IP Library Granted Patent US 10,754,968
Granted Patent B2
US 10,754,968 · App. 15/179,903 · Granted Aug 25, 2020

Peer-to-peer security protocol apparatus, computer program, and method

Inventors: Alexander Sherkin (Vaughan, CA); Ravi Singh (Toronto, CA); Michael Matovsky (Vaughan, CA); Eugene Chin (Oakville, CA)
Assignee: DIGITAL 14 LLC
G06F21/6218H04L9/0897H04L63/06H04L63/061H04L63/0442H04L63/123H04L63/166H04L2463/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,754,968
App. No.
15/179,903
Granted
Aug 25, 2020
Kind
B2
Abstract

An apparatus, computer program, and method are afforded for providing a peer-to-peer security protocol. In operation, a message is identified that is directed from a first peer device to a second peer device. Further, the message is copied, so that a copy of the message is caused to be sent to an auditing server.

Claims (50)

1. A computer program product comprising computer executable instructions stored on a non-transitory computer readable medium that when executed by a processor instruct the processor to:

initialize a first peer device with an auditing server, by:

receiving, by the auditing server from the first peer device, a first data at rest (DAR) key pair that includes a first DAR public key and a first encrypted DAR private key, the first encrypted DAR private key formed by the first peer device encrypting a first DAR private key using an auditing public key provided by the auditing server, and

storing, by the auditing server, the first encrypted DAR private key in association with an identifier of the first peer device;

initialize a second peer device with the auditing server, by:

receiving, by the auditing server from the second peer device, a second data at rest (DAR) key pair that includes a second DAR public key and a second encrypted DAR private key, the second encrypted DAR private key formed by the second peer device encrypting a second DAR private key using the auditing public key provided by the auditing server,

storing, by the auditing server, the second encrypted DAR private key in association with an identifier of the second peer device;

receive, by the auditing server from a routing server, a copy of a peer-to-peer broadcast message sent by the first peer device for transmission to the second peer device, the peer-to-peer broadcast message generated by the first peer device using the second DAR public key and wrapped using a peer-to-peer security protocol;

validate, by the auditing server, the peer-to-peer broadcast message by:

determining that the peer-to-peer broadcast message contains a message copy for the auditing server, and

verifying a digital signature on the peer-to-peer broadcast message and that the second DAR public key is stored for the second peer device that is the intended recipient of the peer-to-peer broadcast message;

responsive to the auditing server validating the peer-to-peer broadcast message:

provide, by the auditing server, an indication of success to the routing server for prompting the routing server to transmit the peer-to-peer broadcast message to the second peer device, and

store, in a database associated with the auditing server, the copy of the peer-to-peer broadcast message and associated metadata indicating the first peer device as a sender of the peer-to-peer broadcast message, the second peer device as a receiver of the peer-to-peer broadcast message, and a timestamp;

wherein the copy of the peer-to-peer broadcast message stored in the database is only accessible to one or more compliance offers having knowledge of an auditing private key, using the second encrypted DAR private key stored by the auditing server in association with the identifier of the second peer device;

wherein the first peer device, the second peer device, the auditing server, and the routing server communicate via a network.

2. The computer program product of claim 1 , wherein the computer program product is further configured such that the auditing private key stored in a hardware security module.

3. An apparatus, comprising:

an auditing server configured to:

initialize a first peer device with the auditing server, by:

receiving, by the auditing server from the first peer device, a first data at rest (DAR) key pair that includes a first DAR public key and a first encrypted DAR private key, the first encrypted DAR private key formed by the first peer device encrypting a first DAR private key using an auditing public key provided by the auditing server, and

storing, by the auditing server, the first encrypted DAR private key in association with an identifier of the first peer device;

initialize a second peer device with the auditing server, by:

receiving, by the auditing server from the second peer device, a second data at rest (DAR) key pair that includes a second DAR public key and a second encrypted DAR private key, the second encrypted DAR private key formed by the second peer device encrypting a second DAR private key using the auditing public key provided by the auditing server,

storing, by the auditing server, the second encrypted DAR private key in association with an identifier of the second peer device;

receive, by the auditing server from a routing server, a copy of a peer-to-peer broadcast message sent by the first peer device for transmission to the second peer device, the peer-to-peer broadcast message generated by the first peer device using the second DAR public key and wrapped using a peer-to-peer security protocol;

validate, by the auditing server, the peer-to-peer broadcast message by:

determining that the peer-to-peer broadcast message contains a message copy for the auditing server, and

verifying a digital signature on the peer-to-peer broadcast message and that the second DAR public key is stored for the second peer device that is the intended recipient of the peer-to-peer broadcast message;

responsive to the auditing server validating the peer-to-peer broadcast message:

provide, by the auditing server, an indication of success to the routing server for prompting the routing server to transmit the peer-to-peer broadcast message to the second peer device, and

store, in a database associated with the auditing server, the copy of the peer-to-peer broadcast message and associated metadata indicating the first peer device as a sender of the peer-to-peer broadcast message, the second peer device as a receiver of the peer-to-peer broadcast message, and a timestamp;

wherein the copy of the peer-to-peer broadcast message stored in the database is only accessible to one or more compliance offers having knowledge of an auditing private key, using the second encrypted DAR private key stored by the auditing server in association with the identifier of the second peer device;

wherein the first peer device, the second peer device, the auditing server, and the routing server communicate via a network.

4. A method, comprising:

initializing a first peer device with an auditing server, by:

receiving, by the auditing server from the first peer device, a first data at rest (DAR) key pair that includes a first DAR public key and a first encrypted DAR private key, the first encrypted DAR private key formed by the first peer device encrypting a first DAR private key using an auditing public key provided by the auditing server, and

storing, by the auditing server, the first encrypted DAR private key in association with an identifier of the first peer device;

initializing a second peer device with the auditing server, by:

receiving, by the auditing server from the second peer device, a second data at rest (DAR) key pair that includes a second DAR public key and a second encrypted DAR private key, the second encrypted DAR private key formed by the second peer device encrypting a second DAR private key using the auditing public key provided by the auditing server,

storing, by the auditing server, the second encrypted DAR private key in association with an identifier of the second peer device;

receiving, by the auditing server from a routing server, a copy of a peer-to-peer broadcast message sent by the first peer device for transmission to the second peer device, the peer-to-peer broadcast message generated by the first peer device using the second DAR public key and wrapped using a peer-to-peer security protocol;

validating, by the auditing server, the peer-to-peer broadcast message by:

determining that the peer-to-peer broadcast message contains a message copy for the auditing server, and

verifying a digital signature on the peer-to-peer broadcast message and that the second DAR public key is stored for the second peer device that is the intended recipient of the peer-to-peer broadcast message;

responsive to the auditing server validating the peer-to-peer broadcast message:

providing, by the auditing server, an indication of success to the routing server for prompting the routing server to transmit the peer-to-peer broadcast message to the second peer device, and

storing, in a database associated with the auditing server, the copy of the peer-to-peer broadcast message and associated metadata indicating the first peer device as a sender of the peer-to-peer broadcast message, the second peer device as a receiver of the peer-to-peer broadcast message, and a timestamp;

wherein the copy of the peer-to-peer broadcast message stored in the database is only accessible to one or more compliance offers having knowledge of an auditing private key, using the second encrypted DAR private key stored by the auditing server in association with the identifier of the second peer device;

wherein the first peer device, the second peer device, the auditing server, and the routing server communicate via a network.

Assignments (3)
CHANGE OF NAME Recorded Nov 7, 2025
From: DIGITAL 14 - L.L.C.
To: KATIM L.L.C.
Reel/Frame 072834/0247 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2020
From: DARK MATTER LLC
To: DIGITAL 14 LLC
Reel/Frame 052089/0184 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 5, 2016
From: SHERKIN, ALEXANDER; SINGH, RAVI; MATOVSKY, MICHAEL; CHIN, EUGENE
To: DARK MATTER L.L.C.
Reel/Frame 039077/0611 →
Continuity (1)
Related Publication 20170357819A1 · Dec 14, 2017