Hardware Security Module
US-2021409210-A1 · Dec 30, 2021 · US
US12580901B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-12580901-B2 |
| Application number | US-202118041943-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jun 17, 2021 |
| Priority date | Sep 22, 2020 |
| Publication date | Mar 17, 2026 |
| Grant date | Mar 17, 2026 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Methods and apparatuses for secure communication between a first and a second communication partner are provided. The method for secure communication between a first and a second communication partner comprises establishing a communication link between the first and the second communication partner. Further, the method comprises determining one or more session identifiers by one of the first and the second communication partner. The method additionally comprises communicating the one or more session identifiers to the other of the first and the second communication partner. The method comprises determining, for each of the one or more session identifiers, a respective symmetric session key in each of the first and the second communication partner. In addition, the method comprises storing the one or more session identifiers and the corresponding symmetric session keys in each of the first and the second communication partner for one or more subsequent secure communication sessions.
Opening claim text (preview).
What is claimed is: 1 . A method for secure communication between a first and a second communication partner, comprising: establishing a communication link between the first and the second communication partner; determining one or more session identifiers by one of the first and the second communication partner for one or more subsequent new secure communication sessions wherein the one or more session identifiers are different from a session identifier of the communication link; communicating the one or more session identifiers to another of the first and the second communication partner using the communication link; determining, for each of the one or more session identifiers, a respective session-specific corresponding symmetric session key bound to the corresponding session identifiers in each of the first and the second communication partner; and storing the one or more session identifiers and the corresponding session-specific symmetric session keys in each of the first and the second communication partner for one or more subsequent new secure communication sessions. 2 . The method according to claim 1 , further comprising in the one or more subsequent secure communication sessions: selecting one of the stored session identifiers by one of the first and the second communication partner; communicating the selected session identifier to the other of the first and the second communication partner; and using the stored corresponding symmetric session key for the one or more subsequent secure communication sessions to secure communication between the first communication partner and the second communication partner. 3 . The method according to claim 2 , further comprising in the one or more subsequent secure communication sessions: setting up a ranging procedure between the first communication partner and the second communication partner in the one or more subsequent secure communication sessions after using the stored corresponding symmetric session key to securely communicate between the first communication partner and the second communication partner. 4 . The method according to claim 3 , wherein, when a distance between the first and the second communication partner falls below a threshold value, performing an unlocking procedure by one of the first and the second communication partner, and wherein, when the distance between the first and the second communication partner exceeds the threshold value, performing a locking procedure by one of the first and the second communication partner. 5 . The method according to claim 4 , wherein the ranging procedure comprises determining the distance between the first and the second communication partner by measuring a time difference between a first time of sending a ranging signal from one of the first and the second communication partner to an other of the first and the second communication partner and a second time of receiving a response signal from the other of the first and the second communication partner. 6 . The method according to claim 5 , wherein a beacon signal is used as the ranging signal. 7 . A method for secure communication between a first and a second communication partner, comprising: establishing a communication link between the first and the second communication partner; determining one or more session identifiers by one of the first and the second communication partner for one or more subsequent secure communication sessions; communicating the one or more session identifiers to an other of the first and the second communication partner; determining, for each of the one or more session identifiers, a respective corresponding symmetric session key in each of the first and the second communication partner; and storing the one or more session identifiers and the corresponding symmetric session keys in each of the first and the second communication partner for one or more subsequent secure communication sessions; in the one or more subsequent secure communication sessions, selecting one of the stored session identifiers by one of the first and the second communication partner, communicating the selected session identifier to the other of the first and the second communication partner, and using the stored corresponding symmetric session key for the one or more subsequent secure communication sessions to secure communication between the first communication partner and the second communication partner, setting up a ranging procedure between the first communication partner and the second communication partner in the one or more subsequent secure communication sessions after using the stored corresponding symmetric session key to securely communicate between the first communication partner and the second communication partner, wherein the ranging procedure comprises determining a distance between the first and the second communication partner by measuring a time difference between a first time of sending a ranging signal from one of the first and the second communication partner to an other of the first and the second communication partner and a second time of receiving a response signal from the other of the first and the second communication partner. 8 . The method according to claim 1 , wherein the selected session identifier is communicated via Bluetooth Low Energy or Ultra Wide-Band to the other of the first and the second communication partner. 9 . The method according to claim 8 , wherein the stored corresponding symmetric session key is used to secure communication via Bluetooth Low Energy or Ultra Wide-Band between the first communication partner and the second communication partner. 10 . The method according to claim 1 , wherein one of the first and the second communication partner is a vehicle. 11 . The method according to claim 1 , wherein one of the first and the second communication partner is a portable user device. 12 . The method according to claim 1 wherein the first communication partner is a vehicle and the second communication partner is a smartphone. 13 . The method according to claim 1 , wherein a Diffie-Hellmann based exchange is used to determine the corresponding symmetric session key. 14 . An apparatus for secure communication, comprising: means for establishing a communication link between one communication partner and another communication partner; means for determining one or more session identifiers wherein the one or more session identifiers are different from a session identifier of the communication link; means for communicating the one or more session identifiers to the one communication partner using the communication link; means for determining, for each of the one or more session identifiers, a respective corresponding session-specific symmetric session key bound to the corresponding session identifiers; and means for storing the one or more session identifiers and the corresponding session-specific symmetric session keys for one or more subsequent new secure communication sessions. 15 . The apparatus according to claim 14 , further comprising: means for selecting one of the session identifiers stored in the means for storing one or more session identifiers; and means for communicating a selected one of the session identifiers to the communication partner; and means for using a corresponding symmetric session key stored in the means for storing for the one or more subsequent secure communication sessions to secure communication between the one communication partner and the another communication partner. 16 . The apparatus of claim 14 wherein
using multiplexing techniques (multiplexing for transmission of signals G08C15/00; multiplexing for electrical communication in general H04J) · CPC title
Key generation or derivation · CPC title
Vehicles · CPC title
Wireless · CPC title
wherein the sending and receiving network entities apply symmetric encryption, i.e. same key used for encryption and decryption (cryptographic mechanisms or cryptographic arrangements for symmetric key encryption H04L9/06) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.