IP Library Granted Patent US 8,464,062
Granted Patent B2
US 8,464,062 · App. 13/434,265 · Granted Jun 11, 2013

Systems, devices, and methods for securely transmitting a security parameter to a computing device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,464,062
App. No.
13/434,265
Granted
Jun 11, 2013
Kind
B2
Abstract

Embodiments of the systems, devices, and methods described herein generally facilitate the secure transmittal of security parameters. In accordance with at least one embodiment, a representation of first data comprising a password is generated at the first computing device as an audio signal. The audio signal is transmitted from the first computing device to the second computing device. The password is determined from the audio signal at the second computing device. A key exchange is performed between the first computing device and the second computing device wherein a key is derived at each of the first and second computing devices. In at least one embodiment, one or more security parameters (e.g. one or more public keys) are exchanged between the first and second computing devices, and techniques for securing the exchange of security parameters or authenticating exchanged security parameters are generally disclosed herein.

Claims (41)

1. A method of transmitting one or more security parameters from a first computing device to a second computing device, the method being performed at the first computing device, the method comprising:

generating an audio signal for transmission to the second computing device, wherein the audio signal is a representation of first data, the first data comprising a password, wherein the password is not derived from the one or more security parameters;

transmitting the audio signal to the second computing device at which the password is determinable from the audio signal; and

performing a key exchange with the second computing device over a communication channel between the first and second computing devices, wherein second data is exchanged between the first and second computing devices in accordance with a key exchange protocol, such that a key is derived at each of the first and second computing devices using the password, and wherein the one or more security parameters is transmitted to the second computing device during the key exchange;

wherein said performing further comprises

computing a confirmation value based on at least the one or more security parameters and the key derived at the first computing device, and

transmitting the confirmation value to the second computing device, wherein the one or more security parameters are authenticated when the confirmation value is successfully verified at the second computing device; and

wherein the one or more security parameters comprise one or more public keys stored on the first computing device.

2. The method of claim 1 , wherein said transmitting the audio signal to the second computing device is performed when the first and second computing devices are in close physical proximity.

3. The method of claim 1 , wherein the confirmation value comprises a keyed-hash message authentication code.

4. The method of claim 1 , wherein the key exchange protocol comprises a SPEKE protocol.

5. The method of claim 1 , wherein the audio signal comprises a plurality of audio tones.

6. The method of claim 1 , wherein at the transmitting, the audio signal is transmitted via a speaker of the first computing device.

7. The method of claim 1 , wherein at the transmitting, the audio signal is transmitted via a channel established during a phone call between the first computing device and the second computing device.

8. The method of claim 1 , wherein the first data further comprises routing data associated with the first computing device.

9. The method of claim 8 , wherein the routing data associated with the first computing device comprises a PIN associated with the first computing device, and wherein the communication channel between the first and second computing devices comprises a PIN-to-PIN channel.

10. The method of claim 1 , further comprising generating the password, wherein the password is generated as a random number or string.

11. The method of claim 10 , wherein the password is generated for a single instance of said generating the audio signal.

12. The method of claim 1 , further comprising receiving one or more second security parameters from the second computing device, receiving a second confirmation value from the second computing device, and verifying the second confirmation value.

13. The method of claim 1 , wherein at least one computing device selected from the following group comprises a mobile device: the first computing device, and the second computing device.

14. A first computing device comprising a processor and a memory, the processor configured to perform a method of transmitting one or more security parameters to a second computing device by executing one or more application modules, said one or more application modules comprising:

a module configured to generate an audio signal for transmission to the second computing device, wherein the audio signal is a representation of first data, the first data comprising a password, wherein the password is not derived from the one or more security parameters;

a module configured to transmit the audio signal to the second computing device at which the password is determinable from the audio signal; and

a module configured to perform a key exchange with the second computing device over a communication channel between the first and second computing devices, wherein second data is exchanged between the first and second computing devices in accordance with a key exchange protocol, such that a key is derived at each of the first and second computing devices using the password, and wherein the one or more security parameters is transmitted to the second computing device during the key exchange;

wherein said module configured to perform the key exchange is further configured to

compute a confirmation value based on at least the one or more security parameters and the key derived at the first computing device, and to

transmit the confirmation value to the second computing device, wherein the one or more security parameters are authenticated when the confirmation value is successfully verified at the second computing device; and

wherein the one or more security parameters comprise one or more public keys stored on the first computing device.

15. The first computing device of claim 14 , wherein at least one computing device selected from the following group comprises a mobile device: the first computing device, and the second computing device.

16. The first computing device of claim 14 , wherein the confirmation value comprises a keyed-hash message authentication code.

17. The first computing device of claim 14 , wherein the key exchange protocol comprises a SPEKE protocol.

18. A non-transitory computer readable storage medium comprising instructions that, when executed by a processor of a first computing device, cause the first computing device to perform acts of a method of transmitting one or more security parameters to a second computing device, the method performed at the first computing device, the acts comprising:

generating an audio signal for transmission to the second computing device, wherein the audio signal is a representation of first data, the first data comprising a password, wherein the password is not derived from the one or more security parameters;

transmitting the audio signal to the second computing device at which the password is determinable from the audio signal; and

performing a key exchange with the second computing device over a communication channel between the first and second computing devices, wherein second data is exchanged between the first and second computing devices in accordance with a key exchange protocol, such that a key is derived at each of the first and second computing devices using the password, and wherein the one or more security parameters is transmitted to the second computing device during the key exchange;

wherein said performing further comprises computing a confirmation value based on at least the one or more security parameters and the key derived at the first computing device, and

transmitting the confirmation value to the second computing device, wherein the one or more security parameters are authenticated when the confirmation value is successfully verified at the second computing device; and

wherein the one or more security parameters comprise one or more public keys stored on the first computing device.

19. The medium of claim 18 , wherein at least one computing device selected from the following group comprises a mobile device: the first computing device, and the second computing device.

20. The medium of claim 18 , wherein the confirmation value comprises a keyed-hash message authentication code.

21. The medium of claim 18 , wherein the key exchange protocol comprises a SPEKE protocol.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded Oct 20, 2014
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 034016/0419 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2012
From: BROWN, MICHAEL S.; LITTLE, HERBERT A.
To: RESEARCH IN MOTION LIMITED
Reel/Frame 027956/0862 →