IP Library Granted Patent US 9,467,283
Granted Patent B2
US 9,467,283 · App. 13/925,299 · Granted Oct 11, 2016

Securing method for lawful interception

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,467,283
App. No.
13/925,299
Granted
Oct 11, 2016
Kind
B2
Abstract

A method is presented for secure communication, the method including generating a signature using a private key, a nonce, and at least one of an identifier and a key component; and transmitting the signature, the nonce, a security parameter, and the at least one of the identifier and the key component, wherein the security parameter associates a user identity with a public key, the public key being associated with the private key.

Claims (55)

1. A method, by an electronic device, for secure communication with at least one other electronic device, the method comprising:

generating, by a processor of the electronic device, a signature using a private key, a nonce, and at least one of an identifier and a key component;

transmitting, by the processor, the signature, the nonce, a security parameter, and the at least one of the identifier and the key component, wherein the security parameter associates a user identity with a public key, the public key being associated with the private key;

receiving, by the processor, based on the transmitting, session security data generated by the at least one other electronic device; and

establishing, by the processor, a secure communication session with the at least one other electronic device based on at least the session security data.

2. The method of claim 1 , wherein the identifier is one of an International Mobile Station Equipment Identity (IMEI), a Globally Routable User Agent URI (GRUU), an International Mobile Subscriber Identity (IMSI), and a Temporary International Mobile Subscriber Identity (TIMSI).

3. The method of claim 1 , wherein the nonce is one of a timestamp, a random number, and a sequence number.

4. The method of claim 1 , wherein the security parameter is a certificate.

5. The method of claim 1 , further comprising:

generating the key component using a master key, the nonce, and a known elliptic curve point.

6. The method of claim 1 , wherein the transmitting step further comprises:

transmitting the signature and the public key.

7. The method of claim 1 , wherein the session security data comprises a second nonce, at least one of a second identifier and a second key component, a second security parameter, and a second signature that was generated using a second private key, the second nonce, and the at least one of the second identifier and the second key component, and

wherein establishing the secure communication session comprises

verifying the second nonce and the at least one of the second identifier and the second key component using the received second signature and the second security parameter, wherein the second security parameter associates a second user identity with a second public key, the second public key being associated with the second private key; and

generating a session key using the at least one of the second identifier and the second key component, when verification is successful in the verifying step.

8. A method, by an electronic device, for secure communication with at least one other electronic device, the method comprising:

receiving, by a processor of the electronic device, a nonce, at least one of an identifier and a key component, a security parameter, and a signature that was generated using a private key, the nonce, and the at least one of the identifier and the key component;

verifying, by the processor, the nonce and the at least one of the identifier and the key component using the received signature and the security parameter, wherein the security parameter associates a user identity with a public key, the public key being associated with the private key; and

establishing, by the processor, a secure communication session with the at least one other electronic device based on at the at least one of the identifier and the key component that has been verified.

9. The method of claim 8 , further comprising, when verification is successful in the verifying step:

generating a session key using the at least one of the identifier and the key component.

10. The method of claim 8 , further comprising, when verification is successful in the verifying step:

generating a second signature using a second private key, a second nonce, and at least one of a second identifier and a second key component; and

transmitting the second signature, the second nonce, a second security parameter, and the at least one of the second identifier and the second key component, wherein the second security parameter associates a second user identity with a second public key, the second public key being associated with the second private key.

11. A method, by an electronic device, for secure communication with at least one other electronic device, the method comprising:

generating, by a processor of the electronic device, a MAC tag using a MAC key, a nonce, and a key component generated by the electronic device based on private key information associated with the electronic device and a publicly known elliptic curve point; and

transmitting, by the processor, the MAC tag, the nonce, and the key component;

receiving, by the processor, based on to the transmitting, session security data generated by the at least one other electronic device; and

establishing, by the processor, a secure communication session with the at least one other electronic device based on at least the session security data.

12. The method of claim 11 , wherein the MAC tag is further generated using an identifier, wherein the identifier is one of an International Mobile Station Equipment Identity (IMEI), a Globally Routable User Agent URI (GRUU), an International Mobile Subscriber Identity (IMSI), and a Temporary International Mobile Subscriber Identity (TIMSI).

13. The method of claim 11 , wherein the nonce is one of a timestamp, a random number, and a sequence number.

14. A method, by an electronic device, for secure communication with at least one other electronic device, the method comprising:

receiving, by a processor of the electronic device, a nonce, a key component, and a MAC tag that was generated by the at least one other electronic device using the nonce, the key component, and a MAC key, wherein the key component was generated by the at least one other electronic device based on private key information associated with the at least one other electronic device and a publicly known elliptic curve point;

verifying, by the processor, the nonce and the key component using the received MAC tag; and

establishing, by the processor, a secure communication session with the at least one other electronic device based on at least the key component that has been verified.

15. An apparatus for secure communication with at least one other apparatus, comprising:

a processing circuit configured to generate a signature using a private key, a nonce, and at least one of an identifier and a key component;

a transmitter configured to transmit the signature, the nonce, a security parameter, and the at least one of the identifier and the key component, wherein the security parameter associates a user identity with a public key, the public key being associated with the private key; and

a receiver configured to receive, based on the transmitting, session security data generated by the at least one other apparatus,

wherein the processing circuit is further configured to establish, a secure communication session with the at least one other apparatus based on at least the session security data.

16. An apparatus for secure communication with at least one other apparatus, comprising:

a receiver configured to receive a nonce, at least one of an identifier and a key component, a security parameter, and a signature that was generated using a private key, the nonce, and the at least one of the identifier and the key component; and

a processing circuit configured to

verify the nonce and the at least one of the identifier and the key component using the received signature and the security parameter, wherein the security parameter associates a user identity with a public key, the public key being associated with the private key, and

establish a secure communication session with the at least one other apparatus based on at the at least one of the identifier and the key component that has been verified.

17. An apparatus for secure communication with at least one other apparatus, comprising:

a processing circuit configured to generate a MAC tag using a MAC key, a nonce, and a key component generated by the apparatus based on private key information associated with the apparatus and a publicly known elliptic curve point; and a transmitter configured to transmit the MAC tag, the nonce, and the at least one of the identifier and the key component; and

a receiver configured to receive, based on to the transmitting, session security data generated by the at least one other apparatus,

wherein the processing circuit is further configured to establish, a secure communication session with the at least one other electronic device based on at least the session security data.

18. An apparatus for secure communication with at least one other apparatus, comprising:

a receiver configured to receive a nonce, a key component, and a MAC tag that was generated using the nonce, the key component, and a MAC key, wherein the key component was generated by the at least one other apparatus based on private key information associated with the at least one other electronic device and a publicly known elliptic curve point; and

a processing circuit configured to

verify the nonce and the at least one of the identifier and the key component using the received MAC tag; and

establish a secure communication session with the at least one other electronic device based on at least the key component that has been verified.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2013
From: LAMBERT, ROBERT JOHN; EBEID, NEVINE MAURICE NASSIF
To: CERTICOM CORP.
Reel/Frame 031443/0795 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2013
From: BUCKLEY, MICHAEL EOIN; HOLLATZ, MICHAEL CHARLES
To: BLACKBERRY CORPORATION
Reel/Frame 031443/0675 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2013
From: BLACKBERRY CORPORATION
To: BLACKBERRY LIMITED
Reel/Frame 031285/0688 →
CHANGE OF NAME Recorded Jul 18, 2013
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 030831/0749 →