IP Library Granted Patent US 10,243,741
Granted Patent B2
US 10,243,741 · App. 15/473,656 · Granted Mar 26, 2019

Key exchange and mutual authentication in low performance devices

Inventors: Yiftach Cohen (Ramat Gan, IL); Erez Geva (Petah Tikva, IL)
Assignee: CHECK POINT SOFTWARE TECHNOLOGIES LTD.
H04L9/321G06F21/44H04L9/3213H04L63/0435H04L63/061H04L63/0869H04W12/04H04W12/06G06F2221/2129
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,243,741
App. No.
15/473,656
Granted
Mar 26, 2019
Kind
B2
Abstract

Securely exchanging keys to establish secure connections to low powered connected devices (LPCDs), such as smart devices and IoT (Internet Of Things) devices, and mutual authentication between these devices and third party controllers is accomplished via a higher performance machine configured with a dedicated remote service (DRS). A known symmetric pre-shared key (PSK) is used to establish a secure first connection between the LPCD and the DRS using another symmetric key. The DRS can then use asymmetric key exchange to securely send a new symmetric key to the 3P, and send the same new symmetric key to the LPCD using the secure first connection. This facilitates LPCDs to securely establish secure communications with other devices, in particular for control by third party (3P) devices. This also allows authentication of the LPCD with cloud services, and enables a DRS to vouch for associated devices to other DRSs.

Claims (58)

1. A method for connecting devices comprising the steps of:

(a) establishing a secure first connection between a server and a first device; and

(b) providing, by said server, a secure third connection between a third device and said first device,

wherein said step of establishing includes said server:

(i) receiving from said first device, an identification of said first device;

(ii) receiving from said first device an initial connection, said initial connection encrypted with a pre-shared key (PSK) of said first device; and

(iii) sending to said first device an initial connection response, said initial connection response being encrypted with said PSK and including a first key for communicating securely via said secure first connection,

wherein said first key is a symmetric key for symmetrically encrypting said secure first connection,

wherein said step of providing includes said server:

(i) receiving from said first device, via said secure first connection, a request to connect including an identification of said third device;

(ii) sending said first device a server acknowledgement;

(iii) providing, via a secure second connection, to said third device a third key; and

(iv) providing via said secure first connection to said first device, said third key for communicating securely via said secure third connection,

wherein:

(i) said server acknowledgement includes a token; and

(ii) said step of providing, via a secure second connection, to said third device a third key, is based on said token,

wherein said third key is:

(i) a symmetric key for symmetrically encrypting said secure third connection; and

(ii) other than a first key that is a symmetric key for symmetrically encrypting said secure first connection.

2. A system for connecting devices comprising:

a processing system containing one or more processors, said processing system being configured to:

(a) establish a secure first connection between a server and a first device; and

(b) provide, by said server, a secure third connection between a third device and said first device,

wherein said server is configured to establish by:

(i) receiving from said first device, an identification of said first device;

(ii) receiving from said first device an initial connection, said initial connection encrypted with a pre-shared key (PSK) of said first device; and

(iii) sending to said first device an initial connection response, said initial connection response being encrypted with said PSK and including a first key for communicating securely via said secure first connection,

wherein said first key is a symmetric key for symmetrically encrypting said secure first connection,

wherein said server is configured to provide by:

(i) receiving from said first device, via said secure first connection, a request to connect including an identification of said third device;

(ii) sending said first device a server acknowledgement;

(iii) providing, via a secure second connection, to said third device a third key; and

(iv) providing via said secure first connection to said first device, said third key for communicating securely via said secure third connection,

wherein:

(i) said server acknowledgement includes a token; and

(ii) said step of providing, via a secure second connection, to said third device a third key, is based on said token,

wherein said third key is:

(i) a symmetric key for symmetrically encrypting said secure third connection; and

(ii) other than a first key that is a symmetric key for symmetrically encrypting said secure first connection.

3. A non-transitory computer-readable storage medium having embedded thereon computer-readable code for connecting devices, the computer-readable code including program code for:

(a) establishing a secure first connection between a server and a first device; and

(b) providing, by said server, a secure third connection between a third device and said first device,

wherein said step of establishing includes said server:

(i) receiving from said first device, an identification of said first device;

(ii) receiving from said first device an initial connection, said initial connection encrypted with a pre-shared key (PSK) of said first device; and

(iii) sending to said first device an initial connection response, said initial connection response being encrypted with said PSK and including a first key for communicating securely via said secure first connection,

wherein said first key is a symmetric key for symmetrically encrypting said secure first connection,

wherein said step of providing includes said server:

(i) receiving from said first device, via said secure first connection, a request to connect including an identification of said third device;

(ii) sending said first device a server acknowledgement;

(iii) providing, via a secure second connection, to said third device a third key; and

(iv) providing via said secure first connection to said first device, said third key for communicating securely via said secure third connection,

wherein:

(i) said server acknowledgement includes a token; and

(ii) said step of providing, via a secure second connection, to said third device a third key, is based on said token,

wherein said third key is:

(i) a symmetric key for symmetrically encrypting said secure third connection; and

(ii) other than a first key that is a symmetric key for symmetrically encrypting said secure first connection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2018
From: COHEN, YIFTACH; GEVA, EREZ
To: CHECK POINT SOFTWARE TECHNOLOGIES LTD.
Reel/Frame 044750/0331 →
Continuity (1)
Related Publication 20180287798A1 · Oct 4, 2018
Cited By (4)
US 12,512,991 US 12,556,611 US 12,580,990 US 12,701,166