IP Library Granted Patent US 12,052,292
Granted Patent B2
US 12,052,292 · App. 18/317,584 · Granted Jul 30, 2024

Network security systems and methods

Inventors: David P. Maher (Livermore, CA); Gilles Boccon-Gibod (San Francisco, CA)
Assignee: Intertrust Technologies Corporation
H04L63/20G06F21/6218H04L67/1068H04W4/70H04W12/04H04W12/50G06F2221/2149H04L12/2803H04L63/065H04L67/51H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,052,292
App. No.
18/317,584
Granted
Jul 30, 2024
Kind
B2
Abstract

This disclosure relates to systems and methods for managing connected devices and associated network connections. In certain embodiments, trust, privacy, safety, and/or security of information communicated between connected devices may be established in part through use of security associations and/or shared group tokens. In some embodiments, these security associations may be used to form an explicit private network associated with the user. A user may add and/or manage devices included in the explicit private network through management of various security associations associated with the network's constituent devices.

Claims (23)

1. A method of managing operation of connected devices, the method comprising:

exposing, by a gateway device, an indication of a composite service offered by the gateway device based on information included in explicit private network state information associated with a plurality of first connected devices in communication with the gateway device, the explicit private network state information being managed, at least in part, by the gateway device, the composite service comprising one or more actions performed by the plurality of first connected devices;

receiving, by the gateway device from a second connected device, a request to perform the composite service;

determining, by the gateway device based, at least in part, on the explicit private network state information, that the gateway device may initiate performance of the composite service by the plurality of first connected devices in accordance with the request;

generating, by the gateway device based on the determination, one or more command messages configured to control the operation of the plurality of first connected devices to perform the composite service; and

transmitting, by the gateway device, the one or more command messages to the plurality of first connected devices.

2. The method of claim 1 , wherein exposing the indication of the composite service offered by the gateway device comprises exposing the indication of the composite service offered by the gateway device to the second connected device.

3. The method of claim 1 , wherein the explicit private network state information comprises identification information associated with the plurality of first connected devices.

4. The method of claim 3 , wherein the identification information comprises information uniquely associated with at least one connected device of the plurality of first connected devices.

5. The method of claim 4 , wherein the information uniquely associated with the at least one connected device of the plurality of first connected devices comprises at least one of a device universally unique identifier and Internet protocol identification information.

6. The method of claim 3 , wherein the identification information comprises a name assigned to at least one connected device of the plurality of first connected devices by an associated entity.

7. The method of claim 1 , wherein the explicit private network state information comprises information relating to one or more acceptable commands associated with at least one connected device of the plurality of first connected devices.

8. The method of claim 1 , wherein the explicit private network state information comprises security association information associated with the plurality of first connected devices.

9. The method of claim 8 , wherein determining that the gateway device may initiate performance of the composite service by the plurality of first connected devices in accordance with the request is based, at least in part, on the security association information.

10. The method of claim 8 , wherein the security association information comprises a group token.

11. The method of claim 10 , wherein the group token comprises a group key.

12. The method of claim 10 , wherein determining that the gateway device may initiate performance of the composite service by the plurality of first connected devices in accordance with the request comprises determining, based on the request to perform the composite service, that the second device is associated with the group token.

13. The method of claim 12 , wherein the request to perform the composite service received from the second connected device comprises the group token.

14. The method of claim 1 , wherein determining that the gateway device may initiate performance of the composite service by the plurality of first connected devices in accordance with the request comprises determining that the second connected device is associated with the plurality of first connected devices based on the explicit private network state information.

15. The method of claim 1 , wherein the explicit private network state information associated with the plurality of first connected devices comprises information relating to acceptable data that may be communicated to at least one connected device of the plurality of first connected devices.

16. The method of claim 1 , wherein the gateway device comprises at least one of a smartphone, a tablet computer system, a desktop computer system, a laptop computer system, a wearable computing device, a connected vehicle, a telematics system, a security system, a home automation system, a connected thermostat, a connected heating system, a connected cooling system, a utility meter, a medical device, a gaming system, a network infrastructure system, a television, a speaker, and a digital camera.

17. The method of claim 1 , wherein at least one connected device of the plurality of first connected devices comprises at least one of a smartphone, a tablet computer system, a desktop computer system, a laptop computer system, a wearable computing device, a connected vehicle, a telematics system, a security system, a home automation system, a connected thermostat, a connected heating system, a connected cooling system, a utility meter, a medical device, a gaming system, a network infrastructure system, a television, a speaker, and a digital camera.

18. The method of claim 1 , wherein the second connected device comprises at least one of a smartphone, a tablet computer system, a desktop computer system, a laptop computer system, a wearable computing device, a connected vehicle, a telematics system, a security system, a home automation system, a connected thermostat, a connected heating system, a connected cooling system, a utility meter, a medical device, a gaming system, a network infrastructure system, a television, a speaker, and a digital camera.

Assignments (3)
SECURITY INTEREST Recorded Mar 25, 2026
From: INTERTRUST TECHNOLOGIES CORPORATION
To: JAMSTER CAPITAL LLC
Reel/Frame 075228/0345 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 26, 2024
From: INTERTRUST TECHNOLOGIES CORPORATION
To: JERA CO., INC.
Reel/Frame 068173/0212 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2023
From: MAHER, DAVID P.; BOCCON-GIBOD, GILLES
To: INTERTRUST TECHNOLOGIES CORPORATION
Reel/Frame 063645/0540 →
Continuity (7)
Continuation 17121192 · Dec 14, 2020
Continuation 16534996 · Aug 7, 2019
Continuation 15951610 · Apr 12, 2018
Continuation 14624405 · Feb 17, 2015
Provisional Application 61946404 · Feb 28, 2014
Provisional Application 61940182 · Feb 14, 2014
Related Publication 20230291770A1 · Sep 14, 2023