Traceable key block-chain ledger

US11956357B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11956357-B2
Application numberUS-202318219144-A
CountryUS
Kind codeB2
Filing dateJul 7, 2023
Priority dateDec 29, 2017
Publication dateApr 9, 2024
Grant dateApr 9, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Techniques are shown for key management using a traceable key blockchain. A first block corresponding to a cryptographic key is generated on the blockchain, and the first block is securely modified to include metadata describing a key source for the cryptographic key. A second block corresponding to a first key transaction with the cryptographic key is generated on the blockchain, the second block is linked to the first block, and the second block is securely modified to include metadata describing the first key transaction with the cryptographic key.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method comprising: generating a first block on a blockchain, the first block corresponding to a cryptographic key; securely modifying the first block to include metadata describing a key source for the cryptographic key; generating a second block on the blockchain, the second block corresponding to a first key transaction with the cryptographic key; linking the second block to the first block; and securely modifying the second block to include metadata describing the first key transaction with the cryptographic key. 2. The computer-implemented method of claim 1 , wherein securely modifying the second block comprises modifying the second block using at least one of a blockchain emend and amend functionality to include metadata describing the first key transaction with the cryptographic key. 3. The computer-implemented method of claim 1 , the method further comprising: detecting an attack on data or a system associated with the cryptographic key; using metadata of one or more blocks in the blockchain to trace the cryptographic key to a point of attack; determining a block corresponding to the point of attack; and generating an alert indicating the point of attack with metadata from the block corresponding to the point of attack. 4. The computer-implemented method of claim 1 , wherein the first key transaction with the cryptographic key comprises rotating the cryptographic key; and wherein the metadata describing the first key transaction comprises metadata describing rotation of the cryptographic key. 5. The computer-implemented method of claim 1 , wherein the metadata describing the first key transaction includes one or more selected from the following: data the cryptographic key was applied to; an operation performed on the cryptographic key; a library utilizing the cryptographic key; a machine where an operation was performed on the cryptographic key; and a machine where the cryptographic key resides. 6. The computer-implemented method of claim 1 , the method further comprising: generating a third block on the blockchain, the third block corresponding to a second key transaction with the cryptographic key; linking the third block to the second block; and securely modifying the third block to include metadata describing the second key transaction with the cryptographic key. 7. The computer-implemented method of claim 1 , the method further comprising: broadcasting the second block to a plurality of nodes, causing a validation solution for the second block to computed in one of the plurality of nodes; and broadcasting the validation solution for the second block to at least one other of the plurality of nodes to validate the second block on the blockchain. 8. A system comprising: one or more processors; and one or more memory devices in communication with the one or more processors, the one or more memory devices having computer-readable instructions stored thereupon that, when executed by the one or more processors, cause the one or more processors to perform operations comprising: generating a first block on a blockchain, the first block corresponding to a cryptographic key; securely modifying the first block to include metadata describing a key source for the cryptographic key; generating a second block on the blockchain, the second block corresponding to a first key transaction with the cryptographic key; linking the second block to the first block; and securely modifying the second block to include metadata describing the first key transaction with the cryptographic key. 9. The system of claim 8 , wherein securely modifying the second block comprises modifying the second block using at least one of a blockchain emend and amend functionality to include metadata describing the first key transaction with the cryptographic key. 10. The system of claim 8 , wherein the operations further comprise: detecting an attack on data or a system associated with the cryptographic key; using metadata of one or more blocks in the blockchain to trace the cryptographic key to a point of attack; determining a block corresponding to the point of attack; and generating an alert indicating the point of attack with metadata from the block corresponding to the point of attack. 11. The system of claim 8 , wherein the first key transaction with the cryptographic key comprises rotating the cryptographic key; and wherein the metadata describing the first key transaction comprises metadata describing rotation of the cryptographic key. 12. The system of claim 8 , wherein the metadata describing the first key transaction includes one or more selected from the following: data the cryptographic key was applied to; an operation performed on the cryptographic key; a library utilizing the cryptographic key; a machine where an operation was performed on the cryptographic key; and a machine where the cryptographic key resides. 13. The system of claim 8 , wherein the operations further comprise: generating a third block on the blockchain, the third block corresponding to a second key transaction with the cryptographic key; linking the third block to the second block; and securely modifying the third block to include metadata describing the second key transaction with the cryptographic key. 14. The system of claim 8 , wherein the operations further comprise: broadcasting the second block to a plurality of nodes, causing a validation solution for the second block to computed in one of the plurality of nodes; and broadcasting the validation solution for the second block to at least one other of the plurality of nodes to validate the second block on the blockchain. 15. One or more non-transitory computer storage media having computer executable instructions stored thereon that, when executed by one or more processors, cause the one or more processors to perform operations comprising: generating a first block on a blockchain, the first block corresponding to a cryptographic key; securely modifying the first block to include metadata describing a key source for the cryptographic key; generating a second block on the blockchain, the second block corresponding to a first key transaction with the cryptographic key; linking the second block to the first block; and securely modifying the second block to include metadata describing the first key transaction with the cryptographic key. 16. The one or more non-transitory computer storage media of claim 15 , wherein securely modifying the second block comprises modifying the second block using at least one of a blockchain emend and amend functionality to include metadata describing the first key transaction with the cryptographic key. 17. The one or more non-transitory computer storage media of claim 15 , wherein the operations further comprise: detecting an attack on data or a system associated with the cryptographic key; using metadata of one or more blocks in the blockchain to trace the cryptographic key to a point of attack; determining a block corresponding to the point of attack; and generating an alert indicating the point of attack with metadata from the block corresponding to the point of attack. 18. The one or more non-transitory computer storage media of claim 15 , wherein the first key transaction with the cryptographic key comprises rotating the cryptographic key; and wherein the metadata describing the first key transaction comprises metadata describing rotation of the cryptographic key. 19. The one or more non-transitory

Assignees

Inventors

Classifications

  • involving passwords or one-time passwords (network architectures or network communication protocols for using one-time keys in a packet data network H04L63/067) · CPC title

  • H04L9/50Primary

    using hash chains, e.g. blockchains or hash trees · CPC title

  • H04L9/0894Primary

    Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage · CPC title

  • G06F21/64Primary

    Protecting data integrity, e.g. using checksums, certificates or signatures · CPC title

  • Countermeasures against attacks on cryptographic mechanisms (network architectures or network communication protocols for protection against malicious traffic H04L63/1441) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11956357B2 cover?
Techniques are shown for key management using a traceable key blockchain. A first block corresponding to a cryptographic key is generated on the blockchain, and the first block is securely modified to include metadata describing a key source for the cryptographic key. A second block corresponding to a first key transaction with the cryptographic key is generated on the blockchain, the second bl…
Who is the assignee on this patent?
Ebay Inc
What technology area does this patent fall under?
Primary CPC classification H04L9/50. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 09 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 11 related publications on this page (citations in our corpus or others sharing the same primary CPC).