Patents by Inventor Derk Norton

Derk Norton has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 11936639
    Abstract: A device comprises: a receiver configured to receive a client certificate; a processor coupled to the receiver and configured to: authenticate the client certificate, extract, in response to the authentication, attributes from the client certificate, and create, in response to the extraction, a message comprising reformatted attributes based on the attributes, wherein the reformatted attributes can be trusted; and a transmitter coupled to the processor and configured to transmit the message. A device comprises: a processor configured to: process a client certificate comprising a certificate identifier (ID) attribute, a tenant ID attribute, and a role ID attribute, and package the client certificate in a request for a shared service; and a transmitter coupled to the processor and configured to transmit the request.
    Type: Grant
    Filed: March 4, 2021
    Date of Patent: March 19, 2024
    Assignee: Blackhawk Network, Inc.
    Inventors: Derk Norton, Tushar Vaish, Jeff Webb
  • Publication number: 20210194865
    Abstract: A device comprises: a receiver configured to receive a client certificate; a processor coupled to the receiver and configured to: authenticate the client certificate, extract, in response to the authentication, attributes from the client certificate, and create, in response to the extraction, a message comprising reformatted attributes based on the attributes, wherein the reformatted attributes can be trusted; and a transmitter coupled to the processor and configured to transmit the message. A device comprises: a processor configured to: process a client certificate comprising a certificate identifier (ID) attribute, a tenant ID attribute, and a role ID attribute, and package the client certificate in a request for a shared service; and a transmitter coupled to the processor and configured to transmit the request.
    Type: Application
    Filed: March 4, 2021
    Publication date: June 24, 2021
    Applicant: Blackhawk Network, Inc.
    Inventors: Derk Norton, Tushar Vaish, Jeff Webb
  • Patent number: 10958636
    Abstract: A device comprises: a receiver configured to receive a client certificate; a processor coupled to the receiver and configured to: authenticate the client certificate, extract, in response to the authentication, attributes from the client certificate, and create, in response to the extraction, a message comprising reformatted attributes based on the attributes, wherein the reformatted attributes can be trusted; and a transmitter coupled to the processor and configured to transmit the message. A device comprises: a processor configured to: process a client certificate comprising a certificate identifier (ID) attribute, a tenant ID attribute, and a role ID attribute, and package the client certificate in a request for a shared service; and a transmitter coupled to the processor and configured to transmit the request.
    Type: Grant
    Filed: December 20, 2018
    Date of Patent: March 23, 2021
    Assignee: Blackhawk Network, Inc.
    Inventors: Derk Norton, Tushar Vaish, Jeff Webb
  • Publication number: 20200036524
    Abstract: Systems and methods are provided for securing a private key on a mobile device for use with public key cryptography. Specifically, a private key is reduced to two partial keys where the partial keys are stored on separate electronic devices. The partial keys combine to temporarily regenerate the private key for the purposes of notarizing (digitally signing) messages or documents, and decrypting a message or document that was encrypted using the corresponding public key. The partial keys in some embodiments may be a secret key, which can be derived from an account identifier and a password, and an exclusive key, which can be derived from the secret key and the private key. The private key can be regenerated from the secret key and the exclusive key. With the partial keys stored on separate devices, another layer of practical security is provided to public key cryptography.
    Type: Application
    Filed: October 7, 2019
    Publication date: January 30, 2020
    Inventor: Derk Norton
  • Publication number: 20190386978
    Abstract: A device comprises: a receiver configured to receive a client certificate; a processor coupled to the receiver and configured to: authenticate the client certificate, extract, in response to the authentication, attributes from the client certificate, and create, in response to the extraction, a message comprising reformatted attributes based on the attributes, wherein the reformatted attributes can be trusted; and a transmitter coupled to the processor and configured to transmit the message. A device comprises: a processor configured to: process a client certificate comprising a certificate identifier (ID) attribute, a tenant ID attribute, and a role ID attribute, and package the client certificate in a request for a shared service; and a transmitter coupled to the processor and configured to transmit the request.
    Type: Application
    Filed: December 20, 2018
    Publication date: December 19, 2019
    Inventors: Derk Norton, Tushar Vaish, Jeff Webb
  • Patent number: 10439811
    Abstract: Systems and methods are provided for securing a private key on a mobile device for use with public key cryptography. Specifically, a private key is reduced to two partial keys where the partial keys are stored on separate electronic devices. The partial keys combine to temporarily regenerate the private key for the purposes of notarizing (digitally signing) messages or documents, and decrypting a message or document that was encrypted using the corresponding public key. The partial keys in some embodiments may be a secret key, which can be derived from an account identifier and a password, and an exclusive key, which can be derived from the secret key and the private key. The private key can be regenerated from the secret key and the exclusive key. With the partial keys stored on separate devices, another layer of practical security is provided to public key cryptography.
    Type: Grant
    Filed: December 22, 2017
    Date of Patent: October 8, 2019
    Assignee: Crater Dog Technologies, LLC
    Inventor: Derk Norton
  • Patent number: 10404671
    Abstract: Disclosed are requesting party and responding party computer systems which perform a message level encryption for messages sent through the computer systems. Using the message level encryption, the computer systems may prevent those with access to an unsecured zone in one or more of the computer systems from viewing the messages.
    Type: Grant
    Filed: October 16, 2018
    Date of Patent: September 3, 2019
    Assignee: BLACKHAWK NETWORK, INC.
    Inventor: Derk Norton
  • Publication number: 20190052612
    Abstract: Disclosed are requesting party and responding party computer systems which perform a message level encryption for messages sent through the computer systems. Using the message level encryption, the computer systems may prevent those with access to an unsecured zone in one or more of the computer systems from viewing the messages.
    Type: Application
    Filed: October 16, 2018
    Publication date: February 14, 2019
    Inventor: Derk Norton
  • Patent number: 10164962
    Abstract: A trusted information communication device comprising a receiver configured to receive a client certificate; a processor coupled to the receiver and configured to: authenticate the client certificate, extract, in response to the authentication, attributes from the client certificate, and create, in response to the extraction, a message comprising reformatted attributes based on the attributes, wherein the reformatted attributes can be trusted; and a transmitter coupled to the processor and configured to transmit the message.
    Type: Grant
    Filed: March 14, 2014
    Date of Patent: December 25, 2018
    Assignee: BLACKHAWK NETWORK, INC.
    Inventors: Derk Norton, Tushar Vaish, Jeff Webb, Rajiv Venkataramana Appana
  • Patent number: 10129225
    Abstract: Disclosed are requesting party and responding party computer systems which perform a message level encryption for messages sent through the computer systems. Using the message level encryption, the computer systems may prevent those with access to an unsecured zone in one or more of the computer systems from viewing the messages.
    Type: Grant
    Filed: November 18, 2016
    Date of Patent: November 13, 2018
    Assignee: BLACKHAWK NETWORK, INC.
    Inventor: Derk Norton
  • Publication number: 20180205544
    Abstract: Systems and methods are provided for securing a private key on a mobile device for use with public key cryptography. Specifically, a private key is reduced to two partial keys where the partial keys are stored on separate electronic devices. The partial keys combine to temporarily regenerate the private key for the purposes of notarizing (digitally signing) messages or documents, and decrypting a message or document that was encrypted using the corresponding public key. The partial keys in some embodiments may be a secret key, which can be derived from an account identifier and a password, and an exclusive key, which can be derived from the secret key and the private key. The private key can be regenerated from the secret key and the exclusive key. With the partial keys stored on separate devices, another layer of practical security is provided to public key cryptography.
    Type: Application
    Filed: December 22, 2017
    Publication date: July 19, 2018
    Inventor: Derk Norton
  • Patent number: 9853813
    Abstract: Systems and methods are provided for securing a private key on a mobile device for use with public key cryptography. Specifically, a private key is reduced to two partial keys where the partial keys are stored on separate electronic devices. The partial keys combine to temporarily regenerate the private key for the purposes of notarizing (digitally signing) messages or documents, and decrypting a message or document that was encrypted using the corresponding public key. The partial keys in some embodiments may be a secret key, which can be derived from an account identifier and a password, and an exclusive key, which can be derived from the secret key and the private key. The private key can be regenerated from the secret key and the exclusive key. With the partial keys stored on separate devices, another layer of practical security is provided to public key cryptography.
    Type: Grant
    Filed: May 10, 2016
    Date of Patent: December 26, 2017
    Assignee: Crater Dog Technologies, LLC
    Inventor: Derk Norton
  • Publication number: 20170272245
    Abstract: Systems and methods are provided for securing a private key on a mobile device for use with public key cryptography. Specifically, a private key is reduced to two partial keys where the partial keys are stored on separate electronic devices. The partial keys combine to temporarily regenerate the private key for the purposes of notarizing (digitally signing) messages or documents, and decrypting a message or document that was encrypted using the corresponding public key. The partial keys in some embodiments may be a secret key, which can be derived from an account identifier and a password, and an exclusive key, which can be derived from the secret key and the private key. The private key can be regenerated from the secret key and the exclusive key. With the partial keys stored on separate devices, another layer of practical security is provided to public key cryptography.
    Type: Application
    Filed: May 10, 2016
    Publication date: September 21, 2017
    Inventor: Derk Norton
  • Publication number: 20170070489
    Abstract: Disclosed are requesting party and responding party computer systems which perform a message level encryption for messages sent through the computer systems. Using the message level encryption, the computer systems may prevent those with access to an unsecured zone in one or more of the computer systems from viewing the messages.
    Type: Application
    Filed: November 18, 2016
    Publication date: March 9, 2017
    Inventor: Derk Norton
  • Patent number: 9531688
    Abstract: Disclosed are requesting party and responding party computer systems which perform a message level encryption for messages sent through the computer systems. Using the message level encryption, the computer systems may prevent those with access to an unsecured zone in one or more of the computer systems from viewing the messages.
    Type: Grant
    Filed: January 14, 2015
    Date of Patent: December 27, 2016
    Assignee: BLACKHAWK NETWORK, INC.
    Inventor: Derk Norton
  • Publication number: 20160359633
    Abstract: Systems and methods are provided for certifying digital tokens and digital transactions that transfer certified digital tokens from one party to another party. Multiple parties such as electronic devices may exchange digital tokens and digital transactions using public key cryptography, which means that each party has a private key that is used to digitally sign a digital token or digital transaction and a public key that is used to verify the signature. After mutual verification, the signed digital tokens and signed digital transactions may be sent to various registries that verify aspects of the tokens, transactions, and related signatures before publicly publishing the signed digital tokens and signed digital transactions such that no party may later repudiate the signed digital tokens, the signed digital transactions, or parties that signed them.
    Type: Application
    Filed: June 2, 2016
    Publication date: December 8, 2016
    Inventor: Derk Norton
  • Publication number: 20150200920
    Abstract: Disclosed are requesting party and responding party computer systems which perform a message level encryption for messages sent through the computer systems. Using the message level encryption, the computer systems may prevent those with access to an unsecured zone in one or more of the computer systems from viewing the messages.
    Type: Application
    Filed: January 14, 2015
    Publication date: July 16, 2015
    Inventor: Derk Norton
  • Publication number: 20140282997
    Abstract: A device comprises: a receiver configured to receive a client certificate; a processor coupled to the receiver and configured to: authenticate the client certificate, extract, in response to the authentication, attributes from the client certificate, and create, in response to the extraction, a message comprising reformatted attributes based on the attributes, wherein the reformatted attributes can be trusted; and a transmitter coupled to the processor and configured to transmit the message. A device comprises: a processor configured to: process a client certificate comprising a certificate identifier (ID) attribute, a tenant ID attribute, and a role ID attribute, and package the client certificate in a request for a shared service; and a transmitter coupled to the processor and configured to transmit the request.
    Type: Application
    Filed: March 14, 2014
    Publication date: September 18, 2014
    Applicant: Blackhawk Network, Inc.
    Inventors: Derk Norton, Tushar Vaish, Jeff Webb, Rajiv Venkataramana Appana
  • Patent number: 7620980
    Abstract: A secure data broker has been developed, which provides a restricted message based data exchange between a client application and a secured information resource by allowing registered or verified messages to be brokered across a security barrier. In some configurations, both requests and responses are validated and brokered across the security barrier. In other configuration, either requests or responses are validated. To support validation, messages are formatted in accordance with a predefined message specification for at least part of a transaction path between a client application and an information resource accessed by the client application.
    Type: Grant
    Filed: July 21, 1999
    Date of Patent: November 17, 2009
    Assignee: Sun Microsystems, Inc.
    Inventors: David L. Wood, Michael B. Dilger, Thomas Pratt, Derk Norton, Stan D. Shurygailo
  • Patent number: 7325128
    Abstract: A security architecture has been developed in which a single sign-on is provided for multiple information resources. Rather than specifying a single authentication scheme for all information resources, the security architecture associates trust-level requirements with information resources. Authentication schemes (e.g., those based on passwords, certificates, biometric techniques, smart cards, etc.) are employed depending on the trust-level requirement(s) of an information resource (or information resources) to be accessed. Once credentials have been obtained for an entity and the entity has been authenticated to a given trust level, access is granted, without the need for further credentials and authentication, to information resources for which the authenticated trust level is sufficient.
    Type: Grant
    Filed: September 19, 2006
    Date of Patent: January 29, 2008
    Assignee: Sun Microsystems, Inc.
    Inventors: David L. Wood, Paul Weschler, Derk Norton, Chris Ferris, Yvonne Wilson, William R. Soley