IP Library Granted Patent US 10,728,043
Granted Patent B2
US 10,728,043 · App. 15/215,047 · Granted Jul 28, 2020

Method and apparatus for providing secure communication among constrained devices

Inventor: Timothy Edward Moses (Ottawa, CA)
Assignee: Entrust, Inc.
H04L9/3263H04L9/006H04L9/083H04L9/0825H04L9/0833H04L9/0891H04L9/16H04L9/30H04L9/3234H04L63/0435H04L63/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,728,043
App. No.
15/215,047
Granted
Jul 28, 2020
Kind
B2
Abstract

In one example, an apparatus such as an authorization server and method for secure communication between constrained devices issues cryptographic communication rights among a plurality of constrained devices. Each of the plurality of constrained devices comprises no more than one cryptographic algorithm code module per cryptographic function. The method includes receiving a cryptographic communication rights request associated with at least a first of the plurality of constrained devices in response to a cryptographic algorithm update request, and includes providing a response including an identification of a subset of the plurality of constrained devices that have cryptographic communication rights with the identified first of the plurality of constrained devices. A software update server then updates the cryptographic code modules in the sub-set of the plurality of constrained devices.

Claims (26)

1. A method for secure communication between constrained devices comprising:

issuing, by an authorization server, cryptographic communication rights among a plurality of constrained devices where each of the plurality of constrained devices comprises no more than one cryptographic algorithm code module per cryptographic function wherein issuing comprises issuing asymmetric key based configuration certificates or symmetric key based tickets to the plurality of constrained devices that include data identifying at least other constrained devices of the plurality of constrained devices with whom a subject constrained device is permitted to cryptographically communicate with to allow the plurality of constrained devices to cryptographically exchange information between specified ones of the plurality of constrained devices;

receiving, by the authorization server, a cryptographic communication rights request associated with at least a first of the plurality of constrained devices in response to a cryptographic algorithm update request that requests a replacement cryptographic code module update for a constrained device;

providing, by the authorization server, a response to the cryptographic communication rights request that requests a replacement cryptographic code module update, comprising an identification of a subset of the plurality of constrained devices that have cryptographic communication rights in common with the identified first of the plurality of constrained devices;

wherein providing, by the authorization server, the response comprising the identification of the subset of the plurality of constrained devices that have cryptographic communication rights comprises determining which of the plurality of constrained devices have cryptographic communication rights with the identified first constrained device based on authorized communication rights authorized by the authorization server; and

wherein the issued asymmetric key based configuration certificates or symmetric key based tickets further include data identifying an action that the subject constrained device is permitted to perform on another constrained device.

2. The method of claim 1 comprising provisioning, by a software update server, the replacement cryptographic code module, in response to the cryptographic algorithm update request, to the subset of the plurality of constrained devices that have cryptographic communication rights with the identified first of the plurality of constrained devices, wherein the replacement cryptographic code module comprises at least one of: a data encryption code module, a key encryption code module, a data signature code module, a key agreement code module and a data digest code module.

3. The method of claim 1 comprising issuing the cryptographic communication rights request by a software update server in response to the software update server receiving the cryptographic algorithm update request.

4. The method of claim 1 comprising issuing the cryptographic communication rights request by a network management device in response to the network management device receiving the cryptographic algorithm update request.

5. An apparatus comprising:

one or more hardware processors operative to:

issue cryptographic communication rights among a plurality of constrained devices where each of the plurality of constrained devices comprises no more than one cryptographic algorithm code module per cryptographic function;

receive a cryptographic communication rights request associated with at least a first of the plurality of constrained devices in response to a cryptographic algorithm update request that requests a replacement cryptographic code module update for a constrained device;

provide a response to the cryptographic communication rights request that requests a replacement cryptographic code module update, comprising an identification of a subset of the plurality of constrained devices that have cryptographic communication rights in common with the identified first of the plurality of constrained devices;

determine which of the plurality of constrained devices have cryptographic communication rights with the identified first constrained device based on authorized communication rights authorized by the authorization server,

wherein the one or more processors is operative to issue asymmetric key based configuration certificates or symmetric key based tickets to the plurality of constrained devices that include data identifying at least other constrained devices of the plurality of constrained devices with whom a subject constrained device is permitted to cryptographically communicate with to allow the plurality of constrained devices to cryptographically exchange information between specified ones of the plurality of constrained devices; and

wherein the issued asymmetric key based configuration certificates or symmetric key based tickets further include data identifying an action that the subject constrained device is permitted to perform on another constrained device.

6. A system comprising:

a plurality of constrained devices;

an authorization server, operatively coupled to the plurality of constrained devices, comprising logic operative to:

issue cryptographic communication rights among the plurality of constrained devices where each of the plurality of constrained devices comprises no more than one cryptographic algorithm code module per cryptographic function wherein issuing comprises issuing asymmetric key based configuration certificates or symmetric key based tickets to the plurality of constrained devices that include data identifying at least other constrained devices of the plurality of constrained devices with whom a subject constrained device is permitted to cryptographically communicate with to allow the plurality of constrained devices to cryptographically exchange information between specified ones of the plurality of constrained devices and wherein the issued asymmetric key based configuration certificates or symmetric key based tickets further include data identifying an action that the subject constrained device is permitted to perform on another constrained device;

receive a cryptographic communication rights request associated with at least a first of the plurality of constrained devices in response to a cryptographic algorithm update request that requests a replacement cryptographic code module update for a constrained device; and

provide a response to the cryptographic communication rights request that requests a replacement cryptographic code module update, comprising an identification of a subset of the plurality of constrained devices that have cryptographic communication rights in common with the identified first of the plurality of constrained devices;

determine which of the plurality of constrained devices have cryptographic communication rights with the identified first constrained device based on authorized communication rights authorized by the authorization server, and

a software update server, operatively coupled to the plurality of constrained devices and to the authorization server, comprising logic operative to provision a replacement cryptographic code module, in response to the cryptographic algorithm update request, to a subset of a plurality of constrained devices that have cryptographic communication rights with an identified first of the plurality of constrained devices, wherein the replacement cryptographic code module comprises at least one of: a data encryption code module, a key encryption code module, a data signature code module, a key agreement code module and a data digest code module.

7. The system of claim 6 comprising a network management server operative to send the cryptographic communication rights request.

Assignments (3)
MERGER Recorded Mar 18, 2024
From: ENTRUST, INC.
To: ENTRUST CORPORATION
Reel/Frame 066806/0175 →
SECURITY AGREEMENT Recorded Apr 16, 2018
From: ENTRUST, INC.
To: BMO HARRIS BANK N.A., AS AGENT
Reel/Frame 045945/0602 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2016
From: MOSES, TIMOTHY E.
To: ENTRUST, INC.
Reel/Frame 040692/0868 →
Continuity (2)
Provisional Application 62195032 · Jul 21, 2015
Related Publication 20170026185A1 · Jan 26, 2017
Cited By (1)
US 12,432,060