IP Library Granted Patent US 12,278,893
Granted Patent B2
US 12,278,893 · App. 15/962,072 · Granted Apr 15, 2025

Lightweight security for internet of things messaging

Inventors: Junping Zhao (Beijing, CN); Mohamed Sohail (Sheikh Zayed, EG)
Assignee: EMC IP Holding Company LLC
H04L9/085G06F21/602H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,278,893
App. No.
15/962,072
Granted
Apr 15, 2025
Kind
B2
Abstract

An apparatus in one embodiment comprises a processing platform configured to communicate over a network with a plurality of Internet of Things (IoT) devices. The processing platform receives at least a first intermediate message from a first gateway of the network, receives one or more additional intermediate messages from each of one or more additional gateways of the network, associates the first and additional intermediate messages with one another based at least in part on a common message identifier detected in each such intermediate message, and processes the associated first and additional intermediate messages to recover a device message from a given one of the IoT devices. The first intermediate message is based at least in part on at least one application of a designated cryptographic function to the device message utilizing a corresponding key. At least one of the one or more additional intermediate messages provides at least a portion of the key.

Claims (52)

1. An apparatus comprising:

a processing platform comprising one or more processing devices each comprising a processor coupled to a memory;

the processing platform being configured to communicate over a network with a plurality of Internet of Things (loT) devices;

the processing platform being configured:

to receive at least a first intermediate message froma first gateway of the network, the first intermediate message comprising an encrypted version of a device message, the encrypted version of the device message being based at least in part on at least one application of a designated cryptographic function to the device message utilizing a first key, the first key being generated by a given one of the plurality of loT devices that is a source of the device message;

to receive one or more additional intermediate messages from each of one or more additional gateways of the network, at least one of the one or more additional intermediate messages received from a given one of the one or more additional gateways comprising an encrypted version of the first key, the encrypted version of the first key being based at least in part on at least one application of the designated cryptographic function to the first key utilizing a second key, the second key being generated by the given one of the one or more additional gateways;

to associate the first and one or more additional intermediate messages with one another based at least in part on a common message identifier detected in the first and one or more additional intermediate messages; and

to process the associated first and one or more additional intermediate messages, utilizing the designated cryptographic function, to recover the device message from the given one of the plurality of loT devices;

wherein the encrypted version of the device message is included in the first intermediate message but is not included in any of the one or more additional intermediate messages; and

wherein the first intermediate message comprises the common message identifier and a result of applying a composite key to the device message, wherein the composite key comprises a result of combining a particular number of other keys, including a third key generated by the first gateway, using the designated cryptographic function.

2. The apparatus of claim 1 wherein the processing platform comprises a cloud-based data center.

3. The apparatus of claim 1 wherein the designated cryptographic function comprises a bitwise exclusive-or function.

4. The apparatus of claim 1 wherein the common message identifier comprises a randomly-generated message identifier that is unique to the device message.

5. The apparatus of claim 1 wherein the common message identifier is generated by the given one of the plurality of loT devices.

6. The apparatus of claim 1 wherein the first intermediate message comprises the common message identifier and a result of a single application of the designated cryptographic function to the device message using the first key.

7. The apparatus of claim 1 wherein a given one of the one or more additional intermediate messages comprises the common message identifier and the second key.

8. The apparatus of claim 1 wherein the particular number of other keys is one less than a number of connected downstream gateways in a first layer of parallel gateways that the given one of the plurality of loT devices utilizes in communicating the device message to the processing platform.

9. The apparatus of claim 1 wherein the one or more additional intermediate messages comprise a plurality of additional intermediate messages each comprising the common message identifier and a corresponding one of the other keys used to generate the composite key.

10. The apparatus of claim 1 wherein the one or more additional intermediate messages comprise a plurality of additional intermediate messages that collectively provide the first key.

11. An apparatus comprising:

a processing platform comprising one or more processing devices each comprising a processor coupled to a memory:

the processing platform being configured to communicate over a network with a plurality of Internet of Things (loT) devices;

the processing platform being configured:

to receive at least a first intermediate message froma first gateway of the network, the first intermediate message comprising an encrypted version of a device message, the encrypted version of the device message being based at least in part on at least one application of a designated cryptographic function to the device message utilizing a first key, the first key being generated by a given one of the plurality of loT devices that is a source of the device message;

to receive one or more additional intermediate messages from each of one or more additional gateways of the network, at least one of the one or more additional intermediate messages received from a given one of the one or more additional gateways comprising an encrypted version of the first key, the encrypted version of the first key being based at least in part on at least one application of the designated cryptographic function to the first key utilizing a second key, the second key being generated by the given one of the one or more additional gateways;

to associate the first and one or more additional intermediate messages with one another based at least in part on a common message identifier detected in the first and one or more additional intermediate messages; and

to process the associated first and one or more additional intermediate messages, utilizing the designated cryptographic function, to recover the device message from the given one of the plurality of loT devices;

wherein the encrypted version of the device message is included in the first intermediate message but is not included in any of the one or more additional intermediate messages; and

wherein the first intermediate message comprises the common message identifier and a result of multiple sequential applications of the designated cryptographic function to the device message using respective ones of a plurality of keys, the plurality of keys comprising the first key and a third key, the third key being generated by the first gateway.

12. The apparatus of claim 11 wherein one of the one or more additional intermediate messages comprises the common message identifier and the third key.

13. A method comprising:

configuring a processing platform to communicate over a network with a plurality of Internet of Things (loT) devices;

wherein the processing platform performs the following steps:

receiving at least a first intermediate message from a first gateway of the network, the first intermediate message comprising an encrypted version of a device message, the encrypted version of the device message being based at least in part on at least one application of a designated cryptographic function to the device message utilizing a first key, the first key being generated by a given one of the plurality of loT devices that is a source of the device message;

receiving one or more additional intermediate messages from each of one or more additional gateways of the network, at least one of the one or more additional inter mediate messages received from a given one of the one or more additional gateways comprising an encrypted version of the first key, the encrypted version of the first key being based at least in part on at least one application of the designated cryptographic function to the first key utilizing a second key, the second key being generated by the given one of the one or more additional gateways;

associating the first and one or more additional intermediate messages with one another based at least in part on a common message identifier detected in the first and one or more additional intermediate messages; and

processing the associated first and one or more additional intermediate messages, utilizing the designated cryptographic function, to recover the device message from the given one of the plurality of loT devices;

wherein the encrypted version of the device message is included in the first intermediate message but is not included in any of the one or more additional intermediate messages; and

wherein the first intermediate message comprises the common message identifier and a result of applying a composite key to the device message, wherein the composite key comprises a result of combining a particular number of other keys, including a third key generated by the first gateway, using the designated cryptographic function.

14. The method of claim 13 wherein the one or more additional intermediate messages comprise a plurality of additional intermediate messages that collectively provide the first key.

15. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by a processing platform, the processing platform being configured to communicate over a network with a plurality of Internet of Things (loT) devices, causes the processing platform:

to receive at least a first intermediate message froma first gateway of the network, the first intermediate message comprising an encrypted version of a device message, the encrypted version of the device message being based at least in part on at least one application of a designated cryptographic function to the device message utilizing a first key, the first key being generated by a given one of the plurality of loT devices that is a source of the device message;

to receive one or more additional intermediate messages from each of one or more additional gateways of the network, at least one of the one or more additional intermediate messages received from a given one of the one or more additional gateways comprising an encrypted version of the first key, the encrypted version of the first key being based at least in part on at least one application of the designated cryptographic function to the first key utilizing a second key, the second key being generated by the given one of the one or more additional gateways;

to associate the first and one or more additional intermediate messages with one another based at least in part on a common message identifier detected in the first and one or more additional intermediate messages; and

to process the associated first and one or more additional intermediate messages, utilizing the designated cryptographic function, to recover the device message from the given one of the plurality of loT devices;

wherein the encrypted version of the device message is included in the first intermediate message but is not included in any of the one or more additional intermediate messages; and

wherein the first intermediate message comprises the common message identifier and a result of applying a composite key to the device message, wherein the composite key comprises a result of combining a particular number of other keys, including a third key generated by the first gateway, using the designated cryptographic function.

16. The computer program product of claim 15 wherein the one or more additional intermediate messages comprise a plurality of additional intermediate messages that collectively provide the first key.

17. The computerprogram product of claim 15 wherein the first intermediate message comprises the common message identifier and a result of a single application of the designated cryptographic function to the device message using the first key.

18. The computer program product of claim 15 wherein a given one of the one or more additional intermediate messages comprises the common message identifier and the second key.

19. The computer program product of claim 15 wherein the first intermediate message comprises the common message identifier and a result of multiple sequential applications of the designated cryptographic function to the device message using respective ones of a plurality of keys, the plurality of keys comprising the first key and a third key, the third key being generated by the first gateway.

20. The computer program product of claim 15 wherein the particular number of other keys is one less than a number of connected downstream gateways in a first layer of parallel gateways that the given one of the plurality of loT devices utilizes in communicating the device message to the processing platform.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (046366/0014) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060450/0306 →
RELEASE OF SECURITY INTEREST AT REEL 046286 FRAME 0653 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0093 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046286/0653 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 046366/0014 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2018
From: ZHAO, JUNPING; SOHAIL, MOHAMED
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 045631/0016 →
Continuity (1)
Related Publication 20190334701A1 · Oct 31, 2019
References Cited (67)
US 4802220A · Marker, Jr. · 1989 [cited by examiner]
US 6021203A · Douceur · 2000 [cited by examiner]
US 6035041A · Frankel · 2000 [cited by examiner]
US 6122743A · Shaffer · 2000 [cited by examiner]
US 6182214B1 · Hardjono · 2001 [cited by examiner]
US 7043022B1 · Blanchard · 2006 [cited by examiner]
US 7171493B2 · Shu · 2007 [cited by examiner]
US 7916739B2 · Trostle · 2011 [cited by examiner]
US 9032203B2 · Takenaka · 2015 [cited by examiner]
US 9219604B2 · Resch · 2015 [cited by examiner]
US 9942212B2 · Gremaud · 2018 [cited by examiner]
US 9998434B2 · Verzun · 2018 [cited by examiner]
US 10084600B1 · Irwan · 2018 [cited by examiner]
US 10169598B1 · Medina, III · 2019 [cited by examiner]
US 10225075B1 · Moritz · 2019 [cited by examiner]
US 10230702B1 · Moritz · 2019 [cited by examiner]
US 10354084B2 · Damgård · 2019 [cited by examiner]
US 10721062B2 · Chen · 2020 [cited by examiner]
US 10805344B2 · Britt · 2020 [cited by examiner]
US 11057293B2 · Aguado Martín et al. · 2021 [cited by examiner]
US 20020015422A1 · Inada · 2002 [cited by examiner]
US 20020120874A1 · Shu · 2002 [cited by examiner]
US 20030081582A1 · Jain · 2003 [cited by examiner]
US 20030126303A1 · Kadakia · 2003 [cited by examiner]
US 20030167314A1 · Gilbert · 2003 [cited by examiner]
US 20040179686A1 · Matsumura · 2004 [cited by examiner]
US 20060129811A1 · Fiske · 2006 [cited by examiner]
US 20080022389A1 · Calcev · 2008 [cited by examiner]
US 20080034197A1 · Engel · 2008 [cited by examiner]
US 20080144836A1 · Sanders · 2008 [cited by examiner]
US 20110138192A1 · Kocher · 2011 [cited by examiner]
US 20120084368A1 · Go · 2012 [cited by examiner]
US 20130227292A1 · Suffling · 2013 [cited by examiner]
US 20130290701A1 · Takenaka · 2013 [cited by examiner]
US 20150186671A1 · O'Hare · 2015 [cited by examiner]
US 20150310219A1 · Haager · 2015 [cited by examiner]
US 20160315921A1 · Dara · 2016 [cited by examiner]
US 20170310472A1 · Garcia-Morchon · 2017 [cited by examiner]
US 20170331800A1 · Wood · 2017 [cited by examiner]
US 20180139190A1 · Chaum · 2018 [cited by examiner]
US 20180241548A1 · Dolev · 2018 [cited by examiner]
US 20180302386A1 · Childress · 2018 [cited by examiner]
US 20180359811A1 · Verzun · 2018 [cited by examiner]
US 20190014094A1 · Le Saint · 2019 [cited by examiner]
US 20190306129A1 · Waltermann · 2019 [cited by examiner]
US 20190306135A1 · Mudulodu · 2019 [cited by examiner]
US 20210195393A1 · Jiménez · 2021 [cited by examiner]
US 20210367775A1 · Grau · 2021 [cited by examiner]
CA 2766719A1 · 2011 [cited by examiner]
EP 0112943A1 · 1984 [cited by examiner]
EP 3528430A1 · 2019 [cited by examiner]
WO WO2006130991A1 · 2006 [cited by examiner]
WO WO2018125989A2 · 2018 [cited by examiner]
WO WO2019110574A1 · 2019 [cited by examiner]
Kurihara, J., Kiyomoto, S., Fukushima, K., and Tanaka, T.: A New (k,n)-Threshold Secret Sharing Scheme and Its Extension. In Proceedings of the 11th international Conference on information Security (Taipei, Taiwan), 200… [cited by examiner]
M. Z. A. Bhuiyan, M. Zaman, G. Wang, T. Wang and J. Wu, “Privacy-Protected Data Collection in Wireless Medical Sensor Networks,” 2017 International Conference on Networking, Architecture, and Storage (NAS), 2017, pp. 1-… [cited by examiner]
E. Luo, M. Z. A. Bhuiyan, G. Wang, M. A. Rahman, J. Wu and M. Atiquzzaman, “PrivacyProtector: Privacy-Protected Patient Data Collection in IoT-Based Healthcare Systems,” in IEEE Communications Magazine, vol. 56, No. 2, … [cited by examiner]
S. Bouam and J. Ben-Othman, “Data security in ad hoc networks using multipath routing,” 14th IEEE Proceedings on Personal, Indoor and Mobile Radio Communications, 2003. PIMRC 2003., Beijing, China, 2003, pp. 1331-1335 v… [cited by examiner]
Al-Rousan, M. & Rjoub, A & Baset, Ahmad. (2009). A Low-Energy Security Algorithm for Exchanging Information in Wireless Sensor Networks. Journal of Information Assurance and Security. 450. 48-59. [cited by examiner]
1. Ghafoor A, Sher M, Imran M, Derhab A. Secure Key Distribution Using Fragmentation and Assimilation in Wireless Sensor and Actor Networks. International Journal of Distributed Sensor Networks. 2015;11(9). doi:10.1155/… [cited by examiner]
K. Sakai, M.-T. Sun, W.-S. Ku, J. Wu and T. H. Lai, “Multi-path Based Avoidance Routing in Wireless Networks,” 2015 IEEE 35th International Conference on Distributed Computing Systems, Columbus, OH, USA, 2015, pp. 706-7… [cited by examiner]
L. Czap, C. Fragouli, V. M. Prabhakaran and S. Diggavi, “Secure Network Coding With Erasures and Feedback,” in IEEE Transactions on Information Theory, vol. 61, No. 4, pp. 1667-1686, Apr. 2015, doi: 10.1109/TIT.2015.240… [cited by examiner]
Li, C. T., & Hwang, M. S. (2011). A lightweight anonymous routing protocol without public key en/decryptions for wireless ad hoc networks. Information Sciences, 181(23), 5333-5347. [cited by examiner]
H. Mohammed, S. Tonyali, K. Rabieh, M. Mahmoud and K. Akkaya, “Efficient Privacy-Preserving Data Collection Scheme for Smart Grid AMI Networks,” 2016 IEEE Global Communications Conference (Globecom), Washington, DC, USA… [cited by examiner]
Pubnub, Inc., “A New Approach to IoT Security: 5 Key Requirements to Securing IoT Communications,” https://www.pubnub.com/static/papers/IoT_Security_Whitepaper_Final.pdf, Jun. 29, 2015, 8 pages. [cited by applicant]
Wikipedia, “Onion Routing,” https://en.wikipedia.org/wiki/Onion_routing, Mar. 16, 2018, 4 pages. [cited by applicant]
Frank Zhao et al., “Improved Reliable Streaming Processing: Apache Storm as Example,” https://www.slideshare.net/HadoopSummit/improved-reliable-streaming-processing-apache-storm-as-example, Sep. 6, 2016, 34 pages. [cited by applicant]