IP Library Granted Patent US 11,153,344
Granted Patent B2
US 11,153,344 · App. 16/568,597 · Granted Oct 19, 2021

Establishing a protected communication channel

Inventor: Richard Hayton (Cambridge, GB)
Assignee: TRUSTONIC LIMITED
H04L63/18H04L9/0643H04L9/0827H04L9/0866H04L9/0869H04L63/0435H04L63/0442
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,344
App. No.
16/568,597
Granted
Oct 19, 2021
Kind
B2
Abstract

To establish a first protected communication channel between a device D and a first server S, a symmetric key K S is derived at the device D, based on a device identifying key K D and public key information dependent on a first server public key S public of the first server S. The symmetric key K S is derived in a corresponding way at a second server T. The symmetric key K S is transmitted from the second server T to the first server S on a second protected communication channel. Communication on the first protected communication channel between the device D and the first server S is protected using a communication key K C which is dependent on the symmetric key K S . This can enable a device D lacking support for asymmetric key cryptography to securely enter into communication with the first server S.

Claims (36)

1. A method for establishing a first protected communication channel between a device and a first server, the first server having a first server public key, and the device having a device identifying key shared with a second server different from the first server, the method comprising:

deriving a symmetric key at the device, based on the device identifying key and public key information dependent on the first server public key;

sending, by the device, a payload message to the first server on the first protected communication channel protected using a communication key which is dependent on the symmetric key;

in response to the payload message, the first server sends a key generation request to the second server to trigger the second server to derive the symmetric key and transmit the symmetric key to the first server on a second protected communication channel;

deriving the symmetric key at the second server, based on the device identifying key and the public key information; and

transmitting the symmetric key from the second server to the first server using the second protected communication channel.

2. The method of claim 1 , in which the second protected communication channel is protected using a public key infrastructure based on asymmetric keys.

3. The method of claim 2 , in which the asymmetric keys for the public key infrastructure comprise said first server public key and a first server private key.

4. The method of claim 1 , in which the communication key is the same as the symmetric key.

5. The method of claim 1 , in which the communication key is derived from the symmetric key based on information shared between the device and the first server.

6. The method of claim 5 , in which the information shared between the device and the first server comprises at least one of:

a class key associated with a class of devices including the device; and

a random or pseudorandom value.

7. The method of claim 1 , in which the public key information is the same as the first server public key.

8. The method of claim 1 , in which the public key information comprises a hash of the first server public key, and has fewer bits than the first server public key.

9. The method of claim 1 , in which the device is incapable of generation of asymmetric keys for supporting a public key infrastructure.

10. The method of claim 1 , in which the payload message and the key generation request each specify a device identifier of the device.

11. At least one non-transitory, computer-readable storage medium storing one or more computer programs, which when executed by one or more data processors in a device, a first server, and a second server different from the first server, cause the one or more data processors to establish a first protected communication channel between the device and the first server, where the first server has a first server public key and the device has a device identifying key shared with the second server by:

deriving a symmetric key at the device, based on the device identifying key and public key information dependent on the first server public key;

sending, by the device, a payload message to the first server on the first protected communication channel protected using a communication key which is dependent on the symmetric key;

in response to the payload message, the first server sending a key generation request to the second server to trigger the second server to derive the symmetric key and transmit the symmetric key to the first server on a second protected communication channel;

deriving the symmetric key at the second server, based on the device identifying key and the public key information; and

transmitting the symmetric key from the second server to the first server using the second protected communication channel.

12. A system comprising:

a device;

a first server; and

a second server different from the first server,

each of the device, the first server, and the second server comprising:

corresponding processing circuitry to perform data processing; and

data storage,

wherein each data storage stores one or more computer programs for controlling corresponding processing circuitry to establish a first protected communication channel between the device and the first server, the first server having a first server public key, and the device having a device identifying key shared with the second server by:

deriving a symmetric key at the device, based on the device identifying key and public key information dependent on the first server public key;

sending, by the device, a payload message to the first server on the first protected communication channel protected using a communication key which is dependent on the symmetric key;

in response to the payload message, the first server sends a key generation request to the second server to trigger the second server to derive the symmetric key and transmit the symmetric key to the first server on a second protected communication channel;

deriving the symmetric key at the second server, based on the device identifying key and the public key information; and

transmitting the symmetric key from the second server to the first server using the second protected communication channel.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2026
From: TT SECURE PLATFORM LIMITED
To: QUALCOMM TECHNOLOGIES, INC.
Reel/Frame 075332/0723 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2026
From: TRUSTONIC LIMITED
To: TT SECURE PLATFORM LIMITED
Reel/Frame 075325/0627 →
CHANGE OF ASSIGNEE ADDRESS Recorded Apr 14, 2023
From: TRUSTONIC LIMITED
To: TRUSTONIC LIMITED
Reel/Frame 064025/0775 →
CHANGE OF ASSIGNEE ADDRESS Recorded Nov 3, 2020
From: TRUSTONIC LIMITED
To: TRUSTONIC LIMITED
Reel/Frame 054283/0428 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2019
From: HAYTON, RICHARD
To: TRUSTONIC LIMITED
Reel/Frame 050355/0627 →
Priority Claims (1)
GB 1815092 · Sep 17, 2018 · national
Continuity (1)
Related Publication 20200092330A1 · Mar 19, 2020
Cited By (7)
US 12,261,838 US 12,301,563 US 12,309,262 US 12,368,580 US 12,463,802 US 12,470,372 US 12,476,793