IP Library Granted Patent US 11,979,491
Granted Patent B2
US 11,979,491 · App. 17/984,989 · Granted May 7, 2024

Transmission of secure information in a content distribution network

Inventor: Xin Qiu (San Diego, CA)
Assignee: ARRIS Enterprises LLC
H04L9/083H04L9/0866H04L9/321
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,979,491
App. No.
17/984,989
Granted
May 7, 2024
Kind
B2
Abstract

A method and apparatus for providing user key material from a server to a client is disclosed. The method comprises receiving a first message from the client in a server, the first message having a user key material request, an access token and an identifier of a transport key (TrK-ID), validating the user key material request according to the access token, generating a response having user key material responsive to the user key material request, encrypting the response according to the transport key (TrK), and transmitting a second message comprising the response from the server to the client. The client decrypts the second message according to the transport key (TrK) and validates the second message using the identifier of the transport key (TrK-ID).

Claims (88)

1. A method of provisioning user key material from a server to a client, comprising:

(a) receiving a first request from the client by the server, the first request made for user key material that contains (i) an access token to authenticate the client and (ii) an identifier of a transport key (TrK-ID);

(b) authenticating the request for the user key material according to the access token;

(c) generating a response for the provisioning of user key material responsive to the request for the user key material;

(d) encrypting the response for the provisioning of the user key material according to a transport key (TrK) identified by the identifier of the transport key (TrK-ID);

(e) provisioning of key material comprising the encrypted response from the server to the client;

(f) wherein the provisioning of key material is configured to be decrypted according to the transport key (TrK) and the provisioning of key material is configured to be validated using the identifier of the transport key (TrK-ID);

(g) wherein the provisioning of key material further comprises the identifier of the transport key (TrK-ID);

(h) wherein said provisioning of key material is further configured to be decrypted according to the transport key (TrK) to recover a decrypted identifier of the transport key (TrK-ID) and said provisioning of key material is further configured to be validated using the decrypted identifier of the transport key (TrK-ID).

2. The method of claim 1 , wherein the provisioning of key material is further configured to be validated by comparing the decrypted identifier of the transport key (TrK-ID) of the provisioning of key material to the identifier of the transport key (TrK-ID) of the decrypted message.

3. A method of provisioning user key material from a server to a client, comprising:

(a) receiving a first request from the client by the server, the first request made for user key material that contains (i) an access token to authenticate the client and (ii) an identifier of a transport key (TrK-ID);

(b) authenticating the request for the user key material according to the access token;

(c) generating a response for the provisioning of user key material responsive to the request for the user key material;

(d) encrypting the response for the provisioning of the user key material according to a transport key (TrK) identified by the identifier of the transport key (TrK-ID);

(e) provisioning of key material comprising the encrypted response from the server to the client;

(f) wherein the provisioning of key material is configured to be decrypted according to the transport key (TrK) and the provisioning of key material is configured to be validated using the identifier of the transport key (TrK-ID);

(g) wherein the provisioning of key material further comprises the identifier of the transport key (TrK-ID);

(h) the first request further comprises an identifier of an integrity key (InK-ID);

the response further comprises the identifier of the integrity key (InK-ID);

the provisioning of key material further comprises the identifier of the integrity key (InK-ID); and

the provisioning of key material configured to be decrypted according to the transport key (TrK) to further recover a decrypted identifier of the integrity key (InK-ID) and the provisioning of key material configured to use the decrypted identifier of the integrity key (InK-ID) to validate the provisioning of key material.

4. The method of claim 3 , wherein the encrypted response is signed by the integrity key or the transport key and is further validated according to the signed encrypted response.

5. A method of provisioning user key material from a server to a client, comprising:

(a) receiving a first request from the client by the server, the first request made for user key material that contains (i) an access token and (ii) an identifier of a transport key (TrK-ID);

(b) authenticating the request for the user key material according to the access token;

(c) generating a response for the provisioning of user key material responsive to the request for the user key material;

(d) encrypting the response for the provisioning of the user key material according to a transport key (TrK) identified by the identifier of the transport key (TrK-ID);

(e) provisioning of key material comprising the encrypted response from the server to the client;

(f) wherein the provisioning of key material is configured to be decrypted according to the transport key (TrK) and the provisioning of key material is configured to be validated using the identifier of the transport key (TrK-ID);

(g) wherein the identifier of the transport key (TrK-ID) forms a part of a digital certificate certified by a trusted entity, and the provisioning of key material is validated via the digital certificate.

6. The method of claim 5 , wherein the identifier of the transport key (TrK-ID) is stored in tamper-resistant storage of the client device.

7. An apparatus for provisioning user key material from a server to a client, comprising:

a processor;

a memory, the memory communicatively coupled to the processor and storing processor instructions comprising processor instructions for:

(a) receiving a first request from the client by the server, the first request made for user key material the contains (i) an access token and (ii) an identifier of a transport key (TrK-ID);

(b) authenticating the request for the user key material according to the access token;

(c) generating a response for the provisioning of user key material responsive to the request for the user key material;

(d) encrypting the response for the provisioning of the user key material according to a transport key (TrK) identified by the identifier of the transport key (TrK-ID);

(e) provisioning of key material comprising the encrypted response from the server to the client;

(f) wherein the provisioning of key material is configured to be decrypted according to the transport key (TrK) and the provisioning of key material is configured to be validated using the identifier of the transport key (TrK-ID);

(g) wherein the provisioning of key material further comprises the identifier of the transport key (TrK-ID);

(h) wherein said provisioning of key material is further configured to be decrypted according to the transport key (TrK) to recover a decrypted identifier of the transport key (TrK-ID) and said provisioning of key material is further configured to be validated using the decrypted identifier of the transport key (TrK-ID).

8. The apparatus of claim 7 , wherein the provisioning of key material is further configured to be validated by comparing a decrypted identifier of the transport key (TrK-ID) of the provisioning of key material to the identifier of the transport key (TrK-ID) of the decrypted message.

9. An apparatus for provisioning user key material from a server to a client, comprising:

a processor;

a memory, the memory communicatively coupled to the processor and storing processor instructions comprising processor instructions for:

(a) receiving a first request from the client by the server, the first request made for user key material the contains (i) an access token and (ii) an identifier of a transport key (TrK-ID);

(b) authenticating the request for the user key material according to the access token;

(c) generating a response for the provisioning of user key material responsive to the request for the user key material;

(d) encrypting the response for the provisioning of the user key material according to a transport key (TrK) identified by the identifier of the transport key (TrK-ID);

(e) provisioning of key material comprising the encrypted response from the server to the client;

(f) wherein the provisioning of key material is configured to be decrypted according to the transport key (TrK) and the provisioning of key material is configured to be validated using the identifier of the transport key (TrK-ID);

(g) wherein the provisioning of key material further comprises the identifier of the transport key (TrK-ID);

(h) the first request further comprises an identifier of an integrity key (InK-ID);

the response further comprises the identifier of the integrity key (InK-ID);

the provisioning of key material further comprises the identifier of the integrity key (InK-ID); and

the provisioning of key material configured to be decrypted according to the transport key (TrK) to further recover a decrypted identifier of the integrity key (InK-ID) and the provisioning of key material configured to use the decrypted identifier of the integrity key (InK-ID) to validate the provisioning of key material.

10. The apparatus of claim 9 , wherein the encrypted response is signed by the transport key or the integrity key and is further validated according to the signed encrypted response.

11. An apparatus for provisioning user key material from a server to a client, comprising:

a processor;

a memory, the memory communicatively coupled to the processor and storing processor instructions comprising processor instructions for:

(a) receiving a first request from the client by the server, the first request made for user key material the contains (i) an access token and (ii) an identifier of a transport key (TrK-ID);

(b) authenticating the request for the user key material according to the access token;

(c) generating a response for the provisioning of user key material responsive to the request for the user key material;

(d) encrypting the response for the provisioning of the user key material according to a transport key (TrK) identified by the identifier of the transport key (TrK-ID);

(e) provisioning of key material comprising the encrypted response from the server to the client;

(f) wherein the provisioning of key material is configured to be decrypted according to the transport key (TrK) and the provisioning of key material is configured to be validated using the identifier of the transport key (TrK-ID);

(g) wherein the provisioning of key material further comprises the identifier of the transport key (TrK-ID);

(h) wherein the identifier of the transport key (TrK-ID) forms a part of a digital certificate certified by a trusted entity, and the provisioning of key material is validated via the digital certificate.

12. A method of receiving user key material by a client from a server, comprising:

(a) providing a first request by the client to the server, the first request made for user key material that contains (i) an access token and (ii) an identifier of a transport key (TrK-ID);

(b) wherein the first request is configured in a manner such that the user key material request is validated according to the access token;

(c) receiving a provisioning of the user key material by the client from the server comprising an encrypted response;

(d) wherein the encrypted response is encrypted according to a transport key (TrK) identified by the identifier of the transport key (TrK-ID) having user key material responsive to the user key material request;

(e) wherein the encrypted response further comprises the identifier of the transport key (TrK-ID);

(f) decrypting the provisioning of the user key material according to the transport key (TrK);

(g) validating the provisioning of the user key material using the identifier of the transport key (TrK-ID).

13. The method of claim 12 further comprising wherein the identifier of the transport key (TrK-ID) forms a part of a digital certificate certified by a trusted entity, and the provisioning of the user key material is validated via the digital certificate.

14. A method of receiving user key material by a client from a server, comprising:

(a) providing a first request by the client to the server, the first request made for user key material that contains (i) an access token and (ii) an identifier of a transport key (TrK-ID);

(b) wherein the first request is configured in a manner such that the user key material request is validated according to the access token;

(c) receiving a provisioning of the user key material by the client from the server comprising an encrypted response;

(d) wherein the encrypted response is encrypted according to a transport key (TrK) identified by the identifier of the transport key (TrK-ID) having user key material responsive to the user key material request;

(e) decrypting the provisioning of the user key material according to the transport key (TrK);

(f) validating the provisioning of the user key material using the identifier of the transport key (TrK-ID);

(g) wherein the identifier of the transport key (TrK-ID) forms a part of a digital certificate certified by a trusted entity, and the provisioning of the user key material is validated via the digital certificate.

15. The method of claim 14 further comprising wherein the encrypted response further comprises the identifier of the transport key (TrK-ID).

Assignments (2)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
Continuity (3)
Continuation 16953017 · Nov 19, 2020
Provisional Application 62937768 · Nov 19, 2019
Related Publication 20230155814A1 · May 18, 2023