IP Library Granted Patent US 10,341,356
Granted Patent B2
US 10,341,356 · App. 15/811,194 · Granted Jul 2, 2019

Method and apparatus for providing an adaptable security level in an electronic communication

Inventor: Marinus Struik (Toronto, CA)
Assignee: Certicom Corp.
H04L63/105H04L9/088H04L63/0428H04L63/08H04L63/123H04L63/164H04L9/00H04L63/162H04W12/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,341,356
App. No.
15/811,194
Granted
Jul 2, 2019
Kind
B2
Abstract

A method of communicating in a secure communication system, comprises the steps of assembling a message at a sender, then determining a security level, and including an indication of the security level in a header of the message. The message is then sent to a recipient.

Claims (38)

1. A method for providing security in an electronic communication system, comprising:

preparing, by a communication device, a plurality of frames, wherein each individual frame in the plurality of frames has a header and data, wherein the preparing the plurality of frames comprises;

for each individual frame:

determining a security level for the individual frame, the security level indicating whether to provide encryption for the individual frame and whether to provide integrity for the individual frame;

based on the security level, including security control bits in the header of the individual frame, wherein the security control bits include one or more security mode bits and integrity level bits, the one or more security mode bits indicate whether encryption is on or off, the integrity level bits indicate which of at least four integrity levels is utilized, the integrity levels corresponding to signing operations of a sender of increasing strength; and

encrypting the data according to the security level for the frame; and

transmitting the plurality of frames to a recipient device.

2. The method of claim 1 , further comprising receiving a frame, wherein the frame indicates a version of a key to be used in an encryption system.

3. The method of claim 1 , wherein the communication device provides the plurality of frames for transmission to a plurality of recipients, and determining the security level includes determining a minimum security level to satisfy the plurality of recipients, wherein the security control bits are based on the minimum security level.

4. The method of claim 1 , wherein the security level is determined based on predetermined minimum requirements.

5. The method of claim 4 , wherein the predetermined minimum requirements are determined among the communication device and at least one recipient device based on an agreed-upon rule.

6. The method of claim 1 , wherein the security level is determined based upon content of the individual frame.

7. The method of claim 1 , wherein the security control bits include an indication of a cryptographic algorithm parameter.

8. The method of claim 1 , further comprising: signing the header and data for each individual frame according to the security level for the frame.

9. The method of claim 1 , wherein a number of integrity levels is four, and the four integrity levels correspond to key lengths of 0, 32, 64, and 128 bits.

10. The method of claim 1 , wherein one of the integrity levels uses a key length of 128 bits.

11. The method of claim 1 , wherein one of the integrity levels indicates no integrity security.

12. A communication device, comprising:

at least one hardware processor; and

a non-transitory computer-readable storage medium coupled to the at least one hardware processor and storing programming instructions for execution by the at least one hardware processor, wherein the programming instructions, when executed, cause the communication device to perform operations comprising:

preparing, by the communication device, a plurality of frames, wherein each individual frame in the plurality of frames has a header and data, wherein the preparing the plurality of frames comprises;

for each individual frame:

determining a security level for the individual frame, the security level indicating whether to provide encryption for the individual frame and whether to provide integrity for the individual frame;

based on the security level, including security control bits in the header of the individual frame, wherein the security control bits include one or more security mode bits and integrity level bits, the one or more security mode bits indicate whether encryption is on or off, the integrity level bits indicate which of at least four integrity levels is utilized, the integrity levels corresponding to signing operations of a sender of increasing strength; and

encrypting the data according to the security level for the frame; and

transmitting the plurality of frames to a recipient device.

13. The communication device of claim 12 , the operations further comprising receiving a frame, wherein the frame indicates a version of a key to be used in an encryption system.

14. The communication device of claim 12 , wherein the communication device provides the plurality of frames for transmission to a plurality of recipients, and determining the security level includes determining a minimum security level to satisfy the plurality of recipients, wherein the security control bits are based on the minimum security level.

15. The communication device of claim 12 , wherein the security level is determined based on predetermined minimum requirements.

16. The communication device of claim 15 , wherein the predetermined minimum requirements are determined among the communication device and at least one recipient device based on an agreed-upon rule.

17. The communication device of claim 12 , wherein the security level is determined based upon content of the individual frame.

18. A non-transitory computer-readable medium storing instructions which, when executed, cause a communication device to perform operations comprising:

preparing, by the communication device, a plurality of frames, wherein each individual frame in the plurality of frames has a header and data, wherein the preparing the plurality of frames comprises;

for each individual frame:

determining a security level for the individual frame, the security level indicating whether to provide encryption for the individual frame and whether to provide integrity for the individual frame;

based on the security level, including security control bits in the header of the individual frame, wherein the security control bits include one or more security mode bits and integrity level bits, the one or more security mode bits indicate whether encryption is on or off, the integrity level bits indicate which of at least four integrity levels is utilized, the integrity levels corresponding to signing operations of a sender of increasing strength; and

encrypting the data according to the security level for the frame; and

transmitting the plurality of frames to a recipient device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2019
From: STRUIK, MARINUS
To: CERTICOM CORP.
Reel/Frame 048196/0523 →
Continuity (6)
Continuation 15215187 · Jul 20, 2016
Continuation 14877072 · Oct 7, 2015
Continuation 14477637 · Sep 4, 2014
Continuation 10885115 · Jul 7, 2004
Provisional Application 60484656 · Jul 7, 2003
Related Publication 20180069870A1 · Mar 8, 2018
Cited By (1)
US 12,407,692