Systems and methods for enabling secure communication between endpoints in a distributed computerized infrastructure for establishing a social network

US9577995B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9577995-B1
Application numberUS-201313757866-A
CountryUS
Kind codeB1
Filing dateFeb 4, 2013
Priority dateFeb 4, 2013
Publication dateFeb 21, 2017
Grant dateFeb 21, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A computer-implemented method performed in a system comprising a first endpoint, the first endpoint comprising at least one central processing unit, a memory, a storage system and a network interface unit, the system being accessible by a user, the method involving: generating a message at the first endpoint for sending to a second endpoint, the message incorporating a message body and a message metadata, the message metadata comprising a secure channel invitation for the second endpoint to securely communicate with the first endpoint, the secure channel invitation being hidden within the message metadata; communicating the message from the first endpoint to the second endpoint; receiving a response message, at a first endpoint, from the second endpoint; and establishing the secure communication channel between the first endpoint and the second endpoint based on the received response message.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method performed in a system comprising a first endpoint, the first endpoint comprising at least one central processing unit, a memory, a storage system and a network interface unit, the system being accessible by a user, the method comprising: a. Generating a message at the first endpoint for sending to a second endpoint, the message comprising a human-readable message body and a message metadata, the message metadata being separate and distinct from the message body, the message metadata comprising a secure channel invitation for the second endpoint to securely communicate with the first endpoint, the secure channel invitation being hidden within the message metadata and does not comprise an instruction to download a communication software; b. Communicating the message from the first endpoint to the second endpoint; c. Receiving a response message, at a first endpoint, from the second endpoint; and d. Establishing the secure communication channel between the first endpoint and the second endpoint based on the received response message, wherein the establishing of the secure communication channel between the first endpoint and the second endpoint comprises performing an encryption key exchange between the first endpoint and the second endpoint, wherein the encryption key exchange between the first endpoint and the second endpoint comprises generating a second message from the first endpoint to the second endpoint, the second message being formatted in accordance with Diffie-Hellman key exchange protocol and sending the second message from the first endpoint to the second endpoint, wherein the encryption key exchange between the first endpoint and the second endpoint is an asymmetric key exchange and wherein the establishing of the secure communication channel between the first endpoint and the second endpoint comprises performing a security association negotiation between the first endpoint and the second endpoint. 2. The computer-implemented method of claim 1 , further comprising protecting subsequent messages between the first endpoint and the second endpoint. 3. The computer-implemented method of claim 2 , wherein the protecting subsequent messages comprises encapsulating the subsequent messages in an encrypted and authenticated container and communicating the encapsulated messages from the first endpoint to the second endpoint. 4. A computer-implemented method performed in a system comprising a first endpoint, the first endpoint comprising at least one central processing unit, a memory, a storage system and a network interface unit, the system being accessible by a user, the method comprising: a. Generating a human-readable message at the first endpoint for sending to a second endpoint, the human-readable message comprising a human-readable message body and a plurality of instructions to install a software for establishing secure communication between the first endpoint and the second endpoint, the plurality of instructions being hidden within a message metadata separate and distinct from the human-readable message body and do not comprise an instruction to download a communication software; b. Communicating the human-readable message from the first endpoint to the second endpoint; c. Receiving a response message, at a first endpoint, from the second endpoint; and d. Establishing the secure communication channel between the first endpoint and the second endpoint based on the received response message using the software for establishing secure communication between the first endpoint and the second endpoint, wherein the establishing of the secure communication channel between the first endpoint and the second endpoint comprises performing an encryption key exchange between the first endpoint and the second endpoint, wherein the encryption key exchange between the first endpoint and the second endpoint comprises generating a second message from the first endpoint to the second endpoint, the second message being formatted in accordance with Diffie-Hellman key exchange protocol and sending the second message from the first endpoint to the second endpoint, wherein the encryption key exchange between the first endpoint and the second endpoint is an asymmetric key exchange and wherein the establishing of the secure communication channel between the first endpoint and the second endpoint comprises performing a security association negotiation between the first endpoint and the second endpoint. 5. The computer-implemented method of claim 4 , further comprising protecting subsequent messages between the first endpoint and the second endpoint. 6. The computer-implemented method of claim 5 , wherein the protecting subsequent messages comprises encapsulating the subsequent messages in an encrypted and authenticated container and communicating the encapsulated messages from the first endpoint to the second endpoint. 7. A computer-implemented method performed in a system comprising a first endpoint, the first endpoint comprising at least one central processing unit, a memory, a storage system and a network interface unit, the system being accessible by a user, the method comprising: a. Generating a message at the first endpoint for sending to a second endpoint, the message comprising a human-readable message body and a plurality of instructions to install a software for establishing secure communication between the first endpoint and the second endpoint, the plurality of instructions being hidden within a message metadata separate and distinct from the human-readable message body and do not comprise an instruction to download a communication software; b. Communicating the generated message from the first endpoint to the second endpoint; c. Receiving a response message, at a first endpoint, from the second endpoint; and d. Establishing the secure communication channel between the first endpoint and the second endpoint based on the received response message using the software for establishing secure communication between the first endpoint and the second endpoint, wherein the establishing of the secure communication channel between the first endpoint and the second endpoint comprises performing an encryption key exchange between the first endpoint and the second endpoint, wherein the encryption key exchange between the first endpoint and the second endpoint comprises generating a second message from the first endpoint to the second endpoint, the second message being formatted in accordance with Diffie-Hellman key exchange protocol and sending the second message from the first endpoint to the second endpoint, wherein the encryption key exchange between the first endpoint and the second endpoint is an asymmetric key exchange and wherein the establishing of the secure communication channel between the first endpoint and the second endpoint comprises performing a security association negotiation between the first endpoint and the second endpoint. 8. The computer-implemented method of claim 7 , further comprising protecting subsequent messages between the first endpoint and the second endpoint. 9. The computer-implemented method of claim 8 , wherein the protecting subsequent messages comprises encapsulating the subsequent messages in an encrypted and authenticated container and communicating the encapsulated messages from the first endpoint to the second endpoint. 10. The computer-implemented method of claim 7 , further comprising hiding at least one of the message, the response message and the second message from the user.

Assignees

Inventors

Classifications

  • H04L63/061Primary

    for key exchange, e.g. in peer-to-peer networks (cryptographic mechanisms or cryptographic arrangements for key agreement H04L9/0838) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9577995B1 cover?
A computer-implemented method performed in a system comprising a first endpoint, the first endpoint comprising at least one central processing unit, a memory, a storage system and a network interface unit, the system being accessible by a user, the method involving: generating a message at the first endpoint for sending to a second endpoint, the message incorporating a message body and a messag…
Who is the assignee on this patent?
Anchorfree Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/061. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 21 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).