IP Library Granted Patent US 10,841,106
Granted Patent B1
US 10,841,106 · App. 16/191,872 · Granted Nov 17, 2020

Combined authentication and encryption

Inventors: Bryan D. O'Connor (Atherton, CA); Eugene Fooksman (Menlo Park, CA)
Assignee: WHATSAPP INC.
H04L9/3271H04L9/0819H04L9/0863H04L9/3234H04L9/3297
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,841,106
App. No.
16/191,872
Granted
Nov 17, 2020
Kind
B1
Abstract

A system and methods are provided for establishing an authenticated and encrypted communication connection between two devices with at most two round-trip communications. During establishment of an initial authenticated, encrypted communication connection (or afterward), a first device (e.g., a server) provides the second device (e.g., a client) with a token (e.g., a challenge) that lives or persists beyond the current connection. After that connection is terminated and the second device initiates a new connection, it uses the token as part of the handshaking process to reduce the necessary round-trip communications to one.

Claims (40)

1. A method comprising:

receiving encrypted authentication data from a device;

generating a session key from a first unsolicited token sent to the device during a prior authenticated communication session, wherein the prior authenticated communication connection is terminated prior to receiving the encrypted authentication data; and

acknowledging to the device establishment of a new communication connection as a response to the receiving of the encrypted authentication data, when the encrypted authentication data is decryptable with the session key, or

providing the device with a second token in response to determining that the encrypted authentication data cannot be decrypted with the session key.

2. The method of claim 1 , wherein the encrypted authentication data comprises:

an identifier of a user of the device;

the first unsolicited token or the second token; and

device-specific data.

3. The method of claim 2 , wherein the identifier of the user of the device is a telephone number associated with the user.

4. The method of claim 2 , wherein the device-specific data is a user agent operating on a second device.

5. The method of claim 1 , wherein generating the session key comprises applying a function to the first unsolicited token and to a secret shared between a first device and the second device.

6. The method of claim 5 , wherein the shared secret is a password to an application hosted by the first device and executed on the second device.

7. A non-transitory computer readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to:

receive encrypted authentication data from a device;

generate a session key from a first unsolicited token sent to the device during a prior authenticated communication session, wherein the prior authenticated communication connection is terminated prior to receiving the encrypted authentication data; and

acknowledge to the device establishment of a new communication connection as a response to the receiving of the encrypted authentication data, when the encrypted authentication data is decryptable with the session key, or

provide the device with a second token in response to determining that the encrypted authentication data cannot be decrypted with the session key.

8. The medium of claim 7 , wherein the encrypted authentication data comprises:

an identifier of a user of the device;

the first unsolicited token or the second token; and

device-specific data.

9. The medium of claim 8 , wherein the identifier of the user of the device is a telephone number associated with the user.

10. The medium of claim 8 , wherein the device-specific data is a user agent operating on a second device.

11. The medium of claim 7 , wherein generating the session key comprises applying a function to the first unsolicited token and to a secret shared between a first device and the second device.

12. The medium of claim 11 , wherein the shared secret is a password to an application hosted by the first device and executed on the second device.

13. A system comprising:

a processor; and

memory configured to store instructions that, when executed by the processor, cause the system to:

receive encrypted authentication data from a device;

generate a session key from a first unsolicited token sent to the device during a prior authenticated communication session, wherein the prior authenticated communication connection is terminated prior to receiving the encrypted authentication data; and

acknowledge to the device establishment of a new communication connection as a response to the receiving of the encrypted authentication data, when the encrypted authentication data is decryptable with the session key, or

provide the device with a second token in response to determining that the encrypted authentication data cannot be decrypted with the session key.

14. The system of claim 13 , wherein the encrypted authentication data comprises:

an identifier of a user of the device;

the first unsolicited token or the second token; and

device-specific data.

15. The system of claim 14 , wherein the identifier of the user of the device is a telephone number associated with the user.

16. The system of claim 14 , wherein the device-specific data is a user agent operating on a second device.

17. The system of claim 13 , wherein generating the session key comprises applying a function to the first unsolicited token and to a secret shared between a first device and the second device, wherein the shared secret is a password to an application hosted by the first device and executed on the second device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2022
From: O'CONNOR, BRYAN D.; FOOKSMAN, EUGENE
To: WHATSAPP INC.
Reel/Frame 061762/0234 →
CHANGE OF NAME Recorded Jun 22, 2021
From: WHATSAPP INC.
To: WHATSAPP LLC
Reel/Frame 056646/0001 →
Continuity (3)
Continuation 15804291 · Nov 6, 2017
Continuation 14945649 · Nov 19, 2015
Continuation 14045192 · Oct 3, 2013