Set of servers for “machine-to-machine” communications using public key infrastructure
Inventors
Assignees
Interested in licensing this patent?
MTEC can help explore whether this patent might be available for licensing for your application.
Abstract
A set of servers can support secure and efficient “Machine to Machine” communications using an application interface and a module controller. The set of servers can record data for a plurality of modules in a shared module database. The set of servers can (i) access the Internet to communicate with a module using a module identity, (i) receive server instructions, and (iii) send module instructions. Data can be encrypted and decrypted using a set of cryptographic algorithms and a set of cryptographic parameters. The set of servers can (i) receive a module public key with a module identity, (ii) authenticate the module public key, and (iii) receive a subsequent series of module public keys derived by the module with a module identity. The application interface can use a first server private key and the module controller can use a second server private key.
Core Innovation
The invention provides a method for secure communications between a client and a computer system including at least a first server. The computer system records a first server private key associated with the first server for a digital signature algorithm and a server certificate associated with the first server public key, where the server certificate is signed by a certificate authority separate from the computer system. The computer system receives a first message from the client including a device public key and generates a response for the client and a second server private key with a corresponding second server public key associated with the first server.
The computer system digitally signs the response using the first server private key to form a digitally signed response. The computer system generates a first mutually derived shared key using Elliptic Curve Diffie-Hellman based on at least the device public key and the second server private key, where the first mutually derived shared key can be derived by the client based on at least the device private key and the second server public key. Using the first mutually derived shared key, the computer system encrypts the digitally signed response, the digital signature, and the server certificate to form at least part of a transmission message.
The computer system transmits the transmission message to the client, enabling the client to decrypt the transmission message using the mutually derived shared key and verify the digitally signed response. The computer system then receives a second message comprising first data to derive a second mutually derived shared key and generates the second mutually derived shared key using a key derivation function with at least the device public key and the first server public key, wherein the second mutually derived shared key comprises a symmetric ciphering key. The computer system encrypts second data using the symmetric ciphering key to form at least part of server encrypted data and transmits the server encrypted data to allow secure transfer of data between the client and the computer system.
Claims Coverage
The document provides one independent claim describing a secure communication method with certificate-based server credentials, device public key exchange, Elliptic Curve Diffie-Hellman mutual key derivation, digital-signature protection, symmetric key derivation via a key derivation function, and encrypted server data transmission.
Certificate-based server credential recording and client message handling
The computer system records a first server private key and a server certificate signed by a certificate authority separate from the computer system, receives a first message from the client including a device public key, and generates a response for the client along with a second server private key and corresponding second server public key associated with the first server.
Elliptic Curve Diffie-Hellman mutual key derivation and encrypted signed response
The computer system digitally signs the response using the first server private key, generates a first mutually derived shared key using Elliptic Curve Diffie-Hellman based on at least the device public key and the second server private key, and encrypts the digitally signed response, the digital signature, and the server certificate using the first mutually derived shared key to form at least part of a transmission message for the client to decrypt and verify.
Key derivation function to obtain symmetric ciphering key and encrypted server data transmission
The computer system receives a second message comprising first data to derive a second mutually derived shared key, generates the second mutually derived shared key using a key derivation function with at least the device public key and the first server public key such that the second mutually derived shared key comprises a symmetric ciphering key, encrypts second data using the symmetric ciphering key to form at least part of server encrypted data, and transmits the server encrypted data to allow secure transfer of data between the client and the computer system.
Overall, the independent claim coverage is centered on the combined use of CA-signed server certificates with device public key exchange, Elliptic Curve Diffie-Hellman mutual shared key derivation for encrypting a digitally signed response, and subsequent symmetric key derivation via a key derivation function for encrypting server data transmitted for secure transfer.
Stated Advantages
Allows secure transfer of data between the client and the computer system.
Documented Applications
Not explicitly described in patent.
Interested in licensing this patent?