IP Library Granted Patent US 8,364,772
Granted Patent B1
US 8,364,772 · App. 13/352,480 · Granted Jan 29, 2013

System, device and method for dynamically securing instant messages

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,364,772
App. No.
13/352,480
Granted
Jan 29, 2013
Kind
B1
Abstract

An Instant Messaging security system that encrypts Instant Messages sent by a Instant Messaging user to an Instant Messaging server by intercepting the messages, negotiating a preferred security algorithm and forwarding the encrypted messages to the server. The security system intercepts and decrypts encrypted messages sent by the server to the user. The security system is able to determine whether a receiving user is equipped with a similar security system without prior knowledge of network addresses, configuration or capability. The security system is transparent to the Instant Message service provider and may provide one or more indicators to users that messages are encrypted during forwarding.

Claims (49)

1. A computer implemented method, comprising:

intercepting an unencrypted instant messaging (IM) communication sent by an originating device for transmission over a wide area network to a remote destination device;

determining, using a first IM security device associated with the originating device, whether a second IM security device is available for the destination device, the determining including:

transmitting, in response to intercepting the unencrypted instant messaging communication, a discovery communication including data indicating that the unencrypted instant messaging communication can be encrypted according to one or more security protocols available at the first IM security device; and

determining whether a response message to the discovery communication is received from the second IM security device;

in response to determining that the second IM security device is available for the destination device:

transmitting a first negotiation communication to the second IM security device, the first negotiation communication including data for negotiating an encryption technique between the first and the second IM security devices to encrypt unencrypted instant messaging communications from the originating device to the destination device and to decrypt encrypted instant messaging communications from the destination device to the originating device;

receiving a second negotiation communication from the second IM security device, the second negotiation communication specifying the encryption technique;

encrypting the unencrypted instant messaging communication from the originating device using the encryption technique; and

transmitting the encrypted instant messaging communication to the destination device, wherein the encrypted instant messaging communication is decrypted by the second IM security device for delivery to the destination device.

2. The method of claim 1 , wherein transmitting the first negotiation communication comprises transmitting a nonce and identifying information, wherein the nonce is a random unique value.

3. The method of claim 2 , wherein transmitting the first negotiation communication further comprises transmitting a key identification, key data, and authentication information.

4. The method of claim 1 , wherein transmitting the first negotiation communication comprises transmitting a master key information request; and the method further comprises:

receiving master key information.

5. The method of claim 1 , wherein the first negotiation communication and the second negotiation communication include information used to generate encryption keys.

6. The method of claim 5 , wherein the information used to generate encryption keys includes Diffie-Hellman keys.

7. A system, comprising:

one or more data processors; and

a data storage apparatus encoded with instructions that when executed by the one or more data processors cause the one or more data processors to perform operations comprising:

intercepting an unencrypted instant messaging (IM) communication sent by an originating device for transmission over a wide area network to a remote destination device;

determining, using a first IM security device associated with the originating device, whether a second IM security device is available for the destination device, the determining including:

transmitting, in response to intercepting the unencrypted instant messaging communication, a discovery communication including data indicating that the unencrypted instant messaging communication can be encrypted according to one or more security protocols available at the first IM security device; and

determining whether a response message to the discovery communication is received from the second IM security device;

in response to determining that the second IM security device is available for the destination device:

transmitting a first negotiation communication to the second IM security device, the first negotiation communication including data for negotiating an encryption technique between the first and the second IM security devices to encrypt unencrypted instant messaging communications from the originating device to the destination device and to decrypt encrypted instant messaging communications from the destination device to the originating device;

receiving a second negotiation communication from the second IM security device, the second negotiation communication specifying the encryption technique;

encrypting the unencrypted instant messaging communication from the originating device using the encryption technique; and

transmitting the encrypted instant messaging communication to the destination device, wherein the encrypted instant messaging communication is decrypted by the second IM security device for delivery to the destination device.

8. The system of claim 7 , wherein transmitting the first negotiation communication comprises transmitting a nonce and identifying information, wherein the nonce is a random unique value.

9. The system of claim 8 , wherein transmitting the first negotiation communication further comprises transmitting a key identification, key data, and authentication information.

10. The system of claim 7 , wherein transmitting the first negotiation communication comprises transmitting a master key information request, and the instructions cause the one or more data processors to further perform operations comprising:

receiving master key information.

11. The system of claim 7 , wherein the first negotiation communication and the second negotiation communication include information used to generate encryption keys.

12. The system of claim 11 , wherein the information used to generate encryption keys includes Diffie-Hellman keys.

13. A non-transitory computer storage medium encoded with a computer program, the program comprising instructions that when executed by one or more data processing apparatuses cause the one or more data processing apparatuses to perform operations, comprising:

intercepting an unencrypted instant messaging (IM) communication sent by an originating device for transmission over a wide area network to a remote destination device;

determining, using a first IM security device associated with the originating device, whether a second IM security device is available for the destination device, the determining including:

transmitting, in response to intercepting the unencrypted instant messaging communication, a discovery communication including data indicating that the unencrypted instant messaging communication can be encrypted according to one or more security protocols available at the first IM security device; and

determining whether a response message to the discovery communication is received from the second IM security device;

in response to determining that the second IM security device is available for the destination device:

transmitting a first negotiation communication to the second IM security device, the first negotiation communication including data for negotiating an encryption technique between the first and the second IM security devices to encrypt unencrypted instant messaging communications from the originating device to the destination device and to decrypt encrypted instant messaging communications from the destination device to the originating device;

receiving a second negotiation communication from the second IM security device, the second negotiation communication specifying the encryption technique;

encrypting the unencrypted instant messaging communication from the originating device using the encryption technique; and

transmitting the encrypted instant messaging communication to the destination device, wherein the encrypted instant messaging communication is decrypted by the second IM security device for delivery to the destination device.

14. The non-transitory computer storage medium of claim 13 , wherein transmitting the first negotiation communication comprises transmitting a nonce and identifying information wherein the nonce is a random unique value.

15. The non-transitory computer storage medium of claim 14 , wherein transmitting the first negotiation communication further comprises transmitting a key identification, key data, and authentication information.

16. The non-transitory computer storage medium of claim 13 , wherein transmitting the first negotiation communication comprises transmitting a master key information request, and the instructions cause the one or more data processing apparatuses to further perform operations comprising:

receiving master key information.

17. The non-transitory computer storage medium of claim 13 , wherein the first negotiation communication and the second negotiation communication include information used to generate encryption keys.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →