Creating Three-Party Trust Relationships for Internet of Things Applications

US2016285891A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016285891-A1
Application numberUS-201514669086-A
CountryUS
Kind codeA1
Filing dateMar 26, 2015
Priority dateMar 26, 2015
Publication dateSep 29, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A trust relationship is established at a first network connected device between the first network connected device and a second network connected device. A communication session is established between the first network connected device and a third network connected device, wherein the third network connected device lacks a trust relationship with the second network connected device. A message is sent from the first network connected device to establish a communication session between the third network connected device and the second network connected device based on the trust relationship between the first network connected device and the second network connected device.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method comprising: establishing, at a first network connected device, a trust relationship between the first network connected device and a second network connected device; establishing a communication session between the first network connected device and a third network connected device, wherein the third network connected device lacks a trust relationship with the second network connected device; and sending a message from the first network connected device to establish a communication session between the third network connected device and the second network connected device based on the trust relationship between the first network connected device and the second network connected device. 2 . The method of claim 1 , wherein the message from the first network connected device establishes a trust relationship between the second network connected device and the third network connected device. 3 . The method of claim 1 , wherein sending the message from the first network connected device comprises sending the message to the second network connected device. 4 . The method of claim 1 , wherein sending the message from the first network connected device comprises sending the message to a gateway device, wherein the gateway device controls access to the second network connected device. 5 . The method of claim 4 , further comprising the gateway device monitoring communications between the second network connected device and the third network connected device. 6 . The method of claim 5 , wherein monitoring the communications comprises filtering, modifying, and/or analyzing the content of the communications. 7 . The method of claim 4 , wherein sending the message from the first network connected device comprises sending the message according to a first protocol, wherein the first protocol is different from a second protocol utilized by the gateway device to communicate with the second network connected device; and causing the gateway device to translate the message from the first protocol to the second protocol. 8 . The method of claim 4 , wherein the message establishes a communication session between the second network connected device and the third network connected device, and wherein messages in the communication session between the second network connected device and the third network connected device pass through the gateway device. 9 . The method of claim 4 , wherein the message establishes a communication session between the second network connected device and the third network connected device, and wherein messages in the communication session between the second network connected device and the third network connected device are communicated directly between the second network connected device and the third network connected device. 10 . The method of claim 1 , wherein the message from the first network connected device includes information indicating at least one of a time duration during which the third network connected device is authorized to communicate with the second network connected device or a resource limit on services the third network connected device is authorized to access on the second network connected device. 11 . The method of claim 1 , wherein sending the message from the first network connected device comprises sending the message including a level of access at which the third network connected device may access the second network connected device. 12 . The method of claim 1 , further comprising monitoring, at the first network connected device, communications of the communication session between the second network connected device and the third network connected device. 13 . The method of claim 12 , further comprising terminating the communication session in response to the monitoring. 14 . The method of claim 1 , further comprising evaluating the communication session between the third network connected device and the second network connected device for at least one of evidence of hacking, forged tokens or signs of attacks; detecting at least one of the evidence of hacking, forged tokens or signs of attacks; and tearing down the communication session between the third network connected device and the second network connected device in response to the detecting. 15 . An apparatus comprising: a network interface unit configured to enable network communications; and a processor coupled to the network interface unit, and configured to: establish a trust relationship with a first network connected device; establish a communication session with a second network connected device, wherein the second network connected device lacks a trust relationship with the first network connected device; and send a message via the network interface unit to establish a communication session between the second network connected device and the first network connected device based on the trust relationship with the first network connected device. 16 . The apparatus of claim 15 , wherein the message establishes a trust relationship between the first network connected device and the second network connected device. 17 . The apparatus of claim 15 , wherein the processor is configured to send the message to a gateway device that controls access to the first network connected device. 18 . The apparatus of claim 17 , wherein the processor is configured to send the message according to a first protocol, wherein the first protocol is different from a second protocol utilized by the gateway device to communicate with the first network connected device. 19 . The apparatus of claim 15 , wherein the processor is configured to send the message that includes a level of access at which the second network connected device may access the first network connected device. 20 . A method comprising: registering a first network connected device at a gateway device; establishing, at the gateway device, a first trust relationship between the gateway device and a second network connected device; receiving a message at the gateway device indicating a second trust relationship between the second network connected device a third network connected device; establishing a third trust relationship between the gateway device and the third network connected device based on the second trust relationship; and passing a control message from the third network connected device to the first network connected device via the gateway device in response to the third trust relationship. 21 . The method of claim 20 , wherein passing the control message from the third network connected device to the first network connected device comprises translating the control message from a first protocol to a second protocol. 22 . The method of claim 20 , further comprising monitoring the control message for at least one of evidence of hacking, forged tokens or signs of attacks. 23 . The method of claim 22 , further comprising: detecting at least one of evidence of hacking, forged tokens or signs of attacks; and tearing down the third trust relationship between the gateway device and the third network connected device. 24 . The method of claim 20 , further comprising tearing down the third trust relationship after at least one of a time duration during which the third network connected device is authorized to control the first network connected device or a resource limit on services the third network connect

Assignees

Inventors

Classifications

  • when the policy decisions are valid for a limited amount of time · CPC title

  • Multiple levels of security · CPC title

  • by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity · CPC title

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • H04L63/123Primary

    received data contents, e.g. message integrity · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016285891A1 cover?
A trust relationship is established at a first network connected device between the first network connected device and a second network connected device. A communication session is established between the first network connected device and a third network connected device, wherein the third network connected device lacks a trust relationship with the second network connected device. A message i…
Who is the assignee on this patent?
Cisco Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1408. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Sep 29 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).