IP Library › Granted Patent US 12,432,258
Granted Patent B2
US 12,432,258 · App. 18/204,615 · Granted Sep 30, 2025

Digital trust broker and end to end trust assurance in multi-domain, multi-operator and cloud networks for high security environments

Inventors: Carlos Solari (Sterling, VA); Surya Kumar Kovvali (Carlisle, MA); Kevin Riley (Amesbury, MA)
Assignee: SecureG
H04L63/205H04L9/3263H04L63/08H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,258
App. No.
18/204,615
Filed
Jun 1, 2023
Granted
Sep 30, 2025
Kind
B2
Art Unit
2434
USPC
726/3
Abstract

System and methods of brokering trust across multiple Authentication and Authorization methods in a multi-domain, multi-operator, private and public cloud networks are identified. A Digital Trust Broker (DTB) is disclosed that brokers trust between infrastructure authentication methods that use digital certificates (PKI) and operator/enterprise Authentication/Authorization methods through interaction with multiple operator/service provider control and management platforms. The Digital Trust Broker interacts with vendor management and security platforms for associating device manufacturing, assembly, supply-chain, and logistics attributes for assuring trust of compute, network, storage and other system components that a high security enterprise or service provider acquires and installs in their networks. Additionally, methods of generating enhanced certificates for secure network slices and other Cloud and SDN hosted virtual network functions as trust assured services are also disclosed.

Claims (21)

1. A method of incorporating security, trust and other policy requirements that include provenance and other metadata policy attributes for a network that includes a plurality of physical and virtual network functions (VNFs) that offer a service, the method comprising:

embedding required policy attributes in an enhanced digital certificate (eDC) in one or more VNF; and

using the eDC to validate before, during and after use of the service;

wherein the VNFs include physical or virtual elements that process, store, or transport data in virtual or physical network environments, wherein the virtual or physical network environments are enterprise data centers, Software Defined Networks, public/private/hybrid Clouds, Wireless operator networks and/or Wireline operator networks.

2. The method of claim 1 , wherein the service comprises an end-to-end secure network slice (SNS) through a multi-domain, multi-operator network; wherein the policy attributes dictate the provenance data, other policy and configuration data for each type of network element and the types of functions performed by the network element, wherein the eDC is referred to as a slice certificate, and wherein the slice certificate determines the policy attributes.

3. The method of claim 2 , wherein the metadata for the virtual network function includes provenance data, geolocation for each type of device/function and configurable features that each network element (NE) involved in providing the service or network slice required to support and the configuration attributes of the device feature while in operation.

4. The method of claim 2 , wherein the slice certificate is incorporated in end points that terminate the SNS.

5. The method of claim 2 , wherein the SNS is constructed by joining multiple secure network slices where each secure network slice includes a slice certificate that corresponds to a segment of the SNS in each transit operator or service provider network.

6. The method of claim 1 , wherein the service corresponds to a physical or virtual distributed function, wherein the function is a database service, an application service, a proxy service, or a network service, that interconnects two different networks with different security domains, and the eDC is referred to as a service certificate and wherein the service certificate is used to orchestrate the service.

7. The method of claim 6 , wherein the service that the service certificate orchestrates corresponds to a virtual network function that is implemented over a distributed system and is incorporated in the virtual/physical nodes that offer the service to clients or manage the service.

8. The method of claim 6 , wherein a Digital Trust Broker interacts with a plurality of management platforms in service provider networks to assure security and trust policies orchestrated by the service certificate, at a granularity of resources and frequency according to policies defined by the service certificate.

9. The method of claim 1 , the service comprises multiple classes of security levels, where each security level orchestrates policy attributes for the specific security level.

10. The method of claim 1 , wherein the policy attributes include authorization for types of accesses while using the service, and/or provenance and metadata attributes for transit physical/virtual network elements that offer the service.

11. A method of facilitating supply chain tracking of a device for high security and trust assurance from manufacturing location to a service provider or enterprise procurement locations, the method comprising:

creating an enhanced Digital Certificate (eDC) for the device, wherein the eDC contains supply chain data;

incorporating additional human and/or machine-readable identifiers which are readable while the device is powered off; and

using the supply chain data in the eDC to validate and assure that the device only traversed through trusted vendors, trusted locations and trusted regions before, during and/or after the device is used in processing highly sensitive data.

12. The method of claim 11 , wherein the additional human and/or machine-readable identifiers comprises a Manufacturing Vendor name, a Vendor location, a Model Name, a Model Number, a MAC address, a bar code, a QR Code, and/or a RFID tag.

13. The method of claim 11 , further comprising: interacting with a plurality of vendor systems involved in the device shipment from manufacturing location to the service provider or enterprise procurement locations.

14. The method of claim 11 , wherein the supply chain data is onboarded as allowed transit paths into the enhanced digital certificate so that the eDC serves to orchestrate allowed transit vendors and their locations.

15. The method of claim 11 , further comprising: using a Digital Trust Broker (DTB) that bridges trust between multiple authorization and authentication systems for validating supply chain attributes.

Continuity (3)
Continuation 17679672 · Feb 24, 2022
Provisional Application 63207419 · Mar 1, 2021
Related Publication 20230328112A1 · Oct 12, 2023
References Cited (40)
US 11240043B1 · Leblang · 2022 [cited by examiner]
US 11418955B2 · Marinho et al. · 2022 [cited by applicant]
US 11418961B2 · Ben Henda · 2022 [cited by examiner]
US 11711401B2 · Solari et al. · 2023 [cited by applicant]
US 20070005801A1 · Kumar et al. · 2007 [cited by applicant]
US 20090240941A1 · Lee et al. · 2009 [cited by applicant]
US 20090319781A1 · Byrum et al. · 2009 [cited by applicant]
US 20100313011A1 · Laffey · 2010 [cited by applicant]
US 20120317569A1 · Payne, Jr. et al. · 2012 [cited by applicant]
US 20130182722A1 · Vishveswaraiah et al. · 2013 [cited by applicant]
US 20140283031A1 · Eksten et al. · 2014 [cited by applicant]
US 20140301192A1 · Lee et al. · 2014 [cited by applicant]
US 20150063166A1 · Sif et al. · 2015 [cited by applicant]
US 20150156191A1 · Schmidt et al. · 2015 [cited by applicant]
US 20160080502A1 · Yadav et al. · 2016 [cited by applicant]
US 20160330749A1 · Mehrabanzad et al. · 2016 [cited by applicant]
US 20170079059A1 · Li et al. · 2017 [cited by applicant]
US 20170164212A1 · Opsenica et al. · 2017 [cited by applicant]
US 20170357818A1 · Sheehan et al. · 2017 [cited by applicant]
US 20180097774A1 · Ore et al. · 2018 [cited by applicant]
US 20190109714A1 · Clark et al. · 2019 [cited by applicant]
US 20190109821A1 · Clark et al. · 2019 [cited by applicant]
US 20190141536A1 · Bachmutsky et al. · 2019 [cited by applicant]
US 20190166506A1 · Ashrafi · 2019 [cited by applicant]
US 20190386969A1 · Verzun et al. · 2019 [cited by applicant]
US 20190387401A1 · Liao et al. · 2019 [cited by applicant]
US 20210144517A1 · Guim Bernat et al. · 2021 [cited by applicant]
US 20210360401A1 · Marinho et al. · 2021 [cited by applicant]
US 20220141192A1 · Silveira et al. · 2022 [cited by applicant]
US 20220207127A1 · Young · 2022 [cited by examiner]
US 20220279023A1 · Solari et al. · 2022 [cited by applicant]
WO 2017200978A1 · 2017 [cited by applicant]
WO 2019197883A1 · 2019 [cited by applicant]
International Search Report and Written Opinion mailed Sep. 28, 2021 in co-pending PCT application No. PCT/US2021/032643. [cited by applicant]
International Search Report and Written Opinion mailed Jun. 6, 2022 in co-pending PCT application No. PCT/uS2022/017669. [cited by applicant]
Kotulski et al., “On end-to-end approach for slice isolation in 5G networks. Fundamental challenges.”, Federated conference on computer science and information systems (FedCSIS). IEEE, Sep. 6, 2017, <https:I/ieeexplore.… [cited by applicant]
Marek. “The security conundrum of network slicing.”, Light Reading., Apr. 13, 2020, <https://www.lightreading.com/security/the-security-conundrum-of-network-slicing/d/d-id/758814>. [cited by applicant]
Slamnik-Kriještorac et al., “Sharing Distributed and Heterogeneous Resources toward End-to-End 5G Networks: A Comprehensive Survey and a Taxonomy” IEEE Communications Surveys & Tutorials, 2020. [cited by applicant]
Office action mailed May 30, 2023 in co-pending U.S. Appl. No. 17/859,610. [cited by applicant]
Office Action mailed Dec. 22, 2023 in co-pending U.S. Appl. No. 17/859,610. [cited by applicant]