IP Library › Granted Patent US 12,495,023
Granted Patent B2
US 12,495,023 · App. 18/393,032 · Granted Dec 9, 2025

Symmetric-key infrastructure

Inventors: Burton S. Kaliski, Jr. (McLean, VA); Glen S. Wiley (Maidens, VA)
Assignee: VeriSign, Inc.
H04L63/062G06F16/958H04L9/0822H04L9/0836H04L9/085H04L9/0861H04L41/0806H04L61/4511
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,495,023
App. No.
18/393,032
Granted
Dec 9, 2025
Kind
B2
Abstract

Techniques for provisioning a key server to facilitate secure communications between a web server and a client by providing the client with a first data structure including information on how the web server may obtain a target symmetric key are presented. The techniques can include: provisioning the key server with a second data structure including information on how the key server may generate the first data structure; receiving a request on behalf of a web server for a third data structure comprising information on how the client may obtain the first data structure from the key server; and obtaining the third data structure, such that the third data structure is published in association with an identification of the web server, and such that the client uses the third data structure to obtain the first data structure and uses the first data structure to communicate with the web server.

Claims (38)

1 . A method to establish communication between a client and a server, the method comprising:

receiving, by a first key server of a plurality of key servers, a first request from the client to establish a connection for use by the client and the server;

sending, by the first key server, a second request to a name server to request a key server record for identifying a second key server of the plurality of key servers, the second key server being associated with the server;

determining, by the first key server, information to obtain a symmetric key for use by the client to establish the connection; and

sending, by the first key server, the information to the client.

2 . The method of claim 1 , wherein the name server comprises a domain name system (DNS) server including a DNS resource record specifying the second key server associated with the server.

3 . The method of claim 1 , further comprising establishing a connection between the client and the first key server using a public-key cryptography.

4 . The method of claim 1 , wherein the first key server comprises a recursive key server and the second key server comprises an authoritative key server.

5 . The method of claim 1 , wherein the information sent to the client to obtain a symmetric key is sufficient for the server to obtain the symmetric key.

6 . The method of claim 1 , further comprising:

sending, by the first key server, a third request to the second key server; and

receiving, by the first key sever, a response to the third request, the response comprising a referral to a third key server.

7 . The method of claim 1 , further comprising:

sending, by the first key server, information to access the second key server to a third key server that lacks information to access the second key server.

8 . The method of claim 1 , wherein the information to obtain the symmetric key comprises one or more of: a key generation method, a key origin, a key server name, a web server name, a client identifier, a counter, a nonce, a validity period, a key identifier, a key type, an algorithm identifier, a key usage restriction, or a policy.

9 . The method of claim 1 , wherein the information to obtain the symmetric key comprises one or more parameters wrapped along with the symmetric key, the one or more parameters being associated with provenance for the symmetric key.

10 . The method of claim 1 , wherein the server comprises a web server, wherein the first key server comprises a recursive key server, and the second key server comprises an authoritative key server.

11 . A system for establishing communication between a client and a server, the system comprising a server computer communicatively coupled to the internet and configured to perform operations comprising:

receiving, by a first key server of a plurality of key servers, a first request from the client to establish a connection for use by the client and the server;

sending, by the first key server, a second request to a name server to request a key server record for identifying a second key server of the plurality of key servers, the second key server being associated with the server;

determining, by the first key server, information to obtain a symmetric key for use by the client to establish the connection; and

sending, by the first key server, the information to the client.

12 . The system of claim 11 , wherein the name server comprises a domain name system (DNS) server including a DNS resource record specifying the second key server associated with the server.

13 . The system of claim 11 , wherein the operations further comprise establishing a connection between the client and the first key server using a public-key cryptography.

14 . The system of claim 11 , wherein the first key server comprises a recursive key server and the second key server comprises an authoritative key server.

15 . The system of claim 11 , wherein the information sent to the client to obtain a symmetric key is sufficient for the server to obtain the symmetric key.

16 . The system of claim 11 , wherein the operations further comprise:

sending, by the first key server, a third request to the second key server; and

receiving, by the first key sever, a response to the third request, the response comprising a referral to a third key sever.

17 . The system of claim 11 , wherein the operations further comprise:

sending, by the first key server, information to access the second key server to a third key server that lacks information to access the second key server.

18 . The system of claim 11 , wherein the information to obtain the symmetric key comprises one or more of a key generation method, a key origin, a key server name, a web server name, a client identifier, a counter, a nonce, a validity period, a key identifier, a key type, an algorithm identifier, a key usage restriction, or a policy.

19 . The system of claim 11 , wherein the information to obtain the symmetric key comprises one or more parameters wrapped along with the symmetric key, the one or more parameters being associated with provenance for the symmetric key.

20 . A non-transitory computer-readable storage medium containing instructions that, when executed by a processor, cause the processor to perform a method comprising:

receiving, by a first key server of a plurality of key servers, a first request from the client to establish a connection for use by a client and a server;

sending, by the plurality of key servers, a second request to a name server to request a key server record for identifying a second key server of the plurality of key servers, the second key server being associated with the server;

determining, by the plurality of key servers, information to obtain a symmetric key for use by the client to establish the connection; and

sending, by the plurality of key servers, the information to the client.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2023
From: KALISKI, BURTON S., JR.; WILEY, GLEN
To: VERISIGN, INC.
Reel/Frame 065936/0156 →
Continuity (5)
Continuation 17882401 · Aug 5, 2022
Continuation 16877804 · May 19, 2020
Continuation 16231095 · Dec 21, 2018
Continuation In Part 15792457 · Oct 24, 2017
Related Publication 20240163269A1 · May 16, 2024
References Cited (34)
US 4386233A · Smid et al. · 1983 [cited by applicant]
US 4850017A · Matyas, Jr. et al. · 1989 [cited by applicant]
US 6231095B1 · Chou et al. · 2001 [cited by applicant]
US 6889321B1 · Kung et al. · 2005 [cited by applicant]
US 8532303B2 · Sunder et al. · 2013 [cited by applicant]
US 10680806B1 · Kaliski, Jr. · 2020 [cited by examiner]
US 10701046B1 · Kaliski, Jr. · 2020 [cited by examiner]
US 11438318B2 · Kaliski, Jr. · 2022 [cited by examiner]
US 11902265B2 · Kaliski, Jr. · 2024 [cited by examiner]
US 20030070067A1 · Saito · 2003 [cited by applicant]
US 20080019526A1 · Fu et al. · 2008 [cited by applicant]
US 20090154708A1 · Kolar Sunder · 2009 [cited by examiner]
US 20100325423A1 · Etchegoyen · 2010 [cited by applicant]
US 20120011360A1 · Engels et al. · 2012 [cited by applicant]
US 20170093802A1 · Norum et al. · 2017 [cited by applicant]
US 20170359323A1 · Weis et al. · 2017 [cited by applicant]
US 20240163269A1 · Kaliski, Jr. · 2024 [cited by examiner]
Atkinson, “Key Exchange Delegation Record for the DNS”, IETF RFC 2230, Nov. 1997, pp. 1-11. [cited by applicant]
ANSI X9.102-2008 (R2017). Symmetric Key Cryptography for the Financial Services Industry—Wrapping of Keys and Associated Data. American National Standards Institute, 2008 (revised 2017), pp. 1-43. [cited by applicant]
Barker et al., “Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography”, NIST Special Publication 800-56A Revision 2, May 2013, pp. 1-127. [cited by applicant]
ISO 8732:1988 (E). Banking—Key management (Wholesale). International Organization for Standardization, Nov. 15, 1988, pp. 1-90. [cited by applicant]
Kohl et al., “The Kerberos Network Authentication Service (V5)”, IETF RFC 1510, Sep. 1993, pp. 1-112. [cited by applicant]
Krawczyk et al., “HMAC-based Extract-and-Expand Key Derivation Function (HKDF)”, IETF RFC 5869, May 2010, pp. 1-14. [cited by applicant]
Krawczyk et al., “The OPTLS Protocol and TLS 1.3” 2016 IEEE European Symposium on Security and Privacy (EuroS P), Mar. 2016, pp. 1-27. [cited by applicant]
Matyas et al., “Generation, distribution, and installation of cryptographic keys”, IBM Systems Journal, vol. 17, Issue 2, 1978, pp. 126-137. [cited by applicant]
Matyas, “Key processing with control vectors”, Journal of Cryptology, vol. 3, Issue 2, Jan. 1991, pp. 113-136. [cited by applicant]
Morris Dworkin, “Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping”, NIST Special Publication 800-38F, Dec. 2012, pp. 1-32. [cited by applicant]
Neuman et al., The Kerberos Network Authentication Service (V5), Network Working Group, Request for Comments: 4120, Standards Track, Jul. 2005, pp. 1-138. [cited by applicant]
NIST, “AES Key Wrap Specification”, Nov. 16, 2001, pp. 1-23. [cited by applicant]
NIST, FIPS 171: Key Management Using ANSI X9.17, Apr. 27, 1992, Retrieved from the Internet: http://securityv.isu.edu/isl/fips171.html, pp. 1-26. [cited by applicant]
Rescorla, “The Transport Layer Security (TLS) Protocol Version 1.3”, Jul. 3, 2017, Retrieved from the Internet: https://tools.ietf.org/pdf/draft-ietf-tls-tls13-21.pdf, pp. 1-143. [cited by applicant]
Salowey et al., “Transport Layer Security (TLS) Session Resumption without Server-Side State”, IETF RFC 5077, Jan. 2008, pp. 1-20. [cited by applicant]
SMID, “Computer Science Technology: A Key Notarization System for Computer Networks”, National Bureau of Standards Special Publication 500-54, 1979, pp. 1-40. [cited by applicant]
U.S. Office Action issued in corresponding U.S. Appl. No. 15/792,457 on Jul. 11, 2019, pp. 1-12. [cited by applicant]