IP Library › Granted Patent US 10,659,444
Granted Patent B2
US 10,659,444 · App. 16/586,839 · Granted May 19, 2020

Network-based key distribution system, method, and apparatus

Inventors: Bimal I. Gandhi (Chatham, NJ); Nishant Kaushik (Jersey City, NJ); Tejas Digambar Limaye (Pune, IN)
Assignee: Uniken, Inc.
H04L63/062H04L41/046H04L41/28H04L63/0435H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,659,444
App. No.
16/586,839
Granted
May 19, 2020
Kind
B2
Abstract

A method includes executing a mobile threat detection function to determine whether an electronic device is corrupt. The method also includes when determining that the electronic device is not corrupt, identifying whether an encrypted user key (UK c -Enc) is stored in the electronic device. The method further includes when the UK c -Enc is not stored in the electronic device, decrypting an application key (AK c ) and transmitting the AK c and a unique universal identifier (UUID) that is associated with the application to a gateway for establishing a secure application specific communication channel between the electronic device and the gateway. In addition, the method includes when the UK c -Enc is stored in the electronic device, decrypting the UK c -Enc to form a user key (UK c ), extracting a UUID from the UK c , and transmitting the UUID from the UK c to the gateway for establishing the secure application specific communication channel between the electronic device and the gateway.

Claims (34)

1. An electronic device comprising:

a memory storing an application containing a client file; and

at least one processor that, when executing one or more network-based key distribution operations, is configured to:

execute a mobile threat detection (MTD) function to determine whether the electronic device is corrupt,

when determining that the electronic device is not corrupt, transmit a verification message to a gateway indicating that the electronic device is not corrupt and identify whether an encrypted user key (UK c -Enc) is stored in the electronic device,

when the UK c -Enc is not stored in the electronic device, decrypt an application key (AK c ) and transmit the AK c and a unique universal identifier (UUID) that is associated with the application to the gateway for establishing a secure application specific communication channel between the electronic device and the gateway, and

when the UK c -Enc is stored in the electronic device, decrypt the UK c -Enc to form a user key (UK c ), extract a UUID from the UK c , and transmit the UUID from the UK c to the gateway for establishing the secure application specific communication channel between the electronic device and the gateway.

2. The electronic device of claim 1 , wherein the application is previously stored in the memory of the electronic device.

3. The electronic device of claim 1 , wherein the at least one processor is further configured to transmit electronic data to the electronic device using the secure application specific communication channel.

4. The electronic device of claim 3 , wherein the electronic data comprises one or more parameters of the electronic device, and wherein after transmitting the one or more parameters of the electronic device to the gateway, the at least one processor is further configured to receive an indication that an application session with the gateway is established using the secure application specific communication channel.

5. The electronic device of claim 1 , wherein the at least one processor is further configured to transmit electronic data to the gateway after performing a self-registration protocol.

6. The electronic device of claim 1 , wherein the at least one processor is further configured to receive an indication that an application session has been established with the gateway when the at least one processor has transmitted a username to the gateway that is unique to the application and the electronic device.

7. A method implemented by at least one processor of an electronic device, the method comprising:

executing, by the at least one processor, a mobile threat detection (MTD) function to determine whether the electronic device is corrupt;

when determining that the electronic device is not corrupt, directing, by the at least one processor, a transmission of a verification message to a gateway indicating that the electronic device is not corrupt and identifying, by the at least one processor, whether an encrypted user key (UK c -Enc) is stored in the electronic device;

when the UK c -Enc is not stored in the electronic device, decrypting, by the at least one processor, an application key (AK c ) and transmitting, by the at least one processor, the AK c and a unique universal identifier (UUID) that is associated with the application to the gateway for establishing a secure application specific communication channel between the electronic device and the gateway; and

when the UK c -Enc is stored in the electronic device, decrypting, by the at least one processor, the UK c -Enc to form a user key (UK c ), extracting, by the at least one processor, a UUID from the UK c , and transmitting, by the at least one processor, the UUID from the UK c to the gateway for establishing the secure application specific communication channel between the electronic device and the gateway.

8. The method of claim 7 , wherein the electronic device comprises an application that was previously stored in a memory of the electronic device.

9. The method of claim 7 , further comprising receiving, by the at least one processor, electronic data from the gateway using the secure application specific communication channel.

10. The method of claim 9 , wherein the electronic data comprises one or more parameters of the electronic device.

11. The method of claim 10 , wherein after transmitting, by the at least one processor, the one or more parameters to the gateway, receiving, by the at least one processor, an indication that an application session with the gateway is established using the secure application specific communication channel.

12. The method of claim 7 , wherein the method further comprises transmitting, by the at least one processor, electronic data after the electronic device has performed a self-registration protocol.

13. The method of claim 7 , wherein the method further comprises receiving, by the at least one processor, an indication that an application session with the gateway has been established when a username that is unique to the application and the electronic device is transmitted to the gateway.

14. A non-transitory, computer-readable storage medium of an electronic device storing one or more executable instructions that, when executed by at least one processor, cause the at least one processor to:

execute a mobile threat detection (MTD) function to determine whether the electronic device is corrupt;

when determining that the electronic device is not corrupt, transmit a verification message to a gateway indicating that the electronic device is not corrupt and identify whether an encrypted user key (UK c -Enc) is stored in the electronic device;

when the UK c -Enc is not stored in the electronic device, decrypt an application key (AK c ) and transmit the AK c and a unique universal identifier (UUID) that is associated with the application to the gateway for establishing a secure application specific communication channel between the electronic device and the gateway; and

when the UK c -Enc is stored in the electronic device, decrypt the UK c -Enc to form a user key (UK c ), extract a UUID from the UK c , and transmit the UUID from the UK c to the gateway for establishing the secure application specific communication channel between the electronic device and the gateway.

15. The non-transitory, computer-readable storage medium of claim 14 , wherein the one or more executable instructions are stored in an application that was previously stored in the non-transitory, computer-readable storage medium of the electronic device.

16. The non-transitory, computer-readable storage medium of claim 14 , wherein the one or more executable instructions, when executed by the at least one processor, further cause the at least one processor to receive electronic data from the gateway using the secure application specific communication channel.

17. The non-transitory, computer-readable storage medium of claim 16 , wherein the electronic data comprises one or more parameters of the electronic device.

18. The non-transitory, computer-readable storage medium of claim 17 , wherein after transmitting the one or more parameters of the electronic device to the gateway, the one or more executable instructions, when executed by the at least one processor, further cause the at least one processor to receive an indication that an application session has been generated with the gateway using the secure application specific communication channel.

19. The non-transitory, computer-readable storage medium of claim 14 , wherein the one or more executable instructions, when executed by the at least one processor, further cause the at least one processor to transmit electronic data to the gateway after the electronic device has performed a self-registration protocol.

20. The non-transitory, computer-readable storage medium of claim 14 , wherein the one or more executable instructions, when executed by the at least one processor, further cause the at least one processor to receive an indication that an application session with the gateway has been generated when a username that is unique to the application and the electronic device is transmitted to the gateway.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2019
From: GANDHI, BIMAL I.; KAUSHIK, NISHANT; LIMAYE, TEJAS DIGAMBAR
To: UNIKEN, INC.
Reel/Frame 050762/0976 →
Continuity (6)
Continuation In Part 16156836 · Oct 10, 2018
Continuation In Part 16018775 · Jun 26, 2018
Continuation In Part 16018885 · Jun 26, 2018
Provisional Application 62525351 · Jun 27, 2017
Provisional Application 62525348 · Jun 27, 2017
Related Publication 20200028836A1 · Jan 23, 2020