IP Library Granted Patent US 9,485,231
Granted Patent B1
US 9,485,231 · App. 14/722,064 · Granted Nov 1, 2016

Securing internet of things communications across multiple vendors

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,485,231
App. No.
14/722,064
Granted
Nov 1, 2016
Kind
B1
Abstract

A secure connection between a user mobile device and a “Internet-of-Things” network-connected device (e.g., a home appliance or a vehicle) may be provided using an internet gateway residing in the public internet and a local gateway residing in a private network behind a firewall. The user device may receive an input through a software application and may generate an electronic instruction based on the input. The user device may then encrypt the electronic instruction and send the encrypted electronic instruction to the internet gateway over a secure connection (e.g., SSH, TLS). The internet gateway then sends the encrypted electronic instruction to the local gateway, which decrypts the encrypted electronic instruction, interprets it, and generates and transmits a device instruction to communicate with the network-connected device, either directly or through an intermediary device such as a third-party bridge or hub. Only the user device and local gateway have encryption/decryption keys.

Claims (34)

1. A method for secure communication, the method comprising:

receiving an encrypted electronic instruction at a local gateway from an internet gateway passing through a firewall, wherein the encrypted electronic instruction transmitted from a user device to the internet gateway over a secure session connection is an electronic instruction generated by the user device and then encrypted by the user device based on a first security key stored in a user memory of the user device;

decrypting the encrypted electronic instruction at the local gateway using a second security key stored in a local memory of the local gateway, wherein the internet gateway stores neither the first security key nor the second security key; and

transmitting a device instruction from the local gateway to a specified network-connected device, the device instruction based on the electronic instruction decrypted by the local gateway using the second security key, the device instruction to trigger the specified network-connected device to perform a device action.

2. The method of claim 1 , further comprising initially generating both the first security key and the second security key at one of the local gateway or the user device.

3. The method of claim 1 , further comprising:

initially generating the first security key at the local gateway;

initially generating the second security key at the user device; and

sharing public security data between the user device and the local gateway.

4. The method of claim 1 , wherein the first security key and the second security key include identical data.

5. The method of claim 1 , wherein the encrypted electronic instruction was received by the internet gateway from the user device using a secure protocol, the secure protocol using one of a Secure Sockets Layer (SSL) protection or a Transport Layer Security (TLS) protection.

6. The method of claim 1 , wherein the encrypted electronic instruction is received at the local gateway after having passed through a firewall.

7. The method of claim 1 , wherein the local gateway includes a discovery protocol and an application programming interface (API) conforming to Representational State Transfer (REST) constraints.

8. The method of claim 1 , wherein the network-connected device is one of a home appliance or a vehicle.

9. The method of claim 1 , wherein transmitting the device instruction from the local gateway to a specified network-connected device is done via a direct network transmission.

10. The method of claim 1 , wherein transmitting the device instruction from the local gateway to a specified network-connected device includes transmitting the device instruction from the local gateway through one or more secondary network devices until at least one of the one or more secondary network devices directly transmits the device instruction to the specified network-connected device.

11. The method of claim 1 , wherein the encrypted electronic instruction includes an identifying signature previously generated by the local gateway.

12. A system for secure communication, comprising:

an internet gateway device that receives an encrypted electronic instruction from a user device over a secure session connection, wherein the encrypted electronic instruction is an electronic instruction generated by the user device and then encrypted by the user device based on a first security key stored in a user memory of the user device; and

a local gateway device that:

receives the encrypted electronic instruction from the internet gateway device based on the encrypted electronic instruction first passing through a firewall,

decrypts the encrypted electronic instruction using a second security key stored in a local memory of the local gateway, wherein the internet gateway stores neither the first security key nor the second security key, and

transmits a device instruction from the local gateway to a specified network-connected device, the device instruction based on the electronic instruction decrypted by the local gateway using the second security key, the device instruction to trigger the specified network-connected device to perform a device action.

13. The system of claim 12 , wherein the local gateway is directly communicatively coupled to the network-connected device through a direct network connection.

14. The system of claim 12 , wherein the local gateway is indirectly communicatively coupled to the network-connected device through a network connection that first passes through one or more secondary network devices, wherein at least one of the one or more secondary network devices has a direct network connection to the local gateway, and wherein the one or more secondary network devices includes at least one of a router, a bridge device, or a secondary gateway device.

15. The system of claim 12 , wherein the first security key and the second security key were both previously generated by the local gateway, and wherein the local gateway provided the first security key to the user device.

16. The system of claim 12 , wherein the first security key and the second security key were both previously generated by the user device, and wherein the user device provided the second security key to the local gateway.

17. The system of claim 12 , wherein the first security key and the second security key include identical data.

18. The system of claim 12 , wherein the secure connection uses one of a Secure Sockets Layer (SSL) protection or a Transport Layer Security (TLS) protection.

19. The system of claim 12 , wherein the network-connected device is one of a home appliance or a vehicle.

20. A non-transitory computer-readable storage medium, having embodied thereon a program executable by a processor to perform a method for secure connections, the method comprising:

receiving an encrypted electronic instruction at a local gateway from an internet gateway passing through a firewall, the encrypted electronic instruction transmitted from a user device to the internet gateway over a secure session connection is an electronic instruction generated by the user device and encrypted by the user device based on a first security key stored in a user memory of the user device;

decrypting the encrypted electronic instruction at the local gateway using a second security key stored in a local memory of the local gateway, wherein the internet gateway stores neither the first security key nor the second security key; and

transmitting a device instruction from the local gateway to a specified network-connected device, the device instruction based on the electronic instruction decrypted by the local gateway using the second security key, the device instruction to trigger the specified network-connected device to perform a device action.

Assignments (12)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2022
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 059912/0097 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 15, 2018
From: DELL SOFTWARE INC.
To: DELL PRODUCTS L.P.
Reel/Frame 044947/0749 →
RELEASE OF SECURITY INTEREST Recorded Nov 4, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION
Reel/Frame 040564/0886 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Nov 4, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; AVENTAIL LLC; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION
Reel/Frame 040564/0897 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →