IP Library Granted Patent US 12701146
Granted Patent B2
US 12701146 · App. 18/759,753 · Granted Aug 4, 2026

Network security systems and methods

Inventors: David P. Maher (Philadelphia, PA); Gilles Boccon-Gibod (San Francisco, CA)
Assignee: Intertrust Technologies Corporation
H04L63/20G06F21/6218H04L67/1068H04W4/70H04W12/04H04W12/50G06F2221/2149H04L12/2803H04L63/065H04L67/51H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12701146
App. No.
18/759,753
Granted
Aug 4, 2026
Kind
B2
Abstract

This disclosure relates to systems and methods for managing connected devices and associated network connections. In certain embodiments, trust, privacy, safety, and/or security of information communicated between connected devices may be established in part through use of security associations and/or shared group tokens. In some embodiments, these security associations may be used to form an explicit private network associated with the user. A user may add and/or manage devices included in the explicit private network through management of various security associations associated with the network's constituent devices.

Claims (23)

1 . A method of managing operation of a group of connected devices, the method comprising:

receiving, by a gateway device from a first connected device, a request to perform a composite service by the group of connected devices, the group of connected devices comprising a plurality of second connected devices, the request comprising an indication of the requested composite service and at least a subset of group token information associated with each device of the plurality of second connected devices;

authenticating the received request to perform the composite service by the group of connected devices;

determining, by the gateway device, based, at least in part, on state information associated with at least a subset of the plurality of second connected devices, that the gateway device may initiate performance of the composite service by the plurality of second connected devices in accordance with the request;

generating, by the gateway device based on the determination, one or more command messages configured to control the operation of one or more devices of the plurality of second connected devices to perform the composite service; and

transmitting, by the gateway device, the one or more command messages to the one or more devices of the plurality of second connected devices.

2 . The method of claim 1 , wherein the request to perform the composite service is included in an encrypted message from the first connected device and wherein the method further comprises decrypting the encrypted message using a public key associated with the first connected device.

3 . The method of claim 1 , wherein the method further comprises exposing an indication of the composite service by the gateway device to the first connected device.

4 . The method of claim 1 , wherein the state information associated with the at least a subset of the plurality of second connected devices comprises identification information associated with the at least a subset of the plurality of second connected devices.

5 . The method of claim 4 , wherein the identification information comprises information uniquely associated with at least one connected device of the at least a subset of the plurality of second connected devices.

6 . The method of claim 5 , wherein the information uniquely associated with the at least one connected device of the at least a subset of the plurality of second connected devices comprises at least one of a device universally unique identifier and Internet protocol identification information.

7 . The method of claim 4 wherein the identification information comprises a name assigned to at least one connected device of the at least a subset of the plurality of second connected devices by an associated entity.

8 . The method of claim 1 , wherein the state information associated with the at least a subset of the plurality of second connected devices comprises information relating to one or more acceptable commands associated with at least one connected device of the at least a subset of the plurality of second connected devices.

9 . The method of claim 1 , wherein the state information associated with the at least a subset of the plurality of second connected devices comprises security association information associated with at least one connected device of the at least a subset of the plurality of second connected devices.

10 . The method of claim 9 , wherein determining that the gateway device may initiate performance of the composite service is based, at least in part, on the security association information.

11 . The method of claim 1 , wherein the state information associated with the at least a subset of the plurality of second connected devices comprises a group token.

12 . The method of claim 11 , wherein the group token comprises a group key.

13 . The method of claim 12 , wherein the request to perform the composite service by the group of connected devices comprises the group key.

14 . The method of claim 11 , wherein the determining that the gateway device may initiate performance of the composite service by the plurality of second connected devices comprises determining that the gateway device is associated with the group token.

15 . The method of claim 14 , wherein the request to perform the composite service comprises the group token.

16 . The method of claim 1 , wherein the state information associated with the at least a subset of the plurality of second connected devices comprises information relating to acceptable data that may be communicated to the at least a subset of the plurality of second connected devices.

17 . The method of claim 1 , wherein the gateway device comprises at least one of a smartphone, a tablet computer system, a desktop computer system, a laptop computer system, a wearable computing device, a connected vehicle, a telematics system, a security system, a home automation system, a connected thermostat, a connected heating system, a connected cooling system, a utility meter, a medical device, a gaming system, a network infrastructure system, a television, a speaker, and a digital camera.

18 . The method of claim 1 , wherein at least one connected device of the plurality of second connected devices comprises at least one of a smartphone, a tablet computer system, a desktop computer system, a laptop computer system, a wearable computing device, a connected vehicle, a telematics system, a security system, a home automation system, a connected thermostat, a connected heating system, a connected cooling system, a utility meter, a medical device, a gaming system, a network infrastructure system, a television, a speaker, and a digital camera.