IP Library Granted Patent US 12,323,510
Granted Patent B1
US 12,323,510 · App. 18/608,780 · Granted Jun 3, 2025

Transmission of secure information in a content distribution network

Inventor: Xin Qiu (San Diego, CA)
Assignee: ARRIS Enterprises LLC
H04L9/083H04L9/0866H04L9/321
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,323,510
App. No.
18/608,780
Filed
Mar 18, 2024
Granted
Jun 3, 2025
Kind
B1
Art Unit
2435
USPC
380/277
Abstract

A method and apparatus for providing user key material from a server to a client is disclosed. The method comprises receiving a first message from the client in a server, the first message having a user key material request, an access token and an identifier of a transport key (TrK-ID), validating the user key material request according to the access token, generating a response having user key material responsive to the user key material request, encrypting the response according to the transport key (TrK), and transmitting a second message comprising the response from the server to the client. The client decrypts the second message according to the transport key (TrK) and validates the second message using the identifier of the transport key (TrK-ID).

Claims (70)

1. A method of provisioning user key material from a server to a client, comprising:

(a) receiving a request for user key material that contains (i) an access token to authenticate the client and (ii) an identifier of a transport key (TrK-ID) from the client by the server;

(b) authenticating the request for the user key material based upon the access token;

(c) generating a response for the provisioning of user key material responsive to the request for the user key material;

(d) encrypting the response for the provisioning of the user key material based upon a transport key (TrK) identified by the identifier of the transport key (TrK-ID);

(e) provisioning of user key material comprising the encrypted response from the server to the client further comprising the identifier of the transport key (TrK-ID);

(f) wherein the provisioning of user key material is configured to be decrypted according to the transport key (TrK) to recover a decrypted identifier of the transport key (TrK-ID) and validated using the decrypted identifier of the transport key (TrK-ID).

2. The method of claim 1 , wherein the provisioning of user key material is further configured in a manner capable of being validated by comparing the decrypted identifier of the transport key (TrK-ID) of the provisioning of key material to the identifier of the transport key (TrK-ID) of the decrypted message.

3. A method of provisioning user key material from a server to a client, comprising:

(a) receiving a request for user key material that contains (i) an access token to authenticate the request, (ii) an identifier of a transport key (TrK-ID), and (iii) an identifier of an integrity key (InK-ID) from the client by the server;

(b) authenticating the request for the user key material based upon the access token;

(c) generating a response for the provisioning of user key material responsive to the request for the user key material;

(d) encrypting the response for the provisioning of the user key material based upon a transport key (TrK) identified by the identifier of the transport key (TrK-ID);

(e) provisioning of user key material comprising the encrypted response from the server to the client further comprising the identifier of the transport key (TrK-ID) and the identifier of the integrity key (InK-ID);

(f) wherein the provisioning of user key material is configured to be decrypted according to the transport key (TrK) to further recover a decrypted identifier of the integrity key (InK-ID) and validated using a decrypted identifier of the transport key (TrK-ID).

4. The method of claim 3 , wherein the encrypted response is signed by the integrity key or the transport key and is further validated according to the signed encrypted response.

5. An apparatus for provisioning user key material from a server to a client, comprising:

a processor;

a memory, the memory communicatively coupled to the processor and storing processor instructions comprising processor instructions for:

(a) receiving a first request for user key material that contains (i) an access token and (ii) an identifier of a transport key (TrK-ID) from the client by the server;

(b) authenticating the request for the user key material based upon the access token;

(c) generating a response for the provisioning of user key material responsive to the request for the user key material;

(d) encrypting the response for the provisioning of the user key material based upon a transport key (TrK) identified by the identifier of the transport key (TrK-ID);

(e) provisioning of user key material comprising the encrypted response from the server to the client further comprising the identifier of the transport key (TrK-ID);

(f) wherein the provisioning of user key material is configured to be decrypted according to the transport key (TrK) to recover a decrypted identifier of the transport key (TrK-ID) and validated using the decrypted identifier of the transport key (TrK-ID).

6. The apparatus of claim 5 , wherein the provisioning of user key material is further configured to be validated by comparing a decrypted identifier of the transport key (TrK-ID) of the provisioning of key material to the identifier of the transport key (TrK-ID) of the decrypted message.

7. An apparatus for provisioning user key material from a server to a client, comprising:

a processor;

a memory, the memory communicatively coupled to the processor and storing processor instructions comprising processor instructions for:

(a) receiving a request or user key material the contains (i) an access token and (ii) an identifier of a transport key (TrK-ID) from the client by the server;

(b) authenticating the request for the user key material based upon the access token;

(c) generating a response for the provisioning of user key material responsive to the request for the user key material;

(d) encrypting the response for the provisioning of the user key material based upon a transport key (TrK) identified by the identifier of the transport key (TrK-ID);

(e) provisioning of key material comprising the encrypted response from the server to the client further comprising the identifier of the transport key (TrK-ID) and an identifier of an integrity key (InK-ID);

(f) wherein the provisioning of user key material is configured to be decrypted according to the transport key (TrK) to further recover a decrypted identifier of the integrity key (InK-ID) and validated using a decrypted identifier of the transport key (TrK-ID.

8. The apparatus of claim 7 , wherein the encrypted response is signed by the transport key or the integrity key and is further validated according to the signed encrypted response.

9. A method of receiving user key material by a client from a server, comprising:

(a) providing a first request for user key material that contains (i) an access token and (ii) an identifier of a transport key (TrK-ID) by the client to the server;

(b) wherein the first request is configured in a manner such that the user key material request is validated based upon the access token;

(c) receiving a provisioning of the user key material by the client from the server comprising an encrypted response comprising the identifier of the transport key (TrK-ID) that is encrypted according to a transport key (TrK) identified by the identifier of the transport key (TrK-ID) and having user key material responsive to the user key material request;

(d) decrypting the provisioning of the user key material based upon the transport key (TrK);

(e) validating the provisioning of the user key material using the identifier of the transport key (TrK-ID).

10. The method of claim 9 further comprising wherein the identifier of the transport key (TrK-ID) forms a part of a digital certificate certified by a trusted entity, and the provisioning of the user key material is validated via the digital certificate.

11. A method of receiving user key material by a client from a server, comprising:

(a) providing a first request for user key material that contains (i) an access token and (ii) an identifier of a transport key (TrK-ID) by the client to the server;

(b) wherein the first request is configured in a manner such that the user key material request is validated based upon the access token;

(c) receiving a provisioning of the user key material by the client from the server comprising an encrypted response that is encrypted based upon a transport key (TrK) identified by the identifier of the transport key (TrK-ID) and having user key material responsive to the user key material request;

(d) decrypting the provisioning of the user key material according to the transport key (TrK);

(e) validating the provisioning of the user key material using the identifier of the transport key (TrK-ID),

(f) wherein the identifier of the transport key (TrK-ID) is used together with a digital certificate certified by a trusted entity, and the provisioning of the user key material is validated based upon the digital certificate;

(g) wherein the encrypted response further comprises the identifier of the transport key (TrK-ID).

12. An apparatus for provisioning user key material from a server to a client, comprising:

a processor;

a memory, the memory communicatively coupled to the processor and storing processor instructions comprising processor instructions for:

(a) providing a first request for user key material that contains (i) an access token and (ii) an identifier of a transport key (TrK-ID) by the client to the server;

(b) wherein the first request is configured in a manner such that the user key material request is validated based upon the access token;

(c) receiving a provisioning of the user key material by the client from the server comprising an encrypted response comprising the identifier of the transport key (TrK-ID) that is encrypted according to a transport key (TrK) identified by the identifier of the transport key (TrK-ID) and having user key material responsive to the user key material request;

(d) decrypting the provisioning of the user key material based upon the transport key (TrK);

(e) validating the provisioning of the user key material using the identifier of the transport key (TrK-ID).

13. The apparatus of claim 12 further comprising wherein the identifier of the transport key (TrK-ID) forms a part of a digital certificate certified by a trusted entity, and the provisioning of the user key material is validated via the digital certificate.

14. An apparatus for provisioning user key material from a server to a client, comprising:

a processor;

a memory, the memory communicatively coupled to the processor and storing processor instructions comprising processor instructions for:

(a) providing a first request for user key material that contains (i) an access token and (ii) an identifier of a transport key (TrK-ID) by the client to the server;

(b) wherein the first request is configured in a manner such that the user key material request is validated based upon the access token;

(c) receiving a provisioning of the user key material by the client from the server comprising an encrypted response that is encrypted based upon a transport key (TrK) identified by the identifier of the transport key (TrK-ID) and having user key material responsive to the user key material request;

(d) decrypting the provisioning of the user key material according to the transport key (TrK);

(e) validating the provisioning of the user key material using the identifier of the transport key (TrK-ID);

(f) wherein the identifier of the transport key (TrK-ID) is used together with a digital certificate certified by a trusted entity, and the provisioning of the user key material is validated based upon the digital certificate;

(g) wherein the encrypted response further comprises the identifier of the transport key (TrK-ID).

Assignments (2)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
Continuity (3)
Continuation 17984989 · Nov 10, 2022
Continuation 16953017 · Nov 19, 2020
Provisional Application 62937768 · Nov 19, 2019
References Cited (11)
US 20050097362A1 · Winget · 2005 [cited by examiner]
US 20150052359A1 · Castillo · 2015 [cited by examiner]
US 20160188317A1 · Hilliar · 2016 [cited by examiner]
US 20180109378A1 · Fu · 2018 [cited by examiner]
US 20200296086A1 · Gray · 2020 [cited by examiner]
Motorola Solutions: “[33.180] R16 TrK-IO and InK-IO”, 3GPP Draft; S3-193998, vol. SA WG3, No. Reno (US); Nov. 18, 2019- Nov. 22, 2019 Nov. 11, 2019 (Nov. 11, 2019), XP051824338 (Year: 2019). [cited by examiner]
International Search Report and Written Opinion Re: Application No. PCT/US2020/061339 dated Feb. 10, 2021. [cited by applicant]
Motorola Solutions: “[33.180] R16 TrK-IO and InK-IO”, 3GPP Draft; S3-193998, vol. SA WG3, No. Reno (US); Nov. 18, 2019-Nov. 22, 2019 Nov. 11, 2019 (Nov. 11, 2019), XP051824338. [cited by applicant]
Samsung: “Security procedure for S-KMC and S-KMS”, 3GPP Draft; S3-194393, vol. SA WG3, No. Reno, US,; Nov. 18, 2019-Nov. 22, 2019 Nov. 11, 2019 (Nov. 11, 2019), XP051824703. [cited by applicant]
Motorola Solutions et al: “Fix KMS reference points”, 3GPP Draft; 33179_CR0002R2_(REL-13)_S3-160751 Rev of 698 Re\ of 479 to Fix KMS Reference Points, vol. SA WG3, No. San Jose del Cabo, Mexico; May 9, 2016-May 13, 2016… [cited by applicant]
Motorola Solutions: “[33.180] R16 TrK-IO and InK-IO indication”, 3GPP Draft; S3-201333, vol. SA WG3, No. e-Meeting; May 11, 2020-May 15, 2020 May 11, 2020 (May 11, 2020), XP051883085. [cited by applicant]