 14218897 · Mar 18, 2014
Continuation In Part 13481553 · May 25, 2012
Continuation In Part 13481553 · May 25, 2012
Continuation In Part 13096764 · Apr 28, 2011
Continuation In Part 13096764 · Apr 28, 2011
Provisional Application 63010547 · Apr 15, 2020
Provisional Application 62994801 · Mar 25, 2020
Provisional Application 62956456 · Jan 2, 2020
Provisional Application 62846737 · May 12, 2019
Provisional Application 62777104 · Dec 8, 2018
Provisional Application 62741409 · Oct 4, 2018
Provisional Application 62718724 · Aug 14, 2018
Provisional Application 62648945 · Mar 28, 2018
Provisional Application 62644470 · Mar 17, 2018
Provisional Application 62611527 · Dec 28, 2017
Provisional Application 62536884 · Jul 25, 2017
Provisional Application 62401150 · Sep 28, 2016
Provisional Application 62373769 · Aug 11, 2016
Provisional Application 62369722 · Aug 1, 2016
Provisional Application 62347822 · Jun 9, 2016
Provisional Application 62330839 · May 2, 2016
Provisional Application 62326812 · Apr 24, 2016
Provisional Application 62313124 · Mar 25, 2016
Provisional Application 62133371 · Mar 15, 2015
Provisional Application 61994885 · May 17, 2014
Provisional Application 61792927 · Mar 15, 2013
Provisional Application 61650866 · May 23, 2012
Provisional Application 61490952 · May 27, 2011
Provisional Application 61416629 · Nov 23, 2010
Provisional Application 61367576 · Jul 26, 2010
Provisional Application 61367574 · Jul 26, 2010
Provisional Application 61330226 · Apr 30, 2010
Related Publication 20230421393A1 · Dec 28, 2023