IP Library Granted Patent US 9,819,686
Granted Patent B2
US 9,819,686 · App. 15/215,187 · Granted Nov 14, 2017

Method and apparatus for providing an adaptable security level in an electronic communication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,819,686
App. No.
15/215,187
Granted
Nov 14, 2017
Kind
B2
Abstract

A method of communicating in a secure communication system, comprises the steps of assembling a message at a sender, then determining a security level, and including an indication of the security level in a header of the message. The message is then sent to a recipient.

Claims (32)

1. A method for providing security in an electronic communication system, comprising:

receiving a plurality of frames, wherein each individual frame in the plurality of frames has a header and associated data, the header of each individual frame including security control bits that indicate for the individual frame whether encryption has been provided for the individual frame and whether integrity has been provided for the individual frame, wherein the security control bits include one or more security mode bits and integrity level bits, wherein the one or more security mode bits are used to indicate whether encryption is on or off, and wherein the integrity level bits indicate which of at least four integrity levels is utilized, the integrity levels corresponding to signing operations of a sender of increasing strength; and

for each individual frame:

identifying a security level for the individual frame based on the security control bits in the header of the individual frame;

checking said security level against predetermined security requirements; and

rejecting the individual frame in response to said security level not meeting said predetermined security requirements.

2. The method of claim 1 , wherein said security level is selected based on said predetermined security requirements.

3. The method of claim 2 , wherein said predetermined security requirements are determined based on an agreed-upon rule.

4. The method of claim 1 , wherein said security control bits include an indication of a cryptographic algorithm parameter.

5. The method of claim 1 , further comprising decrypting each individual frame according to said security level for the individual frame.

6. The method of claim 1 , further comprising verifying the integrity of each individual frame according to said security level for the individual frame.

7. The method of claim 1 , wherein the number of integrity levels is four, and the four integrity levels correspond to key lengths of 0, 32, 64, and 128 bits.

8. The method of claim 1 , wherein one of the integrity levels uses a key length of 128 bits.

9. The method of claim 1 , wherein one of the integrity levels indicates no integrity security.

10. The method of claim 1 , wherein the number of integrity levels is at least four, and the at least four levels include four levels corresponding to key lengths of 0, 32, 64, and 128 bits.

11. A communication device, comprising:

at least one hardware processor;

a non-transitory computer-readable storage medium coupled to the at least one hardware processor and storing programming instructions for execution by the at least one hardware processor, wherein the programming instructions instruct the at least one hardware processor to:

receive a plurality of frames, wherein each individual frame from the plurality of frames has a header and associated data, the header of each individual frame including security control bits that indicate for the individual frame whether encryption has been provided for the individual frame and whether integrity has been provided for the individual frame, wherein the security control bits include one or more security mode bits and integrity level bits, wherein the one or more security mode bits are used to indicate whether encryption is on or off, and wherein the integrity level bits indicate which of at least four integrity levels is utilized, the integrity levels corresponding to signing operations of a sender of increasing strength; and

for each individual frame:

identify a security level for the individual frame based on the security control bits in the header of the individual frame;

check said security level against predetermined security requirements for said communication device; and

reject the individual frame in response to said security level not meeting said predetermined security requirements.

12. The communication device of claim 11 , wherein said security level is selected based on said predetermined security requirements for said communication device.

13. The communication device of claim 12 , wherein said predetermined security requirements are determined based on an agreed-upon rule.

14. The communication device of claim 11 , wherein said security control bits include an indication of a cryptographic algorithm parameter.

15. The communication device of claim 11 , wherein the programming instructions further instruct the at least one hardware processor to decrypt each individual frame according to said security level for the individual frame.

16. The communication device of claim 11 , wherein the programming instructions further instruct the at least one hardware processor to verify the integrity of each individual frame according to said security level for the individual frame.

17. The communication device of claim 11 , wherein the number of integrity levels is four, and the four integrity levels correspond to key lengths of 0, 32, 64, and 128 bits.

18. The communication device of claim 11 , wherein one of the integrity levels uses a key length of 128 bits.

19. The communication device of claim 11 , wherein one of the integrity levels indicates no integrity security.

20. The communication device of claim 11 , wherein the number of integrity levels is at least four, and the at least four levels include four levels corresponding to key lengths of 0, 32, 64, and 128 bits.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2017
From: STRUIK, MARINUS
To: CERTICOM CORP.
Reel/Frame 042301/0431 →