IP Library Granted Patent US 12,603,789
Granted Patent B2
US 12,603,789 · App. 18/367,885 · Granted Apr 14, 2026

Systems and methods for securing interconnecting directories

Inventors: Boy-Anthony Kühne (London, GB); Christopher Paul Kendall (Leighton Buzzard, GB); David Andrew Bray (Richmansworth, GB)
Assignee: VOCALINK INTERNATIONAL LIMITED
H04L9/3268H04L9/0825H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,603,789
App. No.
18/367,885
Granted
Apr 14, 2026
Kind
B2
Abstract

Systems and methods are provided for deploying keys in connection with proxy resolution. One example computer-implemented method includes distributing, by a service core computing device, a root certificate signed by a certificate authority and an intermediate certificate, which is signed by a root private key associated with the root certificate, and receiving, from a participant, a signing request for a participant certificate including a participant public key. The method also includes assessing, by the service core computing device, the signing request for the participant certificate and signing, by the service core computing device, the participant certificate with an intermediate public key included in the intermediate certificate. The method then includes disseminating the signed participant certificate to the participant and another participant, whereby the participants on the participant certificate based on the participant certificate being signed by the intermediate public key.

Claims (46)

1 . A computer-implemented method comprising:

distributing, by a service core computing device, a root certificate signed by a certificate authority and an intermediate certificate, which is signed by a root private key associated with the root certificate, the root certificate having a longer life to expiration than the intermediate certificate;

receiving, from a participant, a signing request for a participant certificate, the participant certificate including a participant public key, the participant certificate having a shorter life to expiration than the intermediate certificate;

assessing, by the service core computing device, the signing request for the participant certificate, based on ordering of content in the signing request;

signing, by the service core computing device, the participant certificate with an intermediate public key included in the intermediate certificate;

disseminating the signed participant certificate to the participant and at least one other participant, whereby the at least one other participant trusts a request from the participant, which is signed by a private key of the participant, based on the participant certificate including the public key validating the signed request and the participant certificate being signed by the intermediate public key, which is dependent on the root certificate;

receiving, by the service core computing device, a message from the participant; and

encrypting data, by the service core computing device, based on the participant certificate of the participant, prior to providing the encrypted data to the participant in response to the message.

2 . The computer-implemented method of claim 1 , wherein the certificate authority is a third party relative to the service core and the participant; and

wherein the root certificate includes an indication of the certificate authority.

3 . The computer-implemented method of claim 1 , wherein assessing the signing request is further based on a channel through which the signing request is received.

4 . The computer-implemented method of claim 1 , wherein assessing the signing request includes assessing a life to expiration of the participant certificate.

5 . The computer-implemented method of claim 1 , wherein the service core computing device includes an authentication service and a core vault;

wherein receiving the signing request includes receiving, by the authentication service, the signing request; and

wherein assessing the signing request and signing the participant certificate includes assessing, by the core vault, the signing request and signing, by the core vault, the participant certificate.

6 . The computer-implemented method of claim 1 , further comprising signing the intermediate certificate with the root private key, which forms a key pair with a root public key.

7 . The computer-implemented method of claim 1 , further comprising authenticating a message sender of the message based on the disseminated participant certificate prior to providing the encrypted data to the participant in response to the message.

8 . The computer-implemented method of claim 1 , further comprising distributing, by the service core computing device, a central certificate signed by an intermediate private key associated with the root certificate.

9 . A non-transitory computer-readable storage medium comprising executable instructions, which when executed by at least one processor in deploying keys in connection with proxy resolution, cause the at least one processor to:

distribute a root certificate signed by a certificate authority and an intermediate certificate, which is signed by a root private key associated with the root certificate, the root certificate having a longer life to expiration than the intermediate certificate;

receive, from a participant, a signing request for a participant certificate, the participant certificate including a participant public key, the participant certificate having a shorter life to expiration than the intermediate certificate;

assess the signing request for the participant certificate, based on ordering of content in the signing request;

sign the participant certificate with an intermediate public key included in the intermediate certificate; and

disseminate the signed participant certificate to the participant and at least one other participant, whereby the at least one other participant trusts a request from the participant, which is signed by a private key of the participant, based on the participant certificate including the public key validating the signed request and the participant certificate being signed by the intermediate public key, which is dependent on the root certificate;

receive a message from the participant; and

encrypt data, based on the participant certificate of the participant, prior to providing the encrypted data to the participant in response to the message.

10 . The non-transitory computer-readable storage medium of claim 9 , wherein the executable instructions, when executed by the at least one processor to assess the signing request, further cause the at least one processor to:

assess a channel through which the signing request is received; and

assess a life to expiration of the participant certificate.

11 . The non-transitory computer-readable storage medium of claim 9 , wherein the executable instructions, when executed by the at least one processor, further cause the at least one processor to sign the intermediate certificate with the root private key, which forms a key pair with a root public key.

12 . The non-transitory computer-readable storage medium of claim 9 , wherein the executable instructions, when executed by the at least one processor, further cause the at least one processor to authenticate a message sender of the message based on the disseminated participant certificate prior to providing the encrypted data in response to the message.

13 . The non-transitory computer-readable storage medium of claim 9 , wherein the executable instructions, when executed by the at least one processor, further cause the at least one processor to distribute a central certificate signed by an intermediate private key associated with the root certificate.

14 . A computer-implemented method comprising:

distributing, by a service core computing device, a root certificate signed by a certificate authority and an intermediate certificate, which is signed by a root private key associated with the root certificate, the root certificate having a longer life to expiration than the intermediate certificate;

receiving, from a participant, a signing request for a participant certificate, the participant certificate including a participant public key, the participant certificate having a shorter life to expiration than the intermediate certificate;

assessing, by the service core computing device, the signing request for the participant certificate, based on ordering of content in the signing request;

signing, by the service core computing device, the participant certificate with an intermediate public key included in the intermediate certificate;

disseminating the signed participant certificate to the participant and at least one other participant, whereby the at least one other participant trusts a request from the participant, which is signed by a private key of the participant, based on the participant certificate including the public key validating the signed request and the participant certificate being signed by the intermediate public key, which is dependent on the root certificate;

receiving, by a computing device of a second participant, a message from the participant; and

encrypting data, by the computing device of the second participant, based on the participant certificate of the participant, prior to providing the encrypted data to the participant in response to the message.

15 . The computer-implemented method of claim 14 , wherein the certificate authority is a third party relative to the service core and the participant; and

wherein the root certificate includes an indication of the certificate authority.

16 . The computer-implemented method of claim 14 , wherein assessing the signing request is further based on a channel through which the signing request is received.

17 . The computer-implemented method of claim 14 , wherein assessing the signing request includes assessing a life to expiration of the participant certificate.

18 . The computer-implemented method of claim 14 , further comprising authenticating a message sender of the message based on the disseminated participant certificate prior to providing the encrypted data in response to the message.

19 . The computer-implemented method of claim 14 , wherein the participant and the second participant are included in different geographic regions.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2023
From: KUHNE, BOY ANTHONY; KENDALL, CHRISTOPHER PAUL; BRAY, DAVID ANDREW
To: VOCALINK INTERNATIONAL LIMITED
Reel/Frame 065185/0202 →
Continuity (4)
Continuation In Part 18243535 · Sep 7, 2023
Provisional Application 63456778 · Apr 3, 2023
Provisional Application 63406542 · Sep 14, 2022
Related Publication 20240089122A1 · Mar 14, 2024
References Cited (29)
US 10454690B1 · Popoveniuc · 2019 [cited by examiner]
US 10728044B1 · Melo · 2020 [cited by examiner]
US 12224991B1 · Joglekar · 2025 [cited by examiner]
US 20030070070A1 · Yeager · 2003 [cited by examiner]
US 20070073621A1 · Dulin · 2007 [cited by examiner]
US 20090193443A1 · Lakshmanan et al. · 2009 [cited by applicant]
US 20110289508A1 · Fell et al. · 2011 [cited by applicant]
US 20120216035A1 · Leggette · 2012 [cited by examiner]
US 20130117560A1 · Resch · 2013 [cited by examiner]
US 20140040415A1 · Mathew et al. · 2014 [cited by applicant]
US 20150262160A1 · Hursta · 2015 [cited by applicant]
US 20150278808A1 · Dulin · 2015 [cited by examiner]
US 20160125370A1 · Grassadonia et al. · 2016 [cited by applicant]
US 20160180299A1 · Sandraz · 2016 [cited by applicant]
US 20170093587A1 · Glisson · 2017 [cited by examiner]
US 20170302755A1 · Mathew et al. · 2017 [cited by applicant]
US 20190036711A1 · Qiu · 2019 [cited by examiner]
US 20190363896A1 · Finlow-Bates · 2019 [cited by examiner]
US 20200028842A1 · Leiserson · 2020 [cited by examiner]
US 20200076807A1 · Driever · 2020 [cited by examiner]
US 20200275272A1 · Montemurro · 2020 [cited by examiner]
US 20200311722A1 · Ginger et al. · 2020 [cited by applicant]
US 20200322332A1 · Haque · 2020 [cited by examiner]
US 20210083882A1 · Venable, Sr. · 2021 [cited by examiner]
US 20210135884A1 · Theodorou · 2021 [cited by examiner]
US 20210247731A1 · Poluri · 2021 [cited by examiner]
US 20210288822A1 · Sorensen · 2021 [cited by examiner]
US 20220393884A1 · Panchamia · 2022 [cited by examiner]
U.S. Appl. No. 18/243,535, filed Sep. 7, 2023, Welsford, et al. [cited by applicant]