IP Library Granted Patent US 9,065,642
Granted Patent B2
US 9,065,642 · App. 13/458,594 · Granted Jun 23, 2015

Intercepting key sessions

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,065,642
App. No.
13/458,594
Granted
Jun 23, 2015
Kind
B2
Abstract

In some implementations, a method for providing a session key to a third party includes identifying a private key associated with a public key certificate in response to an event. A session key for a communication session is based, at least in part, on the private key, an associated seed for a random number generator, and public keys assigned to user equipment participating in the communication session. The private key associated with the public key certificate is automatically transmitted to an interception authority. The interception authorities are configured to grant a third party access to the private key and the associated seed to in response to a request from a third party authorized to access the communication session.

Claims (28)

1. A method for providing a session key to a third party, comprising:

obtaining a private key associated with a public key certificate for a first device,

generating the session key for a communication session between the first device and a second device based, at least in part, on the private key, an associated seed for a random number generator, and public keys assigned to the first device participating in the communication session; and

in connection with establishing the communication session, transmitting, to a first interception authority, by the first device, the private key for the first device,

wherein the second device transmits the associated seed for the random number generated to a second interception authority for storing separate from the private key,

wherein the first interception authority is different from the second interception authority, and,

in response to response to an authorized request to access the communication session between the first device and the second device, the first interception authority is configured to grant the third party access to the private key and the second interception authority is configured to grant the third party access to the associated seed.

2. The method of claim 1 , wherein the public key certificate is an implicit certificate.

3. The method of claim 1 , wherein the session key is determined based on two or more private keys including the private key.

4. The method of claim 1 , wherein the first interception authority comprises a certification authority that issued the public key certificate.

5. The method of claim 1 , wherein the public key certificate comprises a first certificate, the communication session comprises a subsequent communication session, the method further comprising establishing an initial communication session with the first interception authority using a session key generated using a second public key certificate assigned to the first interception authority and the private key, wherein the private key is transmitted to the first interception authority using the session key.

6. The method of claim 1 , wherein the public key certificate is based, at least in part, on an Elliptic Curve Qu-Vanstone (ECQV) protocol and the session key is based on an Menezes-Qu-Vanstone (MQV) protocol.

7. The method of claim 1 , wherein the private key is obtained in response to at least one of activating of second device or receiving a request for a communication session from the second device.

8. User equipment for providing a session key to a third party, comprising:

memory configured to store a private key associated with a public key certificate; and

one or more processors configured to:

obtaining the private key associated with a public key certificate for a first device,

generating the session key for a communication session between the first device and a second device based, at least in part, on the private key, an associated seed for a random number generator, and public keys assigned to the first device participating in the communication session; and

in connection with establishing the communication session, transmitting, to a first interception authority, by the first device, the private key for the first device,

wherein the second device transmits the associated seed for the random number generated to a second interception authority for storing separate from the private key,

wherein the first interception authority is different from the second interception authority, and,

in response to response to an authorized request to access the communication session between the first device and the second device, the first interception authority is configured to grant the third party access to the private key and the second interception authority is configured to grant the third party access to the associated seed.

9. The user equipment of claim 8 , wherein the public key certificate is an implicit certificate.

10. The user equipment of claim 8 , wherein the session key is determined based on two or more private keys including the private key.

11. The user equipment of claim 8 , wherein the first interception authority comprises a certification authority that issued the public key certificate.

12. The user equipment of claim 8 , wherein the public key certificate comprises a first certificate, the communication session comprises a subsequent communication session, the processors further operable to establish an initial communication session with the first interception authority using a session key generated using a second public key certificate assigned to the first interception authority and the private key, wherein the private key is transmitted to the first interception authority using the session key.

13. The user equipment of claim 8 , wherein the key certificate is based, at least in part, on an Elliptic Curve Qu-Vanstone (ECQV) protocol and the session key is based on an Menezes-Qu-Vanstone (MQV) protocol.

14. The user equipment of claim 8 , wherein the private key is obtained in response to at least one of activating of second device or receiving a request for a communication session from the second device.

Assignments (6)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064271/0199 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 10, 2012
From: CERTICOM (U.S.) LIMITED
To: CERTICOM CORP.
Reel/Frame 029106/0660 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2012
From: CAMPAGNA, MATTHEW JOHN
To: CERTICOM (U.S.) LIMITED
Reel/Frame 028538/0541 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2012
From: ZAVERUCHA, GREGORY MARC
To: CERTICOM CORP.
Reel/Frame 028538/0579 →