IP Library Granted Patent US 10,177,911
Granted Patent B2
US 10,177,911 · App. 15/983,957 · Granted Jan 8, 2019

Secure PKI communications for “machine-to-machine” modules, including key derivation by modules and authenticating public keys

Inventor: John A. Nix (Evanston, IL)
Assignee: Network-1 Technologies, Inc.
H04L9/0861G06F21/35H04J11/00H04L9/006H04L9/085H04L9/088H04L9/0816H04L9/0894H04L9/14H04L9/30H04L9/3066H04L9/32H04L9/321H04L9/3239H04L9/3247H04L9/3249H04L9/3263H04L12/2854H04L63/0272H04L63/045H04L63/0435H04L63/0442H04L63/061H04L63/0807H04L63/123H04L63/166H04L67/04H04W4/70H04W8/082H04W12/02H04W12/04H04W12/06H04W40/005H04W52/0216H04W52/0235H04W52/0277H04W76/27H04W80/04G06F2221/2105G06F2221/2107G06F2221/2115H04L63/0464H04L2209/24H04L2209/72H04L2209/805H04W84/12H04W88/12Y02D70/00Y02D70/1222Y02D70/1224Y02D70/1242Y02D70/1244Y02D70/1262Y02D70/1264Y02D70/142Y02D70/144Y02D70/146Y02D70/162Y02D70/164Y02D70/166Y02D70/21Y02D70/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,177,911
App. No.
15/983,957
Granted
Jan 8, 2019
Kind
B2
Abstract

Methods and systems are provided for efficient and secure “Machine-to-Machine” (M2M) between modules and servers. A module can communicate with a server by accessing the Internet, and the module can include a sensor and/or actuator. The module and server can utilize public key infrastructure (PKI) such as public keys to encrypt messages. The module and server can use private keys to generate digital signatures for datagrams sent and decrypt messages received. The module can internally derive pairs of private/public keys using cryptographic algorithms and a set of parameters. A server can use a shared secret key to authenticate the submission of derived public keys with an associated module identity. For the very first submission of a public key derived the module, the shared secret key can comprise a pre-shared secret key which can be loaded into the module using a pre-shared secret key code.

Claims (23)

1. A method of generating keys for a module to securely communicate over a wireless network comprising the steps of:

(a) recording in memory of the module at least the following:

(i) a first set of parameters for a secure hash algorithm;

(ii) a second set of parameters for an elliptic curve algorithm; and

(iii) a first public key which corresponds to a first private key;

(b) deriving, by the module, a module private key and a corresponding module public key using the second set of parameters;

(c) generating, by the module, a first shared secret key using a first elliptic curve Diffie-Hellman key exchange, and based at least in part, on the first public key;

(d) sending, from the module to a first computing device which is connected to the wireless network, a first message including the derived module public key, wherein at least a portion of the first message is encrypted using a third set of parameters that is based on a symmetric ciphering algorithm and the derived first shared secret key;

(e) receiving, by the module from the first computing device, a second message comprising encrypted data, which is encrypted, by the first computer device, using the symmetric ciphering algorithm and a derived second shared secret key, wherein the second shared secret key is derived by the first computer device using a second elliptic curve Diffie-Hellman key exchange based at least, in part, on the derived module public key; and

(f) decrypting, by the module, the encrypted data using the third set of parameters and the derived second shared secret key.

2. The method of claim 1 , wherein first public key is received upon connecting to the wireless network.

3. The method of claim 1 , wherein between steps (b) and (d), the module further generates a first secure hash of the first public key using the first set of parameters; and the message in step (d) comprises the first secure hash.

4. The method of claim 3 , wherein the first secure hash utilizes a SHA-256 hash algorithm.

5. The method of claim 1 , wherein after step (f), the module further generates a first secure hash of the module public key using the first set of parameters; and the encrypted data comprises the first secure hash.

6. The method of claim 5 , wherein the first secure hash utilizes a SHA-256 hash algorithm.

7. The method of claim 1 , wherein the first computing device is a server.

8. The method of claim 1 , wherein a symmetric ciphering key is derived using at least the first shared secret key and a first random number.

9. The method of claim 8 , wherein the symmetric ciphering key is derived also using the second shared secret key and a second random number.

10. The method of claim 1 , wherein the method further comprises the steps of:

(g) generating, at the module, a configuration request;

(h) transmitting, from the module to the first computing device, the configuration request; and

(i) receiving, at the module, encrypted configuration information.

11. The method of claim 1 , wherein the memory is nonvolatile memory.

Assignments (4)
CHANGE OF ADDRESS Recorded Sep 10, 2025
From: NETWORK-1 TECHNOLOGIES, INC.
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 072827/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 3, 2018
From: M2M AND IOT TECHNOLOGIES, LLC
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 046551/0630 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2018
From: VOBAL TECHNOLOGIES, LLC
To: JOHN A. NIX
Reel/Frame 046515/0799 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2018
From: NIX, JOHN
To: M2M AND IOT TECHNOLOGIES, LLC
Reel/Frame 046497/0428 →
Continuity (3)
Continuation 15043293 · Feb 12, 2016
Continuation 14039401 · Sep 27, 2013
Related Publication 20180270059A1 · Sep 20, 2018
Cited By (1)
US 12,309,129