IP Library Granted Patent US 11,943,343
Granted Patent B2
US 11,943,343 · App. 18/210,776 · Granted Mar 26, 2024

ECDHE key exchange for server authentication and a key server

Inventor: John A. Nix (Evanston, IL)
Assignee: IoT and M2M Technologies, LLC
H04L9/0841H04L9/006H04L9/0662H04L9/0825H04L9/085H04L9/14H04L9/3066
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,943,343
App. No.
18/210,776
Granted
Mar 26, 2024
Kind
B2
Abstract

A server can receive a device public key and forward the device public key to a key server. The key server can perform a first elliptic curve Diffie-Hellman (ECDH) key exchange using the device public key and a network private key to derive a secret X1. The key server can send the secret X1 to the server. The server can derive an ECC PKI key pair and send to the device the server public key. The server can conduct a second ECDH key exchange using the derived server secret key and the device public key to derive a secret X2. The server can perform an ECC point addition using the secret X1 and secret X2 to derive a secret X3. The device can derive the secret X3 using (i) the server public key, a network public key, and the device private key and (ii) a third ECDH key exchange.

Claims (18)

1. A method for a server to authenticate a device over a wireless network, the method performed by the server, the method comprising:

a) storing, in a memory, (i) a first point on an elliptic curve, and (ii) a shared key, wherein the shared key is stored by the device;

b) generating a value from a secure hash of at least the shared key;

c) selecting (i) a first integer as a first subset of the value and (ii) a second integer as a second subset of the value;

d) receiving, via a radio connected to the wireless network and from the device, a second point on the elliptic curve from the node, the second point comprising a public key for the device;

e) deriving a shared secret comprising an elliptic curve point addition of (i) the first integer multiplied by the public key for the device and (ii) the second integer multiplied by the first point;

f) deriving a symmetric ciphering key from a key derivation function with the shared secret;

g) receiving, via a radio connected to the wireless network and from the device, a ciphertext comprising (i) a device digital signature and (ii) a device certificate;

h) decrypting the ciphertext with the symmetric ciphering key in order to read the device digital signature and the device certificate; and

i) verifying the device digital signature using a device static public key from the device certificate.

2. The method of claim 1 , wherein the elliptic curve comprises a named curve secp256r1 (p256).

3. The method of claim 1 , wherein the first integer comprises a second value N1 and the second integer comprises a third value N2.

4. The method of claim 1 , wherein the symmetric ciphering key comprises a fourth value K1.

5. The method of claim 1 , further comprising in step d), receiving a random number from the device and in step i) verifying the device digital signature using the random number.

6. The method of claim 1 , further comprising in step d), receiving an identity for the device, wherein the server selects the shared key based on the identity.

7. The method of claim 1 , further comprising in step f) deriving a message authentication code (MAC) key from the key derivation function with the shared secret and in step i) verifying the ciphertext with the MAC key.

8. The method of claim 1 , wherein the device mutually derives the shared secret.

9. The method of claim 1 , further comprising in step i), verifying the device digital signature using an elliptic curve digital signature algorithm (ECDSA).

Assignments (5)
CHANGE OF ADDRESS Recorded Sep 10, 2025
From: NETWORK-1 TECHNOLOGIES, INC.
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 072827/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2025
From: IOT AND M2M TECHNOLOGIES, LLC
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 070752/0719 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2025
From: VOBAL TECHNOLOGIES, LLC
To: IOT AND M2M TECHNOLOGIES, LLC
Reel/Frame 070736/0052 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2025
From: NIX, JOHN
To: IOT AND M2M TECHNOLOGIES, LLC
Reel/Frame 070715/0645 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: NIX, JOHN A.
To: IOT AND M2M TECHNOLOGIES, LLC
Reel/Frame 063971/0736 →
Continuity (3)
Continuation 17253111
Provisional Application 62687411 · Jun 20, 2018
Related Publication 20230336332A1 · Oct 19, 2023
Cited By (1)
US 12,225,130