Patents by Inventor Frederick Bosco
Frederick Bosco has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20260142842Abstract: A method may include receiving a request for a secure partition on an HSM from a client device and provisioning the secure partition on the HSM. The method may include generating a control server and a load balancer. The method may include generating, by a certificate service, a CSR signed by the certificate service. The method may include transmitting the CSR to the client device and receiving a first certificate including the public key of the first public private key pair and a private key of a second public private key pair. The method may include receiving a second certificate generated by an external certificate authority and signed with a public key of the second public private key pair. The method may include storing the first certificate and the second certificate on the secure partition in a location such that the second is accessible by the control server.Type: ApplicationFiled: January 9, 2026Publication date: May 21, 2026Applicant: Oracle International CorporationInventors: Frederick Bosco, Pankaj Bhandula, Ankit Goyal, Nitin Handa
-
Patent number: 12526160Abstract: A method may include receiving a request for a secure partition on an HSM from a client device and provisioning the secure partition on the HSM. The method may include generating a control server and a load balancer. The method may include generating, by a certificate service, a CSR signed by the certificate service. The method may include transmitting the CSR to the client device and receiving a first certificate including the public key of the first public private key pair and a private key of a second public private key pair. The method may include receiving a second certificate generated by an external certificate authority and signed with a public key of the second public private key pair. The method may include storing the first certificate and the second certificate on the secure partition in a location such that the second is accessible by the control server.Type: GrantFiled: May 13, 2024Date of Patent: January 13, 2026Assignee: Oracle International CorporationInventors: Frederick Bosco, Pankaj Bhandula, Ankit Goyal, Nitin Handa
-
Patent number: 12513005Abstract: A method of providing access to a hardware security module (HSM) partition may include receiving request for access to the HSM partition from a client device. The request may include a leaf certificate signed with a public key associated with a user and a secret key associated with the client device. The method may include verifying the request using the leaf certificate and a trust anchor certificate signed with a public key associated with the client device. The method may include a first connection between the HSM partition and the client device. The method may include verifying the request using the leaf certificate and an authentication certificate stored on the HSM partition. The method may include establishing a second connection between the client device and the HSM partition such that the computing system is isolated from the second connection.Type: GrantFiled: May 13, 2024Date of Patent: December 30, 2025Assignee: Oracle International CorporationInventors: Frederick Bosco, Pankaj Bhandula, Ankit Goyal, Nitin Handa
-
Publication number: 20250030542Abstract: Techniques are described for replicating encryption keys using a write ahead log (WAL). An example method can include receiving a request from a user device to transmit encryption keys stored in a first virtual vault of a first hardware security module (HSM) of a first data center to a second virtual vault of a second HSM of a second data center, the request comprising an account identifier. The method can further include identifying a first account-specific WAL of a plurality of account-specific WALs based at least in part on the account identifier, each account-specific WAL corresponding to the first HSM, and configured to record changes to a respective virtual vault of the plurality of virtual vaults. The method can further include accessing the encryption keys from the first account-specific WAL of the first HSM. The method can further include transmitting the encryption keys to the second data center.Type: ApplicationFiled: July 19, 2024Publication date: January 23, 2025Applicant: Oracle International CorporationInventors: Frederick Bosco, Hanyue Zhang, Rakesh Ganimini Baskar, Ankit Goyal, Danyu Yang
-
Publication number: 20240388448Abstract: A method may include receiving a request for a secure partition on an HSM from a client device and provisioning the secure partition on the HSM. The method may include generating a control server and a load balancer. The method may include generating, by a certificate service, a CSR signed by the certificate service. The method may include transmitting the CSR to the client device and receiving a first certificate including the public key of the first public private key pair and a private key of a second public private key pair. The method may include receiving a second certificate generated by an external certificate authority and signed with a public key of the second public private key pair. The method may include storing the first certificate and the second certificate on the secure partition in a location such that the second is accessible by the control server.Type: ApplicationFiled: May 13, 2024Publication date: November 21, 2024Applicant: Oracle International CoporationInventors: Frederick Bosco, Pankaj Bhandula, Ankit Goyal, Nitin Handa
-
Publication number: 20240388451Abstract: A method of providing access to a hardware security module (HSM) partition may include receiving request for access to the HSM partition from a client device. The request may include a leaf certificate signed with a public key associated with a user and a secret key associated with the client device. The method may include verifying the request using the leaf certificate and a trust anchor certificate signed with a public key associated with the client device. The method may include a first connection between the HSM partition and the client device. The method may include verifying the request using the leaf certificate and an authentication certificate stored on the HSM partition. The method may include establishing a second connection between the client device and the HSM partition such that the computing system is isolated from the second connection.Type: ApplicationFiled: May 13, 2024Publication date: November 21, 2024Applicant: Oracle International CorporationInventors: Frederick Bosco, Pankaj Bhandula, Ankit Goyal, Nitin Handa