IP Library › Granted Patent US 12,355,867
Granted Patent B2
US 12,355,867 · App. 18/115,718 · Granted Jul 8, 2025

Secure distribution of cryptographic keys and policy attributes based on geographic trusted location

Inventors: Kapildeep Singh Bakshi (Herndon, VA); Craig Thomas Hill (Sterling, VA); Raymond Allan Blair (Keizer, OR); Michael Alan Kowal (Summit, NJ); Steven M. Carter (College Grove, TN); Stephen Michael Orr (Wallkill, NY)
H04L9/083H04L9/08H04L9/14H04L9/321H04L9/40H04W12/64
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,867
App. No.
18/115,718
Granted
Jul 8, 2025
Kind
B2
Abstract

Techniques for ensuring that geographic location specific security policies are enforce for an agent or agent device. An Agent service of an agent device accesses an Agent Authentication Service for a key to initiate one or more functions of the agent device. The Agent Authentication Service determines the location of the agent device and determines whether the agent device is within an approved geographic location based on geographic location specific security policies. If the agent device is within the approved geographic location, the Agent Authentication Services accesses a Key Management Service for a cryptographic key and delivers the cryptographic key to the Agent. If the Agent Authentication Service determines that the Agent device is outside of the approved location, access to the cryptographic key is denied.

Claims (43)

1. A method for securely distributing cryptographic keys based on geographic location, the method comprising:

receiving at a proxy device, a request from an agent device for access to cryptographic keys managed by a key management service, wherein the proxy device communicates data between the agent device and the key management service, wherein the proxy device is a separate device from the agent device;

determining a geographic location of the agent device;

comparing, at the proxy device, the geographic location of the agent device with a geographic location specific security policy to determine whether the agent device is located within an approved geographic location;

receiving, at the proxy device, a digital certificate of the agent device;

using the digital certificate, validating that the agent device is allowed to be located within the approved geographic location;

in response to determining that the agent device is located within the approved geographic location and validating that the agent device is allowed to be located within the approved geographic location, sending a request to the key management service for a cryptographic key, wherein the request includes the digital certificate of the agent device that is used by the key management service to validate the agent device against the approved geographic location associated with the proxy device;

receiving, at the proxy device, encrypted data that includes the cryptographic key from the key management service; and

sending, from the proxy device, the encrypted data that includes the cryptographic key to the agent device without decrypting the encrypted data.

2. The method as in claim 1 , wherein the proxy device includes logic for determining its own location and determining the location of the agent device based on the location of the proxy device.

3. The method as in claim 1 , wherein the agent device includes logic for determining its own location.

4. The method as in claim 1 , further comprising, in response to determining that the agent device is located within the approved geographic location, sending the cryptographic key to the agent device.

5. The method as in claim 1 , further comprising accessing a policy database to determine the approved geographic location for the agent device.

6. The method as in claim 1 , wherein the cryptographic key allows access to computer memory residing on the agent device.

7. A proxy device that ensures security based on geographic location of a device, the proxy device comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving a request from an agent device for access to cryptographic keys managed by a key management service, wherein the proxy device communicates data between the agent device and the key management service, wherein the proxy device is a separate device from the agent device;

determining a geographic location of the agent device;

comparing the geographic location of the agent device with a geographic location specific security policy to determine whether the agent device is located within an approved geographic location;

receiving a digital certificate of the agent device;

using the digital certificate, validating that the agent device is allowed to be located within the approved geographic location;

in response to determining that the agent device is located within the approved geographic location and validating that the agent device is allowed to be located within the approved geographic location, sending a request to the key management service for a cryptographic key, wherein the request includes the digital certificate of the agent device that is used by the key management service to validate the agent device against the approved geographic location associated with the proxy device;

receiving encrypted data that includes the cryptographic key from the key management service; and

sending the encrypted data that includes the cryptographic key to the agent device without decrypting the encrypted data.

8. The proxy device of claim 7 , wherein the proxy device includes logic for determining its own location and determining the location of the agent device based on the location of the proxy device.

9. The proxy device of claim 7 , wherein the agent device includes logic for determining its own location.

10. The proxy device of claim 7 , the operations further comprising, in response to determining that the agent device is located within the approved geographic location, sending the cryptographic key to the agent device.

11. The proxy device of claim 7 , the operations further comprising accessing a policy database to determine the approved geographic location for the agent device.

12. The proxy device of claim 7 , wherein the cryptographic key allows access to computer memory residing on the agent device.

13. One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving at a proxy device, a request from an agent device for access to cryptographic keys managed by a key management service, wherein the proxy device communicates data between the agent device and the key management service, wherein the proxy device is a separate device from the agent device;

determining a geographic location of the agent device;

comparing, at the proxy device, the geographic location of the agent device with a geographic location specific security policy to determine whether the agent device is located within an approved geographic location;

receiving, at the proxy device, a digital certificate of the agent device;

using the digital certificate, validating that the agent device is allowed to be located within the approved geographic location;

in response to determining that the agent device is located within the approved geographic location and validating that the agent device is allowed to be located within the approved geographic location, sending a request to the key management service for a cryptographic key, wherein the request includes the digital certificate of the agent device that is used by the key management service to validate the agent device against the approved geographic location associated with the proxy device;

receiving, at the proxy device, encrypted data that includes the cryptographic key from the key management service; and

sending, from the proxy device, the encrypted data that includes the cryptographic key to the agent device without decrypting the encrypted data.

14. The one or more non-transitory computer-readable media of claim 13 , wherein the proxy device includes logic for determining its own location and determining the location of the agent device based on the location of the proxy device.

15. The one or more non-transitory computer-readable media of claim 13 , wherein the agent device includes logic for determining its own location.

16. The one or more non-transitory computer-readable media of claim 13 , further comprising, in response to determining that the agent device is located within the approved geographic location, sending the cryptographic key to the agent device.

17. The one or more non-transitory computer-readable media of claim 13 , the operations further comprising, accessing a policy database to determine the approved geographic location for the agent device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2024
From: BAKSHI, KAPILDEEP SINGH; HILL, CRAIG THOMAS; BLAIR, RAYMOND ALLAN; KOWAL, MICHAEL ALAN; CARTER, STEPHEN M.; ORR, STEPHEN MICHAEL
To: CISCO TECHNOLGY, INC.
Reel/Frame 066190/0613 →
Continuity (1)
Related Publication 20240291639A1 · Aug 29, 2024
References Cited (10)
US 6948062B1 · Clapper · 2005 [cited by applicant]
US 8856916B1 · Sobel · 2014 [cited by applicant]
US 20070086593A1 · Denning et al. · 2007 [cited by applicant]
US 20130031598A1 · Whelan · 2013 [cited by examiner]
US 20130309971A1 · Kiukkonen · 2013 [cited by examiner]
US 20150271156A1 · Ronca · 2015 [cited by applicant]
US 20150271157A1 · Ronca · 2015 [cited by applicant]
US 20170126698A1 · Minkovich · 2017 [cited by examiner]
US 20180063101A1 · Clark · 2018 [cited by examiner]
US 20220092193A1 · Nijasure · 2022 [cited by examiner]