IP Library Granted Patent US 10,979,407
Granted Patent B2
US 10,979,407 · App. 16/309,353 · Granted Apr 13, 2021

Data communications

Inventors: Nigel Stuart Moore (Newbury, GB); Huw Hopkins (Basingstoke, GB)
Assignee: Sony Corporation
H04L63/0478H04L63/045H04L63/0414H04L63/0823H04L63/166H04L63/061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,979,407
App. No.
16/309,353
Granted
Apr 13, 2021
Kind
B2
Abstract

A communications system comprises a client device and a server device; the server device comprising server communication circuitry configured to establish a server-authenticated first encrypted data path between the client device and the server device; and the client device comprising client communication circuitry configured to provide client-specific information to the server device using the first encrypted data path; the server communication circuitry being configured to use the client-specific information provided by the client device to establish a second encrypted data path between the server device and the client device, the second encrypted data path being authenticated by at least the client device.

Claims (49)

1. A communications system comprising:

a client device; and

a server device;

the server device comprising server communication circuitry configured to establish a server-authenticated first encrypted data path between the client device and the server device; and

the client device comprising client communication circuitry configured to provide client-specific information to the server device using the first encrypted data path;

the server communication circuitry being configured to use the client-specific information provided by the client device to establish a second encrypted data path between the server device and the client device, the second encrypted data path being authenticated by at least the client device,

wherein the server communication circuitry is configured to establish the first encrypted data path and the second encrypted data path in response to respective connection initiation messages sent by the client device to the server device,

the connection initiation messages each comprise an indication of a server name mapping to a device with which the client device is requesting connection,

the server device is mapped to at least two server names,

the server communication circuitry is configured to respond to a connection initiation message indicating a first server name to establish the first encrypted data path without requiring the client-specific information, and

the server communication circuitry is configured to respond to a connection initiation message indicating a second server name to establish the second encrypted data path using the client-specific information.

2. The system according to claim 1 , wherein

the server communication circuitry comprises first communication circuitry configured to respond to a connection initiation message indicating the first server name and second communication circuitry configured to respond to a connection initiation message indicating the second server name, in which access by the first communication circuitry to at least parts of the functionality of the server device is inhibited.

3. The system according to claim 1 , wherein the client device is configured to detect a server address in respect of at least the first server name.

4. The system according to claim 3 , wherein the client device is configured, in respect of a connection initiation message indicating the second server name, to use the server address detected in respect of the first server name.

5. The system according to claim 1 , wherein the server communication circuitry is configured to respond to a connection initiation message received from the client device over an unencrypted data path to establish the first encrypted data path, and to respond to a connection initiation message received from the client device over an encrypted data path to establish the second encrypted data path.

6. The system according to claim 1 , wherein the client communication circuitry is configured to respond to a message received from a server device requesting client-specific information to be sent to the server device over an unencrypted data path to decline to send the client-specific information.

7. The system according to claim 1 , wherein the server device is configured to provide a decryption key to the client device by the second encrypted data path.

8. The system according to claim 7 , wherein:

the server device comprises content providing circuitry configured to provide encrypted audio and/or visual content to the client device; and

the client device comprises content decryption circuitry configured to decrypt the encrypted audio and/or visual content using the decryption key.

9. The system according to claim 1 , wherein:

the first encrypted data path is a server-authenticated transport level security (TLS) data path; and

the second encrypted data path is selected from the group consisting of: (i) a client-authenticated transport level security (TLS) data path; and (ii) a mutually-authenticated transport level security (TLS) data path.

10. A client device configured to communicate with a server device, the client device comprising:

communication circuitry configured to initiate establishment of an authenticated first encrypted data path between the client device and the server device, and provide client-specific information to the server device using the first encrypted data path to initiate establishment of a second encrypted data path between the server device and the client device, the second encrypted data path being authenticated by at least the client device,

wherein the communication circuitry is configured to establish the first encrypted data path and the second encrypted data path by sending respective connection initiation messages to the server device,

the connection initiation messages each comprise an indication of a server name mapping to a device with which the client device is requesting connection,

the server device is mapped to at least two server names,

the communication circuitry is configured to send a connection initiation message indicating a first server name to establish the first encrypted data path, and

the communication circuitry is configured to send a connection initiation message indicating a second server name to establish the second encrypted data path.

11. The client device according to claim 10 , in which the communication circuitry is configured to respond to a message received from a server device requesting client-specific information to be sent to the server device over an unencrypted data path to decline to send the client-specific information.

12. The client device according to claim 10 , in which the communication circuitry is configured to respond to a message received from a server device requesting client-specific information to be sent to the server device over an unencrypted data path to display a message requesting user permission to send the client-specific information over the unencrypted data path.

13. A server device configured to communicate with a client device, the server device comprising:

communication circuitry configured to establish a server-authenticated first encrypted data path between the client device and the server device, and to receive client-specific information from the client device using the first encrypted data path;

the communication circuitry being configured to use the client-specific information provided by the client device to establish a second encrypted data path between the server device and the client device, the second encrypted data path being authenticated by at least the client device,

wherein communication circuitry is configured to establish the first encrypted data path and the second encrypted data path in response to respective connection initiation messages sent by the client device to the server device,

the connection initiation messages each comprise an indication of a server name mapping to a device with which the client device is requesting connection,

the server device is mapped to at least two server names,

the communication circuitry is configured to respond to a connection initiation message indicating a first server name to establish the first encrypted data path without requiring the client-specific information, and

the communication circuitry is configured to respond to a connection initiation message indicating a second server name to establish the second encrypted data path using the client-specific information.

14. A method of operation of client device, the method comprising:

initiating, by circuitry, establishment of a server-authenticated first encrypted data path between the client device and a server device; and

providing client-specific information to the server device using the first encrypted data path to initiate establishment of a second encrypted data path between the server device and the client device, the second encrypted data path being authenticated by at least the client device,

wherein the first encrypted data path and the second encrypted data path are established by sending respective connection initiation messages to the server device,

the connection initiation messages each comprise an indication of a server name mapping to a device with which the client device is requesting connection,

the server device is mapped to at least two server names,

a connection initiation message indicating a first server name is sent to establish the first encrypted data path, and

a connection initiation message indicating a second server name is sent to establish the second encrypted data path.

Assignments (4)
CHANGE OF NAME Recorded Nov 1, 2024
From: SONY CORPORATION
To: SONY GROUP CORPORATION
Reel/Frame 069289/0880 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2024
From: SONY GROUP CORPORATION
To: SATURN LICENSING LLC
Reel/Frame 069291/0226 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2020
From: SONY EUROPE LIMITED
To: SONY CORPORATION
Reel/Frame 054730/0954 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2019
From: MOORE, NIGEL STUART; HOPKINS, HUW
To: SONY EUROPE LIMITED
Reel/Frame 048925/0693 →
Priority Claims (1)
GB 1611032 · Jun 24, 2016 · national
Continuity (1)
Related Publication 20190260719A1 · Aug 22, 2019