IP Library Granted Patent US 12,381,741
Granted Patent B2
US 12,381,741 · App. 18/498,828 · Granted Aug 5, 2025

Systems and methods for verifying a route taken by a communication

Inventors: Brian R. Knopf (Woodland Hills, CA); Mark Watson (San Francisco, CA)
Assignee: Neustar, Inc.
H04L9/3247H04L9/088H04L9/14H04L9/321H04L63/062H04L63/123H04L63/126
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,381,741
App. No.
18/498,828
Granted
Aug 5, 2025
Kind
B2
Abstract

Computer systems and methods for verifying a route taken by a communication are disclosed. In one implementation, a device for verifying a route taken by a communication may include one or more processors configured to obtain a communication transmitted by a source entity. The communication may include data and digital signatures, and each of the digital signatures may be generated based on at least the data. Further, the digital signatures may include a digital signature associated with the source entity, and a set of digital signatures associated with at least a subset of intermediate entities on a route taken by the communication. The one or more processors may be further configured to verify the digital signatures included in the communication, verify whether the entities associated with the digital signatures form an expected route for the communication, and process the data.

Claims (35)

1. A device for verifying a route taken by a communication, the device comprising:

one or more processors configured to:

obtain a communication transmitted by a source entity, wherein the communication comprises data and a set of digital signatures, wherein the set of digital signatures includes a digital signature associated with the source entity and one or more digital signatures respectively associated with at least a subset of intermediate entities on the route taken by the communication, and wherein the communication further comprises a header that specifies an order in which each signature of the set of digital signatures was included in the communication;

verify the digital signatures included in the communication;

verify that the digital signatures included in the communication were included in the communication in an expected order based at least in part on the header; and

process the data in response to verifying that the digital signatures were included in the expected order,

wherein the communication comprises a JSON Web Token (JWT) comprising a “payload” key-value pair, wherein a value of the “payload” key-value pair includes the data.

2. The device of claim 1 , wherein the one or more processors are configured to process the data after verifying that the respective entities associated with the digital signatures included in the communication form an expected route for the communication.

3. The device of claim 1 , wherein at least one digital signature of the set of digital signatures is generated further based on the digital signature associated with the source entity.

4. The device of claim 1 , wherein a digital signature of the set of digital signatures is included in the communication by an intermediate entity on the route taken by the communication after the intermediate entity verifies at least one of the digital signatures included in the communication.

5. The device of claim 1 , wherein the one or more processors are configured to process the data after verifying that one or more entities associated with the digital signatures included in the communication are authorized to communicate with the device.

6. The device of claim 1 , wherein the data is encrypted.

7. The device of claim 1 , wherein the JWT further comprises a “signatures” key-value pair, wherein a value of the “signatures” key-value pair includes an array of objects.

8. The device of claim 1 , wherein each digital signature of the set of digital signatures is generated based at least in part on the data using a private key.

9. The device of claim 8 , wherein each digital signature is generated by encrypting a hash value of the data using the private key.

10. A method for verifying a route taken by a communication, the method comprising:

obtaining a communication transmitted by a source entity, wherein the communication comprises data and a set of digital signatures, wherein the set of digital signatures includes a digital signature associated with the source entity and one or more digital signatures respectively associated with at least a subset of intermediate entities on the route taken by the communication, and wherein the communication further comprises a header that specifies an order in which each signature of the set of digital signatures was included in the communication;

verifying the digital signatures included in the communication;

verifying that the digital signatures included in the communication were included in the communication in an expected order based at least in part on the header; and

processing the data in response to verifying that the digital signatures were included in the expected order,

wherein the communication comprises a JSON Web Token (JWT) comprising a “payload” key-value pair, wherein a value of the “payload” key-value pair includes the data.

11. The method of claim 10 , further comprising determining an expected route for the communication, and wherein the processing comprises processing the data after verifying that the respective entities associated with the digital signatures included in the communication form the expected route for the communication.

12. The method of claim 10 , wherein a digital signature of the set of digital signatures is included in the communication by an intermediate entity on the route taken by the communication after the intermediate entity verifies at least one of the digital signatures included in the communication.

13. The method of claim 10 , wherein the processing comprises processing the data after verifying that one or more entities associated with the digital signatures included in the communication are authorized to communicate with a device.

14. The method of claim 10 , wherein the JWT further comprises a “signatures” key-value pair, wherein a value of the “signatures” key-value pair includes an array of objects.

15. The method of claim 10 , wherein each digital signature of the set of digital signatures is generated based at least in part on the data using a private key.

16. The method of claim 15 , wherein each digital signature is generated by encrypting a hash value of the data using the private key.

17. A non-transitory computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method for verifying a route taken by a communication, the method comprising:

obtaining a communication transmitted by a source entity, wherein the communication comprises data and a set of digital signatures, wherein the set of digital signatures includes a digital signature associated with the source entity and one or more digital signatures respectively associated with at least a subset of intermediate entities on the route taken by the communication, and wherein the communication further comprises a header that specifies an order in which each signature of the set of digital signatures was included in the communication;

verifying the digital signatures included in the communication;

verifying that the digital signatures included in the communication were included in the communication in an expected order based at least in part on the header; and

processing the data in response to verifying that the digital signatures were included in the expected order,

wherein the communication comprises a JSON Web Token (JWT) comprising a “payload” key-value pair, wherein a value of the “payload” key-value pair includes the data.

18. The non-transitory computer-readable storage medium of claim 17 , wherein a digital signature of the set of digital signatures is included in the communication by an intermediate entity on the route taken by the communication after the intermediate entity verifies at least one of the digital signatures included in the communication.

19. The non-transitory computer-readable storage medium of claim 17 , wherein the JWT further comprises a “signatures” key-value pair, wherein a value of the “signatures” key-value pair includes an array of objects.

Assignments (1)
EMPLOYEE AGREEMENT Recorded Apr 11, 2025
From: KNOPF, BRIAN
To: NEUSTAR, INC.
Reel/Frame 070821/0138 →
Continuity (6)
Continuation 17460837 · Aug 30, 2021
Continuation 15652114 · Jul 17, 2017
Continuation In Part 15588533 · May 5, 2017
Provisional Application 62469346 · Mar 9, 2017
Provisional Application 62332271 · May 5, 2016
Related Publication 20240146538A1 · May 2, 2024
References Cited (185)
US 5455865A · Perlman · 1995 [cited by applicant]
US 5715314A · Payne et al. · 1998 [cited by applicant]
US 6209091B1 · Sudia et al. · 2001 [cited by applicant]
US 6263446B1 · Kausik et al. · 2001 [cited by applicant]
US 6381331B1 · Kato · 2002 [cited by applicant]
US 6801534B1 · Arrowood et al. · 2004 [cited by applicant]
US 6826690B1 · Hind et al. · 2004 [cited by applicant]
US 6850951B1 · Davison · 2005 [cited by applicant]
US 7266695B2 · Nakayama · 2007 [cited by applicant]
US 7320073B2 · Zissimopoulos et al. · 2008 [cited by applicant]
US 7428750B1 · Dunn et al. · 2008 [cited by applicant]
US 7522723B1 · Shaik · 2009 [cited by applicant]
US 8023647B2 · Shaik · 2011 [cited by applicant]
US 8229484B2 · Anisimov · 2012 [cited by applicant]
US 8561187B1 · Hegil · 2013 [cited by applicant]
US 8578468B1 · Yadav · 2013 [cited by applicant]
US 8726379B1 · Stiansen · 2014 [cited by applicant]
US 8769304B2 · Kirsch · 2014 [cited by applicant]
US 8819825B2 · Keromytis et al. · 2014 [cited by applicant]
US 9027135B1 · Aziz · 2015 [cited by applicant]
US 9094811B1 · Rosen · 2015 [cited by applicant]
US 9177005B2 · Mehta et al. · 2015 [cited by applicant]
US 9197673B1 · Gaddy et al. · 2015 [cited by applicant]
US 9203819B2 · Fenton et al. · 2015 [cited by applicant]
US 9215223B2 · Kirsch · 2015 [cited by applicant]
US 9344413B2 · Kirsch · 2016 [cited by applicant]
US 9356942B1 · Joffe · 2016 [cited by applicant]
US 9418222B1 · Rivera et al. · 2016 [cited by applicant]
US 9485231B1 · Reese · 2016 [cited by applicant]
US 9521240B1 · Rosen · 2016 [cited by applicant]
US 9674222B1 · Joffe · 2017 [cited by applicant]
US 9832217B2 · Berger et al. · 2017 [cited by applicant]
US 10244107B1 · Sena · 2019 [cited by applicant]
US 10404472B2 · Knopf · 2019 [cited by applicant]
US 11108562B2 · Knopf et al. · 2021 [cited by applicant]
US 20010024502A1 · Ohkuma et al. · 2001 [cited by applicant]
US 20020076055A1 · Filipi-Martin et al. · 2002 [cited by applicant]
US 20020194163A1 · Hopeman et al. · 2002 [cited by applicant]
US 20030065947A1 · Song · 2003 [cited by applicant]
US 20030110397A1 · Supramaniam et al. · 2003 [cited by applicant]
US 20030147534A1 · Ablay et al. · 2003 [cited by applicant]
US 20030177400A1 · Raley et al. · 2003 [cited by applicant]
US 20030204511A1 · Brundage et al. · 2003 [cited by applicant]
US 20040062400A1 · Sovio et al. · 2004 [cited by applicant]
US 20040088587A1 · Ramaswamy et al. · 2004 [cited by applicant]
US 20040172557A1 · Nakae et al. · 2004 [cited by applicant]
US 20040176123A1 · Chin et al. · 2004 [cited by applicant]
US 20040205342A1 · Roegner · 2004 [cited by applicant]
US 20050010447A1 · Miyasaka et al. · 2005 [cited by applicant]
US 20050036616A1 · Huang · 2005 [cited by examiner]
US 20050044402A1 · Libin et al. · 2005 [cited by applicant]
US 20050054380A1 · Michaelis · 2005 [cited by applicant]
US 20050097320A1 · Golan et al. · 2005 [cited by applicant]
US 20050132060A1 · Mo et al. · 2005 [cited by applicant]
US 20050220080A1 · Ronkainen · 2005 [cited by applicant]
US 20050220095A1 · Narayanan et al. · 2005 [cited by applicant]
US 20060059357A1 · Miyazaki · 2006 [cited by third party]
US 20060059551A1 · Borella · 2006 [cited by applicant]
US 20060080534A1 · Yeap et al. · 2006 [cited by applicant]
US 20060083187A1 · Dekel · 2006 [cited by applicant]
US 20060090166A1 · Dhara et al. · 2006 [cited by applicant]
US 20060101516A1 · Sudaharan · 2006 [cited by applicant]
US 20060129817A1 · Borneman et al. · 2006 [cited by applicant]
US 20060131385A1 · Kim · 2006 [cited by applicant]
US 20060206709A1 · Labrou et al. · 2006 [cited by applicant]
US 20060224508A1 · Fietz · 2006 [cited by applicant]
US 20060236095A1 · Smith · 2006 [cited by applicant]
US 20070061263A1 · Carter et al. · 2007 [cited by applicant]
US 20070198437A1 · Eisner et al. · 2007 [cited by applicant]
US 20070228148A1 · Rable · 2007 [cited by applicant]
US 20080016232A1 · Yared et al. · 2008 [cited by applicant]
US 20080028453A1 · Nguyen et al. · 2008 [cited by applicant]
US 20080028463A1 · Dagon · 2008 [cited by applicant]
US 20080046987A1 · Spector · 2008 [cited by applicant]
US 20080089520A1 · Kessler · 2008 [cited by applicant]
US 20080141313A1 · Kato et al. · 2008 [cited by applicant]
US 20080163354A1 · Ben-Shalom et al. · 2008 [cited by applicant]
US 20080189778A1 · Rowley · 2008 [cited by applicant]
US 20080222711A1 · Michaelis · 2008 [cited by applicant]
US 20080244739A1 · Liu · 2008 [cited by examiner]
US 20080250248A1 · Lieber · 2008 [cited by applicant]
US 20090037994A1 · Buss et al. · 2009 [cited by applicant]
US 20090080408A1 · Natoli et al. · 2009 [cited by applicant]
US 20090089625A1 · Kannappan et al. · 2009 [cited by applicant]
US 20090119778A1 · Bhuyan · 2009 [cited by applicant]
US 20090157799A1 · Sukumaran et al. · 2009 [cited by applicant]
US 20090249014A1 · Obereiner · 2009 [cited by applicant]
US 20090249497A1 · Fitzgerald · 2009 [cited by applicant]
US 20090260064A1 · McDowell · 2009 [cited by applicant]
US 20100003959A1 · Coppage · 2010 [cited by applicant]
US 20100077457A1 · Xu et al. · 2010 [cited by applicant]
US 20100100945A1 · Ozzie et al. · 2010 [cited by applicant]
US 20100100950A1 · Roberts · 2010 [cited by applicant]
US 20100161969A1 · Grebovich et al. · 2010 [cited by applicant]
US 20100162396A1 · Liu · 2010 [cited by applicant]
US 20100174439A1 · Petricoin, Jr. et al. · 2010 [cited by applicant]
US 20100182283A1 · Sip · 2010 [cited by applicant]
US 20100185869A1 · Moore et al. · 2010 [cited by applicant]
US 20100210240A1 · Mahaffey et al. · 2010 [cited by applicant]
US 20100260337A1 · Song · 2010 [cited by examiner]
US 20100275009A1 · Canard et al. · 2010 [cited by applicant]
US 20100306107A1 · Nahari · 2010 [cited by applicant]
US 20100316217A1 · Gammel et al. · 2010 [cited by applicant]
US 20100325685A1 · Sanbower · 2010 [cited by applicant]
US 20110009086A1 · Poremba et al. · 2011 [cited by applicant]
US 20110067095A1 · Leicher et al. · 2011 [cited by applicant]
US 20110078439A1 · Mao et al. · 2011 [cited by applicant]
US 20110103393A1 · Meier et al. · 2011 [cited by applicant]
US 20110167494A1 · Bowen et al. · 2011 [cited by applicant]
US 20110179475A1 · Foell et al. · 2011 [cited by applicant]
US 20110222466A1 · Pance · 2011 [cited by applicant]
US 20110246765A1 · Schibuk · 2011 [cited by applicant]
US 20110252459A1 · Walsh · 2011 [cited by applicant]
US 20110282997A1 · Prince · 2011 [cited by applicant]
US 20120042381A1 · Antonakakis · 2012 [cited by applicant]
US 20120050455A1 · Santamaria et al. · 2012 [cited by applicant]
US 20120124379A1 · Teranishi · 2012 [cited by applicant]
US 20120155637A1 · Lambert et al. · 2012 [cited by applicant]
US 20120158725A1 · Molloy et al. · 2012 [cited by applicant]
US 20120197911A1 · Banka et al. · 2012 [cited by applicant]
US 20120233685A1 · Palanigounder et al. · 2012 [cited by applicant]
US 20120265631A1 · Cronic et al. · 2012 [cited by applicant]
US 20120320912A1 · Estrada · 2012 [cited by applicant]
US 20120324076A1 · Zerr et al. · 2012 [cited by applicant]
US 20120324242A1 · Kirsch · 2012 [cited by applicant]
US 20120331296A1 · Levin et al. · 2012 [cited by applicant]
US 20130133072A1 · Kraitsman et al. · 2013 [cited by applicant]
US 20130198078A1 · Kirsch · 2013 [cited by applicant]
US 20130198516A1 · Fenton et al. · 2013 [cited by applicant]
US 20130198598A1 · Kirsch · 2013 [cited by applicant]
US 20130198834A1 · Kirsch · 2013 [cited by applicant]
US 20130205136A1 · Kirsch · 2013 [cited by applicant]
US 20130239169A1 · Nakhjiri · 2013 [cited by examiner]
US 20130246272A1 · Kirsch · 2013 [cited by applicant]
US 20130246280A1 · Kirsch · 2013 [cited by applicant]
US 20140198791A1 · Lim · 2014 [cited by examiner]
US 20140214902A1 · Mehta et al. · 2014 [cited by applicant]
US 20140344904A1 · Venkataramani et al. · 2014 [cited by applicant]
US 20140351596A1 · Chan · 2014 [cited by applicant]
US 20150033024A1 · Mashima · 2015 [cited by third party]
US 20150047032A1 · Hannis et al. · 2015 [cited by applicant]
US 20150088754A1 · Kirsch · 2015 [cited by applicant]
US 20150321557A1 · Kim et al. · 2015 [cited by applicant]
US 20150326588A1 · Vissamsetty · 2015 [cited by applicant]
US 20160094531A1 · Unnikrishnan · 2016 [cited by examiner]
US 20160173505A1 · Ichihara · 2016 [cited by applicant]
US 20160197932A1 · Hoffman et al. · 2016 [cited by applicant]
US 20160241509A1 · Akcin · 2016 [cited by applicant]
US 20160261413A1 · Kirsch · 2016 [cited by applicant]
US 20160300223A1 · Grey · 2016 [cited by third party]
US 20170324564A1 · Knopf · 2017 [cited by applicant]
US 20170366575A1 · Polepalli et al. · 2017 [cited by applicant]
US 20180013569A1 · Knopf · 2018 [cited by applicant]
US 20180013786A1 · Knopf · 2018 [cited by applicant]
US 20180013824A1 · Knopf · 2018 [cited by applicant]
US 20180183603A1 · Liu et al. · 2018 [cited by applicant]
US 20190124199A1 · Sena · 2019 [cited by applicant]
EP 0683582A1 · 1995 [cited by applicant]
KR 20130083619A · 2013 [cited by applicant]
Siriwardena P, Siriwardena P. JWT, JWS, and JWE. Advanced API Security: Securing APIs with OAuth 2.0, OpenID Connect, JWS, and JWE. 2014:201-20. (Year: 2014). [cited by examiner]
Abe, Tsuyoshi et al., “Implementing Identity Provider on Mobile Phone,” 2007, ACM, pp. 46-52. [cited by applicant]
Balasubramaniam, Sriram et al., “Identity Management and its Impact on Federation in a System-of-Systems Context,” Mar. 23-26, 2009, IEEE, pp. 179-182. [cited by applicant]
Beasley, Jim et al., “Virtual Bluetooth Devices as a Means of Extending Pairing and Bonding in a Bluetooth Network,” 2002, IEEE, vol. 4, pp. 2087-2089. [cited by applicant]
Chen, Liqun et al., Multiple Trusted Authorities in Identified Based Cryptography from Pairings on Elliptic Curves, Mar. 19, 2003, HP, pp. 1-26. [cited by applicant]
International Search Report and Written Opinion of PCT/US2012/042743 mailed on Sep. 18, 2012, 10 pages. [cited by applicant]
International Search Report and Written Opinion of PCT/US2013/022207 mailed on Mar. 29, 2013, 11 pages. [cited by applicant]
International Search Report and Written Opinion of PCT/US2017/31438 mailed Jul. 25, 2017, 8 pages. [cited by applicant]
International Search Report and Written Opinion of PCT/US2018/21877 mailed on May 30, 2018, 8 pages. [cited by applicant]
International Search Report and Written Opinion of PCT/US2018/42524 mailed Oct. 30, 2018, 8 pages. [cited by applicant]
International Search Report and Written Opinion of PCT/US2018/42508 mailed Dec. 13, 2018, 8 pages. [cited by applicant]
Jansen, Wayne et al., “Guidelines on Cell Phone and PDA Security,” Oct. 2008, NIST, pp. 1-52. [cited by applicant]
Kholmatov, Alisher et al., “Identity Authentication Using Improved Online Signature Verification Method,” Nov. 2005, ScienceDirect, vol. 26, Issue 15, pp. 2400-2408. [cited by applicant]
Masmoudi, Khaled et al., “Building Identity-Based Security Associations for Provider-Provisioned Virtual Private Networks,” Dec. 2008, Springer, vol. 39, Issue 3, pp. 215-222. [cited by applicant]
Mayrhofer, Rene et al., “Shake Well Before Use: Intuitive and Secure Pairing of Mobile Devices,” Feb. 27, 2009, IEEE, vol. 8, Issue 6, pp. 792-806. [cited by applicant]
Nguyen, Lan et al., “Secure Authorization, Access Control and Data Integrity in Bluetooth,” 2002, IEEE, pp. 428-433. [cited by applicant]
Novotny, Jason et al., “An Online Credential Repository for the Grid: MyProxy,” 2001, IEEE, pp. 104-111. [cited by applicant]
Poggi, Nicolas et al., “Automatic Detection and Banning of Content Stealing Bots for E-Commerce,” NIPS 2007 Workshop on Machine Learning in Adversarial Environments for Computer Security, 2 pages, Dec. 8, 2007. [cited by applicant]
So-In, Chakchai et al., “Virtual ID: A Technique for Mobility, MultiHoming, and Location Privacy in Next Generation Wireless Networks,” Jan. 9-12, 2010, IEEE, pp. 1-5. [cited by applicant]
Squicciarini, Anna Cinzia et al., “Access Control Strategies for Virtualized Environments in Grid Computing Systems,” Mar. 21-23, 2007, IEEE, pp. 48-54. [cited by applicant]
Tangswongsan, Supachai et al., “A Model of Network Security with Prevention Capability by Using Decoy Technique,” World Academy of Science, Engineering and Technology 29, pp. 184-189, 2007. [cited by applicant]
Heer, Tobias, et al., “ALPHA: an adaptive and lightweight protocol for hop-by-hop authentication.” Proceedings of the 2008 ACM CoNEXT Conference. ACM, 2008. [cited by applicant]
Lu, Bin, and Udo W. Pooch, “A lightweight authentication protocol for mobile ad hoc networks,” International Conference on Information Technology: Coding and Computing (ITCC'05)—vol. II, vol. 2, IEEE, 2005. [cited by applicant]
Sanzgiri, Kimaya, et al., “A secure routing protocol for ad hoc networks,” 10 [cited by applicant]
Request for Comments: 7159. The JavaScript Object Notation (JSON) Data Interchange Format, Mar. 2014. [cited by applicant]
Crockford D. Json, ECMA International, 2012, Retrieved from http://www.json.org/json.pdf on Apr. 19, 2021. [cited by applicant]