IP Library › Granted Patent US 11,853,438
Granted Patent B2
US 11,853,438 · App. 17/488,655 · Granted Dec 26, 2023

Providing cryptographically secure post-secrets-provisioning services

Inventor: Christopher Paul Gorog (Pueblo, CO)
Assignee: BLOCKFRAME, INC.
G06F21/602G06F16/2379G06F21/604G06F21/6209G06Q10/087G06Q10/0835G06Q20/389G06Q20/401H04L9/085H04L9/0827H04L9/0861H04L9/0877H04L63/0442H04L63/0823H04L63/0838
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,853,438
App. No.
17/488,655
Granted
Dec 26, 2023
Kind
B2
Abstract

A system includes a memory device and a processor, operatively coupled to the memory device, to perform operations including receiving a request to provide a post-secrets-provisioning service with respect to a device, in response to receiving the request, determining whether to authorize the request, in response to authorizing the request, obtaining a set of secrets data corresponding to the device, and providing the post-secrets-provisioning service by performing a cryptographic function utilizing the set of secrets data.

Claims (39)

1. A system comprising:

a memory; and

a processor, operatively coupled to the memory, to perform operations comprising:

receiving a request to provide a post-secrets-provisioning service with respect to a device having a supply chain state corresponding to a supply chain associated with the device, wherein the supply chain state is one of: a manufacturing provisioning state corresponding to a manufacturing stage of the supply chain, a vendor provisioning state corresponding to a vendor stage of the supply chain, a network provisioning state corresponding to a network stage of the supply chain, or an operational state corresponding to an operational stage of the supply chain;

in response to receiving the request, determining whether to authorize the request based on a proof of ownership of the device;

in response to authorizing the request, obtaining a set of secrets data corresponding to the supply chain state of the device; and

emulating, by utilizing the set of secrets data, the device having the supply chain state to provide the post-secrets-provisioning service.

2. The system of claim 1 , further comprising a distributed ledger maintaining the proof of ownership of the device.

3. The system of claim 2 , wherein obtaining the set of secrets data comprises generating the set of secrets data using at least one of the distributed ledger or a secrets generator.

4. The system of claim 1 , wherein providing the post-secrets-provisioning service comprises at least one of: providing a data or trust verification service, providing a data production service, providing a file authorization service, or providing a service to locate a secrets and service provider system to handle the request.

5. The system of claim 4 , wherein the set of secrets data comprises a previous set of secrets data, and wherein providing the data production service comprises recovering data encrypted with the previous set of secrets data.

6. The system of claim 4 , wherein providing the file authorization service comprises:

generating, using the set of secrets data, an authorization packet comprising an encrypted version of a file; and

sending, to the device, the authorization packet to enable the device to determine whether the encrypted version of the file is valid for decryption by the device.

7. The system of claim 6 , wherein the file comprises at least one of: a document, an application, or a consumable data packet.

8. A method comprising:

receiving, by a processor, a request to provide a post-secrets-provisioning service with respect to a device having a supply chain state corresponding to a supply chain associated with the device, wherein the supply chain state is one of: a manufacturing provisioning state corresponding to a manufacturing stage of the supply chain, a vendor provisioning state corresponding to a vendor stage of the supply chain, a network provisioning state corresponding to a network stage of the supply chain, or an operational state corresponding to an operational stage of the supply chain;

in response to receiving the request, determining, by the processor, whether to authorize the request based on a proof of ownership of the device;

in response to authorizing the request, obtaining, by the processor, a set of secrets data corresponding to the supply chain state of the device; and

emulating, by the processor utilizing the set of secrets data, the device having the supply chain state to provide the post-secrets-provisioning service.

9. The method of claim 8 , wherein the proof of ownership of the device is maintained on a distributed ledger.

10. The method of claim 9 , wherein obtaining the set of secrets data comprises generating the set of secrets data using at least one of the distributed ledger or a secrets generator.

11. The method of claim 8 , wherein providing the post-secrets-provisioning service comprises at least one of: providing a data or trust verification service, providing a data production service, providing a file authorization service, or providing a service to locate a secrets and service provider system to handle the request.

12. The method of claim 11 , wherein the set of secrets data comprises a previous set of secrets data, and wherein providing the data production service comprises recovering data encrypted with the previous set of secrets data.

13. The method of claim 11 , wherein providing the file authorization service comprises:

generating, using the set of secrets data, an authorization packet comprising an encrypted version of a file; and

sending, to the device, the authorization packet to enable the device to determine whether the encrypted version of the file is valid for decryption by the device.

14. The method of claim 13 , wherein the file comprises at least one of: a document, an application, or a consumable data packet.

15. A non-transitory computer-readable storage medium comprising instructions that, when executed by a processing device, cause the processing device to perform operations comprising:

receiving a request to provide a post-secrets-provisioning service with respect to a device having a supply chain state corresponding to a supply chain associated with the device, wherein the supply chain state is one of: a manufacturing provisioning state corresponding to a manufacturing stage of the supply chain, a vendor provisioning state corresponding to a vendor stage of the supply chain, a network provisioning state corresponding to a network stage of the supply chain, or an operational state corresponding to an operational stage of the supply chain, and wherein the post-secrets-provisioning service comprises at least one of: a data or trust verification service, a data production service, a file authorization service, or a service to locate a secrets and service provider system to handle the request;

in response to receiving the request, determining whether to authorize the request based on a proof of ownership of the device maintained on a distributed ledger;

in response to authorizing the request, obtaining a set of secrets data using the distributed ledger, wherein the set of secrets data corresponds to the supply chain state of the device; and

emulating, by utilizing the set of secrets data, the device having the supply chain state to provide the post-secrets-provisioning service.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the set of secrets data comprises a previous set of secrets data, wherein the post-secrets-provisioning service is a data production service, and wherein providing the data production service comprises recovering data encrypted with the previous set of secrets data.

17. The non-transitory computer-readable storage medium of claim 15 , wherein the post-secrets-provisioning service is a file authorization service, and wherein providing the file authorization service comprises:

generating, using the set of secrets data, an authorization packet comprising an encrypted version of a file; and

sending, to the device, the authorization packet to enable the device to determine whether the encrypted version of the file is valid for decryption by the device.

18. The non-transitory computer-readable storage medium of claim 17 , wherein the file comprises at least one of: a document, an application, or a consumable data packet.

19. The non-transitory computer-readable storage medium of claim 15 , wherein obtaining the set of secrets data comprises generating the set of secrets data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2021
From: GOROG, CHRISTOPHER PAUL
To: BLOCKFRAME, INC.
Reel/Frame 057651/0213 →
Continuity (6)
Provisional Application 63086904 · Oct 2, 2020
Provisional Application 63086925 · Oct 2, 2020
Provisional Application 63086926 · Oct 2, 2020
Provisional Application 63086928 · Oct 2, 2020
Provisional Application 63123067 · Dec 9, 2020
Related Publication 20220108028A1 · Apr 7, 2022