IP Library Granted Patent US 9,577,995
Granted Patent B1
US 9,577,995 · App. 13/757,866 · Granted Feb 21, 2017

Systems and methods for enabling secure communication between endpoints in a distributed computerized infrastructure for establishing a social network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,577,995
App. No.
13/757,866
Granted
Feb 21, 2017
Kind
B1
Abstract

A computer-implemented method performed in a system comprising a first endpoint, the first endpoint comprising at least one central processing unit, a memory, a storage system and a network interface unit, the system being accessible by a user, the method involving: generating a message at the first endpoint for sending to a second endpoint, the message incorporating a message body and a message metadata, the message metadata comprising a secure channel invitation for the second endpoint to securely communicate with the first endpoint, the secure channel invitation being hidden within the message metadata; communicating the message from the first endpoint to the second endpoint; receiving a response message, at a first endpoint, from the second endpoint; and establishing the secure communication channel between the first endpoint and the second endpoint based on the received response message.

Claims (22)

1. A computer-implemented method performed in a system comprising a first endpoint, the first endpoint comprising at least one central processing unit, a memory, a storage system and a network interface unit, the system being accessible by a user, the method comprising:

a. Generating a message at the first endpoint for sending to a second endpoint, the message comprising a human-readable message body and a message metadata, the message metadata being separate and distinct from the message body, the message metadata comprising a secure channel invitation for the second endpoint to securely communicate with the first endpoint, the secure channel invitation being hidden within the message metadata and does not comprise an instruction to download a communication software;

b. Communicating the message from the first endpoint to the second endpoint;

c. Receiving a response message, at a first endpoint, from the second endpoint; and

d. Establishing the secure communication channel between the first endpoint and the second endpoint based on the received response message, wherein the establishing of the secure communication channel between the first endpoint and the second endpoint comprises performing an encryption key exchange between the first endpoint and the second endpoint, wherein the encryption key exchange between the first endpoint and the second endpoint comprises generating a second message from the first endpoint to the second endpoint, the second message being formatted in accordance with Diffie-Hellman key exchange protocol and sending the second message from the first endpoint to the second endpoint, wherein the encryption key exchange between the first endpoint and the second endpoint is an asymmetric key exchange and wherein the establishing of the secure communication channel between the first endpoint and the second endpoint comprises performing a security association negotiation between the first endpoint and the second endpoint.

2. The computer-implemented method of claim 1 , further comprising protecting subsequent messages between the first endpoint and the second endpoint.

3. The computer-implemented method of claim 2 , wherein the protecting subsequent messages comprises encapsulating the subsequent messages in an encrypted and authenticated container and communicating the encapsulated messages from the first endpoint to the second endpoint.

4. A computer-implemented method performed in a system comprising a first endpoint, the first endpoint comprising at least one central processing unit, a memory, a storage system and a network interface unit, the system being accessible by a user, the method comprising:

a. Generating a human-readable message at the first endpoint for sending to a second endpoint, the human-readable message comprising a human-readable message body and a plurality of instructions to install a software for establishing secure communication between the first endpoint and the second endpoint, the plurality of instructions being hidden within a message metadata separate and distinct from the human-readable message body and do not comprise an instruction to download a communication software;

b. Communicating the human-readable message from the first endpoint to the second endpoint;

c. Receiving a response message, at a first endpoint, from the second endpoint; and

d. Establishing the secure communication channel between the first endpoint and the second endpoint based on the received response message using the software for establishing secure communication between the first endpoint and the second endpoint, wherein the establishing of the secure communication channel between the first endpoint and the second endpoint comprises performing an encryption key exchange between the first endpoint and the second endpoint, wherein the encryption key exchange between the first endpoint and the second endpoint comprises generating a second message from the first endpoint to the second endpoint, the second message being formatted in accordance with Diffie-Hellman key exchange protocol and sending the second message from the first endpoint to the second endpoint, wherein the encryption key exchange between the first endpoint and the second endpoint is an asymmetric key exchange and wherein the establishing of the secure communication channel between the first endpoint and the second endpoint comprises performing a security association negotiation between the first endpoint and the second endpoint.

5. The computer-implemented method of claim 4 , further comprising protecting subsequent messages between the first endpoint and the second endpoint.

6. The computer-implemented method of claim 5 , wherein the protecting subsequent messages comprises encapsulating the subsequent messages in an encrypted and authenticated container and communicating the encapsulated messages from the first endpoint to the second endpoint.

7. A computer-implemented method performed in a system comprising a first endpoint, the first endpoint comprising at least one central processing unit, a memory, a storage system and a network interface unit, the system being accessible by a user, the method comprising:

a. Generating a message at the first endpoint for sending to a second endpoint, the message comprising a human-readable message body and a plurality of instructions to install a software for establishing secure communication between the first endpoint and the second endpoint, the plurality of instructions being hidden within a message metadata separate and distinct from the human-readable message body and do not comprise an instruction to download a communication software;

b. Communicating the generated message from the first endpoint to the second endpoint;

c. Receiving a response message, at a first endpoint, from the second endpoint; and

d. Establishing the secure communication channel between the first endpoint and the second endpoint based on the received response message using the software for establishing secure communication between the first endpoint and the second endpoint, wherein the establishing of the secure communication channel between the first endpoint and the second endpoint comprises performing an encryption key exchange between the first endpoint and the second endpoint, wherein the encryption key exchange between the first endpoint and the second endpoint comprises generating a second message from the first endpoint to the second endpoint, the second message being formatted in accordance with Diffie-Hellman key exchange protocol and sending the second message from the first endpoint to the second endpoint, wherein the encryption key exchange between the first endpoint and the second endpoint is an asymmetric key exchange and wherein the establishing of the secure communication channel between the first endpoint and the second endpoint comprises performing a security association negotiation between the first endpoint and the second endpoint.

8. The computer-implemented method of claim 7 , further comprising protecting subsequent messages between the first endpoint and the second endpoint.

9. The computer-implemented method of claim 8 , wherein the protecting subsequent messages comprises encapsulating the subsequent messages in an encrypted and authenticated container and communicating the encapsulated messages from the first endpoint to the second endpoint.

10. The computer-implemented method of claim 7 , further comprising hiding at least one of the message, the response message and the second message from the user.

Assignments (22)
RELEASE OF SECURITY INTEREST Recorded Dec 17, 2024
From: JPMORGAN CHASE BANK, N.A.
To: AURA SUB, LLC; INTERSECTIONS, LLC; TWINGATE INC.
Reel/Frame 069616/0097 →
SECURITY INTEREST Recorded Dec 10, 2024
From: INTERSECTIONS, LLC
To: CERBERUS BUSINESS FINANCE AGENCY, LLC
Reel/Frame 069542/0987 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2023
From: AURA SUB, LLC
To: AURA HOLDCO, LLC
Reel/Frame 065717/0500 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2023
From: CF NEWCO, INC.
To: INTERSECTIONS, LLC
Reel/Frame 065717/0839 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2023
From: CF INTERMEDIATE HOLDINGS, LLC
To: CF NEWCO, INC.
Reel/Frame 065717/0779 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2023
From: AURA HOLDCO, LLC
To: CF INTERMEDIATE HOLDINGS, LLC
Reel/Frame 065717/0668 →
CORRECTIVE ASSIGNMENT TO REMOVE THE ERRONEOUS SERIAL NUMBER 16/000,700 AND 16/149,928 PREVIOUSLY RECORDED AT REEL: 059251 FRAME: 0342. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME Recorded Jun 6, 2023
From: PANGO INC.
To: PANGO LLC
Reel/Frame 064065/0406 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION NUMBER 16000700 AND 16149928 PREVIOUSLY RECORDED AT REEL: 059392 FRAME: 0479. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 14, 2023
From: PORTUNUS PARENT, LLC
To: AURA HOLDCO, LLC
Reel/Frame 063873/0551 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE SERIAL NUMBERS 16000700 AND 16149928 PREVIOUSLY RECORDED AT REEL: 059285 FRAME: 0023. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 14, 2023
From: PANGO LLC
To: PORTUNUS PARENT, LLC
Reel/Frame 063873/0502 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION NUMBERS 16000700 AND 16149928 PREVIOUSLY RECORDED AT REEL: 059462 FRAME: 0043. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 14, 2023
From: AURA HOLDCO, LLC
To: AURA SUB, LLC
Reel/Frame 063859/0966 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2022
From: AURA HOLDCO, LLC
To: AURA SUB, LLC
Reel/Frame 059462/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2022
From: PORTUNUS PARENT, LLC
To: AURA HOLDCO, LLC
Reel/Frame 059392/0479 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2022
From: PANGO LLC
To: PORTUNUS PARENT, LLC
Reel/Frame 059285/0023 →
CHANGE OF NAME Recorded Feb 25, 2022
From: PANGO INC.
To: PANGO LLC
Reel/Frame 059251/0342 →
RELEASE OF SECURITY INTEREST Recorded Dec 8, 2021
From: JPMORGAN CHASE BANK, N.A.
To: PANGO, INC.; INTERSECTIONS INC.
Reel/Frame 058330/0983 →
SECURITY INTEREST Recorded Dec 7, 2021
From: INTERSECTIONS INC.; PANGO INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 058328/0941 →
CHANGE OF NAME Recorded Sep 24, 2020
From: ANCHORFREE INC.
To: PANGO INC.
Reel/Frame 053879/0292 →
SECURITY INTEREST Recorded Jul 2, 2020
From: PANGO, INC.; INTERSECTIONS INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 053105/0591 →
RELEASE OF SECURITY INTEREST Recorded Jul 1, 2020
From: PACIFIC WESTERN BANK
To: PANGO INC. (FORMERLY KNOWN AS ANCHORFREE INC.)
Reel/Frame 053116/0489 →
SECURITY INTEREST Recorded Jun 25, 2020
From: PANGO INC.
To: PACIFIC WESTERN BANK
Reel/Frame 053039/0417 →
SECURITY INTEREST Recorded Nov 28, 2018
From: ANCHORFREE INC.
To: PACIFIC WESTERN BANK
Reel/Frame 047605/0600 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 8, 2018
From: KUZMENKO, ROMAN
To: ANCHORFREE INC
Reel/Frame 045149/0665 →