IP Library Granted Patent US 9,232,024
Granted Patent B2
US 9,232,024 · App. 13/709,363 · Granted Jan 5, 2016

Communicating an identity to a server

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,232,024
App. No.
13/709,363
Granted
Jan 5, 2016
Kind
B2
Abstract

An identity is communicated by a client device to a server without requiring the identity to be disclosed to eavesdroppers and without requiring the use of symmetric or asymmetric cryptography. In one example, the identity is an identity of the client device, where the identity has been assigned to the client device by the server through the provisioning of a unique subset of client-identifying keys. In another example, the identity is an identity of a group shared secret that has been provisioned by the server to the client device.

Claims (34)

1. A method to be performed by a client device, the method comprising:

receiving, via a hardware-implemented communication interface of the client device, a unique subset of M client-identifying keys from a provisioning server;

upon determining a need to communicate an identity of the client device to a server, calculating for each of the M client-identifying keys a hash of a combination comprising the client-identifying key and a current instance of a modulating value; and

communicating the identity of the client device to the server by communicating to the server, via the communication interface, a message comprising a hash-dependent value for each hash, where each hash-dependent value comprises one of the respective hash, a portion of the respective hash, or a value dependent on the respective hash,

wherein the need is determined in response to the client device requesting access to one or more services from the server, the server requiring identification of the client device.

2. A client device operative:

to receive, via a hardware-implemented communication interface of the client device, a unique subset of M client-identifying keys from a provisioning server;

upon determining a need to communicate an identity of the client device to a server, to calculate for each of the M client-identifying keys a hash of a combination comprising the client-identifying key and a current instance of a modulating value; and

to communicate the identity of the client device to the server by communicating to the server, via the communication interface, a message comprising a hash-dependent value for each hash, where each hash-dependent value comprises one of the respective hash, a portion of the respective hash, or a value dependent on the respective hash,

wherein the need is determined in response to the client device requesting access to one or more services from the server the server requiring identification of the client device.

3. A non-transitory computer-readable medium storing code which, when executed by a processor of a client device, causes the client device to:

upon determining a need to communicate an identity of the client device to a server, calculate for each of a unique subset of M client-identifying keys received from a provisioning server via a communication interface of the client device a hash of a combination comprising the client-identifying key and a current instance of a modulating value; and

communicate the identity of the client device to the server by communicating to the server, via the communication interface, a message comprising a hash-dependent value for each hash, where each hash-dependent value comprises one of the respective hash, a portion of the respective hash, or a value dependent on the respective, hash,

wherein the need is determined in response to the client device requesting access to one or more services from the server, the server requiring identification of the client device.

4. The method as claimed in claim 1 , wherein receiving the unique subset of M client-identifying keys from the provisioning server comprises embedding the unique subset of M client-identifying keys in the client device at a time of manufacture of the client device.

5. The method as claimed in claim 1 , wherein receiving the unique subset of M client-identifying keys from the provisioning server comprises receiving the unique subset of M client-identifying keys after a time of manufacture of the client device.

6. The method as claimed in claim 1 , wherein the comprises a web server which requires identification of the client device as a prerequisite to authentication of the client device.

7. The method as claimed in claim 1 , further comprising:

receiving the current instance of the modulating value via a broadcast from the provisioning server or from the server.

8. The method as claimed in claim 1 , further comprising:

receiving an indication of a hash algorithm to calculate the hash via a broadcast from the provisioning server or from the server.

9. The method as claimed in claim 1 , further comprising:

receiving an indication of the nature of the combination via a broadcast from the provisioning server or from the server.

10. The method as claimed in claim 1 , wherein the message further comprises an indication of the number M of client-identifying keys to which the message pertains.

11. The client device as claimed in claim 2 , wherein the client device is operative to receive the unique subset of M client-identifying keys from the provisioning server by embedding the unique subset of M client-identifying keys in the client device at a time of manufacture of the client device.

12. The client device as claimed in claim 2 , wherein the client device is operative to receive the unique subset of M client-identifying keys from the provisioning server after a time of manufacture of the client device.

13. The client device as claimed in claim 2 , wherein the server comprises a web server which requires identification of the client device as a prerequisite to authentication of the client device.

14. The client device as claimed in claim 2 , wherein the client device is operative to receive the current instance of the modulating value via a broadcast from the provisioning server or from the server.

15. The client device as claimed in claim 2 , wherein the client device is operative to receive an indication of a hash algorithm to calculate the hash via a broadcast from the provisioning server or from the server.

16. The client device as claimed in claim 2 , wherein the client device is operative to receive an indication of the nature of the combination via a broadcast from the provisioning server or from the server.

17. The client device as claimed in claim 2 , wherein the message further comprises an indication of the number M of client-identifying keys to which the message pertains.

18. The non-transitory computer-readable medium as claimed in claim 3 , the unique subset of M client-identifying keys having been embedded in the client device at a time of manufacture of the client device.

19. The non-transitory computer-readable medium as claimed in claim 3 , the unique subset of M client-identifying keys having been received after a time of manufacture of the client device.

20. The non-transitory computer-readable medium as claimed in claim 3 , wherein the message further comprises an indication of the number M of client-identifying keys to which the message pertains.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064271/0199 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded Sep 25, 2015
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 036689/0970 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2013
From: SUFFLING, DAVID ROBERT
To: RESEARCH IN MOTION LIMITED
Reel/Frame 030194/0494 →