IP Library › Granted Patent US 12,739,254
Granted Patent B2
US 12,739,254 · App. 18/772,324 · Granted Sep 15, 2026

Secure keyboard resource limiting access of user input to destination resource requesting the user input

Inventors: Billy Gayle Moon (Apex, NC); William Victor Moon (Chapel Hill, NC); Fabian Reddig (Mebane, NC)
Assignee: WhiteStar Communications, Inc.
H04L63/10G06F9/54G06F21/604H04L9/30H04L63/0442G06F3/02G06F3/04886H04L2209/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,254
App. No.
18/772,324
Filed
Jul 15, 2024
Granted
Sep 15, 2026
Kind
B2
Art Unit
2499
USPC
713/164
Abstract

A secure keyboard resource executed in a network device detects a user input, and generates a user input data structure representing the user input relative to input options presented to the user, the user input data structure based on the secure keyboard resource identifying a position of the user input relative to the input options. The secure keyboard resource sends the user input data structure to one or more executable destination resources, having requested supply of the user input data structure responsive to a user selection, only via a corresponding data path providing the destination resource with access to the user input data structure, for execution of a service by the one or more executable destination resources based on the user input data structure. The secure keyboard resource thus minimizes spying by limiting access of the user input data structure to the destination resource via the data path.

Claims (80)

1 . A method comprising:

detecting, by a secure keyboard resource executed in a network device, a user input by a user via a device interface circuit of the network device;

generating, by the secure keyboard resource executed in the network device, a user input data structure representing the user input relative to input options presented to the user, the user input data structure based on the secure keyboard resource identifying a position of the user input relative to the input options;

detecting, by the network device, an authorization by the user of one or more executable destination resources to receive the user input data structure; and

sending, by the secure keyboard resource executed in the network device, the user input data structure to the one or more executable destination resources authorized by the user and having requested supply of the user input data structure responsive to a user selection, wherein the sending of the user input data structure is only via a corresponding data path providing the one or more executable destination resources with access to the user input data structure, for execution of a service by the one or more executable destination resources based on the user input data structure;

the sending of the user input data structure by the secure keyboard resource only via the data path to the one or more executable destination resources preventing any unauthorized sending of the user input data structure to any unauthorized resource.

2 . The method of claim 1 , wherein:

the one or more executable destination resources is executed in the network device;

the data path is an inter-process communications channel established by a device operating system, executed by the network device, according to a prescribed operating system inter-process security policy.

3 . The method of claim 2 , further comprising:

receiving, by the secure keyboard resource from the device operating system, a first notification of an input field having a prescribed input type at a memory location allocated by the device operating system; and

causing a presentation of the input options to the user based on the prescribed input type;

the sending including writing the user input data structure into the memory location, and sending a second notification that causes the device operating system to transfer access of the user input data structure in the memory location to the one or more executable destination resources.

4 . The method of claim 3 , further comprising encrypting, by the secure keyboard resource, the user input data structure into an encrypted data structure based on a public key received by the secure keyboard resource and the prescribed input type indicating encryption support;

the writing including writing, into the memory location, the encrypted data structure as an encrypted representation of the user input data structure;

the second notification enabling a security adapter resource associated with the one or more executable destination resources to decrypt the encrypted data structure, for delivery of the user input data structure following decryption thereof to the one or more executable destination resources.

5 . The method of claim 1 , further comprising:

receiving, by the secure keyboard resource, a public key generated by a secure executable container associated with the one or more executable destination resources; and

encrypting the user input data structure into an encrypted data structure, using the public key, for transfer of the encrypted data structure via the data path.

6 . The method of claim 5 , wherein the secure executable container is executed in the network device, the method further comprising:

generating, by the secure keyboard resource, a plurality of user input data structures representing respective user inputs;

generating, by the secure keyboard resource, a sequence of encrypted data structures based on the respective user input data structures;

generating, by the secure keyboard resource, a Gaussian noise stream based on generating a plurality of encrypted noise data structures, and inserting the encrypted noise data structures within the sequence of encrypted data structures prior to sending the Gaussian noise stream via the data path.

7 . The method of claim 6 , further comprising:

decrypting, by a security adapter resource executed in the network device, the encrypted data structures and the encrypted noise data structures in the Gaussian noise stream received from the data path;

discarding, by the security adapter resource, the encrypted noise data structures following decryption thereof; and

delivering the plurality of user input data structures decrypted from the Gaussian noise stream to the one or more executable destination resources executed in the network device.

8 . The method of claim 5 , wherein:

the secure executable container is executed in a second network device that is reachable via a secure peer-to-peer data network that provides the data path; and

the receiving includes receiving the public key, generated by the secure executable container executed in the second network device, according to a prescribed salutation protocol.

9 . The method of claim 8 , wherein:

the generating includes inserting the user input data structure as an updated hypercontent field of a message object that is referenced in a conversation object allocated for secure keyboard communications with the one or more executable destination resources;

the inserting causing an instant update of the message object by the secure executable container via the secure peer-to-peer data network.

10 . The method of claim 1 , further comprising:

detecting, by the secure keyboard resource, a sequence of the user inputs; and

generating, by the secure keyboard resource, an auto-assist input as a recommendation that replaces the sequence of user inputs, the generating based on auto-assist analytics executed within the network device without any transmission of any of the sequence of the user inputs to any analytics resource outside control by a federation entity securely allocated to the user and comprising the network device; and

sending, by the secure keyboard resource, a second data structure specifying the recommendation to the one or more executable destination resources via the data path.

11 . One or more non-transitory tangible media encoded with logic for execution by a machine and when executed by the machine operable for:

detecting, by a secure keyboard resource executed by the machine implemented as a network device, a user input by a user via a device interface circuit of the network device;

generating, by the secure keyboard resource, a user input data structure representing the user input relative to input options presented to the user, the user input data structure based on the secure keyboard resource identifying a position of the user input relative to the input options;

detecting an authorization by the user of one or more executable destination resources to receive the user input data structure; and

sending, by the secure keyboard resource, the user input data structure to the one or more executable destination resources authorized by the user and having requested supply of the user input data structure responsive to a user selection, wherein the sending of the user input data structure is only via a corresponding data path providing the one or more executable destination resources with access to the user input data structure, for execution of a service by the one or more executable destination resources based on the user input data structure;

the sending of the user input data structure by the secure keyboard resource only via the data path to the one or more executable destination resources preventing any unauthorized sending of the user input data structure to any unauthorized resource.

12 . The one or more non-transitory tangible media of claim 11 , wherein:

the one or more executable destination resources is executed in the network device;

the data path is an inter-process communications channel established by a device operating system, executed by the network device, according to a prescribed operating system inter-process security policy.

13 . The one or more non-transitory tangible media of claim 12 , further operable for:

receiving, by the secure keyboard resource from the device operating system, a first notification of an input field having a prescribed input type at a memory location allocated by the device operating system; and

causing a presentation of the input options to the user based on the prescribed input type;

the sending including writing the user input data structure into the memory location, and sending a second notification that causes the device operating system to transfer access of the user input data structure in the memory location to the one or more executable destination resources.

14 . The one or more non-transitory tangible media of claim 13 , further operable for encrypting, by the secure keyboard resource, the user input data structure into an encrypted data structure based on a public key received by the secure keyboard resource and the prescribed input type indicating encryption support;

the writing including writing, into the memory location, the encrypted data structure as an encrypted representation of the user input data structure;

the second notification enabling a security adapter resource associated with the one or more executable destination resources to decrypt the encrypted data structure, for delivery of the user input data structure following decryption thereof to the one or more executable destination resources.

15 . The one or more non-transitory tangible media of claim 11 , further operable for:

receiving, by the secure keyboard resource, a public key generated by a secure executable container associated with the one or more executable destination resources; and

encrypting the user input data structure into an encrypted data structure, using the public key, for transfer of the encrypted data structure via the data path.

16 . The one or more non-transitory tangible media of claim 15 , further operable for:

generating, by the secure keyboard resource, a plurality of user input data structures representing respective user inputs;

generating, by the secure keyboard resource, a sequence of encrypted data structures based on the respective user input data structures;

generating, by the secure keyboard resource, a Gaussian noise stream based on generating a plurality of encrypted noise data structures, and inserting the encrypted noise data structures within the sequence of encrypted data structures prior to sending the Gaussian noise stream via the data path.

17 . The one or more non-transitory tangible media of claim 16 , further operable for:

decrypting, by a security adapter resource executed in the network device, the encrypted data structures and the encrypted noise data structures in the Gaussian noise stream received from the data path;

discarding, by the security adapter resource, the encrypted noise data structures following decryption thereof; and

delivering the plurality of user input data structures decrypted from the Gaussian noise stream to the one or more executable destination resources executed in the network device.

18 . The one or more non-transitory tangible media of claim 11 , further operable for:

detecting, by the secure keyboard resource, a sequence of the user inputs; and

generating, by the secure keyboard resource, an auto-assist input as a recommendation that replaces the sequence of user inputs, the generating based on auto-assist analytics executed within the network device without any transmission of any of the sequence of the user inputs to any analytics resource outside control by a federation entity securely allocated to the user and comprising the network device; and

sending, by the secure keyboard resource, a second data structure specifying the recommendation to the one or more executable destination resources via the data path.

19 . An apparatus implemented as a physical machine, the apparatus comprising:

non-transitory machine readable media configured for storing executable machine readable code comprising a secure keyboard resource;

a device interface circuit configured for detecting a user input by a user of the apparatus, the apparatus implemented as a network device executing communications with a second network device via a data network; and

a processor circuit configured for executing the machine readable code, and when executing the machine readable code operable for:

detecting, by the secure keyboard resource, the user input,

generating, by the secure keyboard resource, a user input data structure representing the user input relative to input options presented to the user, the user input data structure based on the secure keyboard resource identifying a position of the user input relative to the input options,

detecting, by the network device, an authorization by the user of one or more executable destination resources to receive the user input data structure, and

sending, by the secure keyboard resource, the user input data structure to the one or more executable destination resources authorized by the user and having requested supply of the user input data structure responsive to a user selection, wherein the sending of the user input data structure is only via a corresponding data path providing the one or more executable destination resources with access to the user input data structure, for execution of a service by the one or more executable destination resources based on the user input data structure;

the sending of the user input data structure by the secure keyboard resource only via the data path to the one or more executable destination resources preventing any unauthorized sending of the user input data structure to any unauthorized resource.

20 . The apparatus of claim 19 , wherein the processor circuit is further configured for:

receiving, by the secure keyboard resource, a public key generated by a secure executable container associated with the one or more executable destination resources; and

encrypting the user input data structure into an encrypted data structure, using the public key, for transfer of the encrypted data structure via the data path.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2024
From: MOON, BILLY GAYLE, MR.; MOON, WILLIAM VICTOR, MR.; REDDIG, FABIAN, MR.
To: WHITESTAR COMMUNICATIONS, INC.
Reel/Frame 067984/0168 →
Continuity (2)
Continuation 17496164 · Oct 7, 2021
Related Publication 20240372861A1 · Nov 7, 2024
References Cited (49)
US 7792989B2 · Toebes et al. · 2010 [cited by applicant]
US 7818607B2 · Turner et al. · 2010 [cited by applicant]
US 8407603B2 · Christie · 2013 [cited by examiner]
US 8903716B2 · Chen · 2014 [cited by examiner]
US 11582201B1 · Moon · 2023 [cited by applicant]
US 11582241B1 · Moon · 2023 [cited by applicant]
US 11784813B2 · Moon · 2023 [cited by examiner]
US 11792186B2 · Moon · 2023 [cited by applicant]
US 11924177B2 · Moon · 2024 [cited by applicant]
US 20060190532A1 · Chadalavada · 2006 [cited by examiner]
US 20090177981A1 · Christie · 2009 [cited by examiner]
US 20140101716A1 · Touboul · 2014 [cited by examiner]
US 20180091510A1 · Erez · 2018 [cited by examiner]
US 20180278611A1 · Tan · 2018 [cited by examiner]
US 20190334906A1 · Morris · 2019 [cited by examiner]
US 20210026535A1 · Moon · 2021 [cited by applicant]
US 20210026976A1 · Moon · 2021 [cited by applicant]
US 20210028940A1 · Moon · 2021 [cited by applicant]
US 20210028943A1 · Moon · 2021 [cited by applicant]
US 20210029092A1 · Moon · 2021 [cited by applicant]
US 20210029125A1 · Moon · 2021 [cited by applicant]
US 20210029126A1 · Moon · 2021 [cited by applicant]
US 20210081524A1 · Moon · 2021 [cited by applicant]
US 20210297373A1 · Mikhailov · 2021 [cited by examiner]
US 20220321564A1 · Cossel · 2022 [cited by examiner]
US 20220399995A1 · Moon · 2022 [cited by applicant]
US 20230012373A1 · Moon · 2023 [cited by applicant]
US 20230020504A1 · Moon · 2023 [cited by applicant]
US 20230033192A1 · Sutherland et al. · 2023 [cited by applicant]
US 20230036806A1 · Moon · 2023 [cited by examiner]
US 20230111701A1 · Moon et al. · 2023 [cited by applicant]
“4-Way Handshake”, Jan. 24, 2019, [online], [retrieved on Jun. 1, 2021]. Retrieved from the Internet: URL: <https://www.wifi-professionals.com/2019/01/4-way-handshake>, pp. 1-21. [cited by applicant]
Thubert, Ed., et al., “Address Protected Neighbor Discovery for Low-Power and Lossy Networks”, [online], 6lo Internet Draft, Feb. 23, 2018, [retrieved on Oct. 30, 2018]. Retrieved from the Internet: URL: <https://tools.… [cited by applicant]
Lehembre, “Wi-Fi-security—WEP, WPA and WPA2”, Jun. 2005, [online], [retrieved on Jun. 1, 2021]. Retrieved from the Internet: URL: <http://tele1.dee.fct.unl. pt/rit2_2015_2016/files/hakin9_wifi_EN. pdf>, 14 pages. [cited by applicant]
Leach et al., “A Universally Unique IDentifier (UUID) URN Namespace”, Network Working Group, Request for Comments: 4122, Jul. 2005, [online], [retrieved on May 20, 2021]. Retrieved from the Internet: URL: <https://www.r… [cited by applicant]
Winter, Ed., et al., “RPL: IPv6 Routing Protocol for Low-Power and Lossy Networks”, Internet Engineering Task Force (IETF), Request for Comments: 6550, Mar. 2012, pp. 1-157. [cited by applicant]
Thubert, Ed., et al., “Registration Extensions for IPv6 over Low-Power Wireless Personal Area Network (6LoWPAN) Neighbor Discovery”, [online], Internet Engineering Task Force (IETF), Request for Comments: 8505, Nov. 201… [cited by applicant]
Wikipedia, “Pretty Good Privacy”, May 16, 2021, [online], [retrieved on Jul. 22, 2021]. Retrieved from the Internet: URL: <https://en.wikipedia.org/w/index.php?title=Pretty_Good_Privacy&oldid=1023418223>, pp. 1-8. [cited by applicant]
Arends et al., “DNS Security Introduction and Requirements”, Network Working Group, Request for Comments: 4033, Mar. 2005, [online], [retrieved on Sep. 14, 2021]. Retrieved from the Internet: URL: <https://www.rfc-edito… [cited by applicant]
Wikipedia, “Sandbox (Computer Security)”, Sep. 26, 2021, [online], [retrieved on Oct. 1, 2021]. Retrieved from the Internet: URL: <https://en.wikipedia.org/wiki/Sandbox_(computer_security)>, pp. 1-4. [cited by applicant]
Callas et al., “OpenPGP Message Format”, Network Working Group, Request for Comments: 4880, Nov. 2007, [online], [retrieved on Oct. 28, 2021]. Retrieved from the Internet: URL: <https://www.rfc-editor.org/rfc/pdfrfc/rfc… [cited by applicant]
Society video, “Society Secure Messenger: The world's most secure way to chat”, Text and Screenshots, (Mar. 10, 2020), [online], [Retrieved on Mar. 3, 2022]. Retrieved from the Internet: URL: <https://www.youtube.com/wa… [cited by applicant]
Society video, “Complete AI Security”, Text, Transcript, and Screenshots, (Mar. 19, 2020), [online], [Retrieved on Mar. 3, 2022]. Retrieved from the Internet: URL: <https://www.youtube.com/watch?v=5U2khXXcDMo>, 16 pages. [cited by applicant]
Society video, “Society's Best in Class Security and the Cohort System”, Text, Transcript, and Screenshots, (Mar. 26, 2020), [online], [Retrieved on Mar. 3, 2022]. Retrieved from the Internet: URL: <https://www.youtube.… [cited by applicant]
Society video, “Society Tutorial 6 : Advanced Controls”, Transcript and Screenshots, (Apr. 6, 2020), [online], [Retrieved on Mar. 3, 2022]. Retrieved from the Internet: URL: <https://www.youtube.com/watch?v=5jlVTcQmADw>… [cited by applicant]
Society video, “Society Tutorial 5: Conversation Controls”, Transcript and Screenshots, (Apr. 6, 2020), [online], [Retrieved on Mar. 4, 2022]. Retrieved from the Internet: URL: <https://www.youtube.com/watch?v=v6uDbsFPq… [cited by applicant]
Society video, “Creating a Conversation”, Transcript and Screenshots, (Apr. 6, 2020), [online], [Retrieved on Mar. 4, 2022]. Retrieved from the Internet: URL: <https://www.youtube.com/watch?v=irvX9ZyaPLM>, 4 pages. [cited by applicant]
Society video, “Society Tutorial Part 7 : Notifications and Misc”, Transcript and Screenshots, (Apr. 6, 2020), [online], [Retrieved on Mar. 4, 2022]. Retrieved from the Internet: URL: <https://www.youtube.com/watch?v=mu… [cited by applicant]
Society video, “Society Tutorial 1: Setting Up and Making a Connection”, Transcript and Screenshots, (Jun. 29, 2020), [online], [Retrieved on Mar. 4, 2022]. Retrieved from the Internet: URL: <https://www.youtube.com/wat… [cited by applicant]