IP Library › Granted Patent US 11,283,772
Granted Patent B2
US 11,283,772 · App. 16/874,501 · Granted Mar 22, 2022

Method and system for sending a message through a secure connection

Inventors: Sami Vaarala (Helsinki, FI); Antti Nuopponen (Espoo, FI)
Assignee: MPH Technologies OY
H04L63/0281H04L9/0841H04L9/0844H04L9/321H04L29/1249H04L61/256H04L63/0272H04L63/0428H04L63/061H04L63/08H04L63/123H04L63/164H04L29/1216H04L29/12481H04L61/157H04L61/2557H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,283,772
App. No.
16/874,501
Granted
Mar 22, 2022
Kind
B2
Abstract

The method and system enable secure forwarding of a message from a first computer to a second computer via an intermediate computer in a telecommunication network. A message is formed in the first computer or in a computer that is served by the first computer, and in the latter case, sending the message to the first computer. In the first computer, a secure message is then formed by giving the message a unique identity and a destination address. The message is sent from the first computer to the intermediate computer after which the destination address and the unique identity are used to find an address to the second computer. The current destination address is substituted with the found address to the second computer, and the unique identity is substituted with another unique identity. Then the message is forwarded to the second computer.

Claims (18)

1. An intermediate computer for secure forwarding of messages in a telecommunication network, comprising:

an intermediate computer configured to connect to a telecommunication network;

the intermediate computer configured to receive an encrypted signaling message from a first computer, the first computer being a mobile computer connected to the telecommunication network using a wireless connection;

the intermediate computer configured to access a first mapping between a first unique identity and an address of the first computer;

the intermediate computer configured to change the address of the first computer in the first mapping after receiving the encrypted signaling message from the first computer;

the intermediate computer configured to access a second mapping between a second unique identity and an address of a second computer;

the intermediate computer configured to receive from the first computer a first message containing a first encrypted payload and a single field containing the second unique identity, the first encrypted payload encrypted with a first encryption key derived from a key exchange protocol and the first message being encapsulated with an encapsulation protocol;

the intermediate computer configured to use the second unique identity and the second mapping to find the address of the second computer;

the intermediate computer configured to forward the first encrypted payload to the second computer using the encapsulation protocol, wherein the intermediate computer does not have the first encryption key;

the intermediate computer configured to receive from the second computer a second message containing a second encrypted payload and a single field containing the first unique identity, the second encrypted payload encrypted with a second encryption key derived from the key exchange protocol and the second message being encapsulated with the encapsulation protocol;

the intermediate computer configured to use the first unique identity and the first mapping to find the address of the first computer;

the intermediate computer configured to forward the second encrypted payload to the first computer using the encapsulation protocol, wherein the intermediate computer does not have the second encryption key; and

the intermediate computer configured to perform a retransmission protocol to prevent dropped messages between the first computer and the intermediate computer.

2. The intermediate computer of claim 1 , wherein the retransmission protocol is based on a sequence number.

3. The intermediate computer of claim 1 , wherein the retransmission protocol is based on a replay protection window.

4. The intermediate computer of claim 1 , wherein the encapsulation protocol is SSL or TLS.

5. The intermediate computer of claim 1 , wherein the encapsulation protocol supports NAT traversal.

6. The intermediate computer of claim 1 , wherein the encapsulation protocol is UDP.

Priority Claims (1)
FI 20020112 · Jan 22, 2002 · national
Continuity (7)
Continuation 15610979 · Jun 1, 2017
Continuation 15609312 · May 31, 2017
Continuation 15376558 · Dec 12, 2016
Continuation 15372208 · Dec 7, 2016
Continuation 13685544 · Nov 26, 2012
Continuation 10500930
Related Publication 20200274853A1 · Aug 27, 2020