IP Library Patent Application 15709624
Patent Application
App. No. 15/709,624

SECURE COMMUNICATION METHOD AND SYSTEM

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/709,624
Abstract

The method comprises the following steps: a) establishing a secure communication channel between the first device and the second device; b) transmitting a set of symmetric encryption keys from the first device to the second device under secure transmission conditions through the secure communication channel, and storing the set of symmetric encryption keys in respective protected storage memory areas at the first device and at the second device. When the second device is required to transmit data to the first device, the following steps are performed: c) selecting one of said symmetric encryption keys at the second device; d) generating a data bunch at the second device and encrypting the data bunch with the selected symmetric encryption key; e) transmitting the encrypted data bunch from the second device to the first device; f) decrypting the encrypted data bunch at the first device using the selected symmetric encryption key.

Claims (43)

1 - 16 . (canceled)

17 . A method for secure data transmission between a first device and a second device, the method comprising:

(a) establishing a secure communication channel between the first device and the second device;

(b) transmitting a set of symmetric encryption keys from the first device to the second device under secure transmission conditions through the secure communication channel, and storing the set of symmetric encryption keys in respective protected storage memory areas at the first device and at the second device;

wherein, when the second device is required to transmit data to the first device:

(c) selecting one of said symmetric encryption keys at the second device;

(d) generating a data bunch at the second device and encrypting the data bunch with the selected symmetric encryption key;

(e) transmitting the encrypted data bunch from the second device to the first device; and

(f) decrypting the encrypted data bunch at the first device using the selected symmetric encryption key.

18 . The method of claim 17 , comprising the step of attributing an expiry time or date to each symmetric encryption key.

19 . The method of claim 18 , wherein the expiry time or date is provided individually for each symmetric encryption key, or the expiry time or date is assigned globally to the set of symmetric encryption keys.

20 . The method of claim 18 , wherein the step of selecting one of said symmetric encryption keys comprises:

checking if the selected symmetric encryption key has expired, and

if the selected symmetric encryption key has expired, discarding the selected symmetric encryption key and selecting another symmetric encryption key.

21 . The method of claim 17 , wherein the second device transmits to the first device information identifying the selected symmetric encryption key.

22 . The method of claim 21 , wherein the information identifying the selected symmetric encryption key neither contains the selected symmetric encryption key nor information derived by a digest of the selected symmetric encryption key.

23 . The method of claim 17 , further comprising the step of checking if the selected symmetric encryption key is still valid before transmitting the encrypted data bunch.

24 . The method of claim 23 , wherein the step of checking if the selected symmetric encryption key is still valid comprises:

transmitting, from the second device to the first device, information suitable for the first device to identify the symmetric encryption key selected by the second device;

checking at the first device if the selected symmetric encryption key is valid and transmitting from the first device to the second device

a valid-key message if the selected symmetric encryption key is still valid, or

an invalid-key message if the selected symmetric encryption key is invalid;

wherein if a valid-key message is received by the second device, the step of transmitting the encrypted data bunch is performed; and

wherein if an invalid-key message is received by the second device, the step of transmitting the encrypted data bunch is not performed.

25 . The method of claim 24 , wherein, if an invalid-key message is received, a different symmetric encryption key is selected; or steps (a) and (b) are repeated and a new set of symmetric encryption keys is transmitted from the first device to the second device.

26 . The method of claim 17 , wherein each symmetric encryption key is combined with a unique key identification code.

27 . The method of claim 17 , wherein each symmetric encryption key is combined with a random check key, which is uncorrelated with respect to the symmetric encryption key.

28 . The method of claim 27 , wherein the step of transmitting information identifying the selected symmetric encryption key comprises:

applying a cryptographic hash function to at least the random check key associated to the selected symmetric encryption key, said information containing the digest of the random check key.

29 . The method of claim 28 , wherein the step of transmitting information identifying the selected symmetric encryption key comprises:

generating a stamp;

applying the cryptographic hash function to the random check key and the stamp concatenated thereto; and

transmitting from the second device to the first device said information comprising at least the stamp and the digest of the random check key and the stamp concatenated thereto.

30 . The method of claim 29 , wherein the stamp is a time stamp.

31 . The method of claim 17 , wherein the first device is a server and the second device is a client, in data communication with said server.

32 . A system for secure data transmission, comprising:

a server and a plurality of clients linked via a secure communication channel;

wherein the server is configured to transmit a set of symmetric encryption keys to the clients under secure transmission conditions through the secure communication channel, and store the set of symmetric encryption keys in a first protected storage memory are a;

wherein each of the clients are configured to store the set of symmetric encryption keys in a respective second protected storage memory area, and further in response to a requirement to transmit data to the server, to

select one of said symmetric encryption keys at the second protected storage memory area,

generate a data bunch and encrypt the data bunch with the selected symmetric encryption key, and

transmit the encrypted data bunch to the server;

wherein the server is further configured to decrypt the encrypted data bunch at using the selected symmetric encryption key.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2020
From: ABB SCHWEIZ AG
To: MARICI HOLDINGS THE NETHERLANDS B.V.
Reel/Frame 054205/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2017
From: TAZZARI, DAVIDE; VERNIA, FILIPPO; LAMOGLIE, LUIGI
To: ABB SCHWEIZ AG
Reel/Frame 044162/0801 →