IP Library › Granted Patent US 10,177,917
Granted Patent B2
US 10,177,917 · App. 14/907,914 · Granted Jan 8, 2019

TLS protocol extension

Inventors: Sebastien Roche (Illkirch, FR); Marcel Degtounda (Illkirch, FR)
Assignee: Alcatel Lucent
H04L9/3242H04L63/0869H04L63/205H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,177,917
App. No.
14/907,914
Granted
Jan 8, 2019
Kind
B2
Abstract

A technique is provided for extending a handshake communication between a communication device and an application server. The application server receives at least two messages from the communication device, each message comprising a handshake index and triggering a handshake session so that the application server negotiates with the communication device a set of cryptographic parameters. For each received message, the application server stores a negotiated set of cryptographic parameters in correspondence with a connection state index depending on the handshake index. The application server activates one of the stored sets of cryptographic parameters to establish a secured connection with the communication device.

Claims (30)

1. A method for extending a handshake communication between a communication device and an application server, comprising:

receiving, at the application server in an Internet Protocol network, at least two messages from the communication device, each message comprising a handshake index;

triggering, at the application server, a handshake session with the communication device to negotiate a set of cryptographic parameters;

for each handshake index of the at least two messages received, storing, at the application server, one or more cryptographic parameters of the negotiated set of cryptographic parameters with a corresponding connection state index that depends on an associated handshake index, wherein the corresponding connection state index is a single byte contained in a protocol message field;

activating, at the application server, the one or more cryptographic parameters of the negotiated set of cryptographic parameters stored with a lowest connection state index to establish a secured connection with only one port of the communication device, depending on a confidentiality of data to be transmitted;

receiving, at the application server, a connection state from the communication device; and

switching, at the application server, a security context that corresponds to the received connection state by activating the one or more cryptographic parameters of the negotiated set of cryptographic parameters stored with a corresponding connection state index in correspondence with the received connection state.

2. The method according to claim 1 , wherein the at least two messages are “ClientHello” messages.

3. The method according to claim 1 , wherein the set of cryptographic parameters includes a compression type, an encryption type, and a message authentication code algorithm.

4. The method according to claim 1 , wherein each of the handshake index is a number coded on one byte, from 0 to 255, in a dedicated field.

5. The method according to claim 1 , further comprising aborting, at the application server, a handshake negotiation when receiving a message with an illegal handshake index.

6. The method according to claim 1 , wherein the communication device comprises one of a mobile phone, a landline phone, or a computer.

7. The method according to claim 1 , wherein the secured connection is encrypted and decrypted by the one or more cryptographic parameters of the negotiated set of cryptographic parameters.

8. The method according to claim 1 , further comprising adapting a security level to the data transmitted at any time during the secured connection.

9. A server for extending a handshake communication between a communication device and the server, comprising:

a hardware processor; and

a memory, wherein the memory is configured to store therein executable instructions that when executed by the processor, causes the processor to:

receive at least two messages from the communication device, each message comprising a handshake index;

trigger a handshake session with the communication device to negotiate a set of cryptographic parameters;

store one or more cryptographic parameters of the negotiated set of cryptographic parameters with a corresponding connection state index for each handshake index of the at least two messages received, wherein the corresponding connection state index is a single byte contained in a protocol message field;

activate the one or more cryptographic parameters of the negotiated set of cryptographic parameters stored with a lowest connection state index to establish a secured connection with only one port of the communication device, depending on a confidentiality of data to be transmitted;

receive a connection state from the communication device; and

switch a security context that corresponds to the received connection state by activating the one or more cryptographic parameters of the negotiated set of cryptographic parameters stored with a corresponding connection state index in correspondence with the received connection state.

10. A non-transitory computer information medium storing computer executable instructions for performing the steps of:

receiving, at an application server in an Internet Protocol network, at least two messages from a communication device, each message comprising a handshake index;

triggering, at the application server, a handshake session with the communication device to negotiate a set of cryptographic parameters;

for each handshake index of the at least two messages received, storing, at the application server, one or more cryptographic parameters of the negotiated set of cryptographic parameters with a corresponding connection state index that depends on an associated handshake index, wherein the connection state index is a single byte contained in a protocol message field;

activating, at the application server, the one or more cryptographic parameters of the negotiated set of cryptographic parameters stored with a lowest connection state index to establish a secured connection with only one port of the communication device, depending on a confidentiality of data to be transmitted;

receiving, at the application server, a connection state from the communication device; and

switching, at the application server, a security context that corresponds to the received connection state by activating the one or more cryptographic parameters of the negotiated set of cryptographic parameters stored with a corresponding connection state index in correspondence with the received connection state.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2016
From: ROCHE, SEBASTIEN; DEGTOUNDA, MARCEL
To: ALCATEL LUCENT
Reel/Frame 037630/0424 →
Priority Claims (1)
EP 13306230 · Sep 9, 2013 · regional
Continuity (1)
Related Publication 20160182232A1 · Jun 23, 2016
Cited By (1)
US 12,513,193