IP Library Granted Patent US 12,580,726
Granted Patent B2
US 12,580,726 · App. 18/485,480 · Granted Mar 17, 2026

Using a single AES key to encrypt PKCS #7 files

Inventors: Jarryd Chengalroyen (Cape Town, CA); Darin Scott Andrew (Lehi, UT)
Assignee: DigiCert, Inc.
H04L9/006H04L9/0861H04L9/0891H04L9/3268
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,726
App. No.
18/485,480
Granted
Mar 17, 2026
Kind
B2
Abstract

Cryptographic systems and methods are provided. A method, according to one implementation, includes a step of generating a plurality of key pairs in response to receiving a request from a client for one or more digital certificates. The key pairs are associated respectively with the one or more digital certificates. Also, each key pair includes a public key and a private key. The method further includes a step of utilizing at least the plurality of key pairs to generate the one or more digital certificates. Also, the method includes a step of encrypting the one or more digital certificates and respective private keys using a single Advanced Encryption Standard (AES) key. The method also includes a step of sending the encrypted one or more digital certificates and private keys back to the client.

Claims (23)

1 . A server comprising:

a processing device; and

a memory device configured to store computer code having instructions that enable the processing device to perform the steps of

generating a plurality of key pairs in response to receiving a request from a client for one or more digital certificates, the plurality of key pairs associated respectively with the one or more digital certificates, wherein each key pair includes a public key and a private key,

utilizing at least the plurality of key pairs to generate the one or more digital certificates,

encrypting the one or more digital certificates and respective private keys using a single Advanced Encryption Standard (AES) key, and

sending the encrypted one or more digital certificates and private keys back to the client.

2 . The server of claim 1 , wherein the step of sending the encrypted one or more digital certificates and private keys includes the step of creating a plurality of Public-Key Cryptography Standard 7 (PKCS #7) files, wherein each PKCS #7 file includes a corresponding digital certificate and key pair, and wherein the single AES key is configured to decrypt each PKCS #7 file.

3 . The server of claim 1 , wherein the step of using the single AES key for the one or more digital certificates allows the client to decrypt the single AES key one time to enable decryption of each of the encrypted one or more digital certificates.

4 . The server of claim 1 , further comprising a trust manager configured to receive the request and generate the key pairs.

5 . The server of claim 1 , further comprising a certificate management system configured to generate and encrypt the one or more digital certificates.

6 . The server of claim 1 , wherein the request for the one or more digital certificates is a request for digital certificates to be applied to a plurality of electronic devices.

7 . The server of claim 6 , wherein the one or more digital certificates are applied to the plurality of electronic devices during a predetermined timeframe when the electronic devices are manufactured.

8 . The server of claim 1 , wherein the step of generating the one or more digital certificates further includes utilizing a Certificate Signing Request (CSR) generated along with the generating of the plurality of key pairs.

9 . A non-transitory computer-readable medium configured to store computer logic having instructions that enable a processing system to:

generate a plurality of key pairs in response to receiving a request from a client for one or more digital certificates, the plurality of key pairs associated respectively with the one or more digital certificates, wherein each key pair includes a public key and a private key,

utilize at least the plurality of key pairs to generate the one or more digital certificates,

encrypt the one or more digital certificates and respective private keys using a single Advanced Encryption Standard (AES) key, and

send the encrypted one or more digital certificates and private keys back to the client.

10 . The non-transitory computer-readable medium of claim 9 , wherein sending the encrypted one or more digital certificates and private keys to the client further includes creating a plurality of Public-Key Cryptography Standard 7 (PKCS #7) files, wherein each PKCS #7 file includes a corresponding digital certificate and key pair, and wherein the single AES key is configured to decrypt each PKCS #7 file.

11 . The non-transitory computer-readable medium of claim 9 , wherein using the single AES key for the one or more digital certificates allows the client to decrypt the single AES key one time to enable decryption of each of the encrypted one or more digital certificates.

12 . The non-transitory computer-readable medium of claim 9 , wherein the instructions further enable the processing system to use a trust manager to receive the request and generate the key pairs and use a certificate management system to generate and encrypt the one or more digital certificates.

13 . The non-transitory computer-readable medium of claim 9 , wherein the request for the one or more digital certificates is a request for digital certificates to be applied to a plurality of electronic devices, and wherein the one or more digital certificates are applied to the plurality of electronic devices during a predetermined timeframe when the electronic devices are manufactured.

Assignments (3)
FIRST LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Sep 24, 2025
From: DIGICERT, INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 072947/0203 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Jul 30, 2025
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 072295/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2023
From: CHENGALROYEN, JARRYD; ANDREW, DARIN SCOTT
To: DIGICERT, INC.
Reel/Frame 065196/0819 →
Continuity (1)
Related Publication 20250125950A1 · Apr 17, 2025
References Cited (22)
US 9166970B1 · Dundas et al. · 2015 [cited by applicant]
US 9350536B2 · Sabin · 2016 [cited by applicant]
US 9769046B2 · Sabin · 2017 [cited by applicant]
US 10250397B1 · Singal et al. · 2019 [cited by applicant]
US 10341321B2 · Kumar et al. · 2019 [cited by applicant]
US 10505920B2 · Kumar et al. · 2019 [cited by applicant]
US 10764040B2 · Kumar et al. · 2020 [cited by applicant]
US 10778448B2 · Modi et al. · 2020 [cited by applicant]
US 10958437B2 · Sabin · 2021 [cited by applicant]
US 11206134B2 · Kumar et al. · 2021 [cited by applicant]
US 11604659B2 · Naik · 2023 [cited by applicant]
US 12184792B1 · Stapleton · 2024 [cited by examiner]
US 20020116610A1 · Holmes · 2002 [cited by examiner]
US 20130318353A1 · Skarda · 2013 [cited by applicant]
US 20160365985A1 · Pilcher et al. · 2016 [cited by applicant]
US 20180234256A1 · Bowen · 2018 [cited by examiner]
US 20190123915A1 · Simplicio, Jr. · 2019 [cited by examiner]
US 20210056198A1 · Choules et al. · 2021 [cited by applicant]
US 20220150238A1 · Bhalerao · 2022 [cited by applicant]
US 20220398322A1 · Kumar et al. · 2022 [cited by applicant]
US 20230065060A1 · Kumar et al. · 2023 [cited by applicant]
US 20230208652A1 · Kumar et al. · 2023 [cited by applicant]