IP Library Granted Patent US 12,284,226
Granted Patent B2
US 12,284,226 · App. 18/350,954 · Granted Apr 22, 2025

Methods and devices for establishing secure communication channels

Inventors: Chang Fung Yang (Mississauga, CA); Jason Songbo Xu (Toronto, CA)
Assignee: Malikie Innovations Limited
H04L63/205H04L9/0631H04L9/0637H04L9/0643H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,284,226
App. No.
18/350,954
Granted
Apr 22, 2025
Kind
B2
Abstract

A method of establishing a secure communication channel between a first communication device and a second communication device. The secure communication channel is defined by one or more algorithm options and the one or more algorithm options are associated with one of one or more option categories. The method includes receiving a signal representing one or more selections. The method further includes, for the respective option categories, generating a sorted list of algorithm options based on the received selections and generating a security association proposal including one or more of the algorithm options from the respective sorted lists of algorithm options. The security association proposal is generated based on an order in the sorted list of algorithm options. The method further includes transmitting the security association proposal to the second communication device for establishing the secure communication channel.

Claims (38)

1. A secure communication method comprising:

receiving, by one or more processors of a first communication device, a first signal indicating a plurality of algorithm options selected by a user of the first communication device;

generating, by the one or more processors, one or more security association proposals based on the plurality of algorithm options indicated by the first signal;

transmitting, by the one or more processors, the one or more security association proposals to a second communication device;

receiving, by the one or more processors, from the second communication device, a second signal indicating that one of the one or more security association proposals has been selected; and

establishing, by the one or more processors, a secure communication channel between the first communication device and the second communication device.

2. The secure communication method of claim 1 , further comprising:

generating, by the one or more processors, one or more sorted lists of algorithm options based on the first signal.

3. The secure communication method of claim 2 , wherein the one or more sorted lists of algorithm options are sorted in order of decreasing or increasing security strength.

4. The secure communication method of claim 2 , wherein the one or more sorted lists of algorithm options are sorted in a rules-based order.

5. The secure communication method of claim 2 , wherein one of the one or more sorted lists of algorithm options includes one or more Diffie-Hellman (DH) groups, one or more encryption algorithms, one or more integrity algorithms, and one or more pseudorandom function algorithms.

6. The secure communication method of claim 1 , wherein the algorithm options include Diffie-Hellman (DH) groups.

7. The secure communication method of claim 1 , wherein the algorithm options include encryption algorithms.

8. The secure communication method of claim 1 , wherein the algorithm options include integrity algorithms.

9. The secure communication method of claim 1 , wherein the algorithm options include pseudorandom function algorithms.

10. A first communication device comprising:

a memory configured to store processor-executable instructions for establishing a secure communication channel between the first communication device and a second communication device; and

one or more processors operably coupled with the memory, the one or more processors being configured to:

receive a first signal indicating a plurality of algorithm options selected by a user of the first communication device;

generate one or more security association proposals based on the plurality of algorithm options indicated by the first signal;

transmit the one or more security association proposals to the second communication device;

receive, from the second communication device, a second signal indicating that one of the one or more security association proposals has been selected; and

establish the secure communication channel between the first communication device and the second communication device.

11. The first communication device of claim 10 , wherein the one or more processors are further configured to generate one or more sorted lists of algorithm options based on the first signal.

12. The first communication device of claim 11 , wherein the one or more sorted lists of algorithm options are sorted in order of decreasing or increasing security strength.

13. The first communication device of claim 11 , wherein one of the one or more sorted lists of algorithm options includes one or more Diffie-Hellman (DH) groups, one or more encryption algorithms, one or more integrity algorithms, and one or more pseudorandom function algorithms.

14. The first communication device of claim 11 , wherein the one or more sorted lists of algorithm options are sorted in a rules-based order.

15. The first communication device of claim 10 , wherein the algorithm options include Diffie-Hellman (DH) groups.

16. The first communication device of claim 10 , wherein the algorithm options include encryption algorithms.

17. The first communication device of claim 10 , wherein the algorithm options include integrity algorithms.

18. The first communication device of claim 10 , wherein the algorithm options include pseudorandom function algorithms.

19. A non-transitory computer-readable storage medium storing instructions for establishing a secure communication channel between a first communication device and a second communication device, wherein the instructions, when executed by a processor of a computer system, cause the computer system to:

receive a first signal indicating a plurality of algorithm options selected by a user of the first communication device;

generate one or more security association proposals based on the plurality of algorithm options indicated by the first signal;

transmit the one or more security association proposals to the second communication device;

receive, from the second communication device, a second signal indicating that one of the one or more security association proposals has been selected; and

establish the secure communication channel between the first communication device and the second communication device.

20. The non-transitory computer-readable storage medium of claim 19 , wherein the instructions further cause the computer system to generate one or more sorted lists of algorithm options based on the first signal, wherein the one or more sorted lists of algorithm options are sorted in order of decreasing or increasing security strength.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 3, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064479/0202 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2023
From: YANG, CHANG FUNG; XU, JASON SONGBO
To: BLACKBERRY LIMITED
Reel/Frame 064226/0162 →
Continuity (3)
Continuation 17501068 · Oct 14, 2021
Continuation 16181755 · Nov 6, 2018
Related Publication 20240015186A1 · Jan 11, 2024
References Cited (12)
US 7219223B1 · Bacchus et al. · 2007 [cited by applicant]
US 20110078436A1 · Sato · 2011 [cited by applicant]
US 20130254531A1 · Liang · 2013 [cited by examiner]
US 20180004363A1 · Tompkins · 2018 [cited by applicant]
EP 2007110A1 · 2008 [cited by applicant]
Extended European Search Report issued in corresponding EP application No. 23188392.7 on Sep. 25, 2023. [cited by applicant]
Office Action for Canadian Patent Application No. 3,060,278, Oct. 12, 2023, 5 Pages. [cited by applicant]
Kaufman et al.: Internet Key Exchange Protocol Version 2 (IKEv2), Request for Comments: 7296, Internet Engineering Task Force, 142 pages, dated Oct. 2014. [cited by applicant]
Milutinovic et al.: “Secure Negotiation for Manual Authentication Protocols”, dated Oct. 19, 2007. [cited by applicant]
EPO: Extended European Search Report relating to EP application No. 19206500.1, dated Jan. 23, 2020. [cited by applicant]
EPO: EP Office Action relating to EP application No. 19206500.1, dated Jan. 19, 2022. [cited by applicant]
USPTO, Office Action relating to U.S. Appl. No. 17/501,068 dated Jan. 20, 2023. [cited by applicant]