IP Library Granted Patent US 10,129,229
Granted Patent B1
US 10,129,229 · App. 15/331,726 · Granted Nov 13, 2018

Peer validation

Inventors: Thomas Michael Leavy (Hoboken, NJ); Dipakkumar R. Kasabwala (Clifton, NJ)
Assignee: Wickr Inc.
H04L63/061H04L9/0869H04L9/3247H04L9/3271H04L63/0435H04L63/0442
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,129,229
App. No.
15/331,726
Granted
Nov 13, 2018
Kind
B1
Abstract

The present disclosure describes systems and methods for authenticating a called party during the initialization stage of establishing a secure telecommunication channel to provide assurances to the initiator that they are communicating with whom they intended. A first user issues a challenge that includes a nonce to one or more second user devices. The second user's secure collaboration application receives the challenge, signs the nonce included in the challenge, and sends the response with the signed nonce to the first user. The first user receives the response and determines whether the signature of the first nonce is valid. If the signature is not valid, the first user's secure collaboration application terminates the secure telecommunication. However, if the signature received in the response is valid, the first user's secure collaboration application begins exchanging encrypted telecommunication data with the second user over a secure telecommunication channel.

Claims (58)

1. A system, comprising:

a processor configured to:

initialize a secure telecommunication by transmitting a request to one or more receiver devices over a control channel, wherein the request includes a first meeting identifier and a first communication key;

establish a first secure telecommunication channel with at least one of the one or more receiving devices, wherein the first secure telecommunication channel is separate from the control channel;

transmitting a challenge to the one or more receiver devices over the first secure telecommunication channel, wherein the challenge includes a first nonce;

receive a first response to the challenge from a first receiving device, wherein the response includes a signature of the first nonce;

determine whether the signature of the first nonce is valid; and

transmit encrypted telecommunication data over the first secure telecommunication channel when the signature of the first nonce is valid; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the processor is further configured to:

determine whether the first response is received from the first receiving device within a predetermined amount of time, wherein the predetermined amount of time is a time since the challenge was transmitted to the one or more receiving devices.

3. The system of claim 2 , wherein the processor is further configured to:

terminate the secure telecommunication channel with the first receiving device when the first response was not received before the predetermined amount of time elapsed.

4. The system of claim 1 , wherein the processor is further configured to:

terminate the secure telecommunication channel with the first receiving device when the signature is invalid.

5. The system of claim 1 , wherein the processor is further configured to:

generate the first nonce using a random number generator.

6. The system of claim 5 , further comprising:

obtain a signature verification key from a third party, wherein the signature verification key is a public key that corresponds to a private key used to generate the signature of the first nonce; and

verifying the signature of the first nonce using the signature verification key.

7. A method comprising:

initializing, on a first device, a secure telecommunication by transmitting a request to one or more receiver devices over a control channel, wherein the request includes a first meeting identifier and a first communication key;

establishing, at the first device, a first secure telecommunication channel with at least one of the one or more receiving devices, wherein the first secure telecommunication channel is separate from the control channel;

transmitting, by the first device, a challenge to the one or more receiver devices via the first secure telecommunication channel, wherein the challenge includes a first nonce;

receiving, at the first device, a first response to the challenge from a second device, wherein the response includes a signature of the first nonce;

determining, at the first device, whether the signature of the first nonce is valid; and

transmitting encrypted telecommunication data over the first secure telecommunication channel when the signature of the first nonce is valid.

8. The method of claim 7 , further comprising:

determining, at the first device, whether the first response is received from the second device within a predetermined amount of time, wherein the predetermined amount of time is a time since the challenge was transmitted to the one or more receiving devices.

9. The method of claim 8 , further comprising:

terminating, at the first device, the secure telecommunication channel with the second device when the first response was not received before the predetermined amount of time elapsed.

10. The method of claim 7 , further comprising:

terminating, at the first device, the secure telecommunication channel with the second device when the signature is invalid.

11. The method of claim 7 , further comprising:

generating, at the first device, the first nonce using a random number generator.

12. The method of claim 7 , further comprising:

obtaining, at the first device, a signature verification key from a third party, wherein the signature verification key is a public key that corresponds to a private key used to generate the signature of the first nonce; and

verifying, at the first device, the signature of the first nonce using the signature verification key.

13. The method of claim 7 , further comprising:

generating the first communication key using a first set of pseudorandom bytes derived from one or more operations of the first device.

14. A non-transitory computer-readable medium comprising instructions that when, executed by at least one processor, perform the steps of:

initializing a secure telecommunication by transmitting a request to one or more receiver devices over a control channel, wherein the request includes a first meeting identifier and a first communication key;

establishing a first secure telecommunication channel with at least one of the one or more receiving devices, wherein the first secure telecommunication channel is separate from the control channel;

transmitting a challenge to the one or more receiver devices via the first secure telecommunication channel, wherein the challenge includes a first nonce;

receiving a first response to the challenge from a second device, wherein the response includes a signature of the first nonce;

determining whether the signature of the first nonce is valid; and

transmitting encrypted telecommunication data over the first secure telecommunication channel when the signature of the first nonce is valid.

15. The non-transitory computer-readable medium of claim 14 , further comprising instructions for:

determining whether the first response is received from the second device within a predetermined amount of time, wherein the predetermined amount of time is a time since the challenge was transmitted to the one or more receiving devices.

16. The non-transitory computer-readable medium of claim 15 , further comprising instructions for:

terminating the secure telecommunication channel with the second device when the first response was not received before the predetermined amount of time elapsed.

17. The non-transitory computer-readable medium of claim 14 , further comprising instructions for:

terminating the secure telecommunication channel with the second device when the signature is invalid.

18. The non-transitory computer-readable medium of claim 14 , further comprising instructions for:

generating the first nonce using a random number generator.

19. The non-transitory computer-readable medium of claim 14 , further comprising:

obtaining a signature verification key from a third party, wherein the signature verification key is a public key that corresponds to a private key used to generate the signature of the first nonce; and

verifying the signature of the first nonce using the signature verification key.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2021
From: WICKR LLC
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 057366/0573 →
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 25, 2021
From: SILICON VALLEY BANK
To: WICKR INC.
Reel/Frame 056684/0366 →
SECURITY AGREEMENT Recorded Dec 12, 2017
From: WICKR INC.
To: SILICON VALLEY BANK
Reel/Frame 044872/0729 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2017
From: LEAVY, THOMAS MICHAEL; KASABWALA, DIPAKKUMAR R
To: WICKR INC
Reel/Frame 041765/0693 →
Continuity (1)
Provisional Application 62375388 · Aug 15, 2016
Cited By (3)
US 12,199,978 US 12,562,898 US 12,705,330