IP Library Granted Patent US 12,316,755
Granted Patent B2
US 12,316,755 · App. 18/506,126 · Granted May 27, 2025

Key generation systems and methods

Inventor: Jarl Nilsson (Mountain View, CA)
Assignee: Intertrust Technologies Corporation
H04L9/0861H04L9/0643H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,755
App. No.
18/506,126
Granted
May 27, 2025
Kind
B2
Abstract

This disclosure relates to, among other things, key generation systems and methods. Certain embodiments disclosed herein provide for generation of cryptographic keys based on one or more defined key generation rules. Key generation consistent with various aspects of the disclosed embodiments may increase the difficultly and/or cost of producing public keys and, by extension, discourage the generation of fake keys used in connection with a key flooding attack. In certain embodiments, generated keys and/or associated key generation rules may depend, at least in part, on associated binding data.

Claims (26)

1. A method for generating at least one cryptographic key performed by a system comprising a processor and non-transitory computer-readable medium storing instructions that, when executed by the processor, cause the system to perform the method, the method comprising:

receiving, by a key service executing on the system, a key generation request, the key generation request comprising a request for the key service to generate at least one cryptographic key;

generating, by the key service based on the key generation request, the at least one requested cryptographic key, wherein generating the at least one cryptographic key comprises:

generating one or more candidate cryptographic keys, the one or more candidate cryptographic keys being, at least in part, randomly generated;

comparing the one or more candidate cryptographic keys with one or more key generation rules to determine whether at least one cryptographic key of the one or more candidate cryptographic keys compiles with one or more requirements specified in the one or more key generation rules;

identifying at least one generated cryptographic key of the one or more generated candidate cryptographic keys that complies with the one or more requirements specified in the one or more key generation rules; and

sending, by the key service, a key provisioning response to the key generation request, the key provisioning response comprising the identified at least one generated cryptographic key.

2. The method of claim 1 , wherein the key generation request is received from a system separate from the system executing the key service.

3. The method of claim 1 , wherein the key service comprises a system-level service and the key generation request is received from an application executing on the system.

4. The method of claim 1 , wherein the one or more requirements specified in the one or more key generation rules comprise at least one requirement that a cryptographic key satisfying the at least one requirement comprises at least one specified pattern.

5. The method of claim 4 , wherein the one or more requirements specified in the one or more key generation rules comprise at least one requirement that the cryptographic key satisfying the at least one requirement comprises the at least one specified pattern in a specified location within the cryptographic key.

6. The method of claim 1 , wherein the one or more requirements specified in the one or more key generation rules comprise at least one requirement that a derivative of a cryptographic key satisfying the at least one requirement comprises at least one specified pattern.

7. The method of claim 6 , wherein the one or more requirements specified in the one or more key generation rules comprise at least one requirement that the derivative of a cryptographic key satisfying the at least one requirement comprises the at least one specified pattern in a specified location within the derivative of the cryptographic key.

8. The method of claim 6 , wherein the derivative of the cryptographic key comprises a hash of the cryptographic key.

9. The method of claim 1 , wherein the method further comprises receiving binding data.

10. The method of claim 9 , wherein the binding data is included in the key generation request.

11. The method of claim 9 , wherein the binding data comprises identification information.

12. The method of claim 11 , wherein the identification information comprises an e-mail address.

13. The method of claim 9 , wherein the one or more requirements specified in the one or more key generation rules comprise at least one requirement that a cryptographic key satisfying the at least one requirement has a specified relationship with the binding data.

14. The method of claim 13 , wherein the specified relationship comprises the cryptographic key and the binding data both comprising at least one specified pattern.

15. The method of claim 14 , wherein the specified relationship comprises the cryptographic key and the binding data both comprising the at least one specified pattern in a specified location.

16. The method of claim 9 , wherein the one or more requirements specified in the one or more key generation rules comprise at least one requirement that a derivative of a cryptographic key satisfying the at least one requirement has a specified relationship with a derivative of the binding data.

17. The method of claim 16 , wherein the derivative of the cryptographic key comprises a hash of the cryptographic key and the derivative of the binding data comprises a hash of the binding data.

18. The method of claim 16 wherein the specified relationship comprises the derivative of the cryptographic key and the derivative of the binding data both comprising at least one specified pattern.

19. The method of claim 18 , wherein the specified relationship comprises the derivative of the cryptographic key and the derivative of the binding data both comprising the at least one specified pattern in a specified location.

20. The method of claim 1 , wherein the key generation request specifies at least one of the one or more key generation rules.

Assignments (2)
SECURITY INTEREST Recorded Mar 25, 2026
From: INTERTRUST TECHNOLOGIES CORPORATION
To: JAMSTER CAPITAL LLC
Reel/Frame 075228/0345 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 26, 2024
From: INTERTRUST TECHNOLOGIES CORPORATION
To: JERA CO., INC.
Reel/Frame 068173/0212 →
Continuity (3)
Continuation 17199399 · Mar 11, 2021
Provisional Application 63082855 · Sep 24, 2020
Related Publication 20240080188A1 · Mar 7, 2024
References Cited (6)
US 10193690B1 · Self · 2019 [cited by examiner]
US 20210312546A1 · Yim · 2021 [cited by examiner]
US 20210391990A1 · McElveen · 2021 [cited by examiner]
US 20220231848A1 · Zhang · 2022 [cited by examiner]
Non-Final Office Action dated Apr. 6, 2023 in U.S. Appl. No. 17/199,399. [cited by applicant]
Notice of Allowance dated Aug. 9, 2023 in U.S. Appl. No. 17/199,399. [cited by applicant]