IP Library Granted Patent US 12,567,981
Granted Patent B2
US 12,567,981 · App. 17/570,813 · Granted Mar 3, 2026

Systems and methods for data authentication using composite keys and signatures

Inventor: Massimiliano Pala (Denver, CO)
Assignee: Cable Television Laboratories, Inc.
H04L9/3268H04L9/0825H04L9/14H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,567,981
App. No.
17/570,813
Granted
Mar 3, 2026
Kind
B2
Abstract

A system for enhanced public key infrastructure is provided. The system includes a computer device. The computer device is programmed to receive a digital certificate including a composite signature field including a plurality of signatures. The plurality of signatures includes at least a first signature and a second signature. The computer device is also programmed to retrieve, from the digital certificate, a first key associated with the first signature from the digital certificate. The computer device is further programmed to retrieve the first signature from the composite signature field. In addition, the at least one computer device is programmed to validate the first signature using the first key.

Claims (59)

1 . A system for enhanced public key infrastructure (PKI), comprising:

a computer device having at least one processor in communication with at least one memory device configured to store a plurality of instructions, which, when executed by the at least one processor, cause the at least one processor to:

receive a digital certificate including a first combined signature including a first signature of a plurality of digital signatures and a second combined signature including a second signature of the plurality of digital signatures and different from the first signature, wherein the first combined signature is encrypted with a first key and the second combined signature is encrypted with a second key, wherein the digital certificate includes a plurality of fields, and wherein the plurality of fields include (i) the first key in a first field of the plurality of fields, (ii) a first identifier for a first cryptographic algorithm in a second field of the plurality of fields, (iii) the second key in a third field of the plurality of fields, and (iv) a second identifier for a second cryptographic algorithm in a fourth field of the plurality of fields;

retrieve the first key associated with the first combined signature from the digital certificate;

decrypt the first combined signature using the first key to retrieve first signature and the second combined signature;

validate the first signature;

retrieve, from the digital certificate, a second key associated with the second combined signature;

decrypt the second combined signature using the second key to retrieve the second signature;

validate the second signature; and

deny the digital certificate upon failure to validate a signature of the plurality of digital signatures.

2 . The system in accordance with claim 1 , wherein the instructions further cause the at least one processor to:

decrypt the second combined signature using the second key to retrieve the second signature and a third combined signature including a third signature of the plurality of digital signatures;

retrieve, from the digital certificate, a third key associated with the third signature; and

validate the third signature.

3 . The system in accordance with claim 1 , wherein the instructions further cause the at least one processor to determine the first cryptographic algorithm associated with the first key.

4 . The system in accordance with claim 3 , wherein the instructions further cause the at least one processor to determine if the first cryptographic algorithm is valid.

5 . The system in accordance with claim 4 , wherein the instructions further cause the at least one processor to determine if the first cryptographic algorithm is valid based on at least one of an Online Certificate Status Protocol (OCSP) and a Certificate Revocation List (CRL).

6 . The system in accordance with claim 3 , wherein the instructions further cause the at least one processor to determine if the computer device is capable of processing the first cryptographic algorithm.

7 . The system in accordance with claim 3 , wherein the instructions further cause the at least one processor to determine the second cryptographic algorithm associated with the second signature, wherein the first cryptographic algorithm is different from the second cryptographic algorithm.

8 . The system in accordance with claim 1 , wherein the instructions further cause the at least one processor to validate the digital certificate if all of the plurality of digital signatures associated with the digital certificate are validated.

9 . The system in accordance with claim 1 , wherein an innermost signature of the plurality of digital signatures includes at least one of (i) a secret, and (ii) a public key for decrypting a message.

10 . The system in accordance with claim 1 , wherein the instructions further cause the at least one processor to include a revoked algorithm associated with one of the plurality of digital signatures.

11 . A system for enhanced public key infrastructure (PKI), comprising:

a computer device having at least one processor in communication with at least one memory device configured to store a plurality of instructions, which, when executed by the at least one processor, cause the at least one processor to:

receive a digital certificate including a combined signature field having a plurality of nested signatures and a threshold, wherein the plurality of nested signatures includes at least a first signature and a second signature, wherein the threshold represents a number of valid signatures required, wherein the digital certificate includes a plurality of fields, and wherein the plurality of fields include (i) a first key in a first field of the plurality of fields, (ii) a first identifier for a first cryptographic algorithm in a second field of the plurality of fields, (iii) a second key in a third field of the plurality of fields, and (iv) a second identifier for a second cryptographic algorithm in a fourth field of the plurality of fields;

retrieve, from the digital certificate, the first key associated with the first signature from the digital certificate;

retrieve the first signature and a second combined signature from the combined signature field;

validate the first signature;

retrieve, from the digital certificate, a second key associated with the second signature;

retrieve the second signature from the second combined signature;

validate the second signature;

compare a number of validated signatures;

validate the digital certificate if the number of validated signatures meets the threshold based on the comparison; and

deny the digital certificate upon failure to validate a signature of the plurality of digital signatures.

12 . The system in accordance with claim 11 , wherein the instructions further cause the at least one processor to continue to validate signatures of the plurality of nested signatures until the number of validated signatures meets the threshold or all of the plurality of nested signatures have been analyzed.

13 . The system in accordance with claim 12 , wherein the instructions further cause the at least one processor to:

receive a revocation status message for one or more keys, wherein the revocation status message includes a threshold update; and

update the threshold based on the threshold update, wherein the threshold update increases the threshold.

14 . A computing device for enhanced public key infrastructure (PKI), comprising:

a processor; and

a memory device in communication with the processor,

wherein the memory device is configured to store a plurality of instructions, which, when executed by the processor, cause the processor to:

receive a digital certificate including a first combined signature including a first signature of a plurality of digital signatures and a second combined signature including a second signature of the plurality of digital signatures and different from the first signature, wherein the first combined signature is encrypted with a first key and the second combined signature is encrypted with a second key, wherein the digital certificate includes a plurality of fields, and wherein the plurality of fields include (i) the first key in a first field of the plurality of fields, (ii) a first identifier for a first cryptographic algorithm in a second field of the plurality of fields, (iii) the second key in a third field of the plurality of fields, and (iv) a second identifier for a second cryptographic algorithm in a fourth field of the plurality of fields;

retrieve the first key associated with the first combined signature from the digital certificate;

decrypt the first combined signature using the first key to retrieve first signature and the second combined signature;

validate the first signature;

retrieve, from the digital certificate, a second key associated with the second combined signature;

decrypt the second combined signature using the second key to retrieve the second signature;

validate the second signature; and

deny the digital certificate upon failure to validate a signature of the plurality of digital signatures.

15 . The computer device in accordance with claim 14 , wherein the instructions further cause the at least one processor to:

decrypt the second combined signature using the second key to retrieve the second signature and a third combined signature including a third signature of the plurality of digital signatures;

retrieve, from the digital certificate, a third key associated with the third signature; and

validate the third signature.

16 . The computer device in accordance with claim 14 , wherein the instructions further cause the at least one processor to determine the first cryptographic algorithm associated with the first key.

17 . The computer device in accordance with claim 16 , wherein the instructions further cause the at least one processor to determine if the first cryptographic algorithm is valid.

18 . The computer device in accordance with claim 17 , wherein the instructions further cause the at least one processor to determine if the first cryptographic algorithm is valid based on at least one of an Online Certificate Status Protocol (OCSP) and a Certificate Revocation List (CRL).

19 . The computer device in accordance with claim 16 , wherein the instructions further cause the at least one processor to determine if the computer device is capable of processing the first cryptographic algorithm.

20 . The computer device in accordance with claim 16 , wherein the instructions further cause the at least one processor to determine the second cryptographic algorithm associated with the second signature, wherein the first cryptographic algorithm is different from the second cryptographic algorithm.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2022
From: PALA, MASSIMILIANO
To: CABLE TELEVISION LABORATORIES, INC.
Reel/Frame 061227/0273 →
Continuity (5)
Continuation In Part 16537380 · Aug 9, 2019
Provisional Application 63152978 · Feb 24, 2021
Provisional Application 62869953 · Jul 2, 2019
Provisional Application 62713165 · Aug 1, 2018
Related Publication 20220353061A1 · Nov 3, 2022
References Cited (130)
US 6931537B1 · Takura · 2005 [cited by examiner]
US 8001381B2 · Metke et al. · 2011 [cited by applicant]
US 8855316B2 · Wiseman et al. · 2014 [cited by applicant]
US 9912486B1 · Sharifi Mehr · 2018 [cited by examiner]
US 10205595B2 · Frascadore · 2019 [cited by applicant]
US 10250590B2 · Gryb et al. · 2019 [cited by applicant]
US 10454904B2 · Huh et al. · 2019 [cited by applicant]
US 10615969B1 · Griffin et al. · 2020 [cited by applicant]
US 11115217B2 · Shekh-Yusef et al. · 2021 [cited by applicant]
US 11171964B1 · Huang et al. · 2021 [cited by applicant]
US 11218301B1 · Shea et al. · 2022 [cited by applicant]
US 11405789B1 · Wei et al. · 2022 [cited by applicant]
US 11456867B2 · Schmatz et al. · 2022 [cited by applicant]
US 11552806B2 · Pala · 2023 [cited by applicant]
US 11582031B2 · Wang et al. · 2023 [cited by applicant]
US 11599862B1 · Hecht et al. · 2023 [cited by applicant]
US 11616645B1 · Wang et al. · 2023 [cited by applicant]
US 12028324B1 · Pala · 2024 [cited by applicant]
US 20020199001A1 · Wenocur et al. · 2002 [cited by applicant]
US 20030172269A1 · Newcombe · 2003 [cited by applicant]
US 20060056630A1 · Zimmer et al. · 2006 [cited by applicant]
US 20060136714A1 · Yagi et al. · 2006 [cited by applicant]
US 20060222180A1 · Elliott · 2006 [cited by applicant]
US 20080031459A1 · Voltz et al. · 2008 [cited by applicant]
US 20090016736A1 · Beal et al. · 2009 [cited by applicant]
US 20090031141A1 · Pearson et al. · 2009 [cited by applicant]
US 20090163176A1 · Hasegawa · 2009 [cited by applicant]
US 20090316910A1 · Maeda et al. · 2009 [cited by applicant]
US 20100049975A1 · Parno et al. · 2010 [cited by applicant]
US 20100161817A1 · Xiao et al. · 2010 [cited by applicant]
US 20110010547A1 · Noda · 2011 [cited by applicant]
US 20110126011A1 · Choi et al. · 2011 [cited by applicant]
US 20120177201A1 · Ayling et al. · 2012 [cited by applicant]
US 20120272056A1 · Ganesan · 2012 [cited by applicant]
US 20130083926A1 · Hughes et al. · 2013 [cited by applicant]
US 20130251145A1 · Lowans et al. · 2013 [cited by applicant]
US 20130310006A1 · Chen et al. · 2013 [cited by applicant]
US 20130318343A1 · Bjarnason et al. · 2013 [cited by applicant]
US 20140014715A1 · Moran et al. · 2014 [cited by applicant]
US 20140289520A1 · Tanizawa et al. · 2014 [cited by applicant]
US 20150288517A1 · Evans et al. · 2015 [cited by applicant]
US 20150310221A1 · Lietz et al. · 2015 [cited by applicant]
US 20160248586A1 · Hughes et al. · 2016 [cited by applicant]
US 20170034133A1 · Korondi et al. · 2017 [cited by applicant]
US 20170063827A1 · Ricardo · 2017 [cited by applicant]
US 20170063834A1 · Gryb et al. · 2017 [cited by applicant]
US 20170149568A1 · LaGrone · 2017 [cited by examiner]
US 20170214525A1 · Zhao et al. · 2017 [cited by applicant]
US 20170338951A1 · Fu et al. · 2017 [cited by applicant]
US 20170338952A1 · Hong et al. · 2017 [cited by applicant]
US 20180026982A1 · Wei · 2018 [cited by applicant]
US 20180041497A1 · Morishita et al. · 2018 [cited by applicant]
US 20180062842A1 · Arahira · 2018 [cited by applicant]
US 20180097640A1 · Queralt · 2018 [cited by examiner]
US 20180109378A1 · Fu · 2018 [cited by applicant]
US 20180212779A1 · Bergmann · 2018 [cited by applicant]
US 20180262243A1 · Ashrafi et al. · 2018 [cited by applicant]
US 20180262504A1 · Frederick · 2018 [cited by examiner]
US 20190020641A1 · Wasily · 2019 [cited by examiner]
US 20190036688A1 · Wasily et al. · 2019 [cited by applicant]
US 20190036914A1 · Tzur-David et al. · 2019 [cited by applicant]
US 20190123901A1 · Vijayanarayanan · 2019 [cited by applicant]
US 20190245690A1 · Shah et al. · 2019 [cited by applicant]
US 20190319804A1 · Mathew et al. · 2019 [cited by applicant]
US 20190373471A1 · Li et al. · 2019 [cited by applicant]
US 20200280549A1 · Kaliski, Jr. et al. · 2020 [cited by applicant]
US 20210044433A1 · Hay et al. · 2021 [cited by applicant]
US 20210044976A1 · Avetisov et al. · 2021 [cited by applicant]
US 20210099292A1 · Gilton et al. · 2021 [cited by applicant]
US 20210119788A1 · Wang · 2021 [cited by applicant]
US 20220006835A1 · Gray et al. · 2022 [cited by applicant]
US 20220094675A1 · Madisetti et al. · 2022 [cited by applicant]
US 20220231843A1 · Garcia Morchon et al. · 2022 [cited by applicant]
US 20230014894A1 · M et al. · 2023 [cited by applicant]
US 20230020193A1 · Williams et al. · 2023 [cited by applicant]
US 20230206198A1 · Hecht et al. · 2023 [cited by applicant]
CA 3154434A1 · 2021 [cited by applicant]
CN 104660602A · 2015 [cited by applicant]
CN 107204812A · 2017 [cited by applicant]
CN 107404461A · 2017 [cited by applicant]
CN 114631049A · 2022 [cited by applicant]
EP 1927209A1 · 2008 [cited by applicant]
EP 2164189A1 · 2010 [cited by applicant]
EP 3432509A1 · 2019 [cited by applicant]
JP 2007288694A · 2007 [cited by applicant]
JP 2012080229A · 2012 [cited by applicant]
WO 2011134507A1 · 2011 [cited by applicant]
WO 2016073552A1 · 2016 [cited by applicant]
Fatima et al., X.509 and PGP Public Key Infrastructure Methods, a Critical Review, 2015, IFCSNS International Journal of Computer Science and Network Security, vol. 15, No. 5: pp. 55-59 (Year: 2015). [cited by examiner]
Canetti, R., Jun. 2004, Universally composable signature, certification, and authentication. In Proceedings. 17th IEEE Computer Security Foundations Workshop, 2004. (pp. 219-233). IEEE. (Year: 2004). [cited by examiner]
Wang, X., Bai, Y. and Hu, L., Sep. 2015, Certification with multiple signatures. In Proceedings of the 4th Annual ACM Conference on Research in Information Technology (pp. 13-18). (Year: 2015). [cited by examiner]
Harn, L., and Rn, J., 2011. Generalized digital certificate for user authentication and key establishment for secure communications. IEEE Transactions on Wireless Communications, 10(7), pp. 2372-2379. (Year: 2011). [cited by applicant]
Sun, Y., Zhang, R., Wang, X., Gao, K. and Liu L., Jul. 2018, A decentralizing attribute-based signature for healthcare blockchain. In 2018 27th International conference on computer communication and networks (ICCCN) (pp… [cited by applicant]
Burstinghaus-Steinbach, K., Kraus, C., Niederhagen, R., and Schneider, M., Oct. 2020, Post-quantum TLS on embedded systems: Integrating and evaluating kyber and sphincs+ with mbed tls. In Proceedings of the 15th ACM Asi… [cited by applicant]
Paquin, C., Stebila, D. and Tamvada, G., 2020. Benchmarking post-quantum cryptography in TLS. In Post-Quantum Cryptography; 11th International Conference, PQCrypto 2020, Paris, France, Apr. 15-17, 2020, Proceedings 11 (… [cited by applicant]
[1] The Internet Engineering Task Force (IETF)—IETF RFC 5280. Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile, edited by W. Polk et al., May 2008. Also available at htt… [cited by applicant]
Aes 16: Markus Grassl, Brandon Langenberg, Martin Roetteler, and Rainer Stein-wandt. Applying Grover's Algorithm to AES: Quantum Resource Estimates. In PQCrypto, vol. 9606 of Lecture Notes in Computer Science, pp. 29-43… [cited by applicant]
Aes20: Xavier Bonnetain, Maria Naya-Plasencia and Andre Schrottenloher. Quantum Security Analysis of AES. IACR Transactions on Symmetric Cryptology vol. 0, No. 0, pp. 1-3, Year: 2020. [cited by applicant]
Amaral Gustavo C., et al: “WDM-PON Monitoring with Tunable Photon Counting OTDR,” IEEE Photonics Technology Letters, IEEE, USA, vol. 26, No. 13, Jul. 1, 2014 (Jul. 1, 2014), pp. 1279-1282, XOP011550969, ISSN: 1041-1135,… [cited by applicant]
Chen et al; Metropolitan all-pass and inter-city quantum communication network; Dec. 2010; Optical society of America; pp. 1-9. (Year: 2010). [cited by applicant]
Choi, P.S. et al: “Quantum key distribution on a 10Gb/s WDM-PON,” Optical Fiber Communication (OFC), Collocated National Fiber Optic Engineers Conference, 2010 Conference on (OFC/NFOEC), IEEE, Piscataway, NJ, USA, Mar. … [cited by applicant]
Com20: M. Pala. Composite Public Keys and Signatures, IETF. Feb. 2019. [cited by applicant]
Doc31: Data-Over-Cable Service Interface Specifications, DOCSIS 3.1, Security Specifications. CableLabs Publication, 2020. Available as CM-SP-SECv3.1-IO9-200407; Year: 2020. [cited by applicant]
Doc40: Data-Over-Cable Service Interface Specifications, DOCSIS 4.0, Security Specifications. CableLabs Publication, 2019. Available as CM-SP-SECv4.0-IO1-190815; Year: 2019. [cited by applicant]
Dr99: Joan Daemen and Vincent Rijmen. AES proposal: Rijndael. Year: 1999. [cited by applicant]
Elboukhari, Mohamed et al. “Integration of Quantum Key Distribution in the TLS Protocol.” IJCSNS International Journal of Computer Science and Network Security, vol. 9. No. 12, (2009). (Year: 2009). [cited by applicant]
Gro96: Lov K. Grover. A Fast Quantum Mechanical Algorithm for Database Search. In Gary L. Miller, editor, Proceedings of the Twenty-Eighth Annual ACM Symposium on the Theory of Computing, Philadelphia, Pennsylvania, USA… [cited by applicant]
International Search Report is corresponding application PCTUS2056172 (Mar. 3, 2021). [cited by applicant]
ITU509: ITU-T Recommendation X.509 (2005) | ISO/IEC 9594-8:2005, Information Technology—Open Systems Interconnection—The Directory: Public-key and attribute certificate frameworks; Year: 2005. [cited by applicant]
Kumavor P. D., et al: “Comparison of Four Multi-User Quantum Key Distribution Schemes Over Passive Optical Networks,” Journal of Lightwave Technology, IEEE, USA, vol. 23, No. 1, Jan. 1, 2005 (Jan. 1, 2025), pp. 168- j27… [cited by applicant]
Luo et al; Time Synchronization over Ethernet Passive Optical Networks; Oct. 2012; IEEE; pp. 1-7. (Year: 2012). [cited by applicant]
M. Bagnulo. “Stateful NAT64: Network Address Protocol Translation from IPV6 Clients o IPv4 Servers.” Internet Engineering Task For (IETF). ISSN: 2070-1721. p. 10/39. Apr. 2011. (Year: 2011). [cited by applicant]
Ntru10: American National Standards Institute (2010) Ansi X9.98-2010—Lattice-Based Polynomial Public Key Establishment Algorithm for the Financial Services Industry (ANSI, New York City, United States). Available at htt… [cited by applicant]
Ntru9: Institute of Electrical and Electronics Engineers (2009) IEEE Standard1363.1-2008—Specification for Public Key Cryptographic Techniques Based on Hard Problems over Lattices (IEEE, Piscataway, New Jersey, United S… [cited by applicant]
PKCS11: Oasis Standard, S. Gleeson and C. Zimman, PKCS #11 Cryptographic Token Interface Base Specification, Version 2.40, Apr. 2015. [cited by applicant]
RFC 2986: IETF 2986, M. Nystrom, et al., PKCS #10: Certification Request Syntax Specification, Version 1.7, Nov. 2000. [cited by applicant]
RFC 3279: IETF RFC 3279, W. Polk, et al., Algorithms and Identifiers for the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile, Apr. 2002. [cited by applicant]
RFC 5272: IETF RFC 5272, J. Schaad, et al., Certificate Management over CMS (CMC), Jun. 2008. [cited by applicant]
RFC 5273: IETF RFC 5273, J. Schaad, et al., Certificate Management over CMS (CMC): Transport Protocols, Jun. 2008. [cited by applicant]
RFC 5280: IETF RFC 5280, W. Polk, et al., Cryptographic Message Syntax (CMS), May 2008. [cited by applicant]
RFC 5652: IETF RFC 5652, R. Housley, Cryptographic Message Syntax (CMS), Sep. 2009. [cited by applicant]
RFC 5758: IETF RFC 5758, Q. Dang, et al., Internet X.509 Public Key Infrastructure: Additional Algorithms and Identifiers for DSA and ECDSA, Jan. 2010. [cited by applicant]
RFC 5869: IETF RFC 5869, H. Krawczyk and P. Eronen, HMAC-based Extract-and-Expand Key Derivation Function (HKDF), May 2010. [cited by applicant]
RFC 6402: IETF RFC 6402, J. Schaad, Certificate Management over CMS (CMC) Updates, Nov. 2011. [cited by applicant]
RFC 6818: IETF RFC 6818, P. Yee, Updates to the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile, Jan. 2013. [cited by applicant]
RFC 8446: IETF RFC 8446, E. Rescorla, et al., The Transport Layer Security (TLS) Protocol, Version 1.3, Aug. 2018. [cited by applicant]
RFC 8555: IETF RFC 8555, R. Barnes, et al., Automatic Certificate Management Environment (ACME), Mar. 2019. [cited by applicant]
RFC 8696: IETF RFC 8696, R. Housley, Using Pre-Shared Key (PSK) in the Cryptographic Message Syntax (CMS), Dec. 2019. [cited by applicant]
Rphy18: Data-Over-Cable Service Interface Specifications, DCA—MHAv2. Remote PHY Specification. Available as CM-SP-R-PHY-110-180509; Year. [cited by applicant]
The Internet Engineering Task Force (IETF)—IETF RFC 2986. PKCS#10: Certification Request Syntax Specification Version 1.7, edited by M. Nystrom et al., Nov. 2000. Also available at https://datatracker.ietf.org/doc/rfc29… [cited by applicant]