IP Library Granted Patent US 11,122,018
Granted Patent B2
US 11,122,018 · App. 17/218,842 · Granted Sep 14, 2021

Secure end-to-end transport through intermediary nodes

Inventors: Lee R. Boynton (Lake Oswego, OR); Trevor A. Fiatal (Fremont, CA); Scott M. Burke (Mountain View, CA); Mark Sikes (Ben Lomond, CA)
Assignee: Seven Networks, LLC
H04L63/0428H04L9/3226H04L63/029H04L63/0272H04L63/0464H04L63/0471H04L63/08H04L63/0807H04W12/03H04B7/04H04B7/0417H04B7/0617H04L51/38H04L63/0281H04L67/04H04L67/1095H04L67/14H04L69/329H04W4/12H04W12/04H04W52/0261H04W76/10H04W88/06Y02D10/00Y02D30/70
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,122,018
App. No.
17/218,842
Granted
Sep 14, 2021
Kind
B2
Abstract

A communication network encrypts a first portion of a transaction associated with point-to-point communications using a point-to-point encryption key. A second portion of the transaction associated with end-to-end communications is encrypted using an end-to-end encryption key.

Claims (26)

1. A system for processing a transaction, the system having at least one processor configured for:

receiving an identifier sent from a first computer;

issuing a token for the first computer, wherein a first point-to-point security association is negotiated with the first computer and a second point-to-point security association is negotiated with a second computer;

receiving a transaction message from the second computer, the transaction message comprising control data and payload data, wherein:

the control data provides authentication of a source of the transaction and includes the token; and

the token provides transaction routing information; and

transmitting the payload data to the first computer based on the token.

2. The system of claim 1 , wherein the payload data is transmitted to the first computer via one or more intermediary servers.

3. The system of claim 2 , wherein the payload data is encrypted with a security association not known to the intermediary servers.

4. The system of claim 1 , wherein the token is issued to the first computer after authenticating the first computer.

5. The system of claim 1 , wherein the first computer is a mobile device and the second computer is a personal computer.

6. The system of claim 1 , wherein the first computer and the system are coupled over a mobile network that provides an Internet protocol (IP) infrastructure of a wireless service provider.

7. The system of claim 1 , wherein the payload data is decrypted and displayed on the first computer.

8. A method implemented on a system for processing a transaction, the method comprising:

receiving an identifier sent from a first computer;

issuing a token for the first computer, wherein a first point-to-point security association is negotiated with the first computer and a second point-to-point security association is negotiated with a second computer;

receiving a transaction message from the second computer, the transaction message comprising control data and payload data, wherein:

the control data provides authentication of a source of the transaction and includes the token; and

the token provides transaction routing information; and

transmitting the payload data to the first computer based on the token.

9. The method of claim 8 , wherein the payload data is transmitted to the first computer via one or more intermediary servers.

10. The method of claim 9 , wherein the payload data is encrypted with a security association not known to the intermediary servers.

11. The method of claim 8 , wherein the token is issued to the first computer after authenticating the first computer.

12. The method of claim 8 , wherein the first computer is a mobile device and the second computer is a personal computer.

13. The method of claim 8 , wherein the first computer and the system are coupled over a mobile network that provides an Internet protocol (IP) infrastructure of a wireless service provider.

14. The method of claim 8 , wherein the payload data is decrypted and displayed on the first computer.

Assignments (2)
ENTITY CONVERSION Recorded Mar 31, 2021
From: SEVEN NETWORKS, INC.
To: SEVEN NETWORKS, LLC
Reel/Frame 055900/0059 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2021
From: BOYNTON, LEE R.; FIATAL, TREVOR A.; BURKE, SCOTT M.; SIKES, MARK
To: SEVEN NETWORKS, INC.
Reel/Frame 055784/0230 →