IP Library Granted Patent US 10,187,215
Granted Patent B2
US 10,187,215 · App. 15/804,291 · Granted Jan 22, 2019

Combined authentication and encryption

Inventors: Bryan D O'Connor (Atherton, CA); Eugene Fooksman (Santa Clara, CA)
Assignee: WhatsApp Inc.
H04L9/3271H04L9/0819H04L9/0863H04L9/3234H04L9/3297
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,187,215
App. No.
15/804,291
Granted
Jan 22, 2019
Kind
B2
Abstract

A system and methods are provided for establishing an authenticated and encrypted communication connection between two devices with at most two round-trip communications. During establishment of an initial authenticated, encrypted communication connection (or afterward), a first device (e.g., a server) provides the second device (e.g., a client) with a token (e.g., a challenge) that lives or persists beyond the current connection. After that connection is terminated and the second device initiates a new connection, it uses the token as part of the handshaking process to reduce the necessary round-trip communications to one.

Claims (43)

1. A method comprising:

providing a device with a first unsolicited token during an authenticated first communication connection, wherein the first unsolicited token is associated with a lifetime during which the first unsolicited token remains valid and the lifetime is selected based on a type of the device or a type of user associated with the device;

receiving encrypted authentication data generated from the first unsolicited token from the device after termination of the authenticated first communication connection; and:

if the encrypted authentication data was received within the lifetime of the first unsolicited token, decrypting the encrypted authentication data and establishing a second communication connection based on the decrypted authentication data, or

if the encrypted authentication data was not received within the lifetime of the first unsolicited token, providing the device with a second token configured to authenticate the second communication connection.

2. The method of claim 1 , wherein decrypting the encrypted authentication data comprises:

generating a session key from the first unsolicited token; and

decrypting the encrypted authentication data with the session key.

3. The method of claim 1 , wherein the authentication data comprises:

an identifier of a user of the device;

the first unsolicited token or the second token; and

device-specific data.

4. The method of claim 3 , wherein the identifier of the user of the device is a telephone number associated with the user.

5. The method of claim 1 , wherein the first unsolicited token is a token sent to the device as part of a periodic token replacement schedule.

6. A non-transitory computer readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to:

provide a device with a first unsolicited token during an authenticated first communication connection, wherein the first unsolicited token is associated with a lifetime during which the first unsolicited token remains valid and the lifetime is selected based on a type of the device or a type of user associated with the device;

receive encrypted authentication data generated from the first unsolicited token from the device after termination of the authenticated first communication connection; and:

if the encrypted authentication data was received within the lifetime of the first unsolicited token, decrypting the encrypted authentication data and establishing a second communication connection based on the decrypted authentication data, or

if the encrypted authentication data was not received within the lifetime of the first unsolicited token, providing the device with a second token configured to authenticate the second communication connection.

7. The medium of claim 6 , wherein decrypting the encrypted authentication data comprises:

generating a session key from the first unsolicited token; and

decrypting the encrypted authentication data with the session key.

8. The medium of claim 6 , wherein the authentication data comprises:

an identifier of a user of the device;

the first unsolicited token or the second token; and

device-specific data.

9. The medium of claim 8 , wherein the identifier of the user of the device is a telephone number associated with the user.

10. The medium of claim 6 , wherein the first unsolicited token is a token sent to the device as part of a periodic token replacement schedule.

11. A system comprising:

a processor; and

memory configured to store instructions that, when executed by the processor, cause the system to:

provide a device with a first unsolicited token during an authenticated first communication connection, wherein the first unsolicited token is associated with a lifetime during which the first unsolicited token remains valid and the lifetime is selected based on a type of the device or a type of user associated with the device;

receive encrypted authentication data generated from the first unsolicited token from the device after termination of the authenticated first communication connection; and:

if the encrypted authentication data was received within the lifetime of the first unsolicited token, decrypting the encrypted authentication data and establishing a second communication connection based on the decrypted authentication data, or

if the encrypted authentication data was not received within the lifetime of the first unsolicited token, providing the device with a second token configured to authenticate the second communication connection.

12. The apparatus of claim 11 , wherein decrypting the encrypted authentication data comprises:

generating a session key from the first unsolicited token; and

decrypting the encrypted authentication data with the session key.

13. The apparatus of claim 11 , wherein the authentication data comprises:

an identifier of a user of the device;

the first unsolicited token or the second token; and

device-specific data.

14. The apparatus of claim 13 , wherein the identifier of the user of the device is a telephone number associated with the user.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2022
From: O'CONNOR, BRYAN D.; FOOKSMAN, EUGENE
To: WHATSAPP INC.
Reel/Frame 061762/0234 →
CHANGE OF NAME Recorded Jun 22, 2021
From: WHATSAPP INC.
To: WHATSAPP LLC
Reel/Frame 056646/0001 →
Continuity (3)
Continuation 14945649 · Nov 19, 2015
Continuation 14045192 · Oct 3, 2013
Related Publication 20180076964A1 · Mar 15, 2018