IP Library Granted Patent US 12,381,859
Granted Patent B2
US 12,381,859 · App. 18/477,229 · Granted Aug 5, 2025

Content security at service layer

Inventors: Vinod Kumar Choyi (Conshohocken, PA); Yogendra C. Shah (Exton, PA); Dale N. Seed (Allentown, PA); Michael F. Starsinic (Newtown, PA); Shamim Akbar Rahman (Cote St. Luc, CA); Quang Ly (North Wales, PA); Zhuo Chen (Claymont, DE); William Robert Flynn, IV (Schwenksville, PA)
Assignee: CONVIDA WIRELESS, LLC
H04L63/0435H04L63/0823H04L63/101H04W12/06H04W12/069H04W12/08H04W12/086H04L63/061H04W4/70
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,381,859
App. No.
18/477,229
Granted
Aug 5, 2025
Kind
B2
Abstract

Existing approaches to security within network, for instance oneM2M networks, are limited. For example, content might only be protected while the content is in transit between entities that trust each other. Here, the integrity and the confidentiality of content in an M2M network are protected. Such content may be “at rest,” such that the content is stored at a hosting node. Only authorized entities may store and retrieve the data that is stored at the hosting node, and the data may be protected from a confidentiality perspective and an integrity perspective.

Claims (29)

1. An apparatus for a service supporting service capabilities through a set of Application Programming Interfaces (APIs), the service being provided as middleware between application protocols and a plurality of applications, the apparatus comprising circuitry configured to:

receive, from an entity hosting an application of the plurality of applications via at least one of the set of APIs, a first request to create one or more credentials for encrypting or integrity protecting application content when stored at rest on a first service entity of the service; and

send, based on the request and to the entity, the one or more credentials comprising a credential identifier obtained from a second service entity of the service,

wherein the entity is configured to send, to the service, a second request to create a resource that stores application content that is encrypted or integrity protected by the service, the resource being a uniquely addressable element in a Resource Oriented Architecture (ROA) having representation that can be manipulated via RESTful methods, the second request comprising the one or more credential identifiers for encrypting or integrity protecting the application content.

2. The apparatus as recited in claim 1 , wherein the one or more credentials comprise a master key for symmetric key confidentiality protection.

3. The apparatus as recited in claim 1 , wherein the second service entity corresponds to a trust enablement function.

4. The apparatus as recited in claim 3 , wherein a second entity hosting an application of the plurality of applications that is authorized to obtain the content can obtain the one or more credentials from the trust enablement function or the apparatus.

5. The apparatus as recited in claim 1 , wherein the first request is based on one or more security parameters associated with the application content.

6. The apparatus as recited in claim 1 , wherein the first service entity is a middleware entity located on top of network protocol stacks, wherein the middleware entity is in service layer for IoT services.

7. The apparatus as recited in claim 6 , wherein the service layer is defined according to ETSI/oneM2M standards.

8. A method for a service supporting service capabilities through a set of Application Programming Interfaces (APIs), the service being provided as middleware between application protocols and a plurality of applications, the method comprising:

receiving, from an entity hosting an application of the plurality of applications via at least one of the set of APIs, a first request to create one or more credentials for encrypting or integrity protecting application content when stored at rest on a first service entity of the service; and

sending, based on the request and to the entity, the one or more credentials comprising a credential identifier obtained from a second service entity of the service,

wherein the entity is configured to send, to the service, a second request to create a resource that stores application content that is encrypted or integrity protected by the service, the resource being a uniquely addressable element in a Resource Oriented Architecture (ROA) having representation that can be manipulated via RESTful methods, the second request comprising the one or more credential identifiers for encrypting or integrity protecting the application content.

9. The method as recited in claim 8 , wherein the one or more credentials comprise a master key for symmetric key confidentiality protection.

10. The method as recited in claim 8 , wherein the first request is based on one or more security parameters associated with the application content.

11. The method as recited in claim 8 , wherein the first service entity is a middleware entity located on top of network protocol stacks, wherein the middleware entity is in service layer for IoT services.

12. The method as recited in claim 11 , wherein the service layer is defined according to ETSI/oneM2M standards.

13. The method as recited in claim 8 , wherein the second service entity corresponds to a trust enablement function.

14. The method as recited in claim 13 , wherein a second entity hosting an application of the plurality of applications that is authorized to obtain the content can obtain the one or more credentials from the trust enablement function or the apparatus.

15. An apparatus comprising circuitry configured to:

send, to a service supporting service capabilities through a set of Application Programming Interfaces (APIs), the service being provided as middleware between application protocols and a plurality of applications, the apparatus, a first request to create one or more credentials for encrypting or integrity protecting application content when stored at rest on a first service entity in the service;

receive, based on the request and from the service, the one or more credentials comprising a credential identifier obtained from a second service entity of the service; and

send, to the service, a second request to create a resource that stores application content that is encrypted or integrity protected by the service, the resource being a uniquely addressable element in a Resource Oriented Architecture (ROA) having representation that can be manipulated via RESTful methods, the second request comprising the one or more credential identifiers for encrypting or integrity protecting the application content.

16. The apparatus as recited in claim 15 , wherein the one or more credentials comprise a master key for symmetric key confidentiality protection.

17. The apparatus as recited in claim 15 , wherein the second service entity corresponds to a trust enablement function.

18. The apparatus as recited in claim 17 , wherein a second entity hosting an application of the plurality of applications that is authorized to obtain the content can obtain the one or more credentials from the trust enablement function or the apparatus.

19. The apparatus as recited in claim 15 , wherein the first service entity is a middleware entity located on top of network protocol stacks, wherein the middleware entity is in service layer for IoT services.

20. The apparatus as recited in claim 19 , wherein the service layer is defined according to ETSI/oneM2M standards.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2025
From: CONVIDA WIRELESS, LLC
To: IPLA HOLDINGS INC.
Reel/Frame 072388/0091 →
Continuity (6)
Continuation 17556433 · Dec 20, 2021
Continuation 16826363 · Mar 23, 2020
Continuation 15198984 · Jun 30, 2016
Provisional Application 62248808 · Oct 30, 2015
Provisional Application 62188141 · Jul 2, 2015
Related Publication 20240121227A1 · Apr 11, 2024
References Cited (45)
US 8402526B2 · Ahn · 2013 [cited by applicant]
US 9424432B2 · Holland · 2016 [cited by examiner]
US 20030074580A1 · Knouse · 2003 [cited by examiner]
US 20050204148A1 · Mayo et al. · 2005 [cited by applicant]
US 20070100913A1 · Sumner et al. · 2007 [cited by applicant]
US 20100042929A1 · Berry et al. · 2010 [cited by applicant]
US 20100251353A1 · Hodgkinson · 2010 [cited by applicant]
US 20120159167A1 · Lee et al. · 2012 [cited by applicant]
US 20130095459A1 · Tran · 2013 [cited by applicant]
US 20150003312A1 · Jeong et al. · 2015 [cited by applicant]
US 20150032795A1 · Robbins et al. · 2015 [cited by applicant]
US 20150033311A1 · Seed et al. · 2015 [cited by applicant]
US 20150033312A1 · Seed et al. · 2015 [cited by applicant]
US 20160134599A1 · Ross · 2016 [cited by examiner]
US 20160302069A1 · Kim et al. · 2016 [cited by applicant]
CN 101341691A · 2009 [cited by applicant]
CN 102143134A · 2011 [cited by applicant]
CN 103210627A · 2013 [cited by applicant]
CN 103532981A · 2014 [cited by applicant]
EP 2890073A1 · 2015 [cited by applicant]
JP 2009512077A · 2009 [cited by applicant]
JP 2012069110A · 2012 [cited by applicant]
JP 2015036926A · 2015 [cited by applicant]
WO 2011100331A1 · 2011 [cited by applicant]
WO 2011163561A1 · 2011 [cited by applicant]
WO 2014185754A1 · 2014 [cited by applicant]
WO 2015080515A1 · 2015 [cited by applicant]
Barnes, “Use Cases and Requirements for JSON Object Signing and Encryption (JOSE)”, Internet Engineering Task Force (IETF), RFC 7165, Apr. 2014, 1-25 pages. [cited by applicant]
Dierks, “The Transport Layer Security (TLS) Protocol Version 1.2”, Network Working Group, RFC 5246, Aug. 2008, 1-104 pages. [cited by applicant]
Gao et al., “Research on M2 M Functional Architecture and Security”, Computer Technology and Development, vol. 22, No. 1, Jan. 2012, pp. 250-253. (English Abstract Submitted). [cited by applicant]
Gramm-Leach-Bliley Act, Federal Trade Commission, 2 pages, http://www.ftc.gov/privacy/privacyinitiatives/glbact.html, 2016. [cited by applicant]
Health Insurance Portability And Accountability Act Of 1996, Public Law 104-191—Aug. 21, 1996, 169 pages. [cited by applicant]
Jones et al., “JSON Web Encryption (JWE)”, Internet Engineering Task Force (IETF), RFC 7516, May 2015, 1-51 pages. [cited by applicant]
Jones, “JSON Web Algorithms (JWA)”, Internet Engineering Task Force (IETF), RFC 7518, May 2015, 1-69 pages. [cited by applicant]
Jones, “JSON Web Key (JWK)”, Internet Engineering Task Force (IETF), RFC 7517, May 2015, 1-40 pages. [cited by applicant]
Jones, “JSON Web Signature (JWS)”, Internet Engineering Task Force (IETF), RFC 7515, May 2015, 1-59 pages. [cited by applicant]
Kent et al., “Security Architecture for the Internet Protocol”, Network Working Group, RFC 4301, Dec. 2005, 1-101 pages. [cited by applicant]
Kevin et al., “Guide for Mapping Types of Information and Information Systems of Security Categories,” NIST Special Publication 800-60, vol. I, Rev. 1, Aug. 2008, 1-53 pages. [cited by applicant]
Kevin et al., “Guide for Mapping Types of Information and Information Systems of Security Categories,” NIST Special Publication 800-60, vol. II, Rev. 1, Aug. 2008, 1-304 pages. [cited by applicant]
Korean Application No. 10-2016-7017358: Korean Office Action dated Sep. 22, 2016, 7 pages. [cited by applicant]
Motion Picture Association of America-Content Security Best Practices, V3.0, Apr. 2, 2015, 1-103 pages. [cited by applicant]
OneM2M Technical Specification, TS-0001-V1 .6.1, “Functional Architecture”, Jan. 30, 2015, 1-321 pages. [cited by applicant]
OneM2M Technical Specification, TS-0003-V1 .0.1, “Security Solutions”, Jan. 30, 2015, 1-91 pages. [cited by applicant]
OneM2M TR-0012 End to End Data Security Proposal, Oct. 2015, 9 pages. [cited by applicant]
Rescorla, E. and Modadugu, N., “Datagram Transport Layer Security Version 1.2”, Internet Engineering Task Force (IETF), RFC 6347, Jan. 2012, 1-32 pages. [cited by applicant]