IP Library › Granted Patent US 12,587,388
Granted Patent B2
US 12,587,388 · App. 18/483,317 · Granted Mar 24, 2026

Systems and methods for trusted path secure communication

Inventor: Glenn S. Benson (Newton, MA)
H04L9/3247G06F21/53G06F21/564G06F21/57G06F21/606G06F21/64G06Q20/382H04L63/0272H04L63/123H04W12/03H04W12/10H04W12/12H04W12/128G06F2221/034G06F2221/2111H04L63/145H04W12/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,587,388
App. No.
18/483,317
Granted
Mar 24, 2026
Kind
B2
Abstract

A system for establishing a trusted path for secure communication between client devices and server devices, such as between an account holder and a financial institution, can provide the core security attributes of confidentiality (of the parties), integrity (of the information), anti-replay (protection against replay fraud) and/or anti-tampering (protection against unauthorized changes to information being exchanged and/or modules that generate and communicate such information). A messaging layer implementation in favor of a transport layer implementation can provide a trusted path. This infrastructure features secure cryptographic key storage, and implementation of a trusted path built using the cryptographic infrastructure. The trusted path protects against unauthorized information disclosure, modification, or replays. These services can effectively protect against Man-in-the-Middle, Man-in-the-Application, and other attacks.

Claims (71)

1 . A method for secure exchange of information on a network between a client device and a server on a network, the method comprising:

encrypting, by a data-collection application or a security application associated with the data-collection application on the client device, a data element using a server public key to generate on the client device a secured object,

receiving, by the server, the secured object, wherein the secured object comprises an encrypted message used by the server to authenticate the client device, wherein the encrypted message comprises within the encrypted information at least a timestamp of the time the secured object was composed, a message identifier, a digital signature of the secured object signed by a private key on the client device, and a message digest comprising at least one or more of an anti-replay header and an anti-tamper header;

decrypting, by the server, the encrypted message;

validating, by the server, the digital signature of the decrypted message using a public key associated with the client device;

determining, by the server and the timestamp of the secured object, that the secured object was previously received more than a set threshold period of time before the time of receipt, or when an identifier cache at the server already contains the identifier or contents of the anti-replay header of that secured object;

determining, by the server, that one or more applications on the client device were altered when a message digest at the server does not match the message digest of the secured object as is expected to be produced by untampered versions of those applications on the client device;

discarding the secured object when the digital signature of the secured object cannot be verified, or when the secured object is determined to have been received prior to the set threshold period, or when the message is determined to have been replayed, or when the one or more applications on the client device were determined to be altered, and if the object is not discarded, then,

preparing, by the server, a download in reply to a validated secured object from the client device;

digitally signing, by the server's private key, the download to the client device;

encrypting the download, by the server, using the public key associated with the client device; and

receiving, by the client device, the signed and encrypted download.

2 . The method of claim 1 , further comprising: determining that the timestamp of the secured object corresponds to a time that is later than the current time.

3 . The method of claim 1 , further comprising: clearing, by the server, the identifier cache after a specified time period has passed.

4 . The method of claim 1 wherein the encrypted message further comprises an encrypted message history, the message history comprising a list of previously sent message identifiers and timestamps, wherein each timestamp corresponds to each of the previously sent message identifiers.

5 . The method of claim 4 , wherein determining that the secured object was previously received further comprises: comparing, by the server, the message history of the encrypted message to an expected message history at the server or client device based upon previously received messages;

determining, by the server, that the secured object was previously received when the expected message history does not match the message history of the encrypted message.

6 . The method of claim 5 , further comprising:

removing, by the server, a previously received message identifier and a corresponding timestamp from the expected message history when a difference between the corresponding timestamp and the current time exceeds a specified removal threshold.

7 . The method of claim 1 , further comprising:

sending, when the secured object was determined to be previously received or when the one or more applications on the client device were determined to be altered, a message to the client device that the secured object was discarded.

8 . A system, comprising:

a memory; and

at least one processor coupled to the memory and configured to:

encrypt, by a data-collection application or a security application associated with the data-collection application on the client device, a data element using a first level storage key to generate a secured object, wherein the first level storage key comprises at least one of:

(i) a public key of the server, the public key for encrypting information to be received by the data-collection application in a transmission from the server;

(ii) a private key of the data-collection application, the private key of the data-collection application for generating a signature for the information to be transmitted to the server from the client device;

(iii) a public key of the data-collection application, the public key of the data-collection application for encrypting information to be transmitted from the client device to the server; and

(iv) a private key of the server, the private key of the server generating a signature for information to be transmitted to the client device from the server;

receive on the server the secured object, wherein the secured object comprises an encrypted message used by the server to authenticate the client device, wherein the encrypted message comprises within the encrypted information at least a timestamp of the time the secured object was composed, a message identifier, a digital signature of the secured object signed by a private key of the client device, and a message digest comprising at least one or more of an anti-replay header and an anti-tamper header;

decrypt, by the server, the encrypted message;

validate the digital signature of the decrypted message using a public key associated with the client device;

determine, by the server and the timestamp of the secured object, that the secured object was previously received more than a set threshold period of time before the time of receipt or when an identifier cache at the server already contains the identifier or contents of the anti-replay header of the secured object; determine, by the server, that one or more applications on the client device were altered when a message digest at the server does not match the message digest of the secured object as is expected to be produced by untampered versions of those applications on the client device; and

discard the secured object when the digital signature of the secured object cannot be verified or when the secured object is determined to have been received prior to the set threshold period, or when the message is determined to have been replayed or when the one or more applications on the client device were determined to be altered and if the object is not discarded, then

preparing by the server, a download in reply to a validated secured object from the client device;

digitally signing, by the server private key, the download to the client device;

encrypting the download, by the server, using the public key associated with the client device; and

receiving, by the client device, the signed and encrypted download.

9 . The system of claim 8 , wherein the at least one process is further configured to: determine that the timestamp of the secured object corresponds to a time that is later than the current time.

10 . The system of claim 8 , wherein the at least one process is further configured to: clear the identifier cache after a specified time period has passed.

11 . The system of claim 8 , wherein the encrypted message further comprises an encrypted message history, the message history comprising a list of previously sent message identifiers and timestamps, wherein each timestamp corresponds to each of the previously sent message identifiers.

12 . The system of claim 11 , wherein to determine that the secured object was previously received, the at least one processor is further configured to:

compare the message history of the encrypted message to an expected message history based upon previously received messages at the server or client device;

determine that the secured object was previously received when the expected message history does not match the message history of the encrypted message.

13 . The system of claim 12 , wherein the at least one process is further configured to:

remove a previously received message identifier and a corresponding timestamp from the expected message history when a difference between the corresponding timestamp and the current time exceeds a specified removal threshold.

14 . A non-transitory computer-readable device having instructions stored thereon that, when executed by at least one computing device, causes the at least one computing device to perform operations comprising:

encrypting, by a data-collection application or a security application associated with the data-collection application on the client device, a data element using a server public key to generate on the client device a secure secured object,

to the client device from the server:

receiving, by a server, the secured object, wherein the secured object comprises an encrypted message used by the server to authenticate a client device, wherein the encrypted message comprises within the encrypted information at least a timestamp of the time the secured object was composed, a message identifier, a digital signature of the secured object signed by a private key on the client device, and a message digest comprising at least one of an anti-replay header and an anti-tamper header;

decrypting, by the server, the encrypted message;

validating, by the server, the digital signature of the decrypted message using a public key associated with the client device;

determining, by the server and the timestamp of the secured object, that the secured object was previously received more than a set threshold period of time before the time of receipt, or when an identifier cache at the server already contains the identifier or contents of the anti-replay header of the secured object of that secured object;

determining, by the server, that one or more applications on the client device were altered when a message digest at the server does not match the message digest of the secured object as is expected to be produced by untampered versions of those applications on the client device;

discarding the secured object when the digital signature of the secured object cannot be verified or when the secured object is determined to previously have been received prior to the set threshold period or when the message is determined to have been replayed or when the one or more applications on the client device were determined to be altered, and if the object is not discarded, then

preparing, by the server, a download in reply to a validated secured object from the client device;

digitally signing, by the server private key, the download to the client device;

encrypting the download, by the server, using the public key associated with the client device; and

receiving, by the client device, the signed and encrypted download.

15 . The non-transitory computer-readable device of claim 14 , the operations further comprising:

determining that the timestamp of the secured object corresponds to a time that is later than the current time.

16 . The non-transitory computer-readable device of claim 14 , the operations further comprising:

clearing, by the server, the identifier cache after a specified time period has passed.

17 . The non-transitory computer-readable device of claim 14 , wherein the encrypted message further comprises an encrypted message history, the message history comprising a list of previously sent message identifiers and timestamps, wherein each timestamp corresponds to each of the previously sent message identifiers.

18 . The non-transitory computer-readable device of claim 17 , wherein determining that the secured object was previously received further comprises:

comparing, by the server, the message history of the encrypted message to an expected message history at the server or client device based upon previously received messages;

determining, by the server, that the secured object was previously received when the expected message history does not match the message history of the encrypted message.

19 . The non-transitory computer-readable device of claim 18 , the operations further comprising:

removing, by the server, a previously received message identifier and a corresponding timestamp from the expected message history when the difference between the corresponding timestamp and the current time exceeds a specified removal threshold.

20 . The non-transitory computer-readable device of claim 14 , the operations further comprising:

sending, when the secured object was determined to be previously received or when the one or more applications on the client device were determined to be altered, a message to the client device that the secured object was discarded.

Assignments (3)
SECURITY INTEREST Recorded May 1, 2024
From: ACCERTIFY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 067278/0512 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2023
From: BENSON, GLENN S.
To: INAUTH, INC.
Reel/Frame 065695/0221 →
MERGER AND CHANGE OF NAME Recorded Nov 28, 2023
From: INAUTH, INC.; ACCERTIFY, INC.
To: ACCERTIFY, INC.
Reel/Frame 065688/0244 →
Continuity (6)
Continuation 17521138 · Nov 8, 2021
Continuation 16784863 · Feb 7, 2020
Division 16266702 · Feb 4, 2019
Continuation 15000913 · Jan 19, 2016
Provisional Application 62105148 · Jan 19, 2015
Related Publication 20240039737A1 · Feb 1, 2024
References Cited (186)
US 4933969A · Marshall et al. · 1990 [cited by applicant]
US 4969188A · Schobi · 1990 [cited by applicant]
US 5499298A · Narasimhalu et al. · 1996 [cited by applicant]
US 5761306A · Lewis · 1998 [cited by applicant]
US 5796830A · Johnson et al. · 1998 [cited by applicant]
US 5815583A · Solomon et al. · 1998 [cited by applicant]
US 5917911A · Dabbish et al. · 1999 [cited by applicant]
US 5937066A · Gennaro et al. · 1999 [cited by applicant]
US 6006328A · Drake · 1999 [cited by applicant]
US 6041133A · Califano et al. · 2000 [cited by applicant]
US 6069957A · Richards · 2000 [cited by applicant]
US 6088454A · Nagashima et al. · 2000 [cited by applicant]
US 6151676A · Cuccia · 2000 [cited by examiner]
US 6185316B1 · Buffam · 2001 [cited by applicant]
US 6760752B1 · Liu et al. · 2004 [cited by applicant]
US 6779114B1 · Chow et al. · 2004 [cited by applicant]
US 6842862B2 · Chow et al. · 2005 [cited by applicant]
US 6907127B1 · Kravitz et al. · 2005 [cited by applicant]
US 6915434B1 · Kuroda et al. · 2005 [cited by applicant]
US 6978384B1 · Milliken · 2005 [cited by applicant]
US 6981138B2 · Douceur et al. · 2005 [cited by applicant]
US 6993138B1 · Hardjono · 2006 [cited by applicant]
US 7043024B1 · Dinsmore et al. · 2006 [cited by applicant]
US 7055146B1 · Durr et al. · 2006 [cited by applicant]
US 7082615B1 · Ellison et al. · 2006 [cited by applicant]
US 7107464B2 · Shapira et al. · 2006 [cited by applicant]
US 7143288B2 · Pham et al. · 2006 [cited by applicant]
US 7167564B2 · Asano et al. · 2007 [cited by applicant]
US 7194766B2 · Noehring et al. · 2007 [cited by applicant]
US 7203837B2 · O'Shea · 2007 [cited by examiner]
US 7272728B2 · Pierson et al. · 2007 [cited by applicant]
US 7346170B2 · Asano et al. · 2008 [cited by applicant]
US 7389357B2 · Duffie et al. · 2008 [cited by applicant]
US 7426636B1 · McGrew et al. · 2008 [cited by applicant]
US 7509250B2 · Cruzado et al. · 2009 [cited by applicant]
US 7571343B1 · Xiang et al. · 2009 [cited by applicant]
US 7600131B1 · Krishna et al. · 2009 [cited by applicant]
US 7746781B1 · Xiang · 2010 [cited by applicant]
US 7865741B1 · Wood et al. · 2011 [cited by applicant]
US 8112787B2 · Buer · 2012 [cited by examiner]
US 8139770B2 · Zheng et al. · 2012 [cited by applicant]
US 8190893B2 · Benson et al. · 2012 [cited by applicant]
US 8196194B2 · Lindholm et al. · 2012 [cited by applicant]
US 8213907B2 · Etchegoyen · 2012 [cited by applicant]
US 8285994B2 · Shah et al. · 2012 [cited by applicant]
US 8312157B2 · Jakobsson et al. · 2012 [cited by applicant]
US 8316421B2 · Etchegoyen · 2012 [cited by applicant]
US 8392709B1 · Agrawal · 2013 [cited by applicant]
US 8549644B2 · Sallam · 2013 [cited by applicant]
US 8577803B2 · Chatterjee et al. · 2013 [cited by applicant]
US 8590021B2 · Steeves et al. · 2013 [cited by applicant]
US 8667288B2 · Yavuz · 2014 [cited by examiner]
US 8793192B2 · Hammad · 2014 [cited by examiner]
US 8817984B2 · Miller et al. · 2014 [cited by applicant]
US 8819839B2 · Henry et al. · 2014 [cited by applicant]
US 8961619B2 · Gum · 2015 [cited by applicant]
US 9210183B2 · Sadovsky · 2015 [cited by examiner]
US 9294448B2 · Miller et al. · 2016 [cited by applicant]
US 9559852B2 · Miller et al. · 2017 [cited by applicant]
US 9722804B2 · Miller et al. · 2017 [cited by applicant]
US 9769131B1 · Hartley et al. · 2017 [cited by applicant]
US 9887983B2 · Lindemann et al. · 2018 [cited by applicant]
US 10237073B2 · Benson · 2019 [cited by applicant]
US 10848317B2 · Benson · 2020 [cited by applicant]
US 11171790B2 · Benson · 2021 [cited by applicant]
US 20020044651A1 · Tuvell · 2002 [cited by applicant]
US 20020138735A1 · Felt et al. · 2002 [cited by applicant]
US 20020152380A1 · O'Shea · 2002 [cited by examiner]
US 20020188871A1 · Noehring et al. · 2002 [cited by applicant]
US 20030002676A1 · Stachura et al. · 2003 [cited by applicant]
US 20030012374A1 · Wu · 2003 [cited by examiner]
US 20030023847A1 · Ishibashi et al. · 2003 [cited by applicant]
US 20030028804A1 · Noehrina et al. · 2003 [cited by applicant]
US 20030115341A1 · Sinha et al. · 2003 [cited by applicant]
US 20030179885A1 · Gentry et al. · 2003 [cited by applicant]
US 20030187999A1 · Callum · 2003 [cited by applicant]
US 20030217280A1 · Keaton et al. · 2003 [cited by applicant]
US 20040008711A1 · Lahti et al. · 2004 [cited by applicant]
US 20040015724A1 · Pham et al. · 2004 [cited by applicant]
US 20040028281A1 · Cheng et al. · 2004 [cited by applicant]
US 20040073790A1 · Ateniese et al. · 2004 [cited by applicant]
US 20040139008A1 · Mascavage, III · 2004 [cited by applicant]
US 20040153674A1 · Hayashi · 2004 [cited by applicant]
US 20040259633A1 · Gentles et al. · 2004 [cited by applicant]
US 20040268123A1 · Le et al. · 2004 [cited by applicant]
US 20050018853A1 · Lain et al. · 2005 [cited by applicant]
US 20050021944A1 · Craft et al. · 2005 [cited by applicant]
US 20050091492A1 · Benson et al. · 2005 [cited by applicant]
US 20050138374A1 · Zheng et al. · 2005 [cited by applicant]
US 20050160095A1 · Dick et al. · 2005 [cited by applicant]
US 20050242568A1 · Long et al. · 2005 [cited by applicant]
US 20050246533A1 · Gentry · 2005 [cited by applicant]
US 20050278542A1 · Pierson et al. · 2005 [cited by applicant]
US 20060010324A1 · Appenzeller et al. · 2006 [cited by applicant]
US 20060036862A1 · Tuvell et al. · 2006 [cited by applicant]
US 20060041752A1 · Tuvell et al. · 2006 [cited by applicant]
US 20060050869A1 · Tuvell et al. · 2006 [cited by applicant]
US 20060087883A1 · Ozquz et al. · 2006 [cited by applicant]
US 20060101273A1 · Tan et al. · 2006 [cited by applicant]
US 20060101524A1 · Weber · 2006 [cited by applicant]
US 20060242423A1 · Kussmaul · 2006 [cited by applicant]
US 20060242696A1 · Cruzado et al. · 2006 [cited by applicant]
US 20060282660A1 · Varghese et al. · 2006 [cited by applicant]
US 20060294366A1 · Nadalin et al. · 2006 [cited by applicant]
US 20070083923A1 · Fluhrer et al. · 2007 [cited by applicant]
US 20070115812A1 · Hughes · 2007 [cited by applicant]
US 20070165638A1 · Hasani et al. · 2007 [cited by applicant]
US 20070179904A1 · Hofstee et al. · 2007 [cited by applicant]
US 20070192864A1 · Bryant et al. · 2007 [cited by applicant]
US 20070240217A1 · Tuvell et al. · 2007 [cited by applicant]
US 20070240218A1 · Tuvell et al. · 2007 [cited by applicant]
US 20070240219A1 · Tuvell et al. · 2007 [cited by applicant]
US 20070240220A1 · Tuvell et al. · 2007 [cited by applicant]
US 20070240221A1 · Tuvell et al. · 2007 [cited by applicant]
US 20070240222A1 · Tuvell et al. · 2007 [cited by applicant]
US 20070266434A1 · Reifer · 2007 [cited by applicant]
US 20070300290A1 · Shay et al. · 2007 [cited by applicant]
US 20080022084A1 · Raftelis et al. · 2008 [cited by applicant]
US 20080022389A1 · Calcev et al. · 2008 [cited by applicant]
US 20080065882A1 · Goodman et al. · 2008 [cited by applicant]
US 20080077795A1 · MacMillan · 2008 [cited by applicant]
US 20080086773A1 · Tuvell et al. · 2008 [cited by applicant]
US 20080086776A1 · Tuvell et al. · 2008 [cited by applicant]
US 20080101611A1 · Lindholm et al. · 2008 [cited by applicant]
US 20080104711A1 · Johns et al. · 2008 [cited by applicant]
US 20080130889A1 · Qi et al. · 2008 [cited by applicant]
US 20080130894A1 · Qi et al. · 2008 [cited by applicant]
US 20080159266A1 · Chen et al. · 2008 [cited by applicant]
US 20080159299A1 · Bu et al. · 2008 [cited by applicant]
US 20080172482A1 · Shah · 2008 [cited by applicant]
US 20080196104A1 · Tuvell et al. · 2008 [cited by applicant]
US 20080198832A1 · Chester · 2008 [cited by applicant]
US 20080260151A1 · Fluhrer et al. · 2008 [cited by applicant]
US 20080320263A1 · Nemiroff et al. · 2008 [cited by applicant]
US 20090025084A1 · Siourthas et al. · 2009 [cited by applicant]
US 20090092252A1 · Noll et al. · 2009 [cited by applicant]
US 20090158417A1 · Khanna et al. · 2009 [cited by applicant]
US 20090183263A1 · McMichael et al. · 2009 [cited by applicant]
US 20090228951A1 · Ramesh et al. · 2009 [cited by applicant]
US 20100037319A1 · Steeves et al. · 2010 [cited by applicant]
US 20100229224A1 · Etchegoyen · 2010 [cited by applicant]
US 20100246827A1 · Lauter et al. · 2010 [cited by applicant]
US 20100296653A1 · Richardson · 2010 [cited by applicant]
US 20100332400A1 · Etchegoyen · 2010 [cited by applicant]
US 20110035601A1 · Davidson et al. · 2011 [cited by applicant]
US 20110082768A1 · Eisen · 2011 [cited by applicant]
US 20110093503A1 · Etchegoyen · 2011 [cited by applicant]
US 20110179484A1 · Tuvell et al. · 2011 [cited by applicant]
US 20120030771A1 · Pierson et al. · 2012 [cited by applicant]
US 20120042029A1 · Tuvell et al. · 2012 [cited by applicant]
US 20120150742A1 · Poon et al. · 2012 [cited by applicant]
US 20120185636A1 · Leon et al. · 2012 [cited by applicant]
US 20120198234A1 · Chung · 2012 [cited by examiner]
US 20120201381A1 · Miller et al. · 2012 [cited by applicant]
US 20120317028A1 · Ansari · 2012 [cited by examiner]
US 20130016729A1 · Engel et al. · 2013 [cited by applicant]
US 20130067232A1 · Cheung et al. · 2013 [cited by applicant]
US 20130166729A1 · Gole et al. · 2013 [cited by applicant]
US 20130179681A1 · Benson et al. · 2013 [cited by applicant]
US 20130263211A1 · Neuman et al. · 2013 [cited by applicant]
US 20130268760A1 · Bono et al. · 2013 [cited by applicant]
US 20130290704A1 · Giniger et al. · 2013 [cited by applicant]
US 20130291086A1 · Pontillo · 2013 [cited by applicant]
US 20130326224A1 · Yavuz · 2013 [cited by examiner]
US 20130333038A1 · Chien · 2013 [cited by applicant]
US 20130340052A1 · Jakobsson · 2013 [cited by applicant]
US 20140059642A1 · Deasy et al. · 2014 [cited by applicant]
US 20140095894A1 · Barton et al. · 2014 [cited by applicant]
US 20140115160A1 · Tuvell et al. · 2014 [cited by applicant]
US 20140156991A1 · Baskaran · 2014 [cited by applicant]
US 20140250290A1 · Stahl · 2014 [cited by examiner]
US 20140250511A1 · Kendall · 2014 [cited by applicant]
US 20140359729A1 · Kreiner et al. · 2014 [cited by applicant]
US 20150033027A1 · Miller et al. · 2015 [cited by applicant]
US 20150096031A1 · Benoit et al. · 2015 [cited by applicant]
US 20150163121A1 · Mahaffey et al. · 2015 [cited by applicant]
US 20150227753A1 · Callaghan et al. · 2015 [cited by applicant]
US 20150347753A1 · Tuvell et al. · 2015 [cited by applicant]
US 20150363602A1 · Willis et al. · 2015 [cited by applicant]
US 20160012227A1 · Tuvell et al. · 2016 [cited by applicant]
US 20160204948A1 · Miller et al. · 2016 [cited by applicant]
US 20160261416A1 · Miller et al. · 2016 [cited by applicant]
US 20170213054A1 · Chen et al. · 2017 [cited by applicant]
WO WO1997004394A1 · 1997 [cited by applicant]
WO WO2008113299A1 · 2008 [cited by applicant]
WO WO2013081441A1 · 2013 [cited by applicant]