Systems and methods for “machine-to-machine” (M2M) communications between modules, servers, and an application using public key infrastructure (PKI)

Inventors

Nix, John A.

Assignees

Network 1 Technologies IncM2M and IoT Technologies LLC

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-11606204-B2

Patent

Publication Date

2023-03-14

Expiration Date


Abstract

Methods and systems are provided for supporting efficient and secure “Machine-to-Machine” (M2M) communications using a module, a server, and an application. A module can communicate with the server by accessing the Internet, and the module can include a sensor and/or an actuator. The module, server, and application can utilize public key infrastructure (PKI) such as public keys and private keys. The module can internally derive pairs of private/public keys using cryptographic algorithms and a first set of parameters. A server can authenticate the submission of derived public keys and an associated module identity. The server can use a first server private key and a second set of parameters to (i) send module data to the application and (ii) receive module instructions from the application. The server can use a second server private key and the first set of parameters to communicate with the module.

Core Innovation

The disclosure describes authentication of a mobile device to a wireless network using public key infrastructure (PKI) based cryptography over IP networks. A wireless/wired module communicates with a server and an application server, and the wireless network selects a pre-shared secret key for the mobile device using the module identity, wherein the module identity comprises a permanent identifier for the mobile device.

The module stores a server public key, a module identity, cryptographic algorithms, and a pre-shared secret key. The module derives a module private key and a corresponding module public key using the cryptographic algorithms, and derives a symmetric ciphering key using an elliptic curve integrated encryption scheme (ECIES) with the server public key and the module private key together with an American National Standards Institute X-9.63 key derivation function.

The module generates module encrypted data using the symmetric ciphering key and the symmetric ciphering algorithm, wherein the module encrypted data includes the module identity. The module sends a message to the server including the module encrypted data and the module public key, and the server mutually derives the symmetric ciphering key using at least the module public key. The module authenticates with the wireless network using a message digest with the pre-shared secret key.

The disclosure further covers communication of module encrypted data from a mobile device or wireless module to a server using UDP or UDP Lite, optional channel coding and/or forward error correction, multiple packet copies, server-side decryption and authentication, message structures with module encrypted data and a module public key, and server-to-module response handling across firewalls/NAT using source and destination IP:port mapping. It also includes optional periodic firewall port binding keepalives and packet/response structures for update, query, notification, configuration, acknowledgement, and confirmation.

Claims Coverage

The independent claim coverage is repeated across the items and includes six inventive features covering mobile-device authentication using stored keys and identities, derived module and symmetric keys, encrypted module data sent with the module public key, server-side mutual key derivation, and pre-shared secret selection based on the module identity.

PKI-based mobile device authentication using pre-shared secret selection

A mobile device stores a server public key, a module identity comprising a permanent identifier, cryptographic algorithms including a symmetric ciphering algorithm, and a pre-shared secret key; the wireless network selects the pre-shared secret key for the mobile device using the module identity; and the mobile device authenticates with the wireless network using a message digest with the pre-shared secret key.

Derivation of module key pair

The mobile device derives a module private key and a corresponding module public key using the cryptographic algorithms.

Symmetric ciphering key derivation from ECIES and X-9.63

The mobile device derives a symmetric ciphering key using an elliptic curve integrated encryption scheme with the server public key and the module private key, together with an American National Standards Institute X-9.63 key derivation function.

Encrypted module data including module identity

The mobile device generates module encrypted data using the symmetric ciphering key and the symmetric ciphering algorithm, wherein the module encrypted data includes the module identity, and sends a message to the server including the module encrypted data and the module public key.

Mutual derivation of the symmetric ciphering key at the server

The server mutually derives the symmetric ciphering key using at least the module public key.

Wireless communication with UDP, error protection, and response handling

Module encrypted data is transmitted using UDP or UDP Lite, with optional channel coding and/or forward error correction, multiple packet copies, server-side decryption and authentication, replay protection by discarding duplicates, and server-to-module response handling across firewalls/NAT using source and destination IP:port mapping.

The claims center on wireless-network authentication on a mobile device by combining stored server public key and pre-shared secret selection based on module identity with elliptic-curve-based symmetric key derivation, encryption of authentication payload including the module identity, server mutual derivation, and authentication using a message digest with the pre-shared secret key, together with UDP-based message handling and error protection features.

Stated Advantages

Efficiency for sleeping modules is emphasized through reduced handshakes and single-datagram communication concepts.

Support for firewall traversal is emphasized using NAT-aware IP:port handling and port binding timeout handling.

Mitigation of bit errors in an encrypted payload using channel coding and/or forward error correction.

Resisting replay attacks by discarding duplicate packets using a timer when multiple packet copies are sent.

Enabling server-to-module response handling across firewalls/NAT using source/destination IP:port mapping.

Enabling delayed responses during module sleep by optionally using periodic firewall port binding keepalives.

Documented Applications

Authentication of a module/mobile device to a wireless network using PKI-based cryptography over IP networks, with server processing of encrypted module data and server-generated instructions/acknowledgements.

Machine-to-machine (M2M) communications in which modules with sensors/actuators communicate with a server and an application server over IP networks using cryptographic message protection.

Wireless-network communication where sensor/command data is transmitted to a server using UDP or UDP Lite, including encrypted payload handling with optional channel coding, forward error correction, and multiple packet copies.

Authentication with a wireless network involving mutual derivation, decryption and authentication on the server, and replay attack protection by duplicate discarding.

Server-to-module response handling across firewalls/NAT using IP:port mapping, including optional periodic port binding keepalives to support delayed responses during module sleep.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.