IP Library Granted Patent US 12,278,817
Granted Patent B1
US 12,278,817 · App. 17/347,990 · Granted Apr 15, 2025

Methods, mediums, and systems for verifying devices in an encrypted messaging system

Inventors: Abhinav Raj (San Mateo, CA); Maaz Ali (Redwood City, CA); Evan Christopher DeVrieze (Redwood City, CA)
Assignee: WhatsApp LLC
H04L63/101G06K19/06037H04L9/3247H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,278,817
App. No.
17/347,990
Granted
Apr 15, 2025
Kind
B1
Abstract

This application describes methods, mediums, and systems for verifying a device for use in a messaging system. Using the device verification procedures described, a messaging system can securely authorize new devices to send and receive encrypted messages on behalf of a user, preferably without the need to share a private encryption key between the users' different devices. The application describes several techniques that can be used to provide such a system, including distributing a computer-perceptible code that encodes encryption information between a secondary device and a primary device. This allows the information to be distributed without intervention by a server. Other techniques provide unique ways to build and reverify authorized device lists, distribute encryption keys in chat channels, ensure that lists of authorized devices are distributed in the correct order and remain valid for an appropriate amount of time, add new devices to an ongoing or new conversation, and more.

Claims (40)

1. A method, comprising:

receiving, at a primary device associated with a user in an encrypted messaging system, a computer-perceptible code from a secondary device;

retrieving a reference and an identifier of the secondary device from the computer-perceptible code, the reference configured to identify a location of the secondary device in the encrypted messaging system;

generating, at the primary device, a secondary device signature based on the identifier of the secondary device;

encrypting, using a secret pairing key, a payload including a list of authorized devices of the user and the secondary device signature;

generating a request, including the encrypted payload and the reference, to add the secondary device to the list of authorized devices of the user, the request configured to identify the secondary device to a server of the encrypted messaging system based on the reference; and

transmitting the request to the server, wherein an encrypted session is established between the primary device and the secondary device based on a validation of the request at the secondary device using the identifier of the secondary device.

2. The method of claim 1 , wherein the encrypted messaging system is represented as a set of interconnected nodes representing messaging servers, and the reference identifies a specific node to which the secondary device is connected.

3. The method of claim 1 , wherein the computer-perceptible code further comprises the identifier for the secondary device, and the request is further configured to add the identifier of the secondary device to the list of authorized devices.

4. The method of claim 1 , further comprising generating a signature based on a list of currently authorized devices known to the primary device, wherein the request further comprises the signature.

5. The method of claim 4 , further comprising extracting the secret pairing key from the computer-perceptible code, wherein the signature based on the list of currently authorized devices is encrypted with the secret pairing key.

6. The method of claim 1 , wherein the primary device is the only device associated with the user that is authorized to generate requests to add additional devices to the list of authorized devices.

7. The method of claim 1 , wherein the primary device does not receive identifying information about the secondary device from the server.

8. A non-transitory computer-readable medium storing instructions configured to cause a processor to:

receive, at a primary device associated with a user in an encrypted messaging system, a computer-perceptible code from a secondary device;

retrieve a reference and an identifier of the secondary device from the computer-perceptible code, the reference configured to identify a location of the secondary device in the encrypted messaging system;

generate, at the primary device, a secondary device signature based on the identifier of the secondary device;

encrypt, using a secret pairing key, a payload including a list of authorized devices of the user and the secondary device signature;

generate a request, including the encrypted payload and the reference, to add the secondary device to the list of authorized devices of the user, the request configured to identify the secondary device to a server of the encrypted messaging system based on the reference; and

transmit the request to the server, wherein an encrypted session is established between the primary device and the secondary device based on a validation of the request at the secondary device using the identifier of the secondary device.

9. The non-transitory computer-readable medium of claim 8 , wherein the encrypted messaging system is represented as a set of interconnected nodes representing messaging servers, and the reference identifies a specific node to which the secondary device is connected.

10. The non-transitory computer-readable medium of claim 8 , wherein the computer-perceptible code further comprises the identifier for the secondary device, and the request is further configured to add the identifier of the secondary device to the list of authorized devices.

11. The non-transitory computer-readable medium of claim 8 , further storing instructions configured to cause the processor to generate a signature based on a list of currently authorized devices known to the primary device, wherein the request further comprises the signature.

12. The non-transitory computer-readable medium of claim 11 , further storing instructions configured to cause the processor to extract the secret pairing key from the computer-perceptible code, wherein the signature based on the list of currently authorized devices is encrypted with the secret pairing key.

13. The non-transitory computer-readable medium of claim 8 , wherein the primary device is the only device associated with the user that is authorized to generate requests to add additional devices to the list of authorized devices.

14. The non-transitory computer-readable medium of claim 8 , wherein the primary device does not receive identifying information about the secondary device from the server.

15. An apparatus, comprising:

a processor; and

a non-transitory computer-readable medium storing instructions configured to cause the processor to:

receive, at a primary device associated with a user in an encrypted messaging system, a computer-perceptible code from a secondary device;

retrieve a reference and an identifier of the secondary device from the computer-perceptible code, the reference configured to identify a location of the secondary device in the encrypted messaging system;

generate, at the primary device, a secondary device signature based on the identifier of the secondary device;

encrypt, using a secret pairing key, a payload including a list of authorized devices of the user and the secondary device signature;

generate a request, including the encrypted payload and the reference, to add the secondary device to the list of authorized devices of the user, the request configured to identify the secondary device to a server of the encrypted messaging system based on the reference; and

transmit the request to the server, wherein an encrypted session is established between the primary device and the secondary device based on a validation of the request at the secondary device using the identifier of the secondary device.

16. The apparatus of claim 15 , wherein the encrypted messaging system is represented as a set of interconnected nodes representing messaging servers, and the reference identifies a specific node to which the secondary device is connected.

17. The apparatus of claim 15 , wherein the computer-perceptible code further comprises the identifier for the secondary device, and the request is further configured to add the identifier of the secondary device to the list of authorized devices.

18. The apparatus of claim 15 , wherein the medium further stores instructions configured to cause the processor to generate a signature based on a list of currently authorized devices known to the primary device, wherein the request further comprises the signature.

19. The apparatus of claim 18 , wherein the medium further stores instructions configured to cause the processor to extract the secret pairing key from the computer-perceptible code, wherein the signature based on the list of currently authorized devices is encrypted with the secret pairing key.

20. The apparatus of claim 15 , wherein the primary device is the only device associated with the user that is authorized to generate requests to add additional devices to the list of authorized devices.

Assignments (2)
CHANGE OF NAME Recorded Oct 11, 2022
From: WHATSAPP INC.
To: WHATSAPP LLC
Reel/Frame 061645/0045 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2021
From: RAJ, ABHINAV; ALI, MAAZ; DEVRIEZE, EVAN CHRISTOPHER
To: WHATSAPP INC.
Reel/Frame 058108/0212 →
References Cited (24)
US 9282181B2 · Antos et al. · 2016 [cited by applicant]
US 9673973B1 · Leavy et al. · 2017 [cited by applicant]
US 10158489B2 · Shastri et al. · 2018 [cited by applicant]
US 11070980B1 · Hohler · 2021 [cited by examiner]
US 11128478B2 · Galdo · 2021 [cited by examiner]
US 20140045472A1 · Sharma · 2014 [cited by examiner]
US 20140059351A1 · Braskich et al. · 2014 [cited by applicant]
US 20150085848A1 · Reunamaki et al. · 2015 [cited by applicant]
US 20160066183A1 · Conant et al. · 2016 [cited by applicant]
US 20160360407A1 · Benoit et al. · 2016 [cited by applicant]
US 20170012950A1 · Kim et al. · 2017 [cited by applicant]
US 20170195339A1 · Brown · 2017 [cited by applicant]
US 20170201380A1 · Schaap · 2017 [cited by examiner]
US 20180026787A1 · Le Saint · 2018 [cited by examiner]
US 20190239068A1 · Mudulodu et al. · 2019 [cited by applicant]
US 20190296969A1 · Zimny et al. · 2019 [cited by applicant]
US 20200045022A1 · Liu · 2020 [cited by examiner]
US 20200104081A1 · Miyake · 2020 [cited by applicant]
US 20200187007A1 · Engelen · 2020 [cited by examiner]
US 20210350446A1 · D'Haenens et al. · 2021 [cited by applicant]
EP 3451754A1 · 2019 [cited by examiner]
EP 3451754B1 · 2021 [cited by examiner]
WO 2019136107A1 · 2019 [cited by applicant]
EPO—International Search report and Written Opinion for International Application No. PCT/US2022/033160, mailed Oct. 12, 2022, 9 pages. [cited by applicant]
Cited By (1)
US 12,526,142