IP Library Granted Patent US 12,574,359
Granted Patent B2
US 12,574,359 · App. 17/536,987 · Granted Mar 10, 2026

Reoccuring keying system

Inventors: Nancy Davoust (Louisville, CO); James Fahrny (Parker, CO); Kevin Taylor (Parker, CO)
Assignee: Comcast Cable Communications, LLC
H04L63/062H04L9/0891H04L63/06H04L63/12H04L63/20H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,574,359
App. No.
17/536,987
Granted
Mar 10, 2026
Kind
B2
Abstract

Methods, systems, and apparatuses are described for secure communications. One of a plurality of keys with respective key types may be stored in an object and may be used to establish a secure communication between computing devices. Verification of an establishment of the secure communication may be sent to a trusted computing device.

Claims (51)

1 . A method comprising:

receiving, from a first computing device, a message indicating a key and a type of key usage for the key, wherein the key corresponds to a pairing between the first computing device and a second computing device, wherein the type of key usage identifies a transaction type for communication between the first computing device and the second computing device, and wherein the type of key usage comprises a key-signing key for a higher-level entity to sign keys associated with a lower-level entity;

receiving, from a trusted computing device, an indication that the key and the type of key usage for the key are valid and correspond to the pairing between the first computing device and the second computing device;

generating, based on the indication, confirmation of successful processing of the key and type of key usage of the key, wherein the confirmation comprises an object indicating that the key was successfully processed; and

establishing, based on the confirmation of successful processing of the key and the type of key usage of the key, a secure communication associated with the transaction type between the first computing device and the second computing device.

2 . The method of claim 1 , wherein the generating comprises signing, based on a quantity of previous pairings between the first computing device and the second computing device, a value included in the message.

3 . The method of claim 1 , wherein the generating is after a request to establish the secure communication between the first computing device and the second computing device is approved by the trusted computing device.

4 . The method of claim 1 , wherein:

the message further indicates a plurality of previously installed keys, and for each of the plurality of previously installed keys, a corresponding type of key usage; and

the plurality of previously installed keys is for establishing the secure communication between the first computing device and the second computing device.

5 . The method of claim 1 , further comprising:

sending, to the trusted computing device via the first computing device, a second message indicating a previously installed key and a type of key usage of the previously installed key; and

receiving, from the trusted computing device via the first computing device, a third message indicating that the previously installed key and the type of key usage of the previously installed key are valid and correspond to the pairing between the first computing device and the second computing device.

6 . The method of claim 1 , wherein the receiving the message comprises decrypting the message using a communication decryption key for secure communication between the second computing device and the trusted computing device.

7 . The method of claim 1 , wherein the message indicates that the key is for a transaction associated with a predefined application executing on the first computing device or the second computing device.

8 . The method of claim 1 , wherein the key-signing key is associated with a master authority in a key hierarchy, and the key-signing key is a root key for the master authority to sign other keys in the key hierarchy.

9 . A second computing device comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the second computing device to:

receive, from a first computing device, a message indicating a key and a type of key usage for the key, wherein the key corresponds to a pairing between the first computing device and the second computing device, wherein the type of key usage identifies a transaction type for communication between the first computing device and the second computing device, and wherein the type of key usage comprises a key-signing key for a higher-level entity to sign keys associated with a lower-level entity;

receive, from a trusted computing device, an indication that the key and the type of key usage for the key are valid and correspond to the pairing between the first computing device and the second computing device;

generate, based on the indication, confirmation of successful processing of the key and type of key usage of the key, wherein the confirmation comprises an object indicating that the key was successfully processed; and

establish, based on the confirmation of successful processing of the key and the type of key usage of the key, a secure communication associated with the transaction type between the first computing device and the second computing device.

10 . The second computing device of claim 9 , wherein the instructions, when executed by the one or more processors, cause the second computing device to generate the confirmation of successful processing of the key and the type of key usage of the key by signing, based on a quantity of previous pairings between the first computing device and the second computing device, a value included in the message.

11 . The second computing device of claim 9 , wherein the instructions, when executed by the one or more processors, cause the second computing device to generate the confirmation of successful processing of the key and the type of key usage of the key after a request to establish the secure communication between the first computing device and the second computing device is approved by the trusted computing device.

12 . The second computing device of claim 9 , wherein:

the message further indicates a plurality of previously installed keys, and for each of the plurality of previously installed keys, a corresponding type of key usage; and

the plurality of previously installed keys is for establishing the secure communication between the first computing device and the second computing device.

13 . The second computing device of claim 9 , wherein the instructions, when executed by the one or more processors, cause the second computing device to:

send, to the trusted computing device via the first computing device, a second message indicating a previously installed key and a type of key usage of the previously installed key; and

receive, from the trusted computing device via the first computing device, a third message indicating that the previously installed key and the type of key usage of the previously installed key are valid and correspond to the pairing between the first computing device and the second computing device.

14 . The second computing device of claim 9 , wherein the instructions, when executed by the one or more processors, cause the second computing device to receive the message by decrypting the message using a communication decryption key for secure communication between the second computing device and the trusted computing device.

15 . A system comprising:

a first computing device; and

a second computing device;

wherein the second computing device comprises:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the second computing device to:

receive, from the first computing device, a message indicating a key and a type of key usage for the key, wherein the key corresponds to a pairing between the first computing device and the second computing device, wherein the type of key usage identifies a transaction type for communication between the first computing device and the second computing device, and wherein the type of key usage comprises a key-signing key for a higher-level entity to sign keys associated with a lower-level entity;

receive, from a trusted computing device, an indication that the key and the type of key usage for the key are valid and correspond to the pairing between the first computing device and the second computing device;

generate, based on the indication, confirmation of successful processing of the key and type of key usage of the key, wherein the confirmation comprises an object indicating that the key was successfully processed; and

establish, based on the confirmation of successful processing of the key and the type of key usage of the key, a secure communication associated with the transaction type between the first computing device and the second computing device.

16 . The system of claim 15 , wherein the instructions, when executed by the one or more processors, cause the second computing device to generate the confirmation of successful processing of the key and the type of key usage of the key by signing, based on a quantity of previous pairings between the first computing device and the second computing device, a value included in the message.

17 . The system of claim 15 , wherein the instructions, when executed by the one or more processors, cause the second computing device to generate the confirmation of successful processing of the key and the type of key usage of the key after a request to establish the secure communication between the first computing device and the second computing device is approved by the trusted computing device.

18 . The system of claim 15 , wherein:

the message further indicates a plurality of previously installed keys, and for each of the plurality of previously installed keys, a corresponding type of key usage; and

the plurality of previously installed keys is for establishing the secure communication between the first computing device and the second computing device.

19 . The system of claim 15 , wherein the instructions, when executed by the one or more processors, cause the second computing device to:

send, to the trusted computing device via the first computing device, a second message indicating a previously installed key and a type of key usage of the previously installed key; and

receive, from the trusted computing device via the first computing device, a third message indicating that the previously installed key and the type of key usage of the previously installed key are valid and correspond to the pairing between the first computing device and the second computing device.

20 . The system of claim 15 , wherein the instructions, when executed by the one or more processors, cause the second computing device to receive the message by decrypting the message using a communication decryption key for secure communication between the second computing device and the trusted computing device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2023
From: DAVOUST, NANCY; FAHRNY, JAMES; TAYLOR, KEVIN
To: COMCAST CABLE COMMUNICATIONS, LLC
Reel/Frame 063404/0499 →
Continuity (5)
Continuation 16750974 · Jan 23, 2020
Continuation 15911330 · Mar 5, 2018
Continuation 14186863 · Feb 21, 2014
Continuation 13221035 · Aug 30, 2011
Related Publication 20220158985A1 · May 19, 2022
References Cited (78)
US 7050789B2 · Kallio et al. · 2006 [cited by applicant]
US 7107247B2 · Kinoshita et al. · 2006 [cited by applicant]
US 7373512B1 · Just · 2008 [cited by applicant]
US 7400733B1 · Cam-Winget et al. · 2008 [cited by applicant]
US 7787622B2 · Sprunk · 2010 [cited by applicant]
US 8302153B1 · Garrity et al. · 2012 [cited by applicant]
US 8321584B2 · Dobbins · 2012 [cited by applicant]
US 8352725B1 · O'Toole, Jr. · 2013 [cited by applicant]
US 8582779B2 · Messerges et al. · 2013 [cited by applicant]
US 8625803B1 · Radhakrishnan et al. · 2014 [cited by applicant]
US 8630416B2 · Qi · 2014 [cited by examiner]
US 8683052B1 · Brinskelle · 2014 [cited by examiner]
US 8788825B1 · Le et al. · 2014 [cited by applicant]
US 8924722B2 · Horn et al. · 2014 [cited by applicant]
US 9282455B2 · Aissi et al. · 2016 [cited by applicant]
US 9319224B2 · Nemiroff et al. · 2016 [cited by applicant]
US 9794247B2 · Newton et al. · 2017 [cited by applicant]
US 10587405B2 · Roth et al. · 2020 [cited by applicant]
US 20020004858A1 · Carr · 2002 [cited by examiner]
US 20030056099A1 · Asanoma et al. · 2003 [cited by applicant]
US 20030070092A1 · Hawkes et al. · 2003 [cited by applicant]
US 20030130947A1 · Benantar · 2003 [cited by applicant]
US 20040044891A1 · Hanzlik et al. · 2004 [cited by applicant]
US 20040044897A1 · Lim · 2004 [cited by applicant]
US 20040073796A1 · Kang · 2004 [cited by examiner]
US 20040151319A1 · Proudler · 2004 [cited by examiner]
US 20040158704A1 · Oates et al. · 2004 [cited by applicant]
US 20050086479A1 · Ondet et al. · 2005 [cited by applicant]
US 20050226416A1 · Jung et al. · 2005 [cited by applicant]
US 20060048232A1 · Jung et al. · 2006 [cited by applicant]
US 20060059573A1 · Jung et al. · 2006 [cited by applicant]
US 20060067526A1 · Faccin · 2006 [cited by examiner]
US 20060093149A1 · Zhu · 2006 [cited by examiner]
US 20060107050A1 · Shih · 2006 [cited by applicant]
US 20060230436A1 · Holtmanns et al. · 2006 [cited by applicant]
US 20060236098A1 · Gantman · 2006 [cited by examiner]
US 20060248595A1 · Kelly et al. · 2006 [cited by applicant]
US 20060259965A1 · Chen · 2006 [cited by applicant]
US 20060291664A1 · Suarez et al. · 2006 [cited by applicant]
US 20070046502A1 · Jan · 2007 [cited by examiner]
US 20070113078A1 · Witt et al. · 2007 [cited by applicant]
US 20070118875A1 · Chow et al. · 2007 [cited by applicant]
US 20070223706A1 · Gantman et al. · 2007 [cited by applicant]
US 20070242830A1 · Conrado et al. · 2007 [cited by applicant]
US 20070283420A1 · Rantalahti · 2007 [cited by applicant]
US 20070297613A1 · Ghosh · 2007 [cited by applicant]
US 20080011827A1 · Little · 2008 [cited by examiner]
US 20080022392A1 · Karpati et al. · 2008 [cited by applicant]
US 20080049934A1 · Onoda et al. · 2008 [cited by applicant]
US 20080072038A1 · Yi et al. · 2008 [cited by applicant]
US 20080133414A1 · Qin et al. · 2008 [cited by applicant]
US 20080170693A1 · Spies et al. · 2008 [cited by applicant]
US 20080304661A1 · Kato et al. · 2008 [cited by applicant]
US 20100042838A1 · Ho · 2010 [cited by applicant]
US 20100058060A1 · Schneider · 2010 [cited by applicant]
US 20100058064A1 · Kirovski · 2010 [cited by examiner]
US 20100095126A1 · Masui et al. · 2010 [cited by applicant]
US 20100110837A1 · Jung · 2010 [cited by examiner]
US 20100142711A1 · Weis et al. · 2010 [cited by applicant]
US 20100246824A1 · Xiao et al. · 2010 [cited by applicant]
US 20100280880A1 · Faith et al. · 2010 [cited by applicant]
US 20110013773A1 · Pinder · 2011 [cited by applicant]
US 20110103589A1 · Tie et al. · 2011 [cited by applicant]
US 20110208803A1 · McCoy et al. · 2011 [cited by applicant]
US 20110211693A1 · Carvalho et al. · 2011 [cited by applicant]
US 20110271106A1 · Hinkle et al. · 2011 [cited by applicant]
US 20110307945A1 · Huang · 2011 [cited by applicant]
US 20120011360A1 · Engels et al. · 2012 [cited by applicant]
US 20120030461A1 · Willey et al. · 2012 [cited by applicant]
US 20120072731A1 · Winograd et al. · 2012 [cited by applicant]
US 20120079577A1 · Hao et al. · 2012 [cited by applicant]
US 20120159159A1 · Messerges et al. · 2012 [cited by applicant]
US 20120222135A1 · Chavez · 2012 [cited by applicant]
US 20130031369A1 · Balinsky et al. · 2013 [cited by applicant]
US 20140068744A1 · Bran et al. · 2014 [cited by applicant]
US 20140289521A1 · Davoust et al. · 2014 [cited by applicant]
US 20170235967A1 · Ray et al. · 2017 [cited by applicant]
US 20210092607A1 · Klinkner · 2021 [cited by examiner]