US2016365982A1PendingUtilityA1
System and method for secure end-to-end messaging system
Est. expiryMay 7, 2035(~8.8 yrs left)· nominal 20-yr term from priority
H04L 9/3247H04L 2209/24H04L 67/02H04L 2209/72H04L 63/0428H04L 63/168H04L 9/0841H04L 63/068H04L 9/3066H04L 9/3271H04L 63/045H04L 9/0869H04L 9/3242
45
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
The present invention provides an efficient secure end-to-end messaging system utilizing encrypted ephemeral messages. The method comprises the steps of using a combination of HTTPS for transport security, using symmetric key cryptography with rotating temporary keys for individual message security, and using elliptic curve cryptography for key derivation and message authentication. The key rotation scheme used provides forward secrecy between messages and sessions.
Claims
exact text as granted — not AI-modified1 . A method of securely transferring data during a communications session, comprising:
connecting to a communications server by sending a request over HTTPS with a registration header including a current key signature and an initialization vector; initiating a communications session in response to the request, wherein the communications session includes only users who sent the current key signature; receiving a list of all communications session users and their initialization vectors from the server; and broadcasting an encrypted message to the communications session, wherein the initialization vector (IVec) is part of the encrypted message's payload.
2 . The method of claim 1 , further comprising sending a resynchronization message to allow a new user into the communications session.
3 . The method of claim 2 , wherein the resynchronization message includes said current key signature and the initialization vector.
4 . The method of claim 1 , further comprising creating a subsequent key signature by concatenating the initialization vector (IVec) with said current key signature and hashing the result.
5 . The method of claim 4 , further comprising broadcasting a subsequent encrypted message to the communications session, wherein a new initialization vector (IVec) containing said subsequent key signature is part of the encrypted message's payload.
6 . The method of claim 1 , wherein connecting to the communications server further comprises a challenge response sequence.
7 . A non-transitory, computer-readable storage medium, comprising program instructions that when executed on one or more computers cause the one or more computers to perform:
connecting to a communications server by sending a request over HTTPS with a registration header including a key signature and an initialization vector; initiating a communications session among users in response to said request, wherein the communications session includes only clients who send the key signature; receiving a list of all communications session clients and their initialization vectors from the server; and broadcasting an encrypted message to the communications session, wherein the initialization vector (IVec) is part of the encrypted message's payload.
8 . The non-transitory, computer-readable storage medium of claim 7 , wherein each message in the communications session uses a rotating key.
9 . The non-transitory, computer-readable storage medium of claim 8 , further comprising sending a resynchronization message to allow a new user into the communications session.
10 . The non-transitory, computer-readable storage medium of claim 9 , wherein the resynchronization message includes said key signature and initialization vector.
11 . The non-transitory, computer-readable storage medium of claim 7 , further comprising creating a subsequent key signature by concatenating the initialization vector (IVec) with the key signature and hashing the result.
12 . The method of claim 11 , further comprising broadcasting a subsequent encrypted message to the communications session, wherein a new initialization vector (IVec) containing the subsequent key signature is part of the encrypted message's payload.
13 . The method of claim 7 , wherein connecting to the server further comprises a challenge response sequence.
14 . The method of claim 7 , wherein the communications session will issue challenges to the client at random intervals and the client is disconnected from the communications session if they do not respond within a predetermined amount of time.
15 . A method of securely transferring data during a communications session, comprising:
connecting to a communications server by sending a request over a communications protocol by providing a client id and a server key; validating the connection by a challenge response sequence; initiating a communications session by either randomly generating a symmetric key or generating a key based on a user provided passphrase; broadcasting an encrypted message to a set of communications participants, the encrypted message comprising a randomly generated salt used for calculating the next key for the session.
16 . The method of claim 15 , wherein the challenge response sequence further comprises a random 4-byte string challenge selected by the server to which the client must respond.
17 . The method of claim 16 , wherein the server continues to validate that the client is valid with every message sent.
18 . The method of claim 16 , wherein the server will issue challenges to the client at random intervals that the client must respond to.
19 . The method of claim 16 , wherein the communications device behaves as both a client and a server.Join the waitlist — get patent alerts
Track US2016365982A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.