EP2702732B1

System and method for secure instant messaging

Abstract

This record has no abstract on file.

EP2702732B1, drawing sheet 1
Sheet 1 of 42

Term

5.7 yearsleft in the term

Expires 31 May 2032.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

10 claims: 3 independent, 7 dependent

  1. 1
    A method for implementing secure instant messaging comprising:receiving, by an identity service (3301) from a mobile device (110) of first user, a request to establish an instant messaging session with a second user, the request including an identification code identifying the second user;determining, by the identity service (3301), whether the second user has one or more mobile devices registered on a network service;if the second user has one or more mobile devices registered, providing, by the identity service (3301) to the mobile device (110) of the first user, addressing information identifying the one or more mobile devices of the second user and a public key associated with the second user;providing, by the identity service (3301) to a push notification service (1050), a session key comprising a signature generated with identification codes of the first and second users and network information for the mobile devices of the first and second users;receiving, by the push notification service (1050) from the mobile device (110) of the first user, an encrypted instant message generated by the mobile device (110) of the first user using the public key of the second user and a private key of the first user;' transmitting, by the push notification service (1050) to a secure instant message service (3302), the session key and the encrypted instant message;verifying, by the secure instant message service (3302), the encrypted message using the identification codes of the first and second users, the network information of the first and second users, and the session key;receiving, by the push notification service (1050) from the secure instant message service (3302), the verified encrypted message;and transmitting, by the push notification service (1050) to the one or more mobile devices of the second user, the verified encrypted instant message , the one or more mobile devices of the second user subsequently decrypting the verified encrypted instant message using a private key of the second user.
  2. 9
    A system implementing secure instant messaging including a non-transitory memory for storing program code and at least one processor for processing the program code to perform the operations of:receiving, by an identity service (3301) from a mobile device (110) for a first user, a request to establish an instant messaging session with a second user, the request including an identification code identifying the second user;determining, by the identity service (3301), whether the second user has one or more mobile devices registered on a network service;if the second user has one or more mobile devices registered, providing, by the identity service (3301) to the mobile device (110) of the first user, addressing information identifying the one or more mobile devices of the second user and a public key associated with the second user;receiving, by a push notification service (1050) from the mobile device (110) of the first user, an encrypted instant message generated by the mobile device (110) of the first using the public key of the second user and a private key of the first user;providing, by the identity service (3301) to the push notification service (1050), a session key comprising a signature generated with identification codes of the first and second users and network information of the mobile devices of the first and second users;transmitting, by the push notification service (1050) to a secure instant message service (3302), the session key and the encrypted instant message;verifying, by the secure instant message service (3302), the encrypted instant message using the identification codes of the first and second users, the network information of the first and second users and the session key;receiving, by the push notification service (1050) from the secure message service, the verified encrypted instant message;and transmitting, by the push notification service (1050) to the one or mobile devices of the second user, the verified encrypted instant message, the one or more mobile devices of the second user subsequently decrypting the verified encrypted message using a private key of the second user.
  3. 10
    A non-transitory machine-readable medium having program code stored thereon which, when executed by a machine, causes the machine to perform a method as in any one of claims 1-8.