IP Library › Granted Patent US 12,206,766
Granted Patent B2
US 12,206,766 · App. 18/099,156 · Granted Jan 21, 2025

Internet of things security with multi-party computation (MPC)

Inventors: João Miguel Maia Soares de Resende (Oporto, PT); Rolando da Silva Martins (Oporto, PT); Luís Filipe Coelho Antunes (Oporto, PT); Patrícia Raquel Vieira Sousa (Oporto, PT)
Assignees: INESC TEC—INSTITUTO DE ENGENHARIA DESISTEMAS E COMPUTADORES, TECNOLOGIA E CIÊNCIA; U.PORTO—UNIVERSIDADE DO PORTO
H04L9/0841G16Y30/10H04L63/0435H04L63/061H04L63/0869H04L67/12G06F7/582H04L2209/46H04L2209/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,206,766
App. No.
18/099,156
Granted
Jan 21, 2025
Kind
B2
Abstract

A method and device for establishing a communication along a communications channel between a first device ( 200 A) and a second device ( 200 B) is disclosed. The method comprises mutually discovering the first device ( 200 A) and the second device ( 200 B), validating (F 5 , F 6 , F 7 ) the communications channel between the first device ( 200 A) and the second device ( 200 B) by exchange of data messages, exchanging a secret between the first device ( 200 A) and the second device ( 200 B) and then exchanging encrypted messages along the communications channel.

Claims (19)

1. An IoT network for establishing a peer-to-peer communication along a communications channel between a plurality of devices, wherein the plurality of devices comprise:

a transmitter for transmitting messages along the communications channel to one or more of the other ones of the plurality of devices;

a receiver for receiving messages from the communications channel from one or more of the other ones of the plurality of devices; and

an identifier file for storing secret session keys computed using symmetric keys for the communications channel between one or more of the other ones of the plurality of devices;

wherein a first device of the plurality of devices comprises a first processor and a first multi-party computation (MPC) module in said first processor, and a second device of the plurality of devices comprises a second processor and a second multi-party computation (MPC) module in said second processor;

the first device is adapted to calculate from the secret session keys a first authentication string (SAS) being a sequence of letters and numbers, and the second device is adapted to calculate from the secret session keys a second authentication string (SAS) being a sequence of letters and numbers, wherein the first device is adapted to receive the second authentication string (SAS) from the second device and the second device is adapted to receive the first authentication string from the first device;

the first multi-party computation (MPC) module in the first device is adapted to automatically validate the second SAS by comparing the second SAS with another SAS generated in the first device;

the second multi-party computation (MPC) module in the second device is adapted to automatically validate the first SAS by comparing the first SAS with another SAS generated in the first device, wherein the first multi-party computation (MPC) module and the second multi-party computation (MPC) module are configured to confirm the security of the communications channel; and

a communications channel between the first device and the second device is configured to exchange the messages between the first device and the second device.

2. The network of claim 1 , wherein the plurality of devices further comprises a storage for storing a plurality of secret session keys.

3. The network of claim 1 , wherein the plurality of devices further comprises a pseudo random number generator for generating an identifier for identifying the devices.

4. The network of claim 1 further comprising a server for providing one of the plurality of devices with an identifier of another one of the plurality of devices.

5. The network of claim 4 , wherein the server is adapted to carry out a mutual discovery of one of the plurality of devices with another one of the plurality of devices by exchanging the identifiers between the plurality of devices.

6. The network of claim 1 , wherein the multi-party computation (MPC) module is adapted to implement an equality function between the first SAS in one of the plurality of devices and a second SAS in one of the plurality of devices.

7. The network of claim 6 , wherein the equality function is adapted to compare a first input value t 1 from one of the plurality of devices with a second input value t 2 of another one of the plurality of devices.

8. The network of claim 7 , wherein the multi-party computation (MPC) module is adapted to return a value S=1 and thereby confirm the security of the communications channel if the first input value t 1 is equal to the second input value t 2 .

9. The network of claim 7 , wherein the multi-party computation (MPC) module is adapted to return the value S=0 if the first input value t 1 is not equal to the second input value t 2 .

10. The network of claim 5 , wherein the multi-party computation (MPC) module is adapted to implement the equality function after every N connection established between the first SAS in one of the plurality of devices and a second SAS in one of the plurality of devices.

11. The network of claim 1 , wherein the plurality of devices are sensor devices and/or VOIP devices.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2024
From: INESC TEC – INSTITUTO DE ENGENHARIA DESISTEMAS E COMPUTADORES, TECNOLOGIA E CIÊNCIA
To: U.PORTO - UNIVERSIDADE DO PORTO
Reel/Frame 069259/0990 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2023
From: VIEIRA SOUSA, PATRÍCIA RAQUEL; MAIA SOARES DE RESENDE, JOÃO MIGUEL; DA SILVA MARTINS, ROLANDO; COELHO ANTUNES, LUÍS FILIPE
To: INESC TEC - INSTITUTO DE ENGENHARIA DESISTEMAS E COMPUTADORES, TECNOLOGIA E CIÊNCIA
Reel/Frame 062506/0304 →
Priority Claims (2)
PT 20181000034529 · May 16, 2018 · national
EP 18174412 · May 25, 2018 · regional
Continuity (2)
Continuation 17055671
Related Publication 20230155816A1 · May 18, 2023
References Cited (49)
US 7730309B2 · Zimmermann · 2010 [cited by applicant]
US 9467425B2 · Epp · 2016 [cited by examiner]
US 20050251680A1 · Brown · 2005 [cited by examiner]
US 20070157026A1 · Zimmermann · 2007 [cited by examiner]
US 20150288667A1 · Alder · 2015 [cited by examiner]
JP 2005099980A · 2005 [cited by applicant]
JP 2005354556A · 2005 [cited by applicant]
JP 2006332903A · 2006 [cited by applicant]
Zimmerman ZFONE Project, a Johnston P, et al “ZRTP: Media Path Key Agreement for Unicast Secure RTP; RCF6189.txt”, ZRPT: Media Path Key Agreement for Unicast Secure RTP; RFC6189.TXT, Internet Engineering Task Force, IET… [cited by applicant]
Ming Li, et al: “Group Device Pairing based Secure Sensor Association and Key Management for Body Area Networks”, INFOCOM, 2010 Proceedings IEEE, Piscataway, NJ, USA, Mar. 14, 2010, pp. 1-9. [cited by applicant]
Hu Tao, et al: “Preference-Based Privacy Protection Mechanism for the Internet of Things”, Information Science and Engineering (ISISE), 2010 International Symposium on, IEEE, Dec. 24, 2010, pp. 531-534. [cited by applicant]
Zhen Yan et al: “A survey on trust management for Internet of Things”, Journal of Network and Computer Applications, vol. 42, Jun. 1, 2014, pp. 120-134. [cited by applicant]
Yang, Yuchen, et al. “A Survey on Security and Privacy Issues in Internet-of-Things.” IEEE Internet of Things Journal (2017). [cited by applicant]
H. Sundmaeker, P. Guillemin, P. Friess and S. Woelffle, “Vision and Challenges for Realising the Internet of Things,” Cluster of European Research Projects on the Internet of Things, 2010. [cited by applicant]
Aman, Muhammad, Kee Chaing Chua, and Biplab Sikdar. “Mutual Authentication in IoT Systems using Physical Unclonable Functions.” IEEE Internet of Things Journal (2017). [cited by applicant]
Umar, Amjad. Information Security and Auditing in the Digital Age. nge solutions, inc, 2003. [cited by applicant]
Hao, Feng, and Peter YA Ryan. “Password authenticated key exchange by juggling.” International Workshop on Security Protocols. Springer Berlin Heidelberg, 2008. [cited by applicant]
Ancrenon, Jean, Marjan Å krobot, and Qiang Tang. “Two More Efficient Variants of the J-PAKE Protocol.” International Conference on Applied Cryptography and Network Security. Springer International Publishing, 2016. [cited by applicant]
Hao, Feng. “J-pake: Password authenticated key exchange by juggling.” (2016). [cited by applicant]
Hao, Feng., Ed. “Schnorr NIZK Proof: Non-interactive Zero Knowledge Proof for Discrete Logarithm” (2013). [cited by applicant]
Seo, Dong Hwi, and P. Sweeney. “Simple authenticated key agreement algorithm.” Electronics Letters 35.13 (1999): 1073-1074. [cited by applicant]
Goldreich, Oded. “Secure multi-party computation.” Manuscript. Preliminary version (1998): 86-97. [cited by applicant]
Toorani, Mohsen. “Security analysis of J-PAKE.” Computers and Communication (ISCC), 2014 IEEE Symposium on. IEEE, 2014. [cited by applicant]
Yao, Andrew C. “Protocols for secure computations.” Foundations of Computer Science, 1982. SFCS'08. 23rd Annual Symposium on. IEEE, 1982. [cited by applicant]
Hirt, Martin, Ueli Maurer, and Bartosz Przydatek. “Efficient secure multi-party computation.” International Conference on the Theory and Application of Cryptology and Information Security. Springer Berlin Heidelberg, 20… [cited by applicant]
C++ Implementation of ZRTP protocol—GNU ZRTP C++—https://github.com/wernerd/ZRTPCPP [Online; Accessed Mar. 30, 2017]. [cited by applicant]
Petraschek, Martin, et al. “Security and Usability Aspects of Man-in-the-Middle Attacks on ZRTP.” J. UCS 14.5 (2008): 673-692. [cited by applicant]
ABY—A Framework for Efficient Mixed-protocol Secure Two-party Computation https://github.com/encryptogroup/ABY [Online; Accessed Sep. 15, 2017]. [cited by applicant]
Keller, Marcel, Emmanuela Orsini, and Peter Scholl. “MASCOT: faster malicious arithmetic secure computation with oblivious transfer.” Proceedings of the 2016 Acm Sigsac Conference on Computer and Communications Security… [cited by applicant]
Huang, Yan, Jonathan Katz, and David Evans. “Quid-pro-quo-tocols: Strengthening semi-honest protocols with dual execution.” Security and Privacy (SP), 2012 IEEE Symposium on. IEEE, 2012. [cited by applicant]
Sakarindr, Pitipatana, and Nirwan Ansari. “Security services in group communications over wireless infrastructure, mobile ad hoc, and wireless sensor networks.” IEEE Wireless Communications 14.5 (2007). [cited by applicant]
Laud, Peeter, and Liina Kamm, eds. Applications of Secure Multiparty Computation. vol. 13. IOS Press, 2015. [cited by applicant]
Device Pairing Using Short Authentication Strings (2016) https://tools.ietf.org/id/draft-ietf-dnssd-pairing-01.html [Online; Accessed Apr. 21, 2017]. [cited by applicant]
TLS Handshaking With Certificates and Keys (2017) https://mcuoneclipse.files.wordpress.com/2017/04/tls-handshaking-with-certificates-and-keys.png [Online; Accessed Apr. 25, 2017]. [cited by applicant]
Lyrebird claims it can recreate any voice using just one minute of sample audio. (2017) http://www.theverge.com/2017/4/24/15406882/ai-voice-synthesis-copy-human-speech-lyrebird [Online; Accessed Apr. 25, 2017]. [cited by applicant]
Martini, S.: Session Key Retrieval in J-PAKE Implementations of OpenSSL and OpenSSH. (2010) http://seb.dbzteam.org/crypto/jpake-session-key-retrieval.pdf [Online; Accessed Mar. 4, 2017]. [cited by applicant]
Thermos, Peter, and Ari Takanen. Securing VoIP Networks. Pearson Education, 2007. [cited by applicant]
Canetti, Ran. “Obtaining universally compoable security: Towards the bare bones of trust.” International Conference on the Theory and Application of Cryptology and Information Security. Springer Berlin Heidelberg, 2007. [cited by applicant]
Let's Encrypt issues certs to ‘PayPal’ phishing sites: how to protect yourself (2017) http://bit.ly/2i7Z4bT [Online; Accessed May 19, 2017]. [cited by applicant]
Yao, Andrew Chi-Chih. “How to generate and exchange secrets.” Foundations of Computer Science, 1986., 27th Annual Symposium on. IEEE, 1986. [cited by applicant]
Yao, Andrew C. “Theory and application of trapdoor functions.” Foundations of Computer Science, 1982. SFCS'08. 23rd Annual Symposium on. IEEE, 1982. [cited by applicant]
Lindell, Yehuda, and Benny Pinkas. “Secure multiparty computation for privacy-preserving data mining.” Journal of Privacy and Confidentiality 1.1 (2009): 5. APA. [cited by applicant]
McGrew, D., et al. “RFC 3711: The secure real-time transport protocol (SRTP).” Cisco Systems, Inc and Ericsson Research, Tech. Rep (2004). [cited by applicant]
Sisalem, Dorgham, et al. SIP security. John Wiley & Sons, 2009. [cited by applicant]
Hlavacs, Helmut, et al. “Enhancing ZRTP by using Computational Puzzles.” J. UCS 14.5 (2008): 693-716. [cited by applicant]
Afifi, M. H., et al. “Dynamic Authentication Protocol Using Self-Powered Timers for Passive Internet of Things.” IEEE Internet of Things Journal (2017). [cited by applicant]
Pass, Rafael. “Bounded-concurrent secure multi-party computation with a dishonest majority.” Proceedings of the thirty-sixth annual ACM symposium on Theory of computing. ACM, 2004. [cited by applicant]
Bresciani R, “The ZRTP Protocol Analysis on the Diffie-Hellman Mode”, Trinity College Dublin, Computer Science Department Technical Report, Jun. 12, 2009. [cited by applicant]
Hoepman Jaap-Henk, “The Ephemeral Pairing Problem”, The Department of Computer Science, University of Nijmegen, NL, Feb. 6, 2008. [cited by applicant]