IP Library › Granted Patent US 12,200,122
Granted Patent B1
US 12,200,122 · App. 17/396,089 · Granted Jan 14, 2025

Systems and methods for advanced quantum-safe PKI credentials for authentications

Inventors: Massimiliano Pala (Superior, CO); Bernardo Huberman (Palo Alto, CA); Jing Wang (Broomfield, CO)
Assignee: Cable Television Laboratories, Inc.
H04L9/0891H04L9/3242H04L9/3268H04L63/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,200,122
App. No.
17/396,089
Granted
Jan 14, 2025
Kind
B1
Abstract

A server device is provided for authenticating client devices on a communication network. The server device includes a transceiver configured for operable communication with at least one client of the communication network, and a processor including a memory configured to store computer-executable instructions. When executed by the processor, the instructions cause the server device to receive an authentication request from a client device, generate a seed for a first key for the client device if the client device authenticates, transmit the seed for the first key to the client device, receive a hash of the first key from the client device, and validate the first key based on the hash of the first key.

Claims (66)

1. A server device for authenticating client devices on a communication network, comprising:

a transceiver configured for operable communication with at least one client device of the communication network;

a processor including a memory configured to store computer-executable instructions, which, when executed by the processor, cause the server device to:

receive an authentication request from a client device, wherein the authentication request is received prior to a transition to post-quantum cryptography;

authenticate the client device based upon the authentication request;

if the client device is authenticated, generate a seed for a first post quantum key for the client device;

if the client device is authenticated, encrypt the seed for the first post quantum key;

if the client device is authenticated, transmit, to the client device, an authentication reply including the encrypted seed for the first post quantum key and one or more operations to be performed on the seed for first post quantum key to generate the first post quantum key, wherein the authentication reply is transmitted prior to a transition to post-quantum cryptography;

receive a hash of the first post quantum key from the client device, wherein the client device decrypted the seed and performed the one or more operations on the seed to generate the first post quantum key prior to generating the hash of the first post quantum key; and

validate the first post quantum key based upon the hash of the first post quantum key.

2. The server device of claim 1 , wherein the authentication reply also includes at least one non-reversible operation for the client device to perform on the seed of the first post quantum key to generate the first post quantum key.

3. The server device of claim 1 , wherein the authentication reply further includes a hash of a network key for validation purposes.

4. The server device of claim 1 , wherein the server device is further programmed to:

receive an encrypted network key from the client device;

decrypt and store the network key;

generate a hash of the network key; and

transmit the hash of the network key to the client device for validation.

5. The server device of claim 4 , wherein the server device is further programmed to:

receive at least one operation with the encrypted network key; and

perform the at least one operation on the encrypted network key to generate the network key.

6. The server device of claim 1 , wherein the seed for the first post quantum key is transmitted prior to availability of post-quantum cryptography.

7. The server device of claim 1 , wherein the server device is further programmed to:

determine an update to the first post quantum key;

transmit the update to the first post quantum key to the client device;

receive a hash of the updated first post quantum key from the client device; and

validate the updated first post quantum key based on the hash of the updated first post quantum key.

8. The server device of claim 7 , wherein the update includes one or more non-reversible operations to be performed on the first post quantum key to generate the updated first post quantum key.

9. The server device of claim 7 , wherein the update includes an update key to be applied to the first post quantum key to generate the updated first post quantum key.

10. A server device for authenticating client devices on a communication network, comprising:

a transceiver configured for operable communication with at least one client device of the communication network;

a processor including a memory configured to store computer-executable instructions, which, when executed by the processor, cause the server device to:

receive an authentication request from a client device, wherein the client device stores a first post quantum key, wherein the authentication request is received prior to a transition to post-quantum cryptography;

authenticate the client device based upon the authentication request;

if the client device is authenticated, determine an update to the first post quantum key;

if the client device is authenticated, encrypt the update for the first post quantum key;

if the client device is authenticated, transmit, to the client device, an authentication reply including the encrypted update to the first post quantum key and one or more operations to be performed on the update for first post quantum key and the first post quantum key to generate the updated first post quantum key, wherein the authentication reply is transmitted prior to a transition to post-quantum cryptography;

receive a hash of the updated first post quantum key from the client device, wherein the client device decrypted the update for the first post quantum key and performed the one or more operations on the update for the first post quantum key and the first post quantum key prior to generating the hash of the updated first post quantum key; and

validate the updated first post quantum key based on the hash of the updated first post quantum key.

11. The server device of claim 10 , wherein the update includes one or more non-reversible operations to be performed on the first post quantum key to generate the updated first post quantum key.

12. The server device of claim 10 , wherein the update includes an update key to be applied to the first post quantum key to generate the updated first post quantum key.

13. The server device of claim 10 , wherein the update for the first post quantum key further includes an encrypted version of the updated first post quantum key.

14. The server device of claim 10 , wherein the server device is further programmed to:

generate a seed for the first post quantum key for the client device;

transmit the seed for the first post quantum key to the client device;

receive a hash of the first post quantum key from the client device; and

validate the first post quantum key based on the hash of the first post quantum key.

15. The server device of claim 14 , wherein the server device is further programmed to transmit, to the client device, at least one operation for the client device to perform on the seed of the first post quantum key to generate the first post quantum key.

16. The server device of claim 14 , wherein the seed for the first post quantum key is transmitted prior to availability of post-quantum cryptography.

17. A client device for communicating on a communication network, comprising:

a transceiver configured for operable communication with at least one server device of the communication network;

a processor including a memory configured to store computer-executable instructions, which, when executed by the processor, cause the server device to:

transmit an authentication request to a server device, wherein the authentication request is transmitted prior to a transition to post-quantum cryptography;

receive an authentication reply including an encrypted seed for a first post quantum key and one or more operations to be performed on the seed for first post quantum key to generate the first post quantum key from the server device, wherein the authentication reply is received prior to a transition to post-quantum cryptography;

decrypt the seed for the first post quantum key;

perform the one or more operations on the seed of the first post quantum key to generate the first post quantum key;

store the first post quantum key;

generate a hash of the first post quantum key; and

transmit the hash of the first post quantum key for validation to the server device.

18. The client device of claim 17 , wherein the client device is further programmed to:

receive, from the server device, at least one non-reversible operation for the client device to perform on the seed of the first post quantum key to generate the first post quantum key; and

generate the first post quantum key by performing the at least one non-reversible operation on the seed.

19. The client device of claim 17 , wherein the authentication reply further includes a hash of a network key for validation purposes.

20. The client device of claim 17 , wherein the client device is further programmed to:

transmit an encrypted network key to the server device;

receive a hash of a network key from the server device, wherein the network key is based on the encrypted network key; and

validate the network key based on the hash.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 2, 2021
From: PALA, MASSIMILIANO; HUBERMAN, BERNARDO; WANG, JING
To: CABLE TELEVISION LABORATORIES, INC.
Reel/Frame 057369/0412 →
Continuity (1)
Provisional Application 63062228 · Aug 6, 2020
References Cited (127)
US 6931537B1 · Takura et al. · 2005 [cited by applicant]
US 8001381B2 · Metke et al. · 2011 [cited by applicant]
US 8855316B2 · Wiseman · 2014 [cited by examiner]
US 9912486B1 · Sharifi Mehr · 2018 [cited by applicant]
US 10205595B2 · Frascadore · 2019 [cited by applicant]
US 10250590B2 · Gryb et al. · 2019 [cited by applicant]
US 10454904B2 · Huh et al. · 2019 [cited by applicant]
US 10615969B1 · Griffin · 2020 [cited by examiner]
US 11115217B2 · Shekh-Yusef et al. · 2021 [cited by applicant]
US 11171964B1 · Huang et al. · 2021 [cited by applicant]
US 11218301B1 · Shea · 2022 [cited by examiner]
US 11405789B1 · Wei et al. · 2022 [cited by applicant]
US 11456867B2 · Schmatz · 2022 [cited by examiner]
US 11552806B2 · Pala · 2023 [cited by applicant]
US 11582031B2 · Wang et al. · 2023 [cited by applicant]
US 11599862B1 · Hecht et al. · 2023 [cited by applicant]
US 11616645B1 · Wang et al. · 2023 [cited by applicant]
US 12028324B1 · Pala · 2024 [cited by applicant]
US 20020199001A1 · Wenocur et al. · 2002 [cited by applicant]
US 20030172269A1 · Newcombe · 2003 [cited by applicant]
US 20060136714A1 · Yagi et al. · 2006 [cited by applicant]
US 20060222180A1 · Elliott · 2006 [cited by applicant]
US 20080031459A1 · Voltz et al. · 2008 [cited by applicant]
US 20090016736A1 · Beal et al. · 2009 [cited by applicant]
US 20090031141A1 · Pearson et al. · 2009 [cited by applicant]
US 20090163176A1 · Hasegawa · 2009 [cited by applicant]
US 20090316910A1 · Maeda et al. · 2009 [cited by applicant]
US 20100049975A1 · Parno et al. · 2010 [cited by applicant]
US 20100161817A1 · Xiao et al. · 2010 [cited by applicant]
US 20110010547A1 · Noda · 2011 [cited by applicant]
US 20110126011A1 · Choi · 2011 [cited by examiner]
US 20120177201A1 · Ayling · 2012 [cited by examiner]
US 20120272056A1 · Ganesan · 2012 [cited by examiner]
US 20130083926A1 · Hughes · 2013 [cited by examiner]
US 20130251145A1 · Lowans · 2013 [cited by examiner]
US 20130310006A1 · Chen et al. · 2013 [cited by applicant]
US 20130318343A1 · Bjarnason et al. · 2013 [cited by applicant]
US 20140014715A1 · Moran et al. · 2014 [cited by applicant]
US 20140289520A1 · Tanizawa et al. · 2014 [cited by applicant]
US 20150288517A1 · Evans · 2015 [cited by examiner]
US 20150310221A1 · Lietz et al. · 2015 [cited by applicant]
US 20160248586A1 · Hughes · 2016 [cited by examiner]
US 20170034133A1 · Korondi et al. · 2017 [cited by applicant]
US 20170063827A1 · Ricardo · 2017 [cited by examiner]
US 20170063834A1 · Gryb et al. · 2017 [cited by applicant]
US 20170149568A1 · LaGrone et al. · 2017 [cited by applicant]
US 20170214525A1 · Zhao et al. · 2017 [cited by applicant]
US 20170338951A1 · Fu · 2017 [cited by examiner]
US 20170338952A1 · Hong · 2017 [cited by examiner]
US 20180026982A1 · Wei · 2018 [cited by applicant]
US 20180041497A1 · Morishita et al. · 2018 [cited by applicant]
US 20180062842A1 · Arahira · 2018 [cited by examiner]
US 20180097640A1 · Queralt et al. · 2018 [cited by applicant]
US 20180109378A1 · Fu · 2018 [cited by examiner]
US 20180212779A1 · Bergmann · 2018 [cited by examiner]
US 20180262243A1 · Ashrafi et al. · 2018 [cited by applicant]
US 20180262504A1 · Frederick et al. · 2018 [cited by applicant]
US 20190020641A1 · Wasily et al. · 2019 [cited by applicant]
US 20190036688A1 · Wasily et al. · 2019 [cited by applicant]
US 20190036914A1 · Tzur-David · 2019 [cited by examiner]
US 20190123901A1 · Vijayanarayanan · 2019 [cited by applicant]
US 20190245690A1 · Shah et al. · 2019 [cited by applicant]
US 20190319804A1 · Mathew · 2019 [cited by examiner]
US 20190373471A1 · Li et al. · 2019 [cited by applicant]
US 20200280549A1 · Kaliski, Jr. · 2020 [cited by examiner]
US 20210044433A1 · Hay · 2021 [cited by examiner]
US 20210044976A1 · Avetisov et al. · 2021 [cited by applicant]
US 20210099292A1 · Gilton et al. · 2021 [cited by applicant]
US 20210119788A1 · Wang · 2021 [cited by applicant]
US 20220006835A1 · Gray · 2022 [cited by examiner]
US 20220094675A1 · Madisetti et al. · 2022 [cited by applicant]
US 20220231843A1 · Garcia Morchon · 2022 [cited by examiner]
US 20230014894A1 · M M · 2023 [cited by examiner]
US 20230020193A1 · Williams · 2023 [cited by examiner]
US 20230206198A1 · Hecht et al. · 2023 [cited by applicant]
CA 3154434A1 · 2021 [cited by applicant]
CN 104660602A · 2015 [cited by applicant]
CN 107204812A · 2017 [cited by applicant]
CN 107404461A · 2017 [cited by examiner]
CN 114631049A · 2022 [cited by applicant]
EP 1927209A1 · 2008 [cited by applicant]
EP 2164189A1 · 2010 [cited by applicant]
EP 3432509A1 · 2019 [cited by applicant]
JP 2007288694A · 2007 [cited by applicant]
JP 2012080229A · 2012 [cited by applicant]
WO 2011134507A1 · 2011 [cited by applicant]
WO 2016073552A1 · 2016 [cited by applicant]
The Internet Engineering Task Force (IETF)—IETF RFC 5280. Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile, edited by W. Polk et al., May 2008. Also available at https:/… [cited by applicant]
Aes16: Markus Grassl, Brandon Langenberg, Martin Roetteler, and Rainer Stein-wandt. Applying Grover's Algorithm to AES: Quantum Resource Estimates. In PQCrypto, vol. 9606 of Lecture Notes in Computer Science, pp. 29-43.… [cited by applicant]
Aes20: Xavier Bonnetain, María Naya-Plasencia and André Schrottenloher. Quantum Security Analysis of AES. IACR Transactions on Symmetric Cryptology vol. 0, No. 0, pp. 1-3, Year: 2020. [cited by applicant]
Amaral Gustavo C., et al.: “WDM-PON Monitoring with Tunable Photon Counting OTDR,” IEEE Photonics Technology Letters, IEEE, USA, vol. 26, No. 13, Jul. 1, 2014 (Jul. 1, 2014), pp. 1279-1282, XOP011550969, ISSN: 1041-1135… [cited by applicant]
Burstinghaus-Steinbach, K., Kraus, C., Niederhagen, R., and Schneider, M., 2020, October. Post-quantum TLS on embedded systems: Integrating and evaluating kyber and sphincs+ with mbed tls. In Proceedings of the 15th ACM… [cited by applicant]
Chen et al.; Metropolitan all-pass and inter-city quantum communication network; Dec. 2010; Optical society of America; pp. 1-9. (Year: 2010). [cited by applicant]
Choi, P. S. et al.: “Quantum key distribution on a 10Gb/s WDM-PON,” Optical Fiber Communication (OFC), Collocated National Fiber Optic Engineers Conference, 2010 Conference on (OFC/NFOEC), IEEE, Piscataway, NJ, USA, Mar… [cited by applicant]
Com20: M. Pala. Composite Public Keys and Signatures, IETF I-D 03. Feb. 5, 2019. [cited by applicant]
Doc31: Data-Over-Cable Service Interface Specifications, DOCSIS 3.1, Security Specifications. CableLabs Publication, 2020. Available as CM-SP-SECv3.1-IO9-200407; Year: 2020. [cited by applicant]
Doc40: Data-Over-Cable Service Interface Specifications, DOCSIS 4.0, Security Specifications. CableLabs Publication, 2019. Available as CM-SP-SECv4.0-IO1-190815; Year: 2019. [cited by applicant]
Dr99: Joan Daemen and Vincent Rijmen. AES proposal: Rijndael, Year: 1999. [cited by applicant]
Elboukhari, Mohamed et al. “Integration of Quantum Key Distribution in the TLS Protocol.” IJCSNS International Journal of Computer Science and Network Security, vol. 9. No. 12, (2009). [cited by applicant]
Fatima et al., X.509 and PGP Public Key Infrastructure Methods: A Critical Review, 2015, IFCSNS International Journal of Computer Science and Network Security, vol. 15, No. 5: pp. 55-59 (Year: 2015). [cited by applicant]
Gro96: Lov K. Grover. A Fast Quantum Mechanical Algorithm for Database Search. In Gary L. Miller, editor, Proceedings of the Twenty-Eighth Annual ACM Symposium on the Theory of Computing, Philadelphia, Pennsylvania, USA… [cited by applicant]
Harn, L., and Rn, J., 2011. Generalized digital certificate for user authentication and key establishment for secure communications. IEEE Transactions on Wireless Communications, 10(7), pp. 2372-2379 (Year: 2011). [cited by applicant]
International Search Report is corresponding application PCTUS2056172 (Mar. 3, 2021). [cited by applicant]
ITU509: ITU-T Recommendation X.509 (2005) | ISO/IEC 9594-8:2005, Information Technology—Open Systems Interconnection—The Directory: Public-key and attribute certificate frameworks; Year: 2005. [cited by applicant]
Kumavor P. D., et al.: “Comparison of Four Multi-User Quantum Key Distribution Schemes Over Passive Optical Networks,” Journal of Lightwave Technology, IEEE, USA, vol. 23, No. 1, Jan. 1, 2005 (Jan. 1, 2005), p. 168- j27… [cited by applicant]
Luo et al.; Time Synchronization over Ethernet Passive Optical Networks; Oct. 2012; IEEE; pp. 1-7 (Year: 2012). [cited by applicant]
M. Bagnulo. “Stateful NAT64: Network Address Protocol Translation from IPV6 Clients o IPv4 Servers” Internet Engineering Task For (IETF), ISSN: 2070-1721, p. 10/39, Apr. 2011 (Year: 2011). [cited by applicant]
Ntru10: American National Standards Institute (2010) Ansi X9.98-2010—Lattice-Based Polynomial Public Key Establishment Algorithm for the Financial Services Industry (ANSI, New York City, United States), available at htt… [cited by applicant]
Ntru9: Institute of Electrical and Electronics Engineers (2009) IEEE Standard1363.Jan. 2008—Specification for Public Key Cryptographic Techniques Based on Hard Problems over Lattices (IEEE, Piscataway, New Jersey, Unite… [cited by applicant]
Paquin, C., Stebila, D. and Tamvada, G., 2020. Benchmarking post-quantum cryptography in TLS. In Post-Quantum Cryptography; 11th International Conference, PQCrypto 2020, Paris, France, Apr. 15-17, 2020, Proceedings 11 (… [cited by applicant]
PKCS11: Oasis Standard, S. Gleeson and C. Zimman, PKCS #11 Cryptographic Token Interface Base Specification, Version 2.40, Apr. 2015. [cited by applicant]
RFC 2986: IETF 2986, M. Nystrom, et al., PKCS #10: Certification Request Syntax Specification, Version 1.7, Nov. 2000. [cited by applicant]
RFC 3279: IETF RFC 3279, W. Polk, et al., Algorithms and Identifiers for the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile, Apr. 2002. [cited by applicant]
RFC 5272: IETF RFC 5272, J. Schaad, et al., Certificate Management over CMS (CMC), Jun. 2008. [cited by applicant]
RFC 5273: IETF RFC 5273, J. Schaad, et al., Certificate Management over CMS (CMC): Transport Protocols, Jun. 2008. [cited by applicant]
RFC 5280: IETF RFC 5280, W. Polk, et al., Cryptographic Message Syntax (CMS), May 2008. [cited by applicant]
RFC 5652: IETF RFC 5652, R. Housley, Cryptographic Message Syntax (CMS), Sep. 2009. [cited by applicant]
RFC 5758: IETF RFC 5758, Q. Dang, et al., Internet X.509 Public Key Infrastructure: Additional Algorithms and Identifiers for DSA and ECDSA, Jan. 2010. [cited by applicant]
RFC 5869: IETF RFC 5869, H. Krawczyk and P. Eronen, HMAC-based Extract-and-Expand Key Derivation Function (HKDF), May 2010. [cited by applicant]
RFC 6402: IETF RFC 6402, J. Schaad, Certificate Management over CMS (CMC) Updates, Nov. 2011. [cited by applicant]
RFC 6818: IETF RFC 6818, P. Yee, Updates to the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile, Jan. 2013. [cited by applicant]
RFC 8446: IETF RFC 8446, E. Rescorla, et al., The Transport Layer Security (TLS) Protocol, Version 1.3, Aug. 2018. [cited by applicant]
RFC 8555: IETF RFC 8555, R. Barnes, et al., Automatic Certificate Management Environment (ACME), Mar. 2019. [cited by applicant]
RFC 8696: IETF RFC 8696, R. Housley, Using Pre-Shared Key (PSK) in the Cryptographic Message Syntax (CMS), Dec. 2019. [cited by applicant]
Rphy18: Data-Over-Cable Service Interface Specifications, DCA—MHAv2. Remote PHY Specification. Available as CM-SP-R-PHY-110-180509; Year. [cited by applicant]
Sun, Y., Zhang, R., Wang, X., Gao, K. and Liu L., 2018, July. A decentralizing attribute-based signature for healthcare blockchain. In 2018 27th International conference on computer communication and networks (ICCCN) (p… [cited by applicant]
The Internet Engineering Task Force (IETF)—IETF RFC 2986. PKCS#10: Certification Request Syntax Specification Version 1.7, edited by M. Nystrom et al., Nov. 2000, available at https://datatracker.ietf.org/doc/rfc2986/. [cited by applicant]
Cited By (1)
US 12,476,984