IP Library Granted Patent US 11,349,659
Granted Patent B2
US 11,349,659 · App. 15/689,250 · Granted May 31, 2022

Transmitting an encrypted communication to a user in a second secure communication network

Inventors: Arjun Bhatnagar (Matawan, NJ); Christopher Howell (Freehold, NJ)
Assignee: Amazon Technologies, Inc.
H04L9/321H04L9/088H04L9/0822H04L9/0841H04L9/0844H04L9/0894H04L9/3273H04L51/18H04L63/045H04L63/0428G06F2221/2137H04L9/006H04L63/061H04L63/068H04L63/104H04L2463/061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,349,659
App. No.
15/689,250
Granted
May 31, 2022
Kind
B2
Abstract

The present disclosure describes a method, system, and non-transitory computer readable medium that includes instructions that permit users of different secure communication networks to exchange secure communications. A secure communication platform includes a user database that allows users from different secure communication networks to access keys for recipients outside of their network. Additionally, the secure communication platform provides a high degree of trust regarding the sender's identity, allowing the receiving network to trust the sender.

Claims (45)

1. A method for transmitting an encrypted communication to a user in a second secure communication network, the method comprising:

transmitting, from a first device in a first secure communication network and to a secure communication platform, a first identifier for a second user that belongs to the second secure communication network;

receiving, at the first device, a user profile for the second user in response to transmitting the first identifier to the secure communication platform, wherein the user profile comprises a first ephemeral public key, a first key identifier, and an application identifier associated with an application executing on a second device of the second user;

generating, by the first device, a first encryption key;

deriving, by the first device, a key-encrypting key using at least the first ephemeral public key and the application identifier;

encrypting, by the first device, a first communication to the second user using the first encryption key;

encrypting, by the first device, the first encryption key using the key-encrypting key; and

transmitting, by the first device, the first encrypted communication, the key identifier, the encrypted first encryption key, and routing data to the second device on the second secure communication network, wherein the second device retrieves the key identifier and the encrypted first encryption key from the first encrypted communication using the application identifier.

2. The method of claim 1 , wherein the first device belongs to a first secure communication network.

3. The method of claim 1 , wherein the first secure communication network and the second secure communication network are different networks.

4. The method of claim 1 wherein the first encryption key is calculated by inputting a first set of pseudorandom bytes into a key derivation function.

5. The method of claim 1 , comprising:

generating, by the first device, a second ephemeral key pair.

6. The method of claim 5 , wherein the key-encrypting key is derived according to a key agreement protocol.

7. The method of claim 6 , wherein the key agreement protocol uses the first ephemeral public key and the second ephemeral private key generated by the first device.

8. The method of claim 7 , comprising:

transmitting, by the first device, the second ephemeral public key to the second device with the first encrypted communication, the key identifier, and the encrypted first encryption key.

9. A system for transmitting an encrypted communication to a user in a second secure communication network, the system comprising:

an interface configured to transmit a first identifier for a second user that belongs to the second secure communication network to a secure communication platform, receive a user profile for the second user that comprises a first ephemeral public key, a first key identifier, and an application identifier associated with an application executing on a second device of the second user, and transmit a first encrypted communication, a key identifier, an encrypted first encryption key, and routing data to the second device on the second secure communication network, wherein the second device retrieves the key identifier and the encrypted first encryption key from the first encrypted communication using the application identifier;

a processor configured to generate a first encryption key, derive a key-encrypting key using at least the first ephemeral public key and the application identifier, encrypt a first communication to the second user using the first encryption key, and encrypt the first encryption key using the key-encrypting key; and

a memory coupled to the processor and configured to provide the processor with instructions for generating the first encryption key, deriving the key-encrypting key, encrypting the first communication, and encrypting the first encryption key.

10. The system of claim 9 , wherein the first device belongs to a first secure communication network.

11. The system of claim 9 , wherein the first secure communication network and the second secure communication network are different networks.

12. The system of claim 9 , wherein the first encryption key is calculated by inputting a first set of pseudorandom bytes into a key derivation function.

13. The system of claim 9 , wherein the processor is further configured to generate a second ephemeral key pair.

14. The system of claim 13 , wherein the key-encrypting key is derived according to a key agreement protocol.

15. The system of claim 14 , wherein the key agreement protocol uses the first ephemeral public key and the second ephemeral private key generated by the first device.

16. The system of claim 15 , wherein the processor is configured to transmit the second ephemeral public key to the second user with the first encrypted communication, the key identifier, and the encrypted first encryption key.

17. A non-transitory computer-readable medium comprising instructions that when, executed by at least one processor, perform the steps of:

transmitting, by a first device in a first communication network and to a secure communication platform, a first identifier for a second user that belongs to a second secure communication network;

receiving a user profile for the second user in response to transmitting the first identifier to the secure communication platform, wherein the user profile comprises a first ephemeral public key, a first key identifier, and an application identifier associated with an application executing on a second device of the second user;

generating a first encryption key;

deriving a key-encrypting key using at least the first ephemeral public key and the application identifier;

encrypting a first communication to the second user using the first encryption key;

encrypting the first encryption key using the key-encrypting key; and

transmitting the first encrypted communication, the key identifier, the encrypted first encryption key, and routing data to the second device on the second secure communication network, wherein the second device retrieves the key identifier and the encrypted first encryption key from the first encrypted communication using the application identifier.

18. The non-transitory computer-readable medium of claim 17 , wherein the first device belongs to a first secure communication network.

19. The non-transitory computer-readable medium of claim 17 , wherein the first secure communication network and the second secure communication network are different networks.

20. The non-transitory computer-readable medium of claim 17 , wherein the first encryption key is calculated by inputting a first set of pseudorandom bytes into a key derivation function.

21. The non-transitory computer-readable medium of claim 17 , comprising instructions for:

generating, by the first device, a second ephemeral key pair.

22. The non-transitory computer-readable medium of claim 21 , wherein the key-encrypting key is derived according to a key agreement protocol.

23. The non-transitory computer-readable medium of claim 22 , wherein the key agreement protocol uses the first ephemeral public key and the second ephemeral private key generated by the first device.

24. The non-transitory computer-readable medium of claim 23 , comprising instructions for:

transmitting, by the first device, the second ephemeral public key to the second user with the first encrypted communication, the key identifier, and the encrypted first encryption key.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2021
From: WICKR LLC
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 057366/0573 →
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 25, 2021
From: SILICON VALLEY BANK
To: WICKR INC.
Reel/Frame 056684/0366 →
SECURITY AGREEMENT Recorded Dec 12, 2017
From: WICKR INC.
To: SILICON VALLEY BANK
Reel/Frame 044872/0729 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2017
From: BHATNAGAR, ARJUN; HOWELL, CHRISTOPHER
To: WICKR INC.
Reel/Frame 043435/0545 →
Continuity (1)
Related Publication 20190068372A1 · Feb 28, 2019
Cited By (1)
US 12,506,599