IP Library › Granted Patent US 12,388,627
Granted Patent B2
US 12,388,627 · App. 18/620,485 · Granted Aug 12, 2025

Internet of Things security with multi-party computation (MPC)

Inventors: Patrícia Raquel Vieira Sousa (Oporto, PT); João Miguel Maia Soares de Resende (Oporto, PT); Rolando da Silva Martins (Oporto, PT); Luís Filipe Coelho Antunes (Oporto, PT)
Assignees: INESC TEC—INSTITUTO DE ENGENHARIA DESISTEMAS E COMPUTADORES, TECNOLOGIA E CIÊNCIA; U.PORTO—UNIVERSIDADE DO PORTO
H04L9/0841G16Y30/10H04L63/0435H04L63/061H04L63/0869H04L67/12G06F7/582H04L2209/46H04L2209/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,388,627
App. No.
18/620,485
Granted
Aug 12, 2025
Kind
B2
Abstract

A method and device for establishing a communication along a communications channel between a first device ( 200 A) and a second device ( 200 B). The method comprises mutually discovering the first device ( 200 A) and the second device ( 200 B), validating (F5, F6, F7) the communications channel between the first device ( 200 A) and the second device ( 200 B) by exchange of data messages, exchanging a secret between the first device ( 200 A) and the second device ( 200 B) and then exchanging encrypted messages along the communications channel.

Claims (19)

1. A method for establishing a peer-to-peer communication in an IoT network using encrypted messages along a communications channel between a first device and a second device comprising:

mutually discovering the first device and the second device;

validating the communications channel by establishing secret session keys for the communications channel between the first device and the second device, wherein the secret session keys are computed using symmetric keys;

calculating, from the secret session keys, a first authentication string (SAS) in the first device and a second authentication string (SAS) in the second device;

inserting the first calculated SAS in a first multiparty computation (MPC) module of the first device and the second calculated SAS in a second multiparty computation (MPC) module of the second device and confirming security of the communications channel by evaluating the first SAS in the second MPC module of the second device and the second SAS in the first MPC module of the first device;

establishing, in the event of the confirmation of the security of the communications channel, a shared secret between the first device and the second device using the computed secret session key; and

exchanging the encrypted messages along the communications channel.

2. The method of claim 1 , wherein the mutual discovering comprises providing identifiers between the first device and the second device.

3. The method of claim 2 , wherein the providing of an identifier between the first device and the second device comprising exchanging initiation and acknowledgement messages between the first device and the second device, the initiation and acknowledgement messages include the identifiers.

4. The method of claim 3 , wherein the identifiers are provided by generating a random number identification of at least one of the first device and the second device.

5. The method of claim 2 , wherein the providing identifiers comprises receiving identifiers of the first device and the second device from a server.

6. The method of claim 1 , wherein the validating comprises a first key exchange from the first device to the second device and a second key exchange from the second device to the first device.

7. The method of claim 1 , further comprising sending a confirm message from the first device to the second device and a confirm message from the second device to the first device after successful comparison of the exchanged messages.

8. The method of claim 7 , wherein a first secret key in the first key exchange is generated from a previous first secret key and a second secret key in the second key exchange is generated from a previous second secret key.

9. The method of claim 1 , wherein the validating of the communications channel is carried out before exchanging every message along the communications channel.

10. The method of claim 1 , wherein the validating of the communications channel is carried out only after exchanging a number of messages along the communications channel.

11. The method of claim 1 , wherein the mutual discovering of the first device and the second device is carried out by automatic exchange of messages between the first device and the second device by one of a direct communication or using a server.

12. A use of the method of claim 1 in a network comprising a plurality of IoT devices or including those on moving vehicles.

13. The method of claim 1 , wherein symmetric keys are cached in a Z Real-time Transport Protocol (ZRTP).

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2024
From: INESC TEC – INSTITUTO DE ENGENHARIA DESISTEMAS E COMPUTADORES, TECNOLOGIA E CIÊNCIA
To: U.PORTO - UNIVERSIDADE DO PORTO
Reel/Frame 069259/0990 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2024
From: VIEIRA SOUSA, PATRÍCIA RAQUEL; SOARES DE RESENDE, JOÃO MIGUEL MAIA; MARTINS, ROLANDO DA SILVA; ANTUNES, LUÍS FILIPE COELHO
To: INESC TEC – INSTITUTO DE ENGENHARIA DESISTEMAS E COMPUTADORES, TECNOLOGIA E CIÊNCIA
Reel/Frame 066941/0097 →
Priority Claims (2)
PT 20181000034529 · May 16, 2018 · national
EP 18174412 · May 25, 2018 · regional
Continuity (3)
Continuation 18099156 · Jan 19, 2023
Continuation 17055671
Related Publication 20240243907A1 · Jul 18, 2024
References Cited (51)
US 7730309B2 · Zimmermann · 2010 [cited by applicant]
US 9467425B2 · Epp · 2016 [cited by examiner]
US 20050251680A1 · Brown · 2005 [cited by examiner]
US 20070157026A1 · Zimmermann · 2007 [cited by examiner]
US 20150288667A1 · Alder · 2015 [cited by examiner]
US 20170023038A1 · Izuhara · 2017 [cited by applicant]
US 20180332030A1 · Wu · 2018 [cited by examiner]
JP 2005099980A · 2005 [cited by applicant]
JP 2005354556A · 2005 [cited by applicant]
JP 2006332903A · 2006 [cited by applicant]
Zimmerman Zfone Project, A Johnston P, et al “ZRTP: Media Path Key Agreement for Unicast Secure RTP”; RCF6189.txt, ZRPT: Media Path Key Agreement for Unicast Secure RTP; RFC6189.txt, Internet Engineering Task Force, IET… [cited by applicant]
Ming Li, et al: “Group Device Pairing based Secure Sensor Association and Key Management for Body Area Networks”, INFOCOM, 2010 Proceedings IEEE, Piscataway, NJ, USA, Mar. 14, 2010, pp. 1-9. [cited by applicant]
Hu Tao, et al: “Preference-Based Privacy Protection Mechanism for the Internet of Things”, Information Science and Engineering (ISISE), 2010 International Symposium on, IEEE, Dec. 24, 2010, pp. 531-534. [cited by applicant]
Zhen Yan et al: “A survey on trust management for Internet of Things”, Journal of Network and Computer Applications, vol. 42, Jun. 1, 2014, pp. 120-134. [cited by applicant]
Yang, Yuchen, et al. “A Survey on Security and Privacy Issues in Internet-of-Things.” IEEE Internet of Things Journal (2017). [cited by applicant]
H. Sundmaeker, P. Guillemin, P. Friess and S. Woelffle, “Vision and Challenges for Realising the Internet of Things,” Cluster of European Research Projects on the Internet of Things, 2010. [cited by applicant]
Aman, Muhammad, Kee Chaing Chua, and Biplab Sikdar. “Mutual Authentication in IoT Systems using Physical Unclonable Functions.” IEEE Internet of Things Journal (2017). [cited by applicant]
Umar, Amjad. Information Security and Auditing in the Digital Age. nge solutions, inc, 2003. [cited by applicant]
Hao, Feng, and Peter YA Ryan. “Password authenticated key exchange by juggling.” International Workshop on Security Protocols. Springer Berlin Heidelberg, 2008. [cited by applicant]
Lancrenon, Jean, Marjan Å krobot, and Qiang Tang. “Two More Efficient Variants of the J-PAKE Protocol.” International Conference on Applied Cryptography and Network Security. Springer International Publishing, 2016. [cited by applicant]
Hao, Feng. “J-pake: Password authenticated key exchange by juggling.” (2016). [cited by applicant]
Hao, Feng., Ed. “Schnorr NIZK Proof: Non-interactive Zero Knowledge Proof for Discrete Logarithm” (2013). [cited by applicant]
Seo, Dong Hwi, and P. Sweeney. “Simple authenticated key agreement algorithm.” Electronics Letters 35.13 (1999): 1073-1074. [cited by applicant]
Goldreich, Oded. “Secure multi-party computation.” Manuscript. Preliminary version (1998): 86-97. [cited by applicant]
Toorani, Mohsen. “Security analysis of J-PAKE.” Computers and Communication (ISCC), 2014 IEEE Symposium on. IEEE, 2014. [cited by applicant]
Yao, Andrew C. “Protocols for secure computations.” Foundations of Computer Science, 1982. SFCS'08. 23rd Annual Symposium on. IEEE, 1982. [cited by applicant]
Hirt, Martin, Ueli Maurer, and Bartosz Przydatek. “Efficient secure multi-party computation.” International Conference on the Theory and Application of Cryptology and Information Security. Springer Berlin Heidelberg, 20… [cited by applicant]
C++ Implementation of ZRTP protocol—GNU ZRTP C++—https://github.com/wernerd/ZRTPCPP [Online; Accessed Mar. 30, 2017]. [cited by applicant]
Petraschek, Martin, et al. “Security and Usability Aspects of Man-in-the-Middle Attacks on ZRTP.” J. UCS 14.5 (2008): 673-692. [cited by applicant]
Demmler, Daniel, Thomas Schneider, and Michael Zohner, ABY—A Framework for Efficient Mixed-protocol Secure Two-party Computation, NDSS. 2015, https://github.com/encryptogroup/ABY [Online; Accessed Sep. 15, 2017]. [cited by applicant]
Keller, Marcel, Emmanuela Orsini, and Peter Scholl. “MASCOT: faster malicious arithmetic secure computation with oblivious transfer.” Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security… [cited by applicant]
Huang, Yan, Jonathan Katz, and David Evans. “Quid-pro-quo-tocols: Strengthening semi-honest protocols with dual execution.” Security and Privacy (SP), 2012 IEEE Symposium on. IEEE, 2012. [cited by applicant]
Sakarindr, Pitipatana, and Nirwan Ansari. “Security services in group communications over wireless infrastructure, mobile ad hoc, and wireless sensor networks.” IEEE Wireless Communications 14.5 (2007). [cited by applicant]
Laud, Peeter, and Liina Kamm, eds. Applications of Secure Multiparty Computation. vol. 13. IOS Press, 2015. [cited by applicant]
Device Pairing Using Short Authentication Strings (2016) https://tools.ietf.org/id/draft-ietf-dnssd-pairing-01.html [Online; Accessed Apr. 21, 2017]. [cited by applicant]
TLS Handshaking With Certificates and Keys (2017) https://mcuoneclipse.files.wordpress.com/2017/04/tls-handshaking-with-certificates-and-keys.png [Online; Accessed Apr. 25, 2017]. [cited by applicant]
Lyrebird claims it can recreate any voice using just one minute of sample audio. (2017) http://www.theverge.com/2017/4/24/15406882/ai-voice-synthesis-copy-human-speech-lyrebird [Online; Accessed Apr. 25, 2017]. [cited by applicant]
Martini, S.: Session Key Retrieval in J-PAKE Implementations of OpenSSL and OpenSSH. (2010) http://seb.dbzteam.org/crypto/jpake-session-key-retrieval.pdf [Online; Accessed Mar. 4, 2017]. [cited by applicant]
Thermos, Peter, and Ari Takanen. Securing VoIP Networks. Pearson Education, 2007. [cited by applicant]
Canetti, Ran. “Obtaining universally compoable security: Towards the bare bones of trust.” International Conference on the Theory and Application of Cryptology and Information Security. Springer Berlin Heidelberg, 2007. [cited by applicant]
Let's Encrypt issues certs to ‘PayPal’ phishing sites: how to protect yourself (2017) http://bit.ly/2i7Z4bT [Online; Accessed May 19, 2017]. [cited by applicant]
Yao, Andrew Chi-Chih. “How to generate and exchange secrets.” Foundations of Computer Science, 1986., 27th Annual Symposium on. IEEE, 1986. [cited by applicant]
Yao, Andrew C. “Theory and application of trapdoor functions.” Foundations of Computer Science, 1982. SFCS'08. 23rd Annual Symposium on. IEEE, 1982. [cited by applicant]
Lindell, Yehuda, and Benny Pinkas. “Secure multiparty computation for privacy-preserving data mining.” Journal of Privacy and Confidentiality 1.1 (2009): 5. APA. [cited by applicant]
McGrew, D., et al. “RFC 3711: The secure real-time transport protocol (SRTP).” Cisco Systems, Inc and Ericsson Research, Tech. Rep (2004). [cited by applicant]
Sisalem, Dorgham, et al. SIP security. John Wiley & Sons, 2009. [cited by applicant]
Hlavacs, Helmut, et al. “Enhancing ZRTP by using Computational Puzzles.” J. UCS 14.5 (2008): 693-716. [cited by applicant]
Afifi, M. H., et al. “Dynamic Authentication Protocol Using Self-Powered Timers for Passive Internet of Things.” IEEE Internet of Things Journal (2017). [cited by applicant]
Pass, Rafael. “Bounded-concurrent secure multi-party computation with a dishonest majority.” Proceedings of the thirty-sixth annual ACM symposium on Theory of computing. ACM, 2004. [cited by applicant]
Bresciani R, “The ZRTP Protocol Analysis on the Diffie-Hellman Mode”, Trinity College Dublin, Computer Science Department Technical Report, Jun. 12, 2009. [cited by applicant]
Hoepman Jaap-Henk, “The Ephemeral Pairing Problem”, The Department of Computer Science, University of Nijmegen, NL, Feb. 6, 2008. [cited by applicant]