IP Library › Granted Patent US 12,381,716
Granted Patent B2
US 12,381,716 · App. 18/090,851 · Granted Aug 5, 2025

Optimized key management for data signing systems

Inventors: Tat Keung Chan (San Diego, CA); Alexander Medvinsky (San Diego, CA); Ting Yao (San Diego, CA)
Assignee: ARRIS Enterprises LLC
H04L9/0825H04L9/0877H04L9/3247H04L9/3263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,381,716
App. No.
18/090,851
Filed
Dec 29, 2022
Granted
Aug 5, 2025
Kind
B2
Art Unit
2493
USPC
713/171
Abstract

A system and method for providing a providing security credential is disclosed. In one embodiment, the method comprises accepting a request to generate at least one key in an online data signing system; generating, in a hardware security module communicatively coupled to the online data signing system, a first key K 1 as a temporary object; encrypting, by the hardware security module, the first key K 1 according to a wrapping key Kw to produce an encrypted first key E Kw [K 1 ]; storing the encrypted first key; and providing a second key K 2 associated with the first key K 1 to a user device communicatively coupled to the online data signing system.

Claims (98)

1. A method of providing security credentials, comprising:

accepting a request to generate at least one key in an online data signing system;

generating, in a hardware security module communicatively coupled to the online data signing system, a first key K 1 as a temporary object;

encrypting, by the hardware security module, the first key K 1 according to a wrapping key Kw to produce an encrypted first key E Kw [K 1 ];

storing the encrypted first key;

providing a second key K 2 associated with the first key K 1 to a user device communicatively coupled to the online data signing system;

linking, in the online data signing system, a configuration defined by an administrator to the encrypted first key E Kw [K 1 ];

accepting, in the online data signing system, a request from the user device to perform a cryptographic operation on data according to the configuration;

retrieving the encrypted first key;

decrypting, in the hardware security module, the encrypted first key according to the wrapping key Kw to recover the first key K 1 as a second temporary object;

performing the cryptographic operation on the data in the online data signing system according to the first key K 1 ; and

providing a result of the cryptographic operation to the user device.

2. The method of claim 1 , wherein the first key K 1 is volitively stored in the hardware security module as a session object.

3. The method of claim 1 , wherein:

the first key K 1 is a private key K Pr ; and

the second key K 2 is a public key K pu .

4. The method of claim 3 , wherein:

the public key K pu is generated by the online data signing system at least in part from the private key K Pr .

5. The method of claim 3 , further comprising:

generating, in the online data signing system, a digital certificate corresponding to the private key K Pr ; and

providing the public key K Pu to the user device comprises providing the digital certificate having the public key K Pu to the a user device.

6. The method of claim 3 , further comprising:

generating a certificate signing request according to the public key K Pu ;

providing the generated certificate signing request from the online data signing system to the an administrator;

receiving a digital certificate from the administrator, the digital certificate procured from a certificate authority in response to the certificate signing request;

associating the received digital certificate with the private key K Pr ; and

storing the received digital certificate.

7. The method of claim 6 , wherein:

the digital certificate is uploaded by an administrator to the online data signing system; and

the method further comprises:

linking, in the online data signing system, a configuration defined by the administrator to the digital certificate;

receiving data to be signed from the user device; and

providing a data package having a signature of data and the digital certificate to the user device.

8. The method of claim 6 , wherein:

the user device packages a signature of data obtained from the online data signing system together with the received digital certificate generate a signed data image for use by a target client system.

9. The method of claim 1 , wherein:

the cryptographic operation performed is a digital signing operation that can be validated using the second key.

10. The method of claim 1 , wherein:

the cryptographic operation is an encryption of the data, the encrypted data decryptable using the second key.

11. The method of claim 1 , wherein:

the decrypted first key is erased from the hardware security module following the performance of the cryptographic operation.

12. The method of claim 1 , wherein:

the decrypted first key K 1 is retained as a temporary object in a volatile memory of the hardware security module following the performance of the cryptographic operation; and

the decrypted first key K 1 retained in volatile memory is reused for further cryptographic operations.

13. The method of claim 1 , wherein:

accepting a request to generate at least one key in the online data signing system comprises:

accepting a request to generate a plurality of keys in the online data signing system;

generating, in a hardware security module communicatively coupled to the online data signing system, a first key K 1 as a temporary object comprises:

generating, in the hardware security module communicatively coupled to the online data signing system, a plurality of first keys (K 1,1 , K 1,2 , . . . K 1,n ) as temporary objects;

encrypting, by the hardware security module, the first key K 1 according to a wrapping key Kw to produce an encrypted first key E Kw [K 1 ] comprises:

encrypting, by the hardware security module, each of the plurality of first keys (K 1,1 , K 1,2 , . . . K 1,n ) according to a global wrapping key Kw to produce a plurality of encrypted first keys E Kw [K 1,1 ], E Kw [K 1,2 ,] . . . E Kw [K 1,n ];

storing the encrypted first key comprises:

storing the plurality of encrypted first keys E Kw [K 1,1 ], E Kw [K 1,2 ,] . . . E Kw [K 1,n ]; and

linking, in the online data signing system, a configuration defined by an administrator to the encrypted first key E Kw [K 1 ] comprises:

linking, in the online data signing system, a configuration defined by an administrator to each of the plurality of encrypted first keys E Kw [K 1,1 ], E Kw [K 1,2 ,] . . . E Kw [K 1,n ];

retrieving the encrypted first key comprises:

retrieving the plurality of encrypted first keys E Kw [K 1,1 ], E Kw [K 1,2 ,] . . . E Kw [K 1,n ];

decrypting, in the hardware security module, the encrypted first key according to the wrapping key Kw to recover the first key K 1 as a second temporary object comprises:

decrypting, in the hardware security module, each encrypted first key E Kw [K 1,1 ], E Kw [K 1,2 ,] . . . E Kw [K 1,n ] according to the global wrapping key Kw to recover each first key (K 1,1 , K 1,2 , . . . K 1,n ) as an additional temporary object; and

performing a cryptographic operation on the data in the online data signing system according to the first key K 1 comprises:

performing the cryptographic operation on data with each first key (K 1,1 , K 1,2 , . . . K 1,n ) in the online data signing system.

14. The method of claim 13 , wherein:

the decryption of each encrypted first key E Kw [K 1,1 ], E Kw [K 1,2 ,] . . . E Kw [K 1,n ] is performed during startup and initialization of the online data signing system.

15. The method of claim 13 , wherein:

the method further comprises accepting, in the online data signing system, a request from the user device to perform a cryptographic operation on the data according to the configuration; and

the decryption of each encrypted first key E Kw [K 1,1 ], E Kw [K 1,2 ,] . . . E Kw [K 1,n ] is performed in response to the accepting of the request from the user device.

16. The method of claim 1 , wherein:

the first key K 1 is a symmetric randomly generated key; and

the second key K 2 is identical to the first key.

17. An apparatus for providing security credentials, comprising:

a processor;

a memory, communicatively coupled to the processor, the memory storing processor instructions comprising processor instructions for:

accepting a request to generate at least one key in an online data signing system;

generating, in a hardware security module communicatively coupled to the online data signing system, a first key K 1 as a temporary object;

encrypting, by the hardware security module, the first key K 1 according to a wrapping key Kw to produce an encrypted first key E Kw [K 1 ];

storing the encrypted first key;

providing a second key K 2 associated with the first key K 1 to a user device communicatively coupled to the online data signing system;

linking, in the online data signing system, a configuration defined by an administrator to the encrypted first key E Kw [K 1 ];

accepting, in the online data signing system, a request from the user device to perform a cryptographic operation on data according to the configuration;

retrieving the encrypted first key;

decrypting, in the hardware security module, the encrypted first key according to the wrapping key Kw to recover the first key K 1 as a second temporary object;

performing the cryptographic operation on the data in the online data signing system according to the first key K 1 ; and

providing a result of the cryptographic operation to the user device.

18. The apparatus of claim 17 , wherein:

the first key K 1 is a private key K Pr ;

the second key K 2 is a public key K pu ;

the processor instructions further comprise processor instructions for:

generating, in the online data signing system, a digital certificate corresponding to the private key K Pr ; and

providing the public key K Pu to the user device comprises providing the digital certificate having the public key K Pu to a user device.

19. The apparatus of claim 18 , wherein:

the first key K 1 is a private key K Pr ;

the second key K 2 is a public key K pu ;

the processor instructions further comprise processor instructions for:

generating a certificate signing request according to the public key K Pu ;

providing the generated certificate signing request from the online data signing system to the an administrator;

receiving a digital certificate from the administrator, the digital certificate procured from a certificate authority in response to the certificate signing request;

associating the received digital certificate with the private key K Pr ; and

storing the received digital certificate.

Assignments (3)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2024
From: MEDVINSKY, ALEXANDER; YAO, TING; CHAN, TAT KEUNG
To: ARRIS ENTERPRISES LLC
Reel/Frame 067141/0422 →
Continuity (2)
Provisional Application 63294845 · Dec 30, 2021
Related Publication 20230216662A1 · Jul 6, 2023
References Cited (52)
US 7096355B1 · Marvit · 2006 [cited by examiner]
US 8316237B1 · Felsher · 2012 [cited by examiner]
US 8972733B1 · Wu · 2015 [cited by examiner]
US 9009480B1 · Wu · 2015 [cited by examiner]
US 9037865B1 · Gopalakrishna · 2015 [cited by examiner]
US 9076018B2 · Johnson · 2015 [cited by examiner]
US 9608809B1 · Ghetti · 2017 [cited by examiner]
US 9813414B2 · Camenisch · 2017 [cited by examiner]
US 9984238B1 · Roth · 2018 [cited by examiner]
US 10742634B1 · Shahbazi · 2020 [cited by examiner]
US 11303437B2 · Bursell · 2022 [cited by examiner]
US 11336425B1 · Lablans · 2022 [cited by examiner]
US 11411728B2 · Bursell · 2022 [cited by examiner]
US 11411938B2 · Bursell · 2022 [cited by examiner]
US 11424920B2 · Bursell · 2022 [cited by examiner]
US 11436352B2 · Bursell · 2022 [cited by examiner]
US 20010002486A1 · Kocher · 2001 [cited by examiner]
US 20020129238A1 · Toh · 2002 [cited by examiner]
US 20070192250A1 · Nakamoto · 2007 [cited by examiner]
US 20080077794A1 · Arnold · 2008 [cited by examiner]
US 20080095368A1 · Lida · 2008 [cited by examiner]
US 20090262942A1 · Maeda · 2009 [cited by examiner]
US 20100031014A1 · Senda · 2010 [cited by examiner]
US 20100153735A1 · Guenthner · 2010 [cited by examiner]
US 20110012711A1 · Abe · 2011 [cited by examiner]
US 20120257747A1 · Liardet · 2012 [cited by examiner]
US 20120278869A1 · Guccione · 2012 [cited by examiner]
US 20130047057A1 · Resch · 2013 [cited by examiner]
US 20130124866A1 · Farrugia · 2013 [cited by examiner]
US 20130275744A1 · Resch · 2013 [cited by examiner]
US 20130326221A1 · Murphy · 2013 [cited by examiner]
US 20140040984A1 · Mackler · 2014 [cited by examiner]
US 20140164776A1 · Hook · 2014 [cited by examiner]
US 20140173704A1 · Adams · 2014 [cited by examiner]
US 20150312227A1 · Follis · 2015 [cited by examiner]
US 20150358161A1 · Kancharla · 2015 [cited by examiner]
US 20150358313A1 · Hussain · 2015 [cited by examiner]
US 20160065366A1 · Camenisch · 2016 [cited by examiner]
US 20160164849A1 · Smith · 2016 [cited by examiner]
US 20160239929A1 · Hudson · 2016 [cited by examiner]
US 20160285872A1 · Polar · 2016 [cited by examiner]
US 20170039397A1 · Furuhashi · 2017 [cited by examiner]
US 20170052907A1 · Price, Jr. · 2017 [cited by examiner]
US 20170155634A1 · Camenisch · 2017 [cited by examiner]
US 20170257212A1 · Domosi · 2017 [cited by examiner]
US 20170272472A1 · Adhar · 2017 [cited by examiner]
US 20180211264A1 · Micali · 2018 [cited by examiner]
US 20190028273A1 · Harras · 2019 [cited by examiner]
US 20210173944A1 · Mastenbrook · 2021 [cited by examiner]
US 20210218556A1 · Mastenbrook · 2021 [cited by examiner]
US 20210218558A1 · Mastenbrook · 2021 [cited by examiner]
US 20220138286A1 · Zage · 2022 [cited by examiner]