IP Library Patent Application 13794574
Patent Application
App. No. 13/794,574

Securing Communication over a Network Using User Identity Verification

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/794,574
Abstract

A method for securing communication over a network is disclosed. The method is performed on a server system having one or more processors and memory storing one or more programs for execution by the one or more processors. The server system receives a first encrypted user identifier from a trust broker system associated with the server system, the first encrypted user identifier including information identifying a user of a client system verified by the trust broker system. The server system receives a connection request packet from a first client system. The server system then receives a second encrypted user identifier from the first client system. The server system determines whether first encrypted user identifier matches the second encrypted user identifier. In accordance with a determination that the first encrypted user identifier matches the second encrypted user identifier, the server system establishes an encrypted connection with the first client system.

Claims (57)

1 . A method for securing communication over a network, comprising:

at a server system having one or more processors and memory storing one or more programs for execution by the one or more processors:

receiving a first encrypted user identifier from a trust broker system associated with the server system, the first encrypted user identifier including information identifying a user of a client system verified by the trust broker system;

receiving a connection request packet from a first client system;

receiving a second encrypted user identifier from the first client system;

determining whether first encrypted user identifier matches the second encrypted user identifier; and

in accordance with a determination that the first encrypted user identifier matches the second encrypted user identifier, establishing an encrypted connection with the first client system.

2 . The method of claim 1 , further including:

in accordance with a determination that first encrypted user identifier does not match the second encrypted user identifier, discarding the received packet, without replying to the first client system.

3 . The method of claim 1 , wherein both the first user identifier and the second user identifier are encrypted with a session based key that is changed for each communication session.

4 . The method of claim 1 , wherein all communications between the first client system and the server system are encrypted with a unique session based key that is changed for every communication session.

5 . The method of claim 1 , further including, prior to establishing a connection:

determining the access level permitted to the identified user;

determining whether the identified user is authorized to connect to the requested server agent based on the determined access level permitted to the identified user;

in accordance with a determination that the user is not authorized to connect to the request server agent:

terminating the connection with the user agent; and

sending a lack of authorization notice to the requesting user agent.

6 . The method of claim 5 , wherein the access level permitted to the identified user is determined by the identified user's role.

7 . The method of claim 5 , wherein the access level permitted to the identified user is predetermined by a super user associated with the server system

8 . An electronic device for securing communication over a network, comprising:

one or more processors;

memory storing one or more programs to be executed by the one or more processors;

the one or more programs comprising instructions for:

receiving a first encrypted user identifier from a trust broker system associated with the server system, the first encrypted user identifier including information identifying a user of a client system verified by the trust broker system;

receiving a connection request packet from a first client system;

receiving a second encrypted user identifier from the first client system;

determining whether first encrypted user identifier matches the second encrypted user identifier; and

in accordance with a determination that the first encrypted user identifier matches the second encrypted user identifier, establishing an encrypted connection with the first client system.

9 . The device of claim 8 , further including instructions for:

in accordance with a determination that first encrypted user identifier does not match the second encrypted user identifier, discarding the received packet, without replying to the first client system.

10 . The device of claim 8 , wherein both the first user identifier and the second user identifier are encrypted with a session based key that is changed for each communication session.

11 . The device of claim 8 , wherein all communications between the first client system and the server system are encrypted with a unique session based key that is changed for every communication session.

12 . The device of claim 8 , further including instructions for, prior to establishing a connection:

determining the access level permitted to the identified user;

determining whether the identified user is authorized to connect to the requested server agent based on the determined access level permitted to the identified user;

in accordance with a determination that the user is not authorized to connect to the request server agent:

terminating the connection with the user agent; and

sending a lack of authorization notice to the requesting user agent.

13 . The device of claim 12 , wherein the access level permitted to the identified user is determined by the identified user's role.

14 . The method of claim 12 , wherein the access level permitted to the identified user is predetermined by a super user associated with the server system

15 . A non-transitory computer readable storage medium storing one or more programs configured for execution by an electronic device with a camera, the one or more programs comprising instructions for:

receiving a first encrypted user identifier from a trust broker system associated with the server system, the first encrypted user identifier including information identifying a user of a client system verified by the trust broker system;

receiving a connection request packet from a first client system;

receiving a second encrypted user identifier from the first client system;

determining whether first encrypted user identifier matches the second encrypted user identifier; and

in accordance with a determination that the first encrypted user identifier matches the second encrypted user identifier, establishing an encrypted connection with the first client system.

16 . The non-transitory computer readable storage medium of claim 15 , further including instructions for:

in accordance with a determination that first encrypted user identifier does not match the second encrypted user identifier, discarding the received packet, without replying to the first client system.

17 . The non-transitory computer readable storage medium of claim 15 , wherein both the first user identifier and the second user identifier are encrypted with a session based key that is changed for each communication session.

18 . The non-transitory computer readable storage medium of claim 15 , wherein all communications between the first client system and the server system are encrypted with a unique session based key that is changed for every communication session.

19 . The non-transitory computer readable storage medium of claim 15 , further including instructions for, prior to establishing a connection:

determining the access level permitted to the identified user;

determining whether the identified user is authorized to connect to the requested server agent based on the determined access level permitted to the identified user;

in accordance with a determination that the user is not authorized to connect to the request server agent:

terminating the connection with the user agent; and

sending a lack of authorization notice to the requesting user agent.

20 . The non-transitory computer readable storage medium of claim 19 , wherein the access level permitted to the identified user is determined by the identified user's role.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2018
From: MCI COMMUNICATIONS SERVICES, INC.
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 047592/0888 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2018
From: VIDDER, INC.
To: MCI COMMUNICATIONS SERVICES, INC.
Reel/Frame 047532/0582 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2013
From: ISLAM, JUNAID; BILGER, BRENT; SCHROEDER, TED
To: VIDDER, INC.
Reel/Frame 030665/0110 →