IP Library › Granted Patent US 12,287,965
Granted Patent B2
US 12,287,965 · App. 18/304,309 · Granted Apr 29, 2025

Dynamic group membership for devices

Inventors: Mitchell D. Adler (Cupertino, CA); Michael Brouwer (San Jose, CA); Andrew R. Whalley (San Francisco, CA); John C. Hurley (Santa Clara, CA); Richard F. Murphy (Boulder Creek, CA); David P. Finkelstein (Sunnyvale, CA)
Assignee: Apple Inc.
G06F3/0604G06F3/065G06F3/0683G06Q10/06G06Q10/10G06Q90/00H04L9/3268H04L67/1095H04W4/08H04L67/1044
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,287,965
App. No.
18/304,309
Granted
Apr 29, 2025
Kind
B2
Abstract

Some embodiments provide a method for a first device that identifies definitions of different groups of devices, each of which is defined by a set of properties required for a device to be a member. The method monitors properties of the first device to determine when the device is eligible for membership in a group. When the first device is eligible for membership in a first group of which the device is not a member, the method sends an application for membership in the first group signed with at least a private key of the device to at least one other device that is a member of the first group. When the first device becomes ineligible for membership in a second group of which the first device is a member, the method removes the device from the second group and notifies other devices that are members of the second group.

Claims (54)

1. A method implemented by a first computing device, the method comprising:

establishing at least one cryptographic key;

identifying, based on the at least one cryptographic key, a particular synchronization sub-group to which the at least one cryptographic key corresponds, wherein the particular synchronization sub-group is identified based on a file type associated with the at least one cryptographic key, a software application with which the at least one cryptographic key is associated, or some combination thereof;

tagging the at least one cryptographic key as being included in the particular synchronization sub-group; and

in response to determining that the first computing device and a second computing device both participate in the particular synchronization sub-group:

forming a secure channel with the second computing device,

encrypting, based on requirements of the secure channel used for communicating with the second computing device, the at least one cryptographic key to produce at least one encrypted cryptographic key, and

sending, over the secure channel, the at least one encrypted cryptographic key to the second computing device.

2. The method of claim 1 , wherein the secure channel is formed with the second computing device using an Off-the-Record (OTR) messaging protocol.

3. The method of claim 1 , wherein establishing the at least one cryptographic key comprises:

receiving information through an application executing on the first computing device, and

generating the at least one cryptographic key based on the information.

4. The method of claim 3 , wherein the information comprises:

a username and a password, and/or

a cryptographic credential.

5. The method of claim 1 , wherein the at least one cryptographic key is encrypted using a shared key for encrypting messages transmitted over the secure channel.

6. The method of claim 1 , further comprising, prior to sending the at least one encrypted cryptographic key to the second computing device:

encrypting the at least one encrypted cryptographic key using an additional key that is required to be possessed by both the first and second computing devices in order to participate in the particular synchronization sub-group.

7. At least one non-transitory computer readable storage medium configured to store instructions that, when executed by at least one processor included in a first computing device, cause the first computing device to carry out steps that include:

establishing at least one cryptographic key;

identifying, based on the at least one cryptographic key, a particular synchronization sub-group to which the at least one cryptographic key corresponds, wherein the particular synchronization sub-group is identified based on a file type associated with the at least one cryptographic key, a software application with which the at least one cryptographic key is associated, or some combination thereof;

tagging the at least one cryptographic key as being included in the particular synchronization sub-group; and

in response to determining that the first computing device and a second computing device both participate in the particular synchronization sub-group:

forming a secure channel with the second computing device,

encrypting, based on requirements of the secure channel used for communicating with the second computing device, the at least one cryptographic key to produce at least one encrypted cryptographic key, and

sending, over the secure channel, the at least one encrypted cryptographic key to the second computing device.

8. The at least one non-transitory computer readable storage medium of claim 7 , wherein the secure channel is formed with the second computing device using an Off-the-Record (OTR) messaging protocol.

9. The at least one non-transitory computer readable storage medium of claim 7 , wherein establishing the at least one cryptographic key comprises:

receiving information through an application executing on the first computing device, and

generating the at least one cryptographic key based on the information.

10. The at least one non-transitory computer readable storage medium of claim 9 , wherein the information comprises:

a username and a password, and/or

a cryptographic credential.

11. The at least one non-transitory computer readable storage medium of claim 7 , wherein the at least one cryptographic key is encrypted using a shared key for encrypting messages transmitted over the secure channel.

12. The at least one non-transitory computer readable storage medium of claim 7 , wherein the steps further include, prior to sending the at least one encrypted cryptographic key to the second computing device:

encrypting the at least one encrypted cryptographic key using an additional key that is required to be possessed by both the first and second computing devices in order to participate in the particular synchronization sub-group.

13. A first computing device, comprising:

at least one processor; and

at least one memory storing instructions that, when executed by the at least one processor, cause the first computing device to carry out steps that include:

establishing at least one cryptographic key;

identifying, based on the at least one cryptographic key, a particular synchronization sub-group to which the at least one cryptographic key corresponds, wherein the particular synchronization sub-group is identified based on a file type associated with the at least one cryptographic key, a software application with which the at least one cryptographic key is associated, or some combination thereof;

tagging the at least one cryptographic key as being included in the particular synchronization sub-group; and

in response to determining that the first computing device and a second computing device both participate in the particular synchronization sub-group:

forming a secure channel with the second computing device,

encrypting, based on requirements of the secure channel used for communicating with the second computing device, the at least one cryptographic key to produce at least one encrypted cryptographic key, and

sending, over the secure channel, the at least one encrypted cryptographic key to the second computing device.

14. The first computing device of claim 13 , wherein the secure channel is formed with the second computing device using an Off-the-Record (OTR) messaging protocol.

15. The first computing device of claim 13 , wherein establishing the at least one cryptographic key comprises:

receiving information through an application executing on the first computing device, and

generating the at least one cryptographic key based on the information.

16. The first computing device of claim 15 , wherein the information comprises:

a username and a password, and/or

a cryptographic credential.

17. The first computing device of claim 13 , wherein the at least one cryptographic key is encrypted using a shared key for encrypting messages transmitted over the secure channel.

Continuity (5)
Continuation 16427235 · May 30, 2019
Continuation 14872022 · Sep 30, 2015
Provisional Application 62172127 · Jun 7, 2015
Provisional Application 62168893 · May 31, 2015
Related Publication 20230259276A1 · Aug 17, 2023
References Cited (50)
US 6671695B2 · McFadden et al. · 2003 [cited by applicant]
US 6732144B1 · Kizu et al. · 2004 [cited by applicant]
US 7346705B2 · Hullot et al. · 2008 [cited by applicant]
US 7441117B2 · Matsuzaki et al. · 2008 [cited by applicant]
US 7526649B2 · Wiseman et al. · 2009 [cited by applicant]
US 8458462B1 · Hanna et al. · 2013 [cited by applicant]
US 8892653B2 · Mallet et al. · 2014 [cited by applicant]
US 9054919B2 · Kiang et al. · 2015 [cited by applicant]
US 9077644B2 · Kreiner et al. · 2015 [cited by applicant]
US 9077759B2 · Brouwer et al. · 2015 [cited by applicant]
US 9124637B2 · Brouwer et al. · 2015 [cited by applicant]
US 10198182B2 · Adler et al. · 2019 [cited by applicant]
US 10318154B2 · Adler et al. · 2019 [cited by applicant]
US 20020143944A1 · Traversat et al. · 2002 [cited by applicant]
US 20040133640A1 · Yeager et al. · 2004 [cited by applicant]
US 20070019616A1 · Rantapuska et al. · 2007 [cited by applicant]
US 20090094367A1 · Song · 2009 [cited by examiner]
US 20090158041A1 · Kang et al. · 2009 [cited by applicant]
US 20090262674A1 · Suzuki · 2009 [cited by applicant]
US 20100161974A1 · Lee et al. · 2010 [cited by applicant]
US 20130036211A1 · Messer et al. · 2013 [cited by applicant]
US 20130067243A1 · Tamayo-Rios et al. · 2013 [cited by applicant]
US 20130290948A1 · Gokhale et al. · 2013 [cited by applicant]
US 20130332607A1 · Santamaria et al. · 2013 [cited by applicant]
US 20140053227A1 · Ruppin et al. · 2014 [cited by applicant]
US 20140208434A1 · Brouwer · 2014 [cited by examiner]
US 20140281540A1 · Brouwer · 2014 [cited by examiner]
US 20140289528A1 · Baghdasaryan · 2014 [cited by examiner]
US 20140289833A1 · Briceno · 2014 [cited by examiner]
US 20150215398A1 · Chang · 2015 [cited by examiner]
US 20150222700A1 · Kay et al. · 2015 [cited by applicant]
US 20150350106A1 · Whalley · 2015 [cited by applicant]
US 20160162279A1 · Zamir · 2016 [cited by applicant]
US 20160349999A1 · Adler et al. · 2016 [cited by applicant]
US 20160352526A1 · Adler et al. · 2016 [cited by applicant]
US 20160359965A1 · Murphy et al. · 2016 [cited by applicant]
CN 1682174A · 2005 [cited by applicant]
CN 102036181A · 2011 [cited by applicant]
KR 20100071666A · 2010 [cited by applicant]
WO 2016195798A1 · 2016 [cited by applicant]
International Patent Application No. PCT/US2016/025431—International Search Report and Written Opinion dated Jul. 4, 2016. [cited by applicant]
Author Unknown, “iOS Security,” Oct. 1, 2014, pp. 1-50, Apple Inc., US, available at https://www.apple.com/br/privacy/docs/IOS_Security_Guide_Oct_2014.pdf. [cited by applicant]
Takin, Halil Kemal, “End-to-end Encrypted Communication Between Multi-devise Users,” 7th International Conference on Information Security and Cryptology, Oct. 14, 2014, pp. 173-177, Istanbul, Turkey, available at http:/… [cited by applicant]
International Patent Application No. PCT/US2016/025440—International Search Report and Written Opinion dated Jul. 1, 2016. [cited by applicant]
European Patent Application No. 16718754.1—Examination Report dated Sep. 23, 2019. [cited by applicant]
Korean Patent Application No. 10-2019-7023625—Notice of Preliminary Rejection dated Aug. 19, 2019. [cited by applicant]
Chinese Patent Application No. 201680031832.7—Notification to Grant Patent Right dated Apr. 14, 2021. [cited by applicant]
Korean Patent Application No. 10-2021-7005075—Notice of Preliminary Rejection dated May 30, 2021. [cited by applicant]
Korean Patent Application No. 10-2022-7008901—Notice of Allolwance dated Jul. 27, 2022. [cited by applicant]
Mario Di Raimondo et al., “Secure Off-the-Record Messaging,” WPES05 (Nov. 7, 2005). [cited by applicant]
Cited By (1)
US 12,627,987