IP Library Granted Patent US 11,240,212
Granted Patent B2
US 11,240,212 · App. 16/826,363 · Granted Feb 1, 2022

Content security at service layer

Inventors: Vinod Kumar Choyi (Conshohocken, PA); Yogendra C. Shah (Exton, PA); Dale N. Seed (Allentown, PA); Michael F. Starsinic (Newtown, PA); Shamim Akbar Rahman (Cote St. Luc, CA); Quang Ly (North Wales, PA); Zhuo Chen (Claymont, DE); William Robert Flynn, IV (Schwenksville, PA)
Assignee: Convida Wireless, LLC
H04L63/0435H04L63/0823H04L63/101H04W12/06H04W12/069H04W12/08H04W12/086H04L63/061H04W4/70
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,240,212
App. No.
16/826,363
Granted
Feb 1, 2022
Kind
B2
Abstract

Existing approaches to security within network, for instance oneM2M networks, are limited. For example, content might only be protected while the content is in transit between entities that trust each other. Here, the integrity and the confidentiality of content in an M2M network are protected. Such content may be “at rest,” such that the content is stored at a hosting node. Only authorized entities may store and retrieve the data that is stored at the hosting node, and the data may be protected from a confidentiality perspective and an integrity perspective.

Claims (20)

1. An apparatus comprising a processor, a memory, and communication circuitry, the apparatus being connected to a network via its communication circuitry, the apparatus further comprising computer-executable instructions stored in the memory of the apparatus which, when executed by the processor of the apparatus, cause the apparatus to perform operations comprising:

receiving, from a device, a first request for one or more credentials that encrypt or integrity protect application content when stored at rest on a hosting common services entity, the request based on one or more security parameters associated with the application content; and

sending, based on the request and to the device, the one or more credentials to cause:

encrypting or integrity protecting the application content, and

sending, by the device to the hosting common services entity, a second request to create a resource that stores the encrypted or integrity protected content.

2. The apparatus as recited in claim 1 , wherein the one or more credentials comprise a master key for symmetric key confidentiality protection.

3. The apparatus as recited claim 1 , wherein the apparatus is a common service entity, and the credentials are obtained from a trust enablement function.

4. The apparatus as recited in claim 3 , wherein a second application entity that is authorized to obtain the content can obtain the one or more credentials from the trust enablement function or common service entity.

5. The apparatus as recited claim 1 , wherein the apparatus is a trust enablement function.

6. The apparatus as recited in claim 1 , wherein the one or more credentials comprise a credential identifier.

7. A method comprising:

receiving, from a device, a first request for one or more credentials that encrypt or integrity protect application content when stored at rest on a hosting common services entity, the request based on one or more security parameters associated with the application content; and

sending, based on the request and to the device, the one or more credentials to cause:

encrypting or integrity protecting the application content, and

sending, by the device to the hosting common services entity, a second request to create a resource that stores the encrypted or integrity protected content.

8. The method as recited in claim 7 , wherein the one or more credentials comprise a master key for symmetric key confidentiality protection.

9. The method as recited claim 7 , wherein the method is performed by a common service entity, and the credentials are obtained from a trust enablement function or common service entity.

10. The method as recited in claim 9 , wherein a second application entity that is authorized to obtain the content can obtain the one or more credentials from the trust enablement function.

11. The method as recited claim 7 , wherein the method is performed by a trust enablement function.

12. The method as recited in claim 7 , wherein the one or more credentials comprise a credential identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2025
From: CONVIDA WIRELESS,LLC
To: IPLA HOLDINGS INC.
Reel/Frame 073903/0733 →
Continuity (4)
Continuation 15198984 · Jun 30, 2016
Provisional Application 62188141 · Jul 2, 2015
Provisional Application 62248808 · Oct 30, 2015
Related Publication 20200287876A1 · Sep 10, 2020
Cited By (1)
US 12,375,454