IP Library Granted Patent US 11,283,603
Granted Patent B2
US 11,283,603 · App. 16/843,107 · Granted Mar 22, 2022

Set of servers for “machine-to-machine” communications using public key infrastructure

Inventor: John A. Nix (Evanston, IL)
Assignee: Network-1 Technologies, Inc.
H04L9/0861G06F21/35G06F21/445H04J11/00H04L9/006H04L9/085H04L9/088H04L9/0816H04L9/0841H04L9/0894H04L9/14H04L9/30H04L9/3066H04L9/32H04L9/321H04L9/3239H04L9/3247H04L9/3249H04L9/3263H04L12/2854H04L63/0272H04L63/045H04L63/0435H04L63/0442H04L63/061H04L63/0807H04L63/123H04L63/166H04L67/04H04W4/70H04W8/082H04W12/02H04W12/033H04W12/04H04W12/06H04W12/40H04W40/005H04W52/0216H04W52/0235H04W52/0277H04W76/27H04W80/04H05K999/99G06F2221/2105G06F2221/2107G06F2221/2115H04L63/0464H04L2209/24H04L2209/72H04L2209/805H04W84/12H04W88/12Y02D30/70
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,283,603
App. No.
16/843,107
Granted
Mar 22, 2022
Kind
B2
Abstract

A set of servers can support secure and efficient “Machine to Machine” communications using an application interface and a module controller. The set of servers can record data for a plurality of modules in a shared module database. The set of servers can (i) access the Internet to communicate with a module using a module identity, (i) receive server instructions, and (iii) send module instructions. Data can be encrypted and decrypted using a set of cryptographic algorithms and a set of cryptographic parameters. The set of servers can (i) receive a module public key with a module identity, (ii) authenticate the module public key, and (iii) receive a subsequent series of module public keys derived by the module with a module identity. The application interface can use a first server private key and the module controller can use a second server private key.

Claims (59)

1. A method for secure communications between a client and a computer system including at least a first server, comprising:

(a) recording, by the computer system:

(i) a first server private key associated with the first server for a digital signature algorithm, where the first server private key corresponds to a first server public key associated with the first server; and

(ii) a server certificate, associated with the first server public key, signed by a certificate authority separate from the computer system;

(b) receiving, by the computer system, a first message from the client, the first message including a device public key;

(c) generating, by the computer system:

(i) a response for the client, and

(ii) a second server private key and a corresponding second server public key associated with the first server;

(d) digitally signing, by the computer system, the response with a digital signature using the first server private key to form a digitally signed response;

(e) generating, by the computer system, a first mutually derived shared key using Elliptic Curve Diffie-Hellman based on at least:

(i) the device public key; and

(ii) the second server private key;

wherein the first mutually derived shared key can be derived by the client based on at least:

(iii) a device private key associated with the device public key; and

(iv) the second server public key associated with the second server private key;

(f) encrypting, by the computer system, using the first mutually derived shared key:

(i) the digitally signed response,

(iii) the digital signature, and

(iii) the server certificate,

to form at least part of a transmission message;

(g) transmitting, from the computer system to the client, the transmission message, wherein the client is enabled to decrypt the transmission message using the mutually derived shared key and verify the digitally signed response;

(h) receiving, by the computer system, a second message comprising first data to derive a second mutually derived shared key;

(i) generating, by the computer system, the second mutually derived shared key using a key derivation function with at least the device public key and the first server public key, wherein the second mutually derived shared key comprises a symmetric ciphering key;

(j) encrypting, by the computer system, second data using the symmetric ciphering key to form at least part of server encrypted data; and

(k) transmitting, by the computer system to the client, the server encrypted data in order to allow secure transfer of data between the client and the computer system.

2. The method of claim 1 ,

wherein the client comprises a wireless handset.

3. The method of claim 1 ,

wherein the client comprises a mobile phone handset.

4. The method of claim 1 ,

wherein the client comprises a tablet computer.

5. The method of claim 1 ,

wherein the client comprises a laptop computer.

6. The method of claim 1 ,

wherein the client comprises a payment terminal.

7. The method of claim 1 ,

wherein the client comprises a tracking device.

8. The method of claim 1 ,

wherein the client comprises a circuit board with a radio.

9. The method of claim 1 ,

wherein the computer system comprises a radio.

10. The method of claim 1 ,

wherein the computer system is operatively connected to a radio.

11. The method of claim 1 ,

wherein the computer system communicates with the client via a wireless network.

12. The method of claim 11 ,

wherein the wireless network is a WiFi network.

13. The method of claim 11 ,

wherein the wireless network is a wireless wide area network.

14. The method of claim 11 ,

wherein the wireless network uses a Long Term Evolution Protocol.

15. The method of claim 11 ,

wherein the wireless network uses a Long Term Evolution Advanced Protocol.

16. The method of claim 11 ,

wherein the wireless network uses the Enhanced Data rates for GSM Evolution standard.

17. The method of claim 11 ,

wherein the wireless network communicates using internet protocols.

18. The method of claim 11 ,

wherein the wireless network communicates using IP packets.

Assignments (4)
CHANGE OF ADDRESS Recorded Sep 10, 2025
From: NETWORK-1 TECHNOLOGIES, INC.
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 072827/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2021
From: M2M AND IOT TECHNOLOGIES, LLC
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 055914/0890 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2021
From: VOBAL TECHNOLOGIES, LLC
To: NIX, JOHN A.
Reel/Frame 055795/0719 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2020
From: NIX, JOHN
To: M2M AND IOT TECHNOLOGIES, LLC
Reel/Frame 053046/0751 →
Continuity (5)
Continuation 15972914 · May 7, 2018
Continuation 15457700 · Mar 13, 2017
Continuation 14789255 · Jul 1, 2015
Continuation 14064618 · Oct 28, 2013
Related Publication 20200235923A1 · Jul 23, 2020
Cited By (1)
US 12,355,872