IP Library Granted Patent US 10,110,595
Granted Patent B2
US 10,110,595 · App. 15/071,659 · Granted Oct 23, 2018

End-to-end authentication at the service layer using public keying mechanisms

Inventors: Vinod Kumar Choyi (Norristown, PA); Dale N. Seed (Allentown, PA); Yogendra C. Shah (Exton, PA); Quang Ly (North Wales, PA); William Robert Flynn, IV (Schwenksville, PA); Michael F. Starsinic (Newtown, PA); Shamim Akbar Rahman (Cole St. Luc, CA); Zhuo Chen (Claymont, DE); Qing Li (Princeton Junction, NJ)
Assignee: Convida Wireless, LLC
H04L63/0823G06F21/64H04L9/3247H04L63/06H04L63/062H04L67/12H04W12/06G06F2221/2115H04W4/70H04W84/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,110,595
App. No.
15/071,659
Granted
Oct 23, 2018
Kind
B2
Abstract

In a machine-to-machine/Internet-of-things environment, end-to-end authentication of devices separated by multiple hops is achieved via direct or delegated/intermediated negotiations using pre-provisioned hop-by-hop credentials, uniquely generated hop-by-hop credentials, and-or public key certificates, whereby remote resources and services may be discovered via single-hop communications, and then secure communications with the remote resources may be established using secure protocols appropriate to the resources and services and capabilities of end devices, and communication thereafter conducted directly without the overhead or risks engendered hop-by-hop translation.

Claims (15)

1. An apparatus comprising a processor, a memory, and communication circuitry, the apparatus being connected to a communications network via its communication circuitry, the apparatus further comprising computer-executable instructions stored in the memory of the apparatus which, when executed by the processor of the apparatus, cause the apparatus to:

a. receive, from a message originator, a request to register a service offered by the message originator;

b. register a type of service, the type of service pertaining to the service offered by the message originator;

c. determine, based on the type of service, a set of security features, the set of security features pertaining to the type of service or the service offered by the message originator;

d. register the set of security features;

e. register a public key of the message originator;

f. receive, from a multi-hop transmission recipient, a credential requisition;

g. evaluate the credential requisition in accordance with an access control policy;

h. provide to the multi-hop transmission recipient, when the access control policy allows access by the multi-hop transmission recipient to the registered type of service, a response to the credential requisition comprising the public key of the message originator; and

i. withhold from the multi-hop transmission recipient, when the access control policy does not allow access by the multi-hop transmission recipient to the registered type of service, the response to the credential requisition.

2. The apparatus of claim 1 , wherein the computer-executable instructions further cause the apparatus to obtain the public key of the message originator from a trusted third party.

3. The apparatus of claim 1 , wherein determining the set of security features comprises evaluating one or more device capabilities of the message originator.

4. The apparatus of claim 3 , wherein the one or more device capabilities of the message originator include one or more of battery, memory, and processor resources.

5. The apparatus of claim 4 , wherein the access control policy comprises an access control list, an attribute-based access control, a role-based access control, or a dynamic authorization mechanism.

6. The apparatus of claim 1 , wherein the computer-executable instructions further cause the apparatus to negotiate, with the message originator, proposed security attributes for the service offered by the message originator.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2025
From: CONVIDA WIRELESS, LLC
To: INTERDIGITAL PATENT HOLDINGS, INC.
Reel/Frame 071773/0735 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2016
From: CHOYI, VINOD KUMAR; SEED, DALE N.; SHAH, YOGENDRA C.; LY, QUANG; FLYNN, WILLIAM ROBERT, IV; STARSINIC, MICHAEL F.; RAHMAN, SHAMIM AKBAR; CHEN, ZHUO; LI, QING
To: CONVIDA WIRELESS, LLC
Reel/Frame 039553/0001 →
Continuity (2)
Provisional Application 62133839 · Mar 16, 2015
Related Publication 20160277391A1 · Sep 22, 2016
Cited By (6)
US 12,255,883 US 12,278,807 US 12,356,456 US 12,500,956 US 12,615,578 US 12,712,612