IP Library Granted Patent US 8,527,764
Granted Patent B2
US 8,527,764 · App. 12/601,612 · Granted Sep 3, 2013

Method and system for secure communication

Inventors: Kumar K. Kiran (Seoul, KR); Sung Hyun Cho (Seoul, KR); Min Gyu Chung (Seoul, KR); Koo Yong Pak (Seoul, KR); Il Gon Park (Seoul, KR); Soo Jung Kim (Seoul, KR)
Assignee: LG Electronics Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,527,764
App. No.
12/601,612
Granted
Sep 3, 2013
Kind
B2
Abstract

A method and system for secure communication is provided. The method for secure communication with devices includes: obtaining a parameter for protecting a content; authenticating each other by exchanging a certificate with the device; and exchanging a key with the device using a key authenticated through the certificate to establish a secure authenticated channel with the device. Accordingly, it is possible to establish the secure authenticated channel and perform secure communication by computing a secure authenticated channel key.

Claims (29)

1. A secure communication method between devices, the method comprising:

obtaining, by a first device from a second device, a parameter for protecting a content;

performing, based on the obtained parameter, a mutual authentication with the second device which includes:

transmitting a first authentication message including a certificate of the first device to the second device;

receiving a second authentication message including a certificate of the second device and an on-line certificate status protocol server response indicating verification of the certificate of the second device, and

verifying the certificate of the second device using the on-line certificate status protocol server response;

authenticating the second device using the certificate of the second device;

exchanging a key with the second device, the key authenticated through the certificate of the second device to establish a secure authenticated channel with the second device; and

changing a content license protection mode corresponding to the content from a first content license protection mode to a second content license protection mode when the content is copied or moved from the second device;

wherein the content license protection mode includes any one of: a secure authenticated channel protection mode which protects the license using a secure authenticated channel key during transfer of the license, an authorized domain secret protection mode which protects the license using an authorized domain secret protection, a secure authenticated channel/authorized domain protection mode which protects the license through the secure authenticated channel and authorized domain secret protection, and a device key protection mode which protects the license using a device key during storage of the license.

2. The method of claim 1 , wherein exchanging the key with the device comprises computing a key value required to compute the secure authenticated channel key to be used in the secure authenticated channel, and transferring and receiving the key value to and from the device, respectively.

3. The method of claim 2 , wherein the parameter includes at least one of: identification information of the second device, type of an authentication, a security level for setting a level related to integrity and confidentiality during secure communication between the first device and the second device, and a license protection mode level required for the secure communication between the first device and the second device.

4. The method of claim 1 , wherein the license protection mode is set according to usage state information included in the license of the content, and the method further comprises:

confirming whether a license protection mode level of the parameter corresponds to the license protection mode included in the license of the content.

5. A secure communication system comprising:

a first device; and

a second device, which are interoperable with each other,

wherein the first device is configured to:

obtain from the second device a parameter for protecting a content,

perform, based on the obtained parameter, a mutual authentication with the second device by:

transmitting a first authentication message including a certificate of the first device to the second device,

receiving a second authentication message including a certificate of the second device and an on-line certificate status protocol server response indicating verification of the certificate of the second device, and

verify the certificate of the second device using the on-line certificate status protocol server response,

authenticate the second device using the certificate of the second device,

exchange a key with the second device, the key authenticated by the certificate of the second device to establish a secure authenticated channel between the first device and the second device, and

change a content license protection mode corresponding to the content from a first content license protection mode to a second content license protection mode when the content is copied or moved between the first device and the second device,

wherein the content license protection mode includes any one of: a secure authenticated channel protection mode which protects the license using a secure authenticated channel key during transfer of the license, an authorized domain secret protection mode which protects the license using an authorized domain secret protection, a secure authenticated channel/authorized domain protection mode which protects the license through the secure authenticated channel and authorized domain secret protection, and a device key protection mode which protects the license using a device key during storage of the license.

6. The system of claim 5 , wherein the first device and the second device compute key values required to compute the secure authenticated channel key to be used in the secure authenticated channel and exchange the key values with each other.

7. The system of claim 5 , wherein the parameter includes at least one of: identification information of the second device, type of an authentication, a security level for setting a level related to integrity and confidentiality during secure communication between the first device and the second device, and a license protection mode level required for the secure communication between the first device and the second device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 27, 2010
From: KIRAN, KUMAR K.; CHO, SUNG HYUN; CHUNG, MIN GYU; PAK, KOO YONG; PARK, IL GON; KIM, SOO JUNG
To: LG ELECTRONICS INC.
Reel/Frame 024448/0223 →
Continuity (7)
Provisional Application 60916341 · May 7, 2007
Provisional Application 60949722 · Jul 13, 2007
Provisional Application 60952418 · Jul 27, 2007
Provisional Application 60953834 · Aug 3, 2007
Provisional Application 60955125 · Aug 10, 2007
Provisional Application 60955642 · Aug 14, 2007
Related Publication 20100257363A1 · Oct 7, 2010