Set of servers for “machine-to-machine” communications using public key infrastructure

Inventors

Nix, John A.

Assignees

Network 1 Technologies IncM2M and IoT Technologies LLC

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-11973863-B2

Patent

Publication Date

2024-04-30

Expiration Date


Abstract

A set of servers can support secure and efficient “Machine to Machine” communications using an application interface and a module controller. The set of servers can record data for a plurality of modules in a shared module database. The set of servers can (i) access the Internet to communicate with a module using a module identity, (i) receive server instructions, and (iii) send module instructions. Data can be encrypted and decrypted using a set of cryptographic algorithms and a set of cryptographic parameters. The set of servers can (i) receive a module public key with a module identity, (ii) authenticate the module public key, and (iii) receive a subsequent series of module public keys derived by the module with a module identity. The application interface can use a first server private key and the module controller can use a second server private key.

Core Innovation

The invention provides secure machine to machine communications performed by a server. The server stores a key derivation function that uses an elliptic curve Diffie-Hellman (ECDH) algorithm and a symmetric ciphering algorithm, and derives a server private key and a first server public key using cryptographic parameters that include an elliptic curve. A user module sends a message including a module public key and cryptographic parameters for the module public key.

The server derives a shared symmetric key using the key derivation function by using the first server public key and the module public key and by performing a key exchange for the ECDH algorithm including the server private key and the cryptographic parameters. The server encrypts module instruction data and a server digital signature using the shared symmetric key and the symmetric ciphering algorithm, thereby generating server encrypted data.

The server sends a response including the server encrypted data to the user module. The server encrypted data is decrypted by the user module using the shared symmetric key derived by the user module to provide a second server public key and the server digital signature, and the server digital signature is verified by the user module to confirm an identity of the server.

Claims Coverage

The input includes two independent claims, one for a server-performed method and one for a non-transitory computer program product executed by a server. Both independent claims recite five inventive features centered on ECDH-based key derivation, symmetric ciphering, and encrypted server instructions used for identity verification.

Storing an ECDH key derivation function and symmetric ciphering algorithm

Storing, by the server, a key derivation function that uses an elliptic curve Diffie-Hellman (ECDH) algorithm and a symmetric ciphering algorithm.

Deriving server keys from cryptographic parameters

Deriving, by the server, a server private key and a first server public key using cryptographic parameters.

Receiving module public key with elliptic-curve cryptographic parameters

Receiving, by the server, a message from a user module including a module public key and cryptographic parameters for the module public key, wherein the cryptographic parameters include an elliptic curve.

Deriving a shared symmetric key using ECDH key exchange inputs

Deriving a shared symmetric key using the key derivation function, the first server public key, the module public key, and a key exchange for the ECDH algorithm including the server private key and the cryptographic parameters.

Encrypting module instruction with a server digital signature and sending encrypted response

Encrypting, by the server using the shared symmetric key and the symmetric ciphering algorithm, a module instruction including a second server public key and a server digital signature, and sending a response including the server encrypted data to the user module for decryption and verification of the server digital signature to confirm an identity of the server.

Both independent claims cover a server-side ECDH-based key agreement with elliptic-curve cryptographic parameters, shared symmetric-key derivation from exchanged public keys, and symmetric encryption of a module instruction together with a server digital signature that the user module verifies to confirm an identity of the server.

Stated Advantages

Enables the user module to verify an identity of the server using the server digital signature.

Documented Applications

Secure machine to machine communications supported by a server, for exchanging encrypted responses with server identity verification by a user module.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.