IP Library Granted Patent US 11,483,132
Granted Patent B2
US 11,483,132 · App. 17/112,522 · Granted Oct 25, 2022

Generating and initiating pre-signed transaction requests for flexibly and efficiently implementing secure cryptographic key management

Inventors: Lei Wei (Los Altos Hills, CA); Riyaz Faizullabhoy (Los Altos, CA); Nassim Eddequiouaq (San Francisco, CA)
Assignee: Meta Platforms, Inc.
H04L9/0643G06F16/9035H04L9/0819H04L9/0866H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,483,132
App. No.
17/112,522
Granted
Oct 25, 2022
Kind
B2
Abstract

The present disclosure relates to systems, methods, and non-transitory computer-readable media that utilize pre-signed key rotation transaction requests for initiating transactions to rotate one or more cryptographic keys of a user account of a distributed digital ledger transaction network. For example, in one or more embodiments, the disclosed systems initiate a transaction to delegate a permission for rotating one or more cryptographic keys of a first user account to a second user account. Using the second user account, the disclosed systems generate and store a pre-signed key rotation transaction request. By retrieving the pre-signed key rotation transaction request from storage, the disclosed systems can initiate a key rotation transaction that exchanges the active cryptographic key of the first user account to a modified cryptographic key.

Claims (42)

1. A method comprising:

initiating a transaction, via a distributed digital ledger transaction network, delegating a permission to rotate cryptographic keys of a first user account of the distributed digital ledger transaction network to a second user account of the distributed digital ledger transaction network;

generating, utilizing a cryptographic key of the second user account, a pre-signed key rotation transaction request to generate a modified cryptographic key for the first user account based on delegation of the permission to the second user account;

storing the pre-signed key rotation transaction request in a first digital data storage location that is different than a second digital data storage location of a memory device storing the cryptographic key of the second user account; and

initiating a key rotation transaction, via the distributed digital ledger transaction network, exchanging an active cryptographic key for the first user account to the modified cryptographic key for the first user account by accessing the pre-signed key rotation transaction request from the second digital data storage location of the memory device.

2. The method of claim 1 , further comprising initiating the key rotation transaction, via the distributed digital ledger transaction network, in response to determining that a third-party actor unassociated with the first user account or the second user account has accessed at least one cryptographic key for the first user account.

3. The method of claim 2 , wherein determining that the third-party actor unassociated with the first user account or the second user account has accessed the at least one cryptographic key for the first user account comprises determining that the third-party actor has initiated an exchange of a first cryptographic key for the first user account to the active cryptographic key for the first user account.

4. The method of claim 1 , further comprising initiating the key rotation transaction based on a predetermined time for rotating the active cryptographic key of the first user account.

5. The method of claim 1 , wherein:

the second digital data storage location storing the cryptographic key of the second user account comprises a cold storage location associated with a first data retrieval time; and

storing the pre-signed key rotation transaction request in the first digital data storage location that is different than the second digital data storage location comprises storing the pre-signed key rotation transaction request in a digital data storage location associated with a second data retrieval time that is less than the first data retrieval time.

6. The method of claim 1 , wherein generating the pre-signed key rotation transaction request to exchange the active cryptographic key for the first user account to the modified cryptographic key for the first user account comprises generating a non-expiring pre-signed key rotation transaction request to exchange the active cryptographic key for the first user account to the modified cryptographic key for the first user account.

7. The method of claim 1 , wherein initiating the transaction delegating the permission to rotate the cryptographic keys of the first user account of the distributed digital ledger transaction network to the second user account of the distributed digital ledger transaction network comprises:

generating a transaction request corresponding to the transaction utilizing the active cryptographic key for the first user account; and

submitting the transaction request to the distributed digital ledger transaction network for delegation of the permission to the second user account.

8. The method of claim 1 , further comprising initiating a subsequent transaction, via the distributed digital ledger transaction network, utilizing the modified cryptographic key for the first user account after the modified cryptographic key becomes active for the first user account based on a consensus of the key rotation transaction via the distributed digital ledger transaction network.

9. A non-transitory computer-readable medium storing instructions thereon that, when executed by at least one processor, cause a computing device to:

initiate a transaction, via a distributed digital ledger transaction network, delegating a permission to rotate cryptographic keys of a first user account of the distributed digital ledger transaction network to a second user account of the distributed digital ledger transaction network;

generate, utilizing a cryptographic key of the second user account, a pre-signed key rotation transaction request to generate a modified cryptographic key for the first user account based on delegation of the permission to the second user account;

store the pre-signed key rotation transaction request in a first digital data storage location that is different than a second digital data storage location of a memory device storing the cryptographic key of the second user account; and

initiate a key rotation transaction, via the distributed digital ledger transaction network, exchanging an active cryptographic key for the first user account to the modified cryptographic key for the first user account by accessing the pre-signed key rotation transaction request from the second digital data storage location of the memory device.

10. The non-transitory computer-readable medium of claim 9 , further comprising instructions that, when executed by the at least one processor, cause the computing device to initiate the key rotation transaction, via the distributed digital ledger transaction network, in response to determining that a third-party actor unassociated with the first user account or the second user account has accessed at least one cryptographic key for the first user account.

11. The non-transitory computer-readable medium of claim 10 , wherein determining that the third-party actor unassociated with the first user account or the second user account has accessed the at least one cryptographic key for the first user account comprises determining that the third-party actor has initiated an exchange of a first cryptographic key for the first user account to the active cryptographic key for the first user account.

12. The non-transitory computer-readable medium of claim 9 , further comprising instructions that, when executed by the at least one processor, cause the computing device to initiate the key rotation transaction based on a predetermined time for rotating the active cryptographic key of the first user account.

13. The non-transitory computer-readable medium of claim 9 ,

wherein the second digital data storage location storing the cryptographic key of the second user account comprises a cold storage location associated with a first data retrieval time; and

further comprising instructions that, when executed by the at least one processor, cause the computing device to store the pre-signed key rotation transaction request in the first digital data storage location that is different than the second digital data storage location by storing the pre-signed key rotation transaction request in a digital data storage location associated with a second data retrieval time that is less than the first data retrieval time.

14. The non-transitory computer-readable medium of claim 9 , further comprising instructions that, when executed by the at least one processor, cause the computing device to generate the pre-signed key rotation transaction request to exchange the active cryptographic key for the first user account to the modified cryptographic key for the first user account by generating a non-expiring pre-signed key rotation transaction request to exchange the active cryptographic key for the first user account to the modified cryptographic key for the first user account.

15. The non-transitory computer-readable medium of claim 9 , further comprising instructions that, when executed by the at least one processor, cause the computing device to initiate the transaction delegating the permission to rotate the cryptographic keys of the first user account of the distributed digital ledger transaction network to the second user account of the distributed digital ledger transaction network by:

generating a transaction request corresponding to the transaction utilizing the active cryptographic key for the first user account; and

submitting the transaction request to the distributed digital ledger transaction network for delegation of the permission to the second user account.

16. The non-transitory computer-readable medium of claim 9 , further comprising instructions that, when executed by the at least one processor, cause the computing device to initiate a subsequent transaction, via the distributed digital ledger transaction network, utilizing the modified cryptographic key for the first user account after the modified cryptographic key becomes active for the first user account based on a consensus of the key rotation transaction via the distributed digital ledger transaction network.

17. A system comprising:

at least one processor; and

a non-transitory computer-readable medium comprising instructions that, when executed by the at least one processor, cause the system to:

initiate a transaction, via a distributed digital ledger transaction network, delegating a permission to rotate cryptographic keys of a first user account of the distributed digital ledger transaction network to a second user account of the distributed digital ledger transaction network;

generate, utilizing a cryptographic key of the second user account, a pre-signed key rotation transaction request to generate a modified cryptographic key for the first user account based on delegation of the permission to the second user account;

store the pre-signed key rotation transaction request in a first digital data storage location that is different than a second digital data storage location of a memory device storing the cryptographic key of the second user account; and

initiate a key rotation transaction, via the distributed digital ledger transaction network, exchanging an active cryptographic key for the first user account to the modified cryptographic key for the first user account by accessing the pre-signed key rotation transaction request from the second digital data storage location of the memory device.

18. The system of claim 17 , further comprising instructions that, when executed by the at least one processor, cause the system to initiate the key rotation transaction, via the distributed digital ledger transaction network, in response to determining that a third-party actor unassociated with the first user account or the second user account has accessed at least one cryptographic key for the first user account.

19. The system of claim 18 , wherein determining that the third-party actor unassociated with the first user account or the second user account has accessed the at least one cryptographic key for the first user account comprises determining that the third-party actor has initiated an exchange of a first cryptographic key for the first user account to the active cryptographic key for the first user account.

20. The system of claim 17 , further comprising instructions that, when executed by the at least one processor, cause the system to initiate the key rotation transaction based on a predetermined time for rotating the active cryptographic key of the first user account.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 4, 2025
From: CIRCLE INTERNET FINANCIAL, LLC
To: CIRCLE INTERNET GROUP, INC.
Reel/Frame 072774/0580 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2024
From: META PLATFORMS, INC.
To: CIRCLE INTERNET FINANCIAL, LLC
Reel/Frame 067654/0637 →
CHANGE OF NAME Recorded Dec 20, 2021
From: FACEBOOK, INC.
To: META PLATFORMS, INC.
Reel/Frame 058961/0436 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2020
From: WEI, LEI; FAIZULLABHOY, RIYAZ; EDDEQUIOUAQ, NASSIM
To: FACEBOOK, INC.
Reel/Frame 054616/0355 →
Continuity (1)
Related Publication 20220182222A1 · Jun 9, 2022