IP Library Granted Patent US 11,522,838
Granted Patent B2
US 11,522,838 · App. 17/149,199 · Granted Dec 6, 2022

Secure end-to-end transport through in intermediary nodes

Inventors: Lee R. Boynton (Lake Oswego, OR); Trevor A. Fiatal (Fremont, CA); Scott M. Burke (Mountain View, CA); Mark Sikes (Ben Lomond, CA)
Assignee: Seven Networks, LLC
H04L63/0428H04L9/3226H04L63/029H04L63/0272H04L63/0464H04L63/0471H04L63/08H04L63/0807H04W12/03H04B7/04H04B7/0417H04B7/0617H04L51/58H04L63/0281H04L67/04H04L67/1095H04L67/14H04L69/329H04W4/12H04W12/04H04W52/0261H04W76/10H04W88/06Y02D10/00Y02D30/70
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,522,838
App. No.
17/149,199
Granted
Dec 6, 2022
Kind
B2
Abstract

A communication network encrypts a first portion of a transaction associated with point-to-point communications using a point-to-point encryption key. A second portion of the transaction associated with end-to-end communications is encrypted using an end-to-end encryption key.

Claims (69)

1. A method implemented on a computer, the method comprising:

receiving a token issued by an intermediary server;

encrypting first data of a first data path in a transaction using a first security association; and

transmitting the encrypted first data to the intermediary server, wherein:

the token provides transaction routing information to the intermediary server;

the first data is transmitted to a mobile device by the intermediary server based on the token; and

the intermediary server is coupled to the mobile device over a mobile network.

2. The method of claim 1 , wherein:

the intermediary server provides connectivity between the computer and the mobile device;

the transaction includes control data and payload data;

the control data includes the token;

the mobile device decrypts the first data; and

the method further includes:

encrypting a second data of a second data path using a second security association, wherein the second data path is distinct from the intermediary server; and

transmitting the payload data through the second data path.

3. The method of claim 2 , wherein the mobile device is configured to display the payload data.

4. The method of claim 2 , wherein the token is associated with a registration of a user to the intermediary server.

5. The method of claim 4 , wherein the registration is required prior to transmitting the transaction.

6. The method of claim 4 , wherein the registration comprises authenticating a received username and password by the intermediary server to a user database.

7. The method of claim 2 , wherein at least a portion of the transaction is transmitted over a first connection between the computer and the intermediary server.

8. The method of claim 7 , wherein the intermediary server is configured for:

negotiating a third security association with the mobile device; and

re-encrypting at least the portion of the transaction using the third security association.

9. The method of claim 1 , wherein the mobile device is configured to display the first data.

10. The method of claim 1 , wherein the token is associated with a registration of a user to the intermediary server.

11. The method of claim 10 , wherein the registration is required prior to transmitting the transaction.

12. The method of claim 10 , wherein the registration comprises authenticating a received username and password by the intermediary server to a user database.

13. The method of claim 1 , wherein at least a portion of the transaction is transmitted over a first connection between the computer and the intermediary server.

14. The method of claim 13 , wherein the intermediary server is configured for:

negotiating a second security association with the mobile device; and

re-encrypting at least the portion of the transaction using the second security association.

15. A computer having a processor configured for:

receiving a token issued by an intermediary server;

encrypting first data of a first data path in a transaction using a first security association; and

transmitting the encrypted first data to the intermediary server, wherein:

the token provides transaction routing information to the intermediary server;

the first data is transmitted to a mobile device by the intermediary server based on the token; and

the intermediary server is coupled to the mobile device over a mobile network.

16. The computer of claim 15 , wherein:

the intermediary server provides connectivity between the computer and the mobile device;

the transaction includes control data and payload data;

the control data includes the token;

the mobile device decrypts the first data; and

the processor is further configured for:

encrypting a second data of a second data path using a second security association, wherein the second data path is distinct from the intermediary server; and

transmitting the payload data through the second data path.

17. The computer of claim 16 , wherein the mobile device is configured to display the payload data.

18. The computer of claim 16 , wherein the token is associated with a registration of a user to the intermediary server.

19. The computer of claim 18 , wherein the registration is required prior to transmitting the transaction.

20. The computer of claim 18 , wherein the registration comprises authenticating a received username and password by the intermediary server to a user database.

21. The computer of claim 16 , wherein at least a portion of the transaction is transmitted over a first connection between the computer and the intermediary server.

22. The computer of claim 21 , wherein the intermediary server is configured for:

negotiating a third security association with the mobile device; and

re-encrypting at least a the portion of the transaction using the third security association.

23. The computer of claim 15 , wherein the mobile device is configured to display the first data.

24. The computer of claim 15 , wherein the token is associated with a registration of a user to the intermediary server.

25. The computer of claim 24 , wherein the registration is required prior to transmitting the transaction.

26. The computer of claim 24 , wherein the registration comprises authenticating a received username and password by the intermediary server to a user database.

27. The computer of claim 15 , wherein at least a portion of the transaction is transmitted over a first connection between the computer and the intermediary server.

28. The computer of claim 27 , wherein the intermediary server is configured for:

negotiating a second security association with the mobile device; and

re-encrypting at least the portion of the transaction using the second security association.

29. A non-transitory computer-readable storage medium storing instructions to be implemented by a computer having a processor, wherein the instructions, when executed by the processor, cause the computer to perform steps comprising:

receiving a token issued by an intermediary server;

encrypting first data of a first data path in a transaction using a first security association; and

transmitting the encrypted first data to the intermediary server, wherein:

the token provides transaction routing information to the intermediary server;

the first data is transmitted to a mobile device by the intermediary server based on the token; and

the intermediary server is coupled to the mobile device over a mobile network.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2021
From: BOYNTON, LEE R.; FIATAL, TREVOR A.; BURKE, SCOTT M.; SIKES, MARK
To: SEVEN NETWORKS, INC.
Reel/Frame 054923/0700 →
ENTITY CONVERSION Recorded Jan 14, 2021
From: SEVEN NETWORKS, INC.
To: SEVEN NETWORKS, LLC
Reel/Frame 055000/0663 →