IP Library Granted Patent US 11,758,393
Granted Patent B1
US 11,758,393 · App. 17/709,789 · Granted Sep 12, 2023

VPN authentication with forward secrecy

Inventors: Igor Stolbikov (Apex, NC); John M. Petersen (Wake Forest, NC); Gary D. Cudak (Wake Forest, NC); Nathan Peterson (Oxford, NC)
Assignee: Lenovo (Singapore) Pte. Ltd.
H04W12/041H04L9/088H04L9/0841H04L9/3066H04L9/3236H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,758,393
App. No.
17/709,789
Granted
Sep 12, 2023
Kind
B1
Abstract

Various disclosed embodiments include illustrative apparatuses, methods, and program products. In an illustrative embodiment, an apparatus includes a processor, a network interface, and a memory that stores code executable by the processor. The code receives signed keys from a computing device over a network via the network interface. The signed keys include a key signed by a mobile device associated with the computing device and the signed keys were generated responsive to a first key agreement protocol configured to provide one of forward secrecy protection and time-based expiration. The code authenticates the received signed keys responsive to prior knowledge of public keys associated with at least one of the computing device and the mobile device according to a second key agreement protocol configured to provide one of forward secrecy protection and time-based expiration and code that initiates a communication between the processor and the device responsive to the received signed keys being authenticated.

Claims (43)

1. An apparatus comprising:

a processor;

a network interface; and

a memory that stores code executable by the processor, the code comprising:

code that receives signed keys from a computing device over a network via the network interface, wherein the signed keys include a key signed by a mobile device associated with the computing device and wherein the signed keys were generated responsive to a first key agreement protocol configured to provide one of forward secrecy protection, post-compromise protection, and reply attack protection in the form of time-based expiration;

code that authenticates the received signed keys responsive to prior knowledge of public keys associated with at least one of the computing device and the mobile device according to a second key agreement protocol configured to provide one of forward secrecy protection, post-compromise protection, and reply attack protection in the form of time-based expiration; and

code that initiates a communication between the processor and the computing device responsive to the received signed keys being authenticated.

2. The apparatus of claim 1 , wherein the code further comprising:

code that receives encrypted session data; and

code that decrypts the encrypted session data,

wherein the session data was signed based on the second key agreement protocol.

3. The apparatus of claim 1 , wherein the first key agreement protocol is configured to provide forward secrecy protection and time-based expiration, and the second key agreement protocol configured to provide one of forward secrecy protection and time-based expiration.

4. The apparatus of claim 1 , wherein the first and second key agreement protocols include extended triple Diffie-Hellman protocol.

5. The apparatus of claim 1 , wherein the first and second key agreement protocols include elliptical curve Diffie-Hellman protocol.

6. The apparatus of claim 1 , wherein the first and second key agreement protocols include hashing cryptographic ratcheting.

7. The apparatus of claim 5 , wherein the hashing cryptographic ratcheting includes double ratcheting.

8. The apparatus of claim 1 , wherein the initiated communication includes communication over a virtual private network (VPN).

9. A method comprising:

at a server apparatus,

receiving signed keys from a computing device over a network via the network interface, wherein the signed keys include a key signed by a mobile device associated with the computing device and wherein the signed keys were generated responsive to a first key agreement protocol configured to provide one of forward secrecy protection, post-compromise protection, and reply attack protection in the form of time-based expiration;

authenticating the received signed keys responsive to prior knowledge of public keys associated with at least one of the computing device and the mobile device according to a second key agreement protocol configured to provide one of forward secrecy protection, post-compromise protection, and reply attack protection in the form of time-based expiration; and

initiating a communication between the processor and the computing device responsive to the received signed keys being authenticated.

10. The method of claim 9 , further comprising:

at the server apparatus,

receiving encrypted session data; and

decrypting the encrypted session data,

wherein the session data was signed based on the second key agreement protocol.

11. The method of claim 9 , wherein the first key agreement protocol is configured to provide forward secrecy protection and time-based expiration, and the second key agreement protocol configured to provide one of forward secrecy protection and time-based expiration.

12. The method of claim 9 , wherein the first and second key agreement protocols include extended triple Diffie-Hellman protocol.

13. The method of claim 9 , wherein the first and second key agreement protocols include elliptical curve Diffie-Hellman protocol.

14. The method of claim 9 , wherein the first and second key agreement protocols include hashing cryptographic ratcheting.

15. The method of claim 9 , wherein the hashing cryptographic ratcheting includes double ratcheting.

16. The method of claim 9 , wherein the initiating a communication includes initiating communication over a virtual private network (VPN).

17. A program product comprising a non-transitory computer readable storage medium that stores code executable by a processor, the executable code comprising code to perform:

receiving signed keys from a computing device over a network via the network interface, wherein the signed keys include a key signed by a mobile device associated with the computing device and wherein the signed keys were generated responsive to a first key agreement protocol configured to provide one of forward secrecy protection, post-compromise protection, and reply attack protection in the form of time-based expiration;

authenticating the received signed keys responsive to prior knowledge of public keys associated with at least one of the computing device and the mobile device according to a second key agreement protocol configured to provide one of forward secrecy protection, post-compromise protection, and reply attack protection in the form of time-based expiration; and

initiating a communication between the processor and the computing device responsive to the received signed keys being authenticated.

18. The program product of claim 17 , the code to further perform:

receiving encrypted session data; and

decrypting the encrypted session data,

wherein the session data was signed based on the second key agreement protocol.

19. The program product of claim 17 , wherein the first and second key agreement protocols include one of extended triple Diffie-Hellman protocol or elliptical curve Diffie-Hellman protocol with a double ratcheting algorithm.

20. The program product of claim 17 , wherein the initiating a communication includes initiating communication over a virtual private network (VPN).

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: LENOVO PC INTERNATIONAL LIMITED
To: LENOVO SWITZERLAND INTERNATIONAL GMBH
Reel/Frame 070269/0092 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2025
From: LENOVO (SINGAPORE) PTE LTD.
To: LENOVO PC INTERNATIONAL LIMITED
Reel/Frame 070266/0925 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2022
From: LENOVO (UNITED STATES) INC.
To: LENOVO (SINGAPORE) PTE. LTD.
Reel/Frame 061880/0110 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2022
From: STOLBIKOV, IGOR; PETERSEN, JOHN M; CUDAK, GARY D; PETERSON, NATHAN
To: LENOVO (UNITED STATES) INC.
Reel/Frame 060028/0385 →
Cited By (2)
US 12,621,143 US 12,632,239