Secure Key Management for Blockchain Transactions
US-2024420118-A1 · Dec 19, 2024 · US
US9780952B1 · US · B1
| Field | Value |
|---|---|
| Publication number | US-9780952-B1 |
| Application number | US-201414569596-A |
| Country | US |
| Kind code | B1 |
| Filing date | Dec 12, 2014 |
| Priority date | Dec 12, 2014 |
| Publication date | Oct 3, 2017 |
| Grant date | Oct 3, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A client establishes an cryptographically protected communications session and determines information usable to distinguish the session from other sessions. The client digitally signs the information using a cryptographic key that is independent of the session to enable a server to check whether the information matches the session that it established and whether the digital signature is correct. The server may perform mitigating operations if either or both of the information or the digital signature is/are invalid.
Opening claim text (preview).
What is claimed is: 1. A computer-implemented method, comprising: establishing a cryptographically protected communications session; after the cryptographically protected communications session is established, receiving, from a client over the cryptographically protected communications session, a request and a digital signature, the request including a parameter specific to a cryptographically protected communications session over which the request was submitted; determining whether the cryptographically protected communications session is the same as the cryptographically protected communications session over which the request was submitted by at least: determining information specific to the cryptographically protected communications session; determining whether the information specific to the cryptographically protected communications session matches the parameter specific to the cryptographically protected communications session over which the request was submitted; accessing a cryptographic key registered prior to establishment of the cryptographically protected communications session and in association with the client; and determining, based at least in part on the request and the cryptographic key, whether the digital signature is valid; and as a result of both the digital signature being valid and the information specific to the cryptographically protected communications session matching the parameter specific to the cryptographically protected communications session over which the request was submitted: generating a response to the request; using the cryptographic key to generate a digital signature of the response; and transmitting the generated response and the generated digital signature to the client over the cryptographically protected communications session. 2. The computer-implemented method of claim 1 , wherein the information specific to the cryptographically protected communications session is based at least in part on a secret negotiated as part of a handshake process to establish the cryptographically protected communications session. 3. The computer-implemented method of claim 2 , wherein determining whether the information specific to the cryptographically protected communications session matches the parameter specific to the cryptographically protected communications session over which the request was submitted comprises deriving a reference parameter specific to the cryptographically protected communications session from the secret. 4. The computer-implemented method of claim 1 , wherein the cryptographically protected communications session is a transport layer security session. 5. A system, comprising at least one computing device configured to implement one or more services, the one or more services configured to: receive, over an established cryptographically protected communications session, a digital signature and a request associated with a client; obtain, prior to establishment of the established cryptographically protected communications session, a cryptographic key associated with the client; perform, based at least in part on the request, the cryptographic key, and the digital signature, a verification of whether the request was transmitted from the client to the system over the established cryptographically protected communications session; and perform one or more mitigating actions if the verification results in the request being transmitted from the client to the system over the established cryptographically protected communications session being unverified. 6. The system of claim 5 , wherein: the one or more services are further configured to determine information specific to the established cryptographically protected communications session; and the verification includes determining whether the determined information specific to the established cryptographically protected communications session matches a parameter in the request. 7. The system of claim 6 , wherein the verification further comprises determining, based at least in part on the cryptographic key and the request, whether the digital signature is valid. 8. The system of claim 5 , wherein the cryptographic key is shared as a secret between the client and the system prior to establishment of the established cryptographically protected communications session. 9. The system of claim 5 , wherein the verification includes determining whether information resulting from a handshake process for establishing the established cryptographically protected communications session matches a parameter in the request. 10. The system of claim 5 , wherein the one or more services are further configured such that successful verification that the request was transmitted from the client to the system over the established cryptographically protected communications session and successful verification of the digital signature are prerequisites for fulfilling the request. 11. The system of claim 5 , wherein the one or more services are further configured to: if determined that the digital signature is valid and that the request was transmitted from the client to the system over the established cryptographically protected communications session: determine a response to the request; and digitally sign the response to the request using a cryptographic key that is independent of the established cryptographically protected communications session. 12. The system of claim 11 , wherein: the cryptographic key that is associated with the client and the cryptographic key that is registered to the client independent of the established cryptographically protected communications session are a same symmetric cryptographic key. 13. The system of claim 5 , wherein the one or more mitigating actions include digitally signing a denial of the request using a cryptographic key that is independent of the established cryptographically protected communications session. 14. A non-transitory computer-readable storage medium having stored thereon executable instructions that, when executed by one or more processors of a computer system, cause the computer system to at least: establish a cryptographically protected communications session; after establishment of the cryptographically protected communications session, determine information usable to distinguish the established cryptographically protected communications session from other cryptographically protected communications session; digitally sign a request that includes the determined information using a cryptographic key obtained prior to establishment of the cryptographically protected communications session, thereby generating a digital signature; and transmit the request and the digital signature over the cryptographically protected communications session. 15. The non-transitory computer-readable storage medium of claim 14 , wherein the instructions further comprise instructions that, when executed by the one or more processors, cause the computer system to: receive a response to the request and a digital signature; verify the digital signature using the cryptographic key; and process the received response dependent on whether the digital signature is verified as valid. 16. The non-transitory computer-readable storage medium of claim 14 , wherein the instructions further comprise instructions that, when executed by the one or more processors, cause the computer system to: determine information specific to the request; generate the request to include the determined information specific to the request; and verify, based at least in part on the deter
involving Diffie-Hellman or related key agreement protocols · CPC title
Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks · CPC title
at the transport layer · CPC title
for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title
involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements (network architectures or network communication protocols for supporting authentication of entities using certificates in a packet data network H04L63/0823) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.