IP Library › Granted Patent US 12,367,485
Granted Patent B2
US 12,367,485 · App. 18/680,839 · Granted Jul 22, 2025

Federated custodian

Inventors: Sivanarayana Gaddam (Santa Clara, CA); Atul Luykx (San Francisco, CA); Cuy Sheffield (Menlo Park, CA)
Assignee: Visa International Service Association
G06Q20/3674G06Q20/027G06Q20/401H04L9/0825H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,367,485
App. No.
18/680,839
Granted
Jul 22, 2025
Kind
B2
Abstract

An enhanced federated custodian system is described. One embodiment is directed to a computer system executing instructions to: receive, from one or more members of a federated blockchain on a network of computing devices, an approval for a transaction associated with an authentication capsule; generate, via a first trusted execution environment, a first machine readable code in response to receiving the approval for the transaction; transmit to a cold interaction system, the first machine readable code; and the cold interaction system comprising one or more processors and one or more memories, the one or more memories comprising instructions executable by the one or more processors to: receive the first machine readable code comprising the encrypted information and the approval; decrypt the encrypted information for the transaction and the approval; and generate a private key that corresponds to a public key for the transaction.

Claims (48)

1. A computer system, comprising:

a gateway comprising a first processor, and a first memory including instructions that, when executed by the first processor causes the gateway to:

receive, from a plurality of members of a federated blockchain on a network of computing devices, approvals for a transaction associated with an authentication capsule, wherein each of the plurality of members receives the authentication capsule and approves of the transaction based upon data in the authentication capsule, the authentication capsule including one or more authentication policies, encrypted credentials, and device and application metadata, the one or more authentication policies identifying at least the plurality of members required to authenticate the transaction for the approvals, a number of the plurality of members required to authenticate the transaction determined based on device data of a device conducting the transaction and a geographic location of the transaction, the device data including an IP address of the device and application data of the device;

generate, via a first trusted execution environment implemented by the computer system, a first machine readable code in response to receiving the approvals for the transaction, the first machine readable code including encrypted information for the transaction and the approvals; and

transmit, to a cold interaction system, the first machine readable code generated in response to receiving approvals for the transaction; and the cold interaction system comprising one or more processors and one or more memories, the one or more memories comprising instructions executable by the one or more processors to:

receive the first machine readable code comprising the encrypted information and the approvals;

decrypt the encrypted information for the transaction and the approvals from the first machine readable code;

generate a first private key that corresponds to a public key for the transaction, the public key maintained by the plurality of members of the federated blockchain on the network of computing devices;

encrypt the transaction using the first private key; and

transmit, to the gateway, a second machine readable code, the second machine readable code verifying completion of the transaction.

2. The computer system according to claim 1 , wherein the computer system is further configured to transmit to the plurality of members of the federated blockchain on the network of computing devices information verifying completion of the transaction.

3. The computer system according to claim 2 , wherein the plurality of members of the federated blockchain on the network of computing devices maintain an audit log of transactions conducted by the plurality of members that is updated with the information verifying completion of the transaction.

4. The computer system according to claim 1 , wherein the first machine readable code and the second machine readable code include an audio machine readable code that utilizes audible or inaudible sound frequencies.

5. The computer system according to claim 4 , wherein the cold interaction system further comprises an offline server, and wherein the gateway and the offline server are configured to utilize speakers and microphones for capturing and transmitting audio corresponding to the audio machine readable code.

6. The computer system according to claim 1 , wherein a member of the plurality of members signs the transaction as part of authenticating the transaction for approval.

7. The computer system according to claim 1 , wherein a member of the plurality of members generates the public key for the transaction.

8. The computer system according to claim 1 , wherein the gateway and the cold interaction system are physically separated and not in electrical communication with each other.

9. The computer system according to claim 1 , wherein the device data further includes SIM card data of the device.

10. The computer system according to claim 1 , wherein the first trusted execution environment comprises a hot wallet.

11. The computer system according to claim 10 , wherein the hot wallet is utilized in an entity network domain of a respective associated entity.

12. The computer system according to claim 10 , wherein the hot wallet comprises a cryptocurrency wallet that is connected to the internet.

13. A computer implemented method comprising:

receiving, by a computer system and from a plurality of members of a federated blockchain on a network of computing devices, approvals for a transaction associated with an authentication capsule, wherein each of the plurality of members receives the authentication capsule and approves of the transaction based upon data in the authentication capsule, the authentication capsule including one or more authentication policies, encrypted credentials, and device and application metadata, the one or more authentication policies identifying at least the plurality of members required to authenticate the transaction for the approvals, a number of the plurality of members required to authenticate the transaction determined based on device data of a device conducting the transaction and a geographic location of the transaction, the device data including an IP address of the device and application data of the device;

generating, via a first trusted execution environment implemented by the computer system, a first machine readable code in response to receiving the approvals for the transaction, the first machine readable code including encrypted information for the transaction and the approvals;

transmitting, to an offline server, the first machine readable code generated in response to receiving approvals for the transaction; by presenting the first machine readable code to the offline server; and

receiving, from the offline server, a second machine readable code generated by the offline server in a second trusted execution environment, the second machine readable code verifying completion of the transaction, wherein the offline server is configured for:

receiving the first machine readable code;

verifying proximity of the computer system to the offline server in response to receiving the first machine readable code;

decrypting, via the second trusted execution environment implemented by the offline server, the encrypted information for the transaction and the approvals from the first machine readable code in response to verifying proximity of the computer system;

requesting, via an associated hardware security module, for generation of a private key that corresponds to a public key for the transaction, the public key maintained by the plurality of members of the federated blockchain on the network of computing devices;

encrypting, via the second trusted execution environment, the transaction using the private key from the hardware security module; and

transmitting, to the computer system, the second machine readable code.

14. The computer implemented method according to claim 13 , further comprising transmitting to the plurality of members of the federated blockchain on the network of computing devices information verifying completion of the transaction.

15. The computer implemented method according to claim 14 , wherein the plurality of members of the federated blockchain of computing devices are configured to maintain an audit log of transactions conducted by the plurality of members that is updated with the information verifying completion of the transaction.

16. The computer implemented method according to claim 13 , wherein the first trusted execution environment comprises a hot wallet.

17. A computer implemented method comprising:

generating, by a computer system, a first audio machine readable code in response to receiving approvals for a transaction from a plurality of members of a federated blockchain on a network of computing devices, the first audio machine readable code including encrypted information for the transaction and the approval, the approvals associated with an authentication capsule, the authentication capsule including one or more authentication policies, encrypted credentials, and device and application metadata, the one or more authentication policies identifying the plurality of members required to authenticate the transaction for the approvals, a number of the plurality of members determined based on device data of a device conducting the transaction and a geographic location of the transaction, the device data including an IP address of the device and application data of the device, wherein each of the plurality of members receives the authentication capsule and approves of the transaction based upon data in the authentication capsule; and

transmitting, to an offline server, the first audio machine readable code generated in response to receiving approvals for the transaction by presenting the first audio machine readable code to the offline server, wherein the offline server is configured for:

receiving the first audio machine readable code;

verifying proximity of the computer system to the offline server in response to receiving the first audio machine readable code;

decrypting, via a trusted execution environment implemented by the offline server, the encrypted information for the transaction and the approvals from the first audio machine readable code in response to verifying proximity of the computer system;

requesting, via an associated hardware security module, for generation of a private key that corresponds to a public key for the transaction, the public key maintained by the plurality of members of the federated blockchain on the network of computing devices;

encrypting, via the trusted execution environment, the approvals of the transaction using the private key from the hardware security module;

generating a second audio machine readable code that includes the approvals of the transaction; and

transmitting, to the computer system, the second audio machine readable code.

18. The computer implemented method according to claim 17 , wherein the trusted execution environment comprises a hot wallet.

19. The computer implemented method according to claim 18 , wherein the hot wallet is utilized in an entity network domain of a respective associated entity.

20. The computer implemented method according to claim 18 , wherein the hot wallet comprises a cryptocurrency wallet that is connected to the internet.

Continuity (2)
Continuation 16518764 · Jul 22, 2019
Related Publication 20240320658A1 · Sep 26, 2024
References Cited (33)
US 9471698B1 · Liu et al. · 2016 [cited by applicant]
US 9672499B2 · Yang et al. · 2017 [cited by applicant]
US 11170370B1 · Balakrishnan et al. · 2021 [cited by applicant]
US 20150262176A1 · Langschaedel et al. · 2015 [cited by applicant]
US 20160162897A1 · Feeney · 2016 [cited by applicant]
US 20180158051A1 · Arora · 2018 [cited by applicant]
US 20180276663A1 · Arora · 2018 [cited by applicant]
US 20180309567A1 · Wooden · 2018 [cited by applicant]
US 20180349994A1 · Kunjachan et al. · 2018 [cited by applicant]
US 20180367316A1 · Cheng et al. · 2018 [cited by applicant]
US 20190158482A1 · Wang · 2019 [cited by applicant]
US 20190266576A1 · McCauley et al. · 2019 [cited by applicant]
US 20190268332A1 · Wang · 2019 [cited by examiner]
US 20190378098A1 · Lam et al. · 2019 [cited by applicant]
US 20190378119A1 · Hyuga · 2019 [cited by examiner]
US 20200013055A1 · Sandor · 2020 [cited by applicant]
US 20200059369A1 · Li et al. · 2020 [cited by applicant]
US 20200118096A1 · Yang et al. · 2020 [cited by applicant]
US 20200119926A1 · Buki · 2020 [cited by applicant]
US 20200266997A1 · Monica · 2020 [cited by examiner]
US 20200366480A1 · Noonan · 2020 [cited by examiner]
US 20220029813A1 · Wakabayashi · 2022 [cited by applicant]
US 20220131845A1 · Gaddam · 2022 [cited by applicant]
US 20220292137A1 · Suh et al. · 2022 [cited by applicant]
CN 109523261A · 2019 [cited by applicant]
KR 20190083284A · 2019 [cited by applicant]
WO 2019068893A1 · 2019 [cited by applicant]
“Bips/bip-0032.Mediawiki at Master”, GitHub, Available Online At: https://github.com/bitcoin/bips/blob/master/bip-0032.mediawiki, Accessed from internet on Jul. 19, 2019, 16 pages. [cited by applicant]
“BitGo Platform V2 Reference (2.0.0)”, Available online at: https://www.bitgo.com/api/v2/, Accessed from internet on Jul. 19, 2019, 238 pages. [cited by applicant]
Square/Subzero: Square's Bitcoin Cold Storage Solution, GitHub, Available Online At: https://github.com/square/subzero, Accessed from internet on Jul. 19, 2019, 2 pages. [cited by applicant]
Kokalitcheva , “Andreessen Horowitz Invests in Digital Custody Startup Anchor Labs”, Axios, Available Online At : https://www.axios.com/andreessen-horowitz-invests-in-in-digital-custody-startup-anchorlabs-c565e0ce-d350-… [cited by applicant]
Application No. PCT/US2020/042797 , International Search Report and Written Opinion, Mailed On Nov. 6, 2020, 11 pages. [cited by applicant]
Sharma , “What Are Cryptocurrency Custody Solutions?”, Investopedia, Available Online At: https://www.investopedia.com/news/what-are-cryptocurrency-custody-solutions/, Jul. 27, 2018, 7 pages. [cited by applicant]