Systems and methods of protecting secrets in use with containerized applications
Summary
The USPTO granted Visa International Service Association Patent No. US12591655B2 for systems and methods protecting cryptographic keys and sensitive data in containerized applications. The invention describes a key protection service implemented as a lightweight virtual machine with containerized processes and attestation clients for secured key storage.
What changed
The USPTO granted Patent US12591655B2 to Visa International Service Association, inventors Michael Joseph Quinlan, Ajit Gaddam, and Rashmi Krishnan. The patent discloses systems and methods for securing cryptographic keys during use via a key protection service that performs cryptographic operations on behalf of client applications. The service is implemented as a lightweight virtual machine appearing externally as a container, executed in a secured environment, and includes containerized processes supporting an API for client application interaction and an attestation client for external secured key storage communication. The patent contains 18 claims covering H04L cryptographic and key management technologies.
Patent grants do not impose compliance obligations on third parties. Technology companies developing containerized applications, cloud services, or payment processing systems may consider the disclosed key protection architecture for enhanced security of cryptographic operations. Financial institutions and fintech companies handling sensitive data may reference this patent when evaluating container security technologies.
Source document (simplified)
Systems and methods of protecting secrets in use with containerized applications
Grant US12591655B2 Kind: B2 Mar 31, 2026
Assignee
Visa International Service Association
Inventors
Michael Joseph Quinlan, Ajit Gaddam, Rashmi Krishnan
Abstract
Data encryption keys (and other sensitive data) can be secured during use by a key protection service that performs cryptographic operations on behalf of a client application. The key protection service can be implemented as a lightweight virtual machine that appears externally as a container and that can be executed in a secured environment. The lightweight virtual machine can include containerized processes to support an application program interface to interact with the client application and an attestation client to interact with a secured key storage system external to the secured environment.
CPC Classifications
H04L 63/10 H04L 63/102 H04L 63/108 H04L 63/105 H04L 63/08 H04L 63/0876 H04L 9/08 H04L 9/088 H04L 9/0897 H04L 9/0894 H04L 9/32 H04L 9/3234 H04L 9/3239 H04L 9/3236 H04L 9/3271 H04L 9/3273 G06F 21/575 G06F 21/577 G06F 21/57 G06F 21/50
Filing Date
2022-03-29
Application No.
18552877
Claims
18
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Telecom & Technology alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when ChangeBridge: Patent Grants - Networking (H04L) publishes new changes.