IP Library › Patent Application 17055671
Patent Application
App. No. 17/055,671

INTERNET OF THINGS SECURITY WITH MULTI-PARTY COMPUTATION (MPC)

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/055,671
Abstract

A method and device for establishing a communication along a communications channel between a first device ( 200 A) and a second device ( 200 B) is disclosed. The method comprises mutually discovering the first device ( 200 A) and the second device ( 200 B), validating (F 5 , F 6 , F 7 ) the communications channel between the first device ( 200 A) and the second device ( 200 B) by exchange of data messages, exchanging a secret between the first device ( 200 A) and the second device ( 200 B) and then exchanging encrypted messages along the communications channel.

Claims (29)

1 . A method for establishing a communication using encrypted messages along a communications channel between a first device and a second device comprising:

mutually discovering the first device and the second device;

validating the communications channel by establishing secret session keys for the communications channel between the first device and the second device;

calculating a first authentication string (SAS) in the first device and a second authentication string (SA) in the second device;

inserting the first calculated SAS in a first MPC module of the first device and the second calculated SAS in a second MPC module of the second device and confirming security of the communications channel by evaluating the first SAS in the second MPC module of the second device and the second SAS in the first MPC module of the first device;

establishing, in the event of the confirmation of the security of the communications channel, a shared secret between the first device and the second device using the exchanged secret session key; and

exchanging the encrypted messages along the communications channel.

2 . The method of claim 1 , wherein the mutual discovering comprises providing identifiers between the first device and the second device.

3 . The method of claim 2 , wherein the providing of an identifier between the first device and the second device comprising exchanging initiation and acknowledgement messages between the first device and the second device, the initiation and acknowledgement messages include the identifiers.

4 . The method of claim 2 , wherein the identifiers are provided by generating a random number identification of at least one of the first device and the second device.

5 . The method of claim 2 , wherein the providing identifiers comprising receiving identifiers of the first device and the second device from a server.

6 . The method of claim 1 , wherein the validating comprises a first key exchange from the first device to the second device and a second key exchange from the second device to the first device.

7 . The method of claim 1 , further comprising sending a confirm message from the first device to the second device and a confirm message from the second device to the first device after successful comparison of the exchanged messages.

8 . The method of claim 7 , wherein a first secret key in the first key exchange is generated from a previous first secret key and a second secret key in the second key exchange is generated from a previous second secret key.

9 . The method of claim 1 , wherein the validating of the communications channel is carried out before exchanging every message along the communications channel.

10 . The method of claim 1 , wherein the validating of the communications channel is carried out only after exchanging a number of messages along the communications channel.

11 . The method of claim 1 , wherein the mutual discovery of the first device and the second device is carried out by automatic exchange of messages between the first device and the second device by one of a direct communication or using a server.

12 . A use of the method of claim 1 in a network comprising a plurality of IoT devices, including those on moving vehicles, or a plurality of VoIP devices.

13 . A network comprising a plurality of devices, wherein the plurality of devices comprise:

a transmitter for transmitting messages along a communications channel to one or more of the other ones of the plurality of devices;

a receiver for receiving messages from the communications channel from one or more of the other ones of the plurality of devices;

an identifier file for storing a session key;

a multi-party computation module for receiving an authentication string (SAS) from one of the plurality of devices over a communications channel and confirming the security of the communications channel; and

a communications module for encrypting and decrypting messages to and from the communications channel using the session key.

14 . The network of claim 13 , wherein the multi-party computation module is adapted to have a first authentication string and to receive a second authentication string from one of the other ones of the plurality of devices, and thereby confirming the security of the communications channel.

15 . The network of claim 13 , wherein the devices further comprise a storage for storing a plurality of session keys.

16 . The network of claim 13 , wherein the devices further comprises a pseudo random number generator for generating an identifier identifying the devices.

17 . The network of claim 13 further comprising a server for providing the devices with an identifier of another one of the devices.

18 . The network of claim 13 , wherein the plurality of devices are devices in an IoT network, an autonomous vehicle network or VoIP devices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2023
From: VIEIRA SOUSA, PATRÍCIA RAQUEL; MAIA SOARES DE RESENDE, JOÃO MIGUEL; DA SILVA MARTINS, ROLANDO; COELHO ANTUNES, LUÍS FILIPE
To: INESC TEC - INSTITUTO DE ENGENHARIA DESISTEMAS E COMPUTADORES, TECNOLOGIA E CIÊNCIA
Reel/Frame 062506/0304 →