IP Library Granted Patent US 10,003,577
Granted Patent B2
US 10,003,577 · App. 15/013,322 · Granted Jun 19, 2018

Secure transmission of local private encoding data

Inventors: Thomas Jakobi (Ingolstadt, DE); Doris Hausen (Ottobrunn, DE); Frank Schmidberger (Ravensburg, DE)
Assignee: virtual solution AG
H04L63/04H04L63/061H04W12/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,003,577
App. No.
15/013,322
Granted
Jun 19, 2018
Kind
B2
Abstract

A method of secure transfer of local private encoding data between a first communication device and a second communication device, the first communication device and the second communication device being operable to communicate with each other via a communication connection there between, a respectively adapted first communication device, a respectively adapted second communication device, a system comprising such first and second communication devices and also a computer program product for carrying out the above method.

Claims (49)

1. A method of secure transfer of local private encoding data between a first communication device having a first interface unit and a second communication device having a second interface unit, the first communication device and the second communication device being configured to communicate with each other via a communication connection there between, the method comprising:

providing secure access information by the second communication device;

transmitting the secure access information from the second communication device to the first communication device via a first secure communication path, the first secure communication path comprising the second interface unit and the first interface unit and being physically and/or logically separated from the communication connection, wherein the transmitting comprises:

displaying or sending, by the second interface unit, of the secure access information; and

acquiring or receiving, by the first interface unit, of the secure access information;

establishing, based on the secure access information, a secure communication link between the first communication device and the second communication device on the communication connection between the first communication device and the second communication device; and

transferring the local private encoding data via the secure communication link on the communication channel between the first communication device and the second communication device.

2. A method according to claim 1 ,

wherein the first communication device has the local private encoding data, wherein the transferring of the local private encoding data is from the first communication device to the second communication device, the method further comprising:

storing the received local private encoding data at the second communication device.

3. A method according to claim 1 , wherein the second communication device has the local private encoding data, wherein the transferring the local private encoding data is from the second communication device to the first communication device, the method further comprising:

storing the received local private encoding data at the first communication device.

4. A method according to claim 1 , further comprising:

verifying the secure communication link via a second secure communication path.

5. A method according to claim 1 , wherein the local private encoding data includes one of the following: a public encoding key, a private encoding key, a public encoding key certificate, a symmetric encoding key, a symmetric HMAC key.

6. A method according to claim 1 , wherein the secure access information includes one of the following: a public encoding key, an IP address of the other communication device, a physical access interface, a UDP port of the second communication device, a Bluetooth device ID of the second communication device, a displayable code.

7. A method according to claim 1 , wherein the second interface unit comprises a display unit of the second communication device, wherein the first secure communication path comprises the display unit and wherein the transmitting comprises displaying, by the display unit, of the secure access information.

8. A method according to claim 1 , wherein the first interface unit comprises an input unit or an image/video camera and wherein the transmitting comprises acquiring the secure access information.

9. A method according to claim 1 , wherein the secure communication link comprises one of the following: a TCP connection, a TLS connection.

10. A communication device, comprising:

a first communication interface configured to communicate with another communication device via a communication connection;

a processor configured to:

receive or acquire, via a first interface unit and a first secure communication path being physically and/or logically separated from the communication connection, secure access information provided by the other communication device;

establish, based on the secure access information, a secure communication link to the other communication device on the communication connection to the other communication device; and

transfer local private encoding data to the other communication device via the secure communication link on the communication connection.

11. A communication device according to claim 10 , further comprising:

a data memory unit comprising the local private encoding data to be transferred.

12. A communication device according to claim 10 , further comprising:

a memory unit being configured to store local private encoding data of the other communication device transferred therefrom via the secure communication link on the communication connection.

13. A communication device according to claim 10 , wherein the processor is configured to verify the secure communication link by means of at least one of:

verifying identification information provided by the other communication device,

reproducing identification information provided by the other communication device.

14. A system comprising:

a first communication device comprising:

a first communication interface configured to communicate with another communication device via a communication connection;

a first processor configured to:

receive or acquire, via a first interface unit and a first secure communication path being physically and/or logically separated from the communication connection, secure access information provided by the other communication device;

establish, based on the secure access information, a secure communication link to the other communication device on the communication connection to the other communication device;

transfer local private encoding data to the other communication device via the secure communication link on the communication connection, and

a second communication device comprising:

a second communication interface configured to communicate with another communication device via a communication connection; and

a second processor configured to provide secure access in a manner that the secure access information is adapted for transmission to the other communication device via a second interface unit and the first secure communication path and configured to receive local private encoding data from the other communication device via the secure communication link on the communication channel.

15. A computer program product stored on a non-transitory computer readable storage medium including program code configured to, when executed by a computing device, to at least:

provide secure access information by a second communication device having a second interface unit;

transmit the secure access information from the second communication device to a first communication device having a first interface unit via a first secure communication path, the first secure communication path comprising the second interface unit and the first interface unit and being physically and/or logically separated from the communication connection, wherein the transmitting comprises:

displaying or sending, by the second interface unit, of the secure access information and

acquiring or receiving, by the first interface unit, of the secure access information;

establish, based on the secure access information, a secure communication link between the first communication device and the second communication device on the communication connection between the first communication device and the second communication device; and

transfer the local private encoding data via the secure communication link on the communication channel.

Assignments (3)
CHANGE OF NAME Recorded Dec 14, 2022
From: VIRTUAL SOLUTION AG
To: MATERNA VIRTUAL SOLUTION GMBH
Reel/Frame 062321/0058 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE ADDRESS PREVIOUSLY RECORDED AT REEL: 040836 FRAME: 0739. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 10, 2017
From: JAKOBI, THOMAS; HAUSEN, DORIS, DR.; SCHMIDBERGER, FRANK
To: VIRTUAL SOLUTION AG
Reel/Frame 041316/0026 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2017
From: JAKOBI, THOMAS; HAUSEN, DORIS, DR.; SCHMIDBERGER, FRANK
To: VIRTUAL SOLUTION AG
Reel/Frame 040836/0739 →
Priority Claims (1)
EP 15003586 · Dec 16, 2015 · regional
Continuity (1)
Related Publication 20170180326A1 · Jun 22, 2017
Cited By (1)
US 12,464,360