IP Library Granted Patent US 12,143,478
Granted Patent B2
US 12,143,478 · App. 18/479,099 · Granted Nov 12, 2024

Public key exchange with authenicated ECDHE and security against quantum computers

Inventor: John A Nix (Evanston, IL)
Assignee: IoT and M2M Technologies, LLC
H04L9/0844H04L9/0618H04L9/0852H04L9/0869H04L9/3066G06N10/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,143,478
App. No.
18/479,099
Granted
Nov 12, 2024
Kind
B2
Abstract

Elliptic Curve Cryptography (ECC) can provide security against quantum computers that could feasibly determine private keys from public keys. A server communicating with a device can store and use PKI keys comprising server private key ss, device public key Sd, and device ephemeral public key Ed. The device can store and use the corresponding PKI keys, such as server public key Ss. The key use can support all of (i) mutual authentication, (ii) forward secrecy, and (iii) shared secret key exchange. The server and the device can conduct an ECDHE key exchange with the PKI keys to mutually derive a symmetric ciphering key K1. The device can encrypt a device public key PK.Device with K1 and send to the server as a first ciphertext. The server can encrypt a server public key PK.Network with at least K1 and send to the device as a second ciphertext.

Claims (20)

1. A method for securely communicating with a device, the method performed by a network, the method comprising:

a) storing, in a first memory of a first server, (i) first elliptic curve cryptography (ECC) parameters for an elliptic curve Diffie Hellman (ECDH) key exchange algorithm, and (ii) a first server private key corresponding to a first server public key for the first ECC parameters;

b) storing, in a second memory of a second server, (i) second ECC parameters, (ii) a second server private key corresponding to a second server public key for the second ECC parameters, and (iii) a domain name for the second server;

c) receiving, at the first server, a message from the device comprising:

(i) a first device public key supporting the first ECC parameters;

(ii) a value for selecting the first server private key; and

(iii) a symmetric ciphertext comprising a second device public key supporting the second ECC parameters, the domain name for the second server, and a first random number;

d) generating, by the first server, a first symmetric ciphering key from the ECDH key exchange algorithm with the first device public key and the first server private key;

e) decrypting, by the first server, the symmetric ciphertext in order to read the second device public key, the domain name, and the random number as plaintext;

f) selecting, by the first server, the second server using the domain name;

g) sending, from the first server to the second server, the second device public key and the first random number;

h) generating, by the second server, (i) a second symmetric ciphering key from the ECDH key exchange algorithm with the second device public key and the second server private key and (ii) a response comprising a second random number;

i) encrypting, by the second server, the response with the second symmetric ciphering key in order to generate an encrypted response; and

j) sending, from the second server and for the device, the encrypted response.

2. The method of claim 1 , wherein the network comprises a plurality of second servers and a plurality of domain names for the plurality of second servers.

3. The method of claim 1 , wherein the first memory of the first server comprises a nonvolatile memory, and wherein the first server private key is static and the corresponding first server public key is static.

4. The method of claim 1 , wherein the first memory of the first server stores a plurality of first server private keys and first server public keys with a plurality of values, and wherein the value identifies the first server private and first server public key.

5. The method of claim 4 further comprising after step c) and before step d): selecting the first server private key using the value received in the message.

6. The method of claim 1 , wherein the device mutually derives the first symmetric ciphering key from the ECDH key exchange algorithm with (i) a first device private key corresponding to the first device public key and (ii) the first server public key.

7. The method of claim 6 , further comprising sending, by the first server, the second server public key, wherein the device mutually derives the second symmetric ciphering key from the ECDH key exchange algorithm with (i) a second device private key corresponding to the second device public key and (ii) the second server public key.

Assignments (5)
CHANGE OF ADDRESS Recorded Sep 10, 2025
From: NETWORK-1 TECHNOLOGIES, INC.
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 072827/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2025
From: IOT AND M2M TECHNOLOGIES, LLC
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 070752/0719 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2025
From: VOBAL TECHNOLOGIES, LLC
To: IOT AND M2M TECHNOLOGIES, LLC
Reel/Frame 070736/0052 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2025
From: NIX, JOHN
To: IOT AND M2M TECHNOLOGIES, LLC
Reel/Frame 070715/0846 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2023
From: NIX, JOHN A.
To: IOT AND M2M TECHNOLOGIES, LLC
Reel/Frame 065083/0817 →
Continuity (4)
Continuation 17748706 · May 19, 2022
Continuation 16805172 · Feb 28, 2020
Provisional Application 62812710 · Mar 1, 2019
Related Publication 20240031137A1 · Jan 25, 2024