IP Library Patent Application 11105363
Patent Application
App. No. 11/105,363

Secure communication protocol

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/105,363
Abstract

A method, of establishing secure communication, may include: generating a first symmetric key; encrypting at least the first symmetric key according to a public key; sending a first message that includes at least the encrypted first symmetric key to a communication counterpart using a connectionless protocol; and receiving, as part of a connection-oriented-protocol first session, a second message that includes an acknowledgement encrypted via the first symmetric key. A counterpart method may include: receiving and decrypting the first message according to the corresponding private key; and encrypting and then sending the second message. Another such method may include: encrypting a chunk of information according to a first symmetric key, the first symmetric key having been used in a previous and now-stopped connection-oriented session with a communication counterpart; and sending to a communication counterpart a first message whose payload at least in part the encrypted chunk of information.

Claims (56)

1 - 14 . (canceled)

15 . A method of securely communicating, the method comprising:

encrypting a chunk of information according to a first symmetric key, the first symmetric key having been used in a previous and now-stopped connection-oriented session with a communication counterpart; and

sending a first message to a communication counterpart, the first message having a payload at least a portion of which includes the encrypted chunk of information.

16 . The method of claim 15 , further comprising:

using a connectionless protocol to send the first message.

17 . The method of claim 16 , wherein the connectionless protocol is UDP.

18 . The method of claim 15 , further comprising:

generating a second symmetric key; and

wherein the chunk of information is the second symmetric key.

19 . The method of claim 18 , wherein the previous connection-oriented session was a first session, and the method further comprises:

receiving, as part of a second connection-oriented-protocol session, at least a second message from the counterpart, at least a part of the payload of the at-least-second message being encrypted with the second symmetric key.

20 . The method of claim 19 , wherein a protocol for the second session is TCP (transmission control protocol).

21 . The method of claim 20 , further comprising:

letting the first session stop; and

keeping the first symmetric key available for use with a future second connection-oriented protocol session.

22 . The method of claim 21 , wherein the keeping available of the first symmetric key includes not deallocating volatile memory allocated thereto.

23 . The method of claim 15 , further comprising:

receiving a second message from the counterpart, at least a part of the payload of the at-least-second message being encrypted with the first symmetric key.

24 . The method of claim 23 , wherein a protocol for the second message is a connectionless protocol.

25 . The method of claim 24 , wherein the connectionless protocol is UDP (user datagram protocol).

26 . The method of claim 23 , wherein the chunk of information is a first chunk, the second message includes at least a second symmetric key that has been encrypted according to the first symmetric key, and the method further comprises:

decrypting the second message according to the first symmetric key to obtain at least the second symmetric key;

encrypting a second chunk of information according to the second symmetric key; and

sending at least a third message to the counterpart, the third message having a payload at least a portion of which includes the second encrypted chunk of information.

27 . The method of claim 26 , wherein the second chunk of information includes at least one of acknowledgment data and data desired to be kept confidential.

28 . The method of claim 26 , wherein:

the sending of the at-least-third message is a part of a connection-oriented-protocol first session.

29 . The method of claim 28 , wherein the connection-oriented-protocol is TCP (transmission control protocol).

30 . The method of claim 29 , further comprising:

letting the first session stop; and

keeping the first symmetric key available for use with a future second connection-oriented protocol session.

31 . The method of claim 30 , wherein the keeping available of the first symmetric key includes not deallocating volatile memory allocated thereto.

32 - 35 . (canceled)

36 . A machine-readable medium comprising instructions, execution of which by a machine facilitates establishing secure communication, the machine-readable instructions including:

a first code segment to encrypt a chunk of information according to a first symmetric key, the first symmetric key having been used in a previous and now-stopped connection-oriented session with a communication counterpart; and

a second code segment to send a first message to a communication counterpart, the first message having a payload at least a portion of which includes the encrypted chunk of information.

37 . The machine-readable instructions of claim 36 , further comprising:

a third code segment to generate a second symmetric key; and

wherein the chunk of information is the second symmetric key.

38 . The machine-readable instructions of claim 37 , wherein the previous connection-oriented session was a first session, and the machine-readable instructions further comprise:

a fourth code segment to receive, as part of a second connection-oriented-protocol session, at least a second message from the counterpart, at least a part of the payload of the at-least-second message being encrypted with the second symmetric key.

39 . The machine-readable instructions of claim 38 , wherein a fifth code segment to let the first session stop; and

a sixth code segment to keep the first symmetric key available for use with a future second connection-oriented protocol session.

40 . The machine-readable instructions of claim 37 , further comprising:

a fourth code segment to receive a second message from the counterpart, at least a part of the payload of the at-least-second message being encrypted with the first symmetric key.

41 . The machine-readable instructions of claim 40 , wherein the chunk of information is a first chunk, the second message includes at least a second symmetric key that has been encrypted according to the first symmetric key, and the machine-readable instructions further comprise:

a fifth code segment to decrypt the second message according to the first symmetric key to obtain at least the second symmetric key;

a sixth code segment to encrypt a second chunk of information according to the second symmetric key; and

a seventh code segment to send at least a third message to the counterpart, the third message having a payload at least a portion of which includes the second encrypted chunk of information.

42 - 43 . (canceled)

44 . An apparatus for establishing secure communication, the apparatus comprising:

means for encrypting a chunk of information according to a first symmetric key, the first symmetric key having been used in a previous and now-stopped connection-oriented session with a communication counterpart; and

means for sending a first message to a communication counterpart, the first message having a payload at least a portion of which includes the encrypted chunk of information.

45 - 46 . (canceled)

47 . A machine configured to implement the method of claim 15.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2014
From: COLORADO REMEDIATION TECHNOLOGIES, LLC
To: FORTINET, INC.
Reel/Frame 032113/0928 →
RELEASE Recorded Nov 20, 2008
From: SECURE ELEMENTS, INCORPORATED
To: VENTURE LENDING & LEASING IV, INC.
Reel/Frame 021899/0419 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2008
From: SECURE ELEMENTS, INCORPORATED
To: FORTINET, INC.
Reel/Frame 021738/0586 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2007
From: DIEFENDERFER, KRISTOPHER G.; LOVELL, PETER DAVID; BEZILLA, DANIEL BAILEY
To: SECURE ELEMENTS, INC.
Reel/Frame 019882/0020 →
SECURITY AGREEMENT Recorded Mar 14, 2006
From: SECURE ELEMENTS, INCORPORATED
To: VENTURE LENDING & LEASING IV, INC.
Reel/Frame 017679/0372 →