IP Library › Granted Patent US 11,882,449
Granted Patent B1
US 11,882,449 · App. 17/220,446 · Granted Jan 23, 2024

Systems and methods for protecting cellular network messages

Inventor: Tao Wan (Ottowa, CA)
Assignee: Cable Television Laboratories, Inc.
H04W12/106H04L9/3242H04L9/3247H04L9/3263H04L9/3297H04W4/06H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,882,449
App. No.
17/220,446
Granted
Jan 23, 2024
Kind
B1
Abstract

A client-side electronic device includes a receiver, a processor, and a memory. The receiver communicates with a message server over a communication medium of a communication network. The memory stores computer-executable instructions, which, when executed by the processor, cause the device to receive, from the message server, a broadcast message, a timestamp associated with the broadcast message, and a first digital signature of the broadcast message and a second digital signature of the timestamp. The executed instruction further cause the device to verify an integrity of the broadcast message based the first or second digital signatures, determine a freshness of the broadcast message based on the received timestamp, calculate a trust state of the broadcast message based on the integrity verification and the freshness determination, and store the broadcast message in the memory along with the calculated trust state.

Claims (27)

1. A message server for broadcasting messages over a communication network, comprising:

a transceiver configured for operable communication with a signing server and at least one client-side device over a communication medium of the communication network;

a processor including a memory configured to store computer-executable instructions, which, when executed by the processor, cause the message server to:

transmit a digital signing request to the signing server;

receive, from the signing server, a signing response to the digital signing request, wherein the signing response includes a digital certificate;

compute a digital signature over a Master Information Block (MIB), a System Information Block (SIB), and a timestamp;

transmit the MIB and SIB to the client-side device; and

transmit a message comprising the timestamp, the digital signature, and the digital certificate to the client-side device.

2. The message server of claim 1 , wherein the message server comprises a gNB.

3. The message server of claim 1 , wherein the client-side device is configured to verify the signature and the timestamp.

4. The message server of claim 1 , wherein an access and mobility management function (AMF) is disposed as a first interface between the message server and the signing server.

5. The message server of claim 4 , wherein the AMF includes a second interface between the signing server and a plurality of different message servers.

6. The message server of claim 4 , wherein the instructions further cause the message server to open a connection to the AMF prior to transmitting the digital signing request.

7. The message server of claim 6 , wherein the instructions further cause the message server to close the connection to the AMF subsequent to receiving the digital certificate.

8. The message server of claim 1 , wherein the digital certificate is short-lived and includes an expiration time.

9. The message server of claim 8 , wherein the instructions further cause the message server to replace the short-lived digital certificate on a periodic basis.

10. The message server of claim 1 , wherein the digital certificate has a short key length.

11. The message server of claim 1 , wherein the instructions further cause the message server to:

generate a public and private key pair; and

generate the digital signing request based on the public and private key pair.

12. The message server of claim 1 , wherein the instructions further cause the message server to:

generate a key chain including at least 64 iterations, wherein a last iteration of the key chain is an anchor key; and

compute the digital signature over the Master Information Block (MIB), the System Information Block (SIB), the timestamp, and the anchor key.

13. The message server of claim 12 , wherein the instructions further cause the message server to:

generate a plurality of message authentication codes (MAC) for a plurality of values of dynamic content;

iterate through the plurality of values of dynamic content by transmitting the MIB, the SIB, and a MAC associated with the current value of dynamic content to the client-side device; and

transmit the message comprising the timestamp, the anchor key, the digital signature, and a current key of the key chain to the client-side device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2021
From: WAN, TAO
To: CABLE TELEVISION LABORATORIES, INC.
Reel/Frame 055799/0514 →
Continuity (6)
Continuation In Part 17102169 · Nov 23, 2020
Provisional Application 62938870 · Nov 21, 2019
Provisional Application 63135461 · Jan 8, 2021
Provisional Application 63108014 · Oct 30, 2020
Provisional Application 63003373 · Apr 1, 2020
Provisional Application 63014890 · Apr 24, 2020
Cited By (2)
US 12,519,655 US 12,695,631