IP Library Granted Patent US 11,063,958
Granted Patent B2
US 11,063,958 · App. 16/459,269 · Granted Jul 13, 2021

Method and apparatus for providing an adaptable security level in an electronic communication

Inventor: Marinus Struik (Toronto, CA)
Assignee: BlackBerry Limited
H04L63/105H04L9/088H04L63/0428H04L63/08H04L63/123H04L63/164H04L9/00H04L63/162H04W12/02H04W12/67
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,063,958
App. No.
16/459,269
Granted
Jul 13, 2021
Kind
B2
Abstract

A method of communicating in a secure communication system, comprises the steps of assembling a message at a sender, then determining a security level, and including an indication of the security level in a header of the message. The message is then sent to a recipient.

Claims (39)

1. A method for providing security in an electronic communication system, comprising:

preparing, by a communication device, a plurality of frames, wherein each individual frame in the plurality of frames has a header and data, wherein the preparing the plurality of frames comprises;

for each individual frame:

determining a security level for the individual frame, the security level indicating whether to provide encryption for the individual frame and whether to provide integrity for the individual frame;

based on the security level, including security control bits in the header of the individual frame, wherein the security control bits include one or more security mode bits and integrity level bits, the one or more security mode bits indicate whether encryption is on or off, the integrity level bits indicate which of at least three integrity levels is utilized, the integrity levels corresponding to signing operations of a sender of increasing strength; and

encrypting the data according to the security level for the frame; and

transmitting the plurality of frames to a recipient device.

2. The method of claim 1 , further comprising receiving a frame, wherein the frame indicates a version of a key to be used in an encryption system.

3. The method of claim 1 , wherein the communication device provides the plurality of frames for transmission to a plurality of recipients, and determining the security level includes determining a minimum security level to satisfy the plurality of recipients, wherein the security control bits are based on the minimum security level.

4. The method of claim 1 , wherein the security level is determined based on predetermined minimum requirements.

5. The method of claim 4 , wherein the predetermined minimum requirements are determined among the communication device and at least one recipient device based on an agreed-upon rule.

6. The method of claim 1 , wherein the security level is determined based upon content of the individual frame.

7. The method of claim 1 , wherein the security control bits include an indication of a cryptographic algorithm parameter.

8. The method of claim 1 , further comprising: signing the header and data for each individual frame according to the security level for the frame.

9. The method of claim 1 , wherein a number of integrity levels is three, and the integrity levels correspond to key lengths of 32, 64, and 128 bits.

10. The method of claim 1 , wherein one of the integrity levels uses a key length of 128 bits.

11. A communication device, comprising:

at least one hardware processor; and

a non-transitory computer-readable storage medium coupled to the at least one hardware processor and storing programming instructions for execution by the at least one hardware processor, wherein the programming instructions, when executed, cause the communication device to perform operations comprising:

preparing, by the communication device, a plurality of frames, wherein each individual frame in the plurality of frames has a header and data, wherein the preparing the plurality of frames comprises;

for each individual frame:

determining a security level for the individual frame, the security level indicating whether to provide encryption for the individual frame and whether to provide integrity for the individual frame;

based on the security level, including security control bits in the header of the individual frame, wherein the security control bits include one or more security mode bits and integrity level bits, the one or more security mode bits indicate whether encryption is on or off, the integrity level bits indicate which of at least three integrity levels is utilized, the integrity levels corresponding to signing operations of a sender of increasing strength; and

encrypting the data according to the security level for the frame; and

transmitting the plurality of frames to a recipient device.

12. The communication device of claim 11 , the operations further comprising receiving a frame, wherein the frame indicates a version of a key to be used in an encryption system.

13. The communication device of claim 11 , wherein the communication device provides the plurality of frames for transmission to a plurality of recipients, and determining the security level includes determining a minimum security level to satisfy the plurality of recipients, wherein the security control bits are based on the minimum security level.

14. The communication device of claim 11 , wherein the security level is determined based on predetermined minimum requirements.

15. The communication device of claim 14 , wherein the predetermined minimum requirements are determined among the communication device and at least one recipient device based on an agreed-upon rule.

16. The communication device of claim 11 , wherein the security level is determined based upon content of the individual frame.

17. A non-transitory computer-readable medium storing instructions which, when executed, cause a communication device to perform operations comprising:

preparing, by the communication device, a plurality of frames, wherein each individual frame in the plurality of frames has a header and data, wherein the preparing the plurality of frames comprises;

for each individual frame:

determining a security level for the individual frame, the security level indicating whether to provide encryption for the individual frame and whether to provide integrity for the individual frame;

based on the security level, including security control bits in the header of the individual frame, wherein the security control bits include one or more security mode bits and integrity level bits, the one or more security mode bits indicate whether encryption is on or off, the integrity level bits indicate which of at least three integrity levels is utilized, the integrity levels corresponding to signing operations of a sender of increasing strength; and

encrypting the data according to the security level for the frame; and

transmitting the plurality of frames to a recipient device.

18. The non-transitory computer-readable medium of claim 17 , the operations further comprising receiving a frame, wherein the frame indicates a version of a key to be used in an encryption system.

19. The non-transitory computer-readable medium of claim 17 , wherein the communication device provides the plurality of frames for transmission to a plurality of recipients, and determining the security level includes determining a minimum security level to satisfy the plurality of recipients, wherein the security control bits are based on the minimum security level.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2020
From: STRUIK, MARINUS
To: CERTICOM CORP.
Reel/Frame 051506/0303 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2020
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 051506/0322 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
Continuity (7)
Continuation 15811194 · Nov 13, 2017
Continuation 15215187 · Jul 20, 2016
Continuation 14877072 · Oct 7, 2015
Continuation 14477637 · Sep 4, 2014
Continuation 10885115 · Jul 7, 2004
Provisional Application 60484656 · Jul 7, 2003
Related Publication 20190394207A1 · Dec 26, 2019