IP Library Granted Patent US 10,804,976
Granted Patent B2
US 10,804,976 · App. 15/931,060 · Granted Oct 13, 2020

Secure end-to-end transport through intermediary nodes

Inventors: Lee R. Boynton (Lake Oswego, OR); Trevor A. Fiatal (Fremont, CA); Scott M. Burke (Mountain View, CA); Mark Sikes (Ben Lomond, CA)
Assignee: Seven Networks, LLC
H04B7/0417H04B7/04H04B7/0617H04L51/38H04L63/029H04L63/0272H04L63/0428H04L63/0464H04L63/0471H04L63/08H04L63/0807H04L67/04H04W12/001H04W52/0261H04W4/12H04W88/06Y02D10/00Y02D30/70
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,804,976
App. No.
15/931,060
Granted
Oct 13, 2020
Kind
B2
Abstract

A communication network encrypts a first portion of a transaction associated with point-to-point communications using a point-to-point encryption key. A second portion of the transaction associated with end-to-end communications is encrypted using an end-to-end encryption key.

Claims (66)

1. A method implemented on a first computer, the method comprising:

establishing a first security association with a second computer;

encrypting first data of a first data path in a transaction using the first security association, wherein:

the first data path is through an intermediary server that provides connectivity between the first computer and the second computer;

the first security association is not known to the intermediary server; and

the transaction comprises a transaction message that includes control data and payload data;

transmitting the control data to the intermediary server, wherein:

the control data includes a token associated with the intermediary server;

the token provides transaction routing information;

the second computer receives the first data from the intermediary server; and

the second computer decrypts the first data;

encrypting second data of a second data path using a second security association, wherein the second data path is distinct from the intermediary server; and

transmitting the payload data through the second data path.

2. The method of claim 1 , wherein the token is issued by the intermediary server.

3. The method of claim 1 , wherein the first computer is a first mobile device.

4. The method of claim 3 , wherein the first mobile device and the intermediary server are coupled over a mobile network.

5. The method of claim 4 , wherein the mobile network provides an Internet protocol (IP) infrastructure of a wireless service provider.

6. The method of claim 4 , wherein the first mobile device is a source for the transaction and the second computer is a target for the transaction.

7. The method of claim 6 , wherein the transaction message includes a device identification associated with the second computer.

8. The method of claim 7 , wherein the transaction message is modified by the first computer based on the device identification.

9. The method of claim 8 , wherein the device identification is associated within the intermediary server to a third security association between the intermediary server and the second computer.

10. The method of claim 4 , wherein the second computer is a personal computer.

11. A first computer having a processor configured for:

establishing a first security association with a second computer;

encrypting first data of a first data path in a transaction using the first security association, wherein:

the first data path is through an intermediary server that provides connectivity between the first computer and the second computer;

the first security association is not known to the intermediary server; and

the transaction comprises a transaction message that includes control data and payload data;

transmitting the control data to the intermediary server, wherein:

the control data includes a token associated with the intermediary server;

the token provides transaction routing information;

the second computer receives the first data from the intermediary server; and

the second computer decrypts the first data;

encrypting second data of a second data path using a second security association, wherein the second data path is distinct from the intermediary server; and

transmitting the payload data through the second data path.

12. The first computer of claim 11 , wherein the token is issued by the intermediary server.

13. The first computer of claim 11 , wherein the first computer is a first mobile device.

14. The first computer of claim 13 , wherein the first mobile device and the intermediary server are coupled over a mobile network.

15. The first computer of claim 14 , wherein the mobile network provides an Internet protocol (IP) infrastructure of a wireless service provider.

16. The first computer of claim 14 , wherein the first mobile device is a source for the transaction and the second computer is a target for the transaction.

17. The first computer of claim 16 , wherein the transaction message includes a device identification associated with the second computer.

18. The first computer of claim 17 , wherein the transaction message is modified by the first computer based on the device identification.

19. The first computer of claim 18 , wherein the device identification is associated within the intermediary server to a third security association between the intermediary server and the second computer.

20. The first computer of claim 14 , wherein the second computer is a personal computer.

21. A non-transitory computer-readable storage medium, the non-transitory computer-readable storage medium storing instructions to be implemented on a first computer including at least one processor, the instructions when executed by the at least one processor cause the first computer to perform a method, the method comprising:

establishing a first security association with a second computer;

encrypting first data of a first data path in a transaction using the first security association, wherein:

the first data path is through an intermediary server that provides connectivity between the first computer and the second computer;

the first security association is not known to the intermediary server; and

the transaction comprises a transaction message that includes control data and payload data;

transmitting the control data to the intermediary server, wherein:

the control data includes a token associated with the intermediary server;

the token provides transaction routing information;

the second computer receives the first data from the intermediary server; and

the second computer decrypts the first data;

encrypting second data of a second data path using a second security association, wherein the second data path is distinct from the intermediary server; and

transmitting the payload data through the second data path.

22. The method of claim 21 , wherein the token is issued by the intermediary server.

23. The method of claim 21 , wherein the first computer is a first mobile device.

24. The method of claim 23 , wherein the first mobile device and the intermediary server are coupled over a mobile network.

25. The method of claim 24 , wherein the mobile network provides an Internet protocol (IP) infrastructure of a wireless service provider.

26. The method of claim 24 , wherein the first mobile device is a source for the transaction and the second computer is a target for the transaction.

27. The method of claim 26 , wherein the transaction message includes a device identification associated with the second computer.

28. The method of claim 27 , wherein the transaction message is modified by the first computer based on the device identification.

29. The method of claim 28 , wherein the device identification is associated within the intermediary server to a third security association between the intermediary server and the second computer.

30. The method of claim 24 , wherein the second computer is a personal computer.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2020
From: BOYNTON, LEE R.; FIATAL, TREVOR A.; BURKE, SCOTT M.; SIKES, MARK
To: SEVEN NETWORKS, INC.
Reel/Frame 052651/0947 →
ENTITY CONVERSION Recorded May 13, 2020
From: SEVEN NETWORKS, INC.
To: SEVEN NETWORKS, LLC
Reel/Frame 052655/0369 →
Continuity (11)
Continuation 16176946 · Oct 31, 2018
Continuation 15639014 · Jun 30, 2017
Continuation 15140284 · Apr 27, 2016
Continuation 14043772 · Oct 1, 2013
Continuation 13396464 · Feb 14, 2012
Continuation 12889252 · Sep 23, 2010
Continuation 11875785 · Oct 19, 2007
Continuation In Part 10339369 · Jan 8, 2003
Provisional Application 60403249 · Aug 12, 2002
Provisional Application 60346881 · Jan 8, 2002
Related Publication 20200274584A1 · Aug 27, 2020