Secure data exchange using messaging service
Claim Score by NHIP
Abstract
A system for securely communicating over a network includes a sending device and a receiving device. The sending device includes first processing hardware configured to encrypt a symmetric key associated with the sending device with a public key associated with a receiving device. The first processing hardware is further configured to steganographically embed the symmetric key into an image. The sending device further includes a first signal interface configured to send the image to the receiving device. The receiving device includes second signal interface for receiving the image from the sending device. The receiving device also includes second processing hardware configured to decrypt the symmetric key with a private key stored on the receiving device and to further secure communications with the sender via the symmetric key.

Term
Projected expiry 15 August 2032.
- Priority and filed
- Published
- Today
- Projected expiry
30 claims: 4 independent, 26 dependent
- 1A receiving device for receiving secure communications, comprising:a signal interface for receiving an image, the image including a steganographically embedded symmetric key from the sender, the symmetric key being encrypted with a public key associated with the receiving device;and processing hardware configured to decrypt the symmetric key with a private key stored on the receiving device and to further secure communications with the sender via the symmetric key, wherein the processing hardware is further configured to encrypt future communications from the receiving device using the symmetric key.
- 10Broadest claimClaim Score 82, broad(NHIP)A sending device for sending secure messages, comprising:processing hardware configured to encrypt a symmetric key associated with the sending device with a public key associated with a receiving device and to steganographically embed the symmetric key into an image;and a signal interface configured to send the image to the receiving device, wherein the symmetric key is decryptable by a private key associated with the receiving device.
- 18A system for securely communicating over a non-secure network, comprising:a sending device including: first processing hardware configured to encrypt a symmetric key associated with the sending device with a public key associated with a receiving device and to steganographically embed the symmetric key into an image;and a first signal interface configured to the image to the receiving device;and a receiving device including: a second signal interface for receiving the image from the sending device;and second processing hardware configured to decrypt the symmetric key with a private key stored on the receiving device and to further secure communications with the sender via the symmetric key.
- 25A system for securely communicating in a network, comprising:a sending device including: first processing hardware configured to encrypt a symmetric key associated with the sending device with a public key associated with a receiving device;and a first signal interface configured to send the encrypted symmetric key to the receiving device;and a receiving device including: a second signal interface for receiving the encrypted symmetric key from the sending device;and second processing hardware configured to decrypt the symmetric key with a private key stored on the receiving device and to further secure communications with the sender via the symmetric key.
Independent claims4
68 paragraphs in 5 sections, as filed
FIELD OF THE INVENTION
0001The present invention relates to systems and methods for sending and receiving secure messages, and, more particularly, to systems and methods for sending and receiving secure messages using encryption keys for establishing and maintaining a secure communication via a messaging service.
BACKGROUND OF THE INVENTION
0002Consumers throughout the world utilize electronic communications to send and receive information, both for purely social and for work-related purposes. Information is passed via various communication channels, including instant messaging, text messaging, picture messaging, voicemail, email, via social networks, and others. Security and confidentiality of information is a key concern for many consumers.
0003A wide variety of social networks, including TWITTER, FACEBOOK, LINKED IN, FOURSQUARE, etc. exist. The social networks have a growing population of end-users, with each network claiming several hundreds of millions of users throughout the world. A majority of internet users use one or more type of social networks. The social networks are readily accessible from a wide variety of portals with internet access including personal computers, laptops, smartphones, gaming systems, PDAs, tablets, etc. Access to such sites is generally available free of charge to any user that fills out a simple registration form. Depending on the type of social network and an individual user's privacy setting, a communication sent by a user of such social networking sites may reach either a very large (e.g., millions of people) or a very small (e.g., a few people) audience. The social networks generally also allow for private communications between users. Many companies also establish their own private social networks to facilitate communication and transmission of information between employees.
0004Social networks are commonly used to transmit various types of information, including text, pictures, or videos. The transmission of information is instantaneous. Moreover, depending on the social network, other users may receive instant notification about another user's transmission. One drawback of information transmission via social networks is that the amount or type of information transmitted may be limited by the particular social network. For example, TWITTER currently limits users' text transmissions to 140 characters. A further drawback is censorship of information transmitted on the social networks by certain governments. For example, certain governments could scan messages for certain words, or could completely or partially block certain social networks.
SUMMARY OF THE INVENTION
0005The present invention relates to systems and methods for sending and receiving secure messages or communications using encryption keys for establishing and maintaining a secure communication via a messaging service. For example, an embodiment may relate to a microblogging service that uses encryption technologies to enable private communications. The private communications may take place between two users, or between a user and a group or several groups. Embodiments may relate to an end-to-end social networking service for commercial and government entities, allowing organizations to send and receive private messages or communications using encryption and decryption techniques. Such embodiments allow members of a mobile workforce to share information and files confidentially no matter where they are, while knowing that only the intended recipients can open the communication and the privacy and security of the communication will not be compromised during the transmission or afterwards.
0006One aspect of the present invention relates to a receiving device for receiving secure communications including a signal interface and processing hardware. The signal interface is configured to receive an image. The image includes a steganographically embedded symmetric key from the sender. The symmetric key is encrypted with a public key associated with the receiving device. The processing hardware is configured to decrypt the symmetric key with a private key stored on the receiving device and to further secure communications with the sender via the symmetric key. The processing hardware is configured to encrypt future communications from the receiving device using the symmetric key. In a further aspect of the present invention, the receiving device includes a user interface for communicating subsequent decrypted communications to a user of the receiving device.
0007A further aspect of the present invention relates to a sending device including processing hardware and a signal interface. The processing hardware is configured to encrypt a symmetric key associated with the sending device with a public key associated with the receiving device and to steganographically embed the symmetric key into an image. The signal interface is configured to send the image to the receiving device, wherein the symmetric key is decryptable by a private key associated with the receiving device.
0008In a further aspect of the present invention, the receiving device includes a second image associated therewith. The second image includes the public key steganographically embedded into the second image. The processing hardware of the sending device is configured to retrieve the public key from the second image.
0009Yet another aspect of the present invention relates to a system for securely communicating over a network. The system includes a sending device and a receiving device. The sending device includes first processing hardware configured to encrypt a symmetric key associated with the sending device with a public key associated with a receiving device. The first processing hardware is further configured to steganographically embed the symmetric key into an image. The sending device further includes a first signal interface configured to send the image to the receiving device. The receiving device includes second signal interface for receiving the image from the sending device. The receiving device also includes second processing hardware configured to decrypt the symmetric key with a private key stored on the receiving device and to further secure communications with the sender via the symmetric key.
0010A further aspect of the present invention relates to a method of securely communicating over an unsecure network. The method includes receiving an image from a sender by a signal interface of a receiving device. The image includes a steganographically embedded symmetric key from the sender. The symmetric key is encrypted with a public key associated with the receiving device. Processing hardware of the receiving device decrypts the symmetric key via a private key stored on the receiving device. The processing hardware further secures communications with the sender via the symmetric key.
0011Another aspect of the present invention relates to a method of securely communicating over an unsecure network. The method includes encrypting, by processing hardware of a sending device, a symmetric key associated with the sending device with a public key associated with a receiving device. The processing hardware steganographically embeds the symmetric key into an image. A signal interface of the sending device sends the image to the receiving device. The symmetric key is decryptable by a private key associated with the receiving device.
0012Yet another aspect of the present invention relates to a system for securely communicating in a network. The system includes a sending device and a receiving device. The sending device includes first processing hardware configured to encrypt a symmetric key associated with the sending device with a public key associated with a receiving device. The sending device additionally includes a first signal interface configured to send the encrypted symmetric key to the receiving device. The receiving device includes a second signal interface for receiving the encrypted symmetric key from the sending device. The receiving device additionally includes second processing hardware configured to decrypt the symmetric key with a private key stored on the receiving device and to further secure communications with the sender via the symmetric key.
BRIEF DESCRIPTION OF THE DRAWINGS
0013The foregoing and other advantages of the present disclosure will become apparent upon reading the following detailed description and upon reference to the drawings.
0014<figref idref="DRAWINGS">FIG. 1A</figref> is a system for establishing secure communications in a network;
0015<figref idref="DRAWINGS">FIG. 1B</figref> is another aspect of the system for establishing secure communications in a network;
0016<figref idref="DRAWINGS">FIG. 1C</figref> is another aspect of the system for establishing secure communications in a network;
0017<figref idref="DRAWINGS">FIG. 2</figref> is a flowchart illustrating the key exchange process between two devices in a network;
0018<figref idref="DRAWINGS">FIG. 3</figref> is a system illustrating a symmetric key subscription service;
0019While the invention is susceptible to various modifications and alternative forms, specific embodiments have been shown by way of example in the drawings and will be described in detail herein. It should be understood, however, that the invention is not intended to be limited to the particular forms disclosed. Rather, the invention is to cover all modifications, equivalents, and alternatives falling within the spirit and scope of the invention as defined by the appended claims.
DETAILED DESCRIPTION OF ILLUSTRATED EMBODIMENTS
0020In the following description, for purposes of explanation and not limitation, specific details are set forth, such as particular embodiments, procedures, techniques, etc. in order to provide a thorough understanding of the present invention. However, it will be apparent to those ordinarily skilled in the art that the present invention may be practiced in other embodiments that depart from these specific details.
0021One aspect of the present invention relates to a system for establishing secure communications that is compatible with a variety of mobile and non-mobile platforms, including BLACKBERRY, APPLE iOS, ANDROID, MICROSOFT (WINDOWS), Web, and other platforms. The system is a microblogging service that allows users to communicate and transmit information securely and confidentially. The system allows for secure and confidential transmission of text messages and files, including images, video, voicemail, and other information. The system is accessible from any device that can be connected to the Internet, including a computer, a portable game console, a mobile device such as a smartphone, a personal digital assistant, a tablet, and the like. One aspect of the present invention allows for the data that is present on a mobile device utilizing the system to be synchronized with the data present on the other devices, such as tablets, computers, and the like.
0022The system or application for establishing secure communications may be downloaded onto a device, such as a smartphone or a tablet, from an application store, such as GOOGLE PLAY, APPLE APP STORE, or the like. According to a further aspect of the present invention, the application may be an enterprise application that is hosted on a server or cloud network. Each authorized user downloads an application onto his or her device to enable secure communications with the other enterprise application users.
0023<figref idref="DRAWINGS">FIG. 1A</figref> illustrates a system <b>100</b> for establishing secure communications including a sender <b>102</b> and a receiver <b>104</b>. Each one of the sender <b>102</b> and the receiver <b>104</b> has a user account associated therewith. The system for establishing secure communications may include several receivers <b>104</b> as shown in <figref idref="DRAWINGS">FIG. 1C</figref>. The user accounts may be accessed from a variety of devices, including mobile devices such as smartphones, portable digital assistants, tablets, computers, portable game consoles and other devices capable of sending and receiving messages.
0024The devices <b>102</b> and <b>104</b> communicate through a social networking service or infrastructure, including, but not limited to, TWITTER, YAMMER, E-CHIRP, FACEBOOK, HANDSHAKE, other third-party social networks, private social networks, and the like. According to a further aspect of the present invention, devices <b>102</b> and <b>104</b> communicate through a variety of different services and servers, including social networking services (such as TWITTER, FACEBOOK, YAMMER, or the like), private enterprise servers, instant messaging services, text messaging services, email servers (private and public), and the like. The system <b>100</b> is configured to integrate with any third party social networking service. Accordingly, organizations that already have operational social networks in place can add to such social networks the private messaging capability described in the present invention. In turn, this saves the organizations time and money as they do not have to establish new communication networks in order to have secure and confidential messaging capabilities.
0025The sender <b>102</b> includes a symmetric key <b>107</b> associated therewith. The receiver <b>104</b> includes a public key <b>108</b> and a private key <b>110</b> associated therewith. According to one embodiment of the present invention, the sender <b>102</b> includes processing hardware configured to generate the symmetric key <b>107</b>, and the receiver <b>104</b> includes processing hardware configured to generate the public key <b>108</b> and the private key <b>110</b>. In this case, the sender <b>102</b> and the receiver <b>104</b> do not have access to and/or are not coupled to a key source.
0026Alternatively, according to a second embodiment of the present invention, each one of the sender <b>102</b> and the receiver <b>104</b> is coupled to a key source <b>114</b>. The sender <b>102</b> includes a public key and a private key associated therewith. The sender <b>102</b> includes processing hardware configured to generate the public key and the private key associated with the sender <b>102</b>. The key source <b>114</b> obtains the public key associated with the sender <b>102</b> via any method discussed below or any known method. The key source <b>114</b> generates a symmetric key <b>107</b> for the sender <b>102</b>. The key source <b>114</b> includes processing hardware configured to encrypt (or wrap) the symmetric key <b>107</b> with the public key associated with the sender <b>102</b>. The key source <b>114</b> transmits the encrypted symmetric key <b>107</b> to the sender <b>102</b>. The sender <b>102</b> uses the private key associated with the sender <b>102</b> to decrypt the encrypted symmetric key <b>107</b>. The receiver <b>104</b> includes a public key <b>108</b> and a private key <b>110</b> associated therewith. The receiver <b>104</b> includes processing hardware configured to generate the public key <b>108</b> and the private key <b>110</b>. The sender <b>102</b> obtains the public key <b>108</b> associated with the receiver <b>104</b> by any method discussed below or any known method. The sender <b>102</b> encrypts the symmetric key <b>107</b> received from the key source <b>114</b> with the public key <b>108</b> associated with the receiver <b>104</b>. The sender <b>102</b> transmits the encrypted symmetric key <b>107</b> to the receiver <b>104</b>. The receiver <b>104</b> uses its private key <b>110</b> to decrypt the symmetric key <b>107</b>. According to another aspect of the present invention, the key source <b>114</b> obtains the public key <b>108</b> associated with the receiver <b>104</b>. The key source <b>114</b> encrypts the symmetric key <b>107</b> with the public key <b>108</b> associated with the receiver <b>104</b>. The key source <b>114</b> transmits the encrypted symmetric key <b>107</b> to the receiver <b>104</b>. The receiver <b>104</b> uses its private key <b>110</b> to decrypt the symmetric key <b>107</b>.
0027According to another embodiment of the present invention, each one of the sender <b>102</b> and the receiver <b>104</b> is coupled to the key source <b>114</b>. The key source <b>114</b> includes processing hardware configured to generate public keys for the devices in a network or other infrastructure <b>105</b>, including the sender <b>102</b> and the receiver <b>104</b>. The network <b>105</b> is any infrastructure that allows users to transmit data between two or more points. The key source <b>114</b> transmits the generated public keys to the devices in the network <b>105</b> via the network <b>105</b> which may be an unsecure network. The key source <b>114</b> includes processing hardware configured to generate the symmetric key <b>107</b>. The key source <b>114</b> includes processing hardware configured to encrypt the symmetric key <b>107</b> with a public key corresponding to the device in the network <b>105</b> to which the key source <b>114</b> is transmitting the encrypted symmetric key <b>107</b>. Accordingly, if the key source <b>114</b> is transmitting the encrypted symmetric key <b>107</b> to the sender <b>102</b>, the key source encrypts the symmetric key <b>107</b> with the public key associated with the sender <b>102</b>. The sender <b>102</b> then uses a private key associated with the sender <b>102</b> to decrypt the encrypted symmetric key <b>107</b>.
0028The key source <b>114</b> is configured to provide users with the strongest encryption technology required or needed, including encryption keys for the military, the intelligence community, or law enforcement. The key source <b>114</b> is configured to update or roll over the keys generated by the key source <b>114</b> based on a predetermined set of criteria or based on a direct request.
0029According to another embodiment of the present invention, the key source <b>114</b> is coupled to a key management service <b>118</b>. According to this embodiment, any key generated by the key source <b>114</b> is transmitted first to the key management service <b>118</b>. The key management service <b>118</b> is configured to transmit the key received from the key source <b>114</b> to the sender <b>102</b> and/or the receiver <b>104</b>. The key management service <b>118</b> stores the keys and transmits them to the receiver <b>104</b> and/or the sender <b>102</b> based on a predetermined criterion or trigger or based on a specific request from the receiver and/or the sender <b>102</b>. The key management service <b>118</b> is configured to send a request to the key source <b>114</b> to update or roll over the keys generated by the key source <b>114</b> based on a predetermined set of criteria or based on a direct request.
0030<figref idref="DRAWINGS">FIG. 1B</figref> illustrates a system <b>101</b> for establishing secure communications. The key management service <b>118</b> is a mechanism by which key exchanges occur between clients. The key management service <b>118</b> allows behind the scenes, safe key handling once the system <b>101</b> has been set up. The key management service <b>118</b> is configured to work with a variety of systems for enabling secure communications between devices within the network, including system <b>100</b> of <figref idref="DRAWINGS">FIG. 1A</figref> and system <b>101</b> of <figref idref="DRAWINGS">FIG. 1B</figref>. According to one aspect of the present invention, the key management service <b>118</b> is provided on a cloud or private enterprise.
0031Users of the systems <b>100</b> and <b>101</b> include organizations that would like to pass secure messages between employees. Such users may select an appropriate key management architecture based on their individual needs, budgets, and security requirements.
0032The systems <b>100</b> and <b>101</b> may be used with email, instant messaging, text messaging, Internet forums and blogs, and any other communication platforms. The systems <b>100</b> and <b>101</b> are compatible with BLACKBERRY, APPLE iOS, ANDROID, MICROSOFT (WINDOWS), Web, and other platforms. The systems <b>100</b> and <b>101</b> are configured to operate in a variety of networks, including public internet and private networks including NIPRNET, private 3G, private 4G as well as mobile and temporary networks and hotspots. The systems <b>100</b> and <b>101</b> may be integrated with a variety of technologies, including video recordings, voice recordings and memos, biometric data input or collected from phone sensors, encrypted voicemail, GPS/map data for military, recorded phone calls, sensor messages (such as SIGINT, MASINT, IMINT, GEOINT, health status/diagnostics, and others), sensor metadata, and the like.
0033According to one aspect of the present invention, the receiver <b>104</b> includes an image <b>106</b>, such as a profile picture or other publicly available image, associated therewith. The image <b>106</b> is publicly available to anyone viewing or searching for the receiver <b>104</b>'s account.
0034The image <b>106</b> includes the public key <b>108</b> associated therewith. The public key <b>108</b> is steganographically embedded into the image <b>106</b> and may be retrieved by anyone who has access to or permission to view the image <b>106</b> associated with the receiver <b>104</b>. By posting or broadcasting the image <b>106</b>, the receiver <b>104</b> makes the public key <b>108</b> available to selected users or accounts. The public key <b>108</b> is embedded into the image <b>106</b> using steganography for use by any other client, user, or account who has the permission to view the image <b>106</b>. According to one aspect of the present invention, the image <b>106</b> may be entirely public, and any other client, user, or account is able to view the image <b>106</b> and retrieve the steganographically embedded public key <b>108</b>.
0035The public key <b>108</b> may be any key that is known in the art, including Public Key Infrastructure (PKI) key and others. As is known, the TWITTER service allows for transmission of messages limited to 140 characters. However, the TWITTER service allows for transmission of pictures or images of significantly larger sizes. The public key <b>108</b> is typically larger than 140 characters, and it may not be transmitted in the text of the TWEET. Accordingly, steganographially embedding the public key <b>108</b> into the image <b>106</b> allows for the sender to retrieve and use the public key <b>108</b> without the need for the receiver <b>104</b> to send the public key <b>108</b> directly to the sender <b>102</b>.
0036According to another aspect of the present invention, the sender <b>102</b> and the receiver <b>104</b> communicate over a network <b>105</b> that allows for transmission of messages that are large enough to include the public key <b>108</b>. The receiver <b>104</b> transmits the public key <b>108</b> to the sender <b>102</b> either based on a predetermined triggering criteria (e.g., time, signal, etc.) or based on a specific request from the sender <b>102</b>. According to a further aspect of the present invention, the public key <b>108</b> is stored on a public or private cloud. Pre-selected users have access to the public key <b>108</b> on the public or private cloud.
0037The sender <b>102</b> and the receiver <b>104</b> exchange cryptographic keys in order to achieve secure communications between the sender <b>102</b> and the receiver <b>104</b>. The sender <b>102</b> and the receiver <b>104</b> exchange cryptographic keys using any known suitable key exchange technique. According to one aspect of the present invention, the sender <b>102</b> and the receiver <b>104</b> utilize asymmetric key cryptography techniques (e.g., RSA), Diffie-Hellman key exchange, elliptic curve cryptography (ECC), including elliptic curve Diffie-Hellman key agreement scheme, and other suitable techniques.
0038According to one aspect of the present invention, the sender <b>102</b> retrieves the public key <b>108</b> from the image <b>106</b> over an unsecure network or data service <b>105</b>. The sender <b>102</b> includes processing hardware that is configured to retrieve or decode the steganographically embedded public key <b>108</b>. The sender <b>102</b> encrypts the symmetric key <b>107</b> using the public key <b>108</b>. The encrypted symmetric key <b>107</b> may be sent to the receiving device <b>104</b> by any secondary mechanism that is distinguishable from a primary mechanism by which the actual encrypted communications between the sender <b>102</b> and the receiver <b>104</b> are sent.
0039According to one aspect of the present invention, the sender <b>102</b> embeds the encrypted symmetric key <b>107</b> into a second image using steganography. The second image is then transmitted by the sender <b>102</b> to the receiver <b>104</b>. In a further aspect of the present invention, the second image is broadcast over the network <b>105</b>. The second image including the steganographically embedded encrypted symmetric key <b>107</b> may be sent to the receiving device <b>104</b> by any secondary mechanism that is distinguishable from a primary mechanism by which the actual encrypted communications between the sender <b>102</b> and the receiver <b>104</b> are sent.
0040In a further aspect of the present invention, the receiver <b>104</b> transmits the public key <b>108</b> directly to the sender <b>102</b> without embedding the public key <b>108</b> into an image. The sender <b>102</b> then transmits the encrypted symmetric key <b>107</b> to the receiver <b>104</b> without embedding the encrypted symmetric key <b>107</b> into the second image. Once the receiver <b>104</b> receives and decrypts the symmetric key <b>107</b>, the receiver <b>104</b> may securely communicate with other devices within the network <b>105</b> that have received or that possess the symmetric key <b>107</b> by encrypting all communications or messages from the receiver <b>104</b> with the symmetric key <b>107</b>. Other devices in the network <b>105</b> that receive and decrypt the symmetric key <b>107</b> may also securely communicate with the other devices in the network <b>106</b> by encrypting all outgoing communications with the symmetric key <b>107</b>. The receiver <b>104</b> is also configured to transmit the symmetric key <b>107</b> to other network devices by encrypting the symmetric key <b>107</b> with the public key associated with the device receiving the symmetric key <b>107</b>.
0041The network <b>105</b> does not have the capability to decode or decrypt the communication between the sender <b>102</b> and the receiver <b>104</b>. The encryption keys are opaque to the network <b>105</b>. The network <b>105</b> only sees the encrypted communications.
0042According to one aspect of the present invention, only users that know the symmetric key <b>107</b> can encrypt the communications between the sender <b>102</b> and the receiver <b>104</b> (or between other devices in the network communicating by encrypting their messages with the symmetric key <b>107</b>) that are encrypted with the symmetric key <b>107</b>. The communication between the sender <b>102</b> and the receiver <b>104</b> in step <b>208</b> is set up in such a way that the network within which the communication takes place (e.g., a third party social network, such as TWITTER or a private enterprise network) is unable to decrypt the communication. The communication between the sender <b>102</b> and the receiver <b>104</b> appears to the network to be an encrypted communication. The network <b>105</b> only sees the encrypted (e.g., cyphertext) transmission between the sender <b>102</b> and the receiver <b>104</b>. The network <b>105</b> cannot see the communication that is encrypted within the transmission from the sender <b>102</b> to the receiver <b>104</b> in step <b>210</b> or in further communications encrypted with the symmetric key <b>107</b> between other devices within the network <b>105</b>. The encrypted transmission also appears as an encrypted transmission to third parties. Moreover, the network <b>105</b> or third parties (unless specifically authorized by receiving the symmetric key <b>107</b> from the sender <b>102</b> or from another device) are unable to decrypt the encrypted communication between the sender <b>102</b> and the receiver <b>104</b> as they do not possess the symmetric key <b>107</b>.
0043In turn, this prevents the persistent problem of security breaches. Commercial messaging and social networking services typically lack security measures for transmitting messages. Messages are susceptible to being monitored, intercepted, or otherwise read by third parties. One aspect of the present invention relates to achieving and ensuring that private, confidential messages can only be delivered to the intended recipients and/or their devices. Since no third party or network possesses the capability to decrypt the encrypted communication, this eliminates the problem that occurs when the network's security is compromised, such as when a hacker or another unauthorized user unlawfully gains access to the network's secure data. According to one aspect of the present invention, even if such an unauthorized user were able to gain access to the network's secure data, they would be unable to access the encrypted communication, as the communication may only be decrypted by those users that possess the symmetric key <b>107</b>. This also allows users to securely transmit messages without fear of censorship (by a government or otherwise) and communication interception. Server cooperation is not required or needed.
0044Some networks, email servers, messaging servers, or third party social networking services store all communications between users. Such messages may be stored on a server <b>112</b> (e.g., network server) associated with the network <b>105</b>. The server <b>112</b> hosts all social networking and microblogging data, including messages, files, images, etc. Since the network <b>105</b> cannot decrypt the messages communicated between the sender <b>102</b> and the receiver <b>104</b>, any messages stored on the server <b>112</b> are stored in encrypted form. In other words, once these messages are stored on the server <b>112</b>, they may not be decrypted by anyone because the keys used to encrypt the message are not stored with the encrypted message. The network <b>105</b> only sees and stores the encrypted messages and cannot see the keys transmitted with these messages. Accordingly, if someone intercepted the transmission between the sender <b>102</b> and the receiver <b>104</b> or if someone gained access to the contents of the server <b>112</b>, they could only see the encrypted messages and would not have access to the keys needed to decode these messages. Even network administrators may not gain access to the decrypted messages.
0045The receiver <b>104</b> receives the encrypted message from the sender <b>102</b>. The receiver <b>104</b> decodes or decrypts the symmetric key <b>107</b> using the private key <b>110</b>. According to one aspect of the present invention, the decrypted message and the symmetric key are stored on an escrow server <b>116</b> to comply with government and enterprise record retention policies. The escrow server <b>116</b> is not accessible from the internet, which improves the security of the system <b>100</b>.
0046The escrow server <b>116</b> stores both the keys and the messages between the sender <b>102</b> and the receiver <b>104</b> or other devices within the network <b>105</b>. According to one aspect of the present invention, the escrow server <b>116</b> receives the message through the network <b>105</b> into the escrow server <b>116</b> using either a Data Diode cable, or a Cross Domain Solution (CDS). The Data Diode cable and the CDS are devices configured to ensure that unencrypted messages cannot get back out to the network <b>105</b>. The escrow server <b>116</b> decrypts the encrypted message from the network <b>105</b> with the retrieved symmetric key <b>107</b>. The escrow server <b>116</b> then stores the decrypted message. According to one aspect of the present invention, the escrow server <b>116</b> connects to the network through the Data Diode cable or the CDS. The escrow server <b>116</b> may be coupled to a pre-escrow server (not shown). The pre-escrow server is configured to retrieve messages from the network <b>105</b> and send those messages through the Data Diode or the CDS to the escrow server <b>116</b>. According to a further aspect of the present invention, the key source <b>114</b> is coupled to the Data Diode or the CDS. The key source <b>114</b> is configured to provide the symmetric key <b>107</b> in an unencrypted form to the escrow server <b>116</b>.
0047The sender <b>102</b> and the receiver <b>104</b> utilize symmetric keys for encryption and decryption—the sender <b>102</b> encrypts the symmetric key with the receiver's public key <b>108</b> and the receiver <b>104</b> decrypts with the private key <b>110</b>. Certain conventional systems use public key infrastructure (PKI) to encrypt and decrypt information. Using PKI to encrypt and decrypt places a significant strain on computational resources. Using symmetric keys solves this problem and frees up valuable computational resources. Moreover, broadcasting the public key <b>108</b> by the receiver <b>104</b> makes the public key <b>108</b> concurrently available to the entire audience selected by the receiver <b>104</b>. In other words, the receiver <b>104</b> does not have to send a separate transmission to each individual account or user with the receiver <b>104</b>'s public key <b>108</b>. Symmetric key techniques according to the present invention include Advanced Encryption Standard (AES), TWOFISH, SERPENT, BLOWFISH, CASTS, RC4, 3DES, IDEA, and others.
0048Referring now to <figref idref="DRAWINGS">FIG. 1B</figref>, a system <b>101</b> for securely communicating in a network includes a sender client application <b>102</b> and a receiver client application <b>104</b>. The sender <b>102</b> and the receiver <b>104</b> communicate within a data service <b>105</b> which may be a social network, a private enterprise network, or any other network or infrastructure over which data is communicated. The data service or network <b>105</b> may be a secure or an unsecure network. The sender <b>102</b> retrieves the public key <b>108</b> associated with the receiver <b>104</b>. The public key <b>108</b> may be steganographically embedded into the image <b>106</b> or it may be hosted on a public or private cloud. According to one aspect of the present invention, the receiver <b>104</b> transmits the public key <b>108</b> to the sender <b>102</b>. The sender <b>102</b> encrypts the symmetric key <b>107</b> with the public key <b>108</b> associated with the receiving device <b>104</b> based on a predetermined trigger or user request. The sender <b>102</b> then transmits the encrypted message to the receiver <b>104</b> over the network or data service <b>105</b>. The network or data service <b>105</b> cannot see or intercept the communication between the sender <b>102</b> and the receiver <b>104</b>: the communication appears as an encrypted (e.g., cyphertext) message. The receiver <b>104</b> decrypts the symmetric key <b>107</b> with the private key <b>110</b> associated with the receiver <b>104</b> and stores the symmetric key <b>107</b> for future use. The receiver <b>104</b> uses the symmetric key <b>107</b> to encrypt future communications from the receiver <b>104</b> to devices within the network <b>105</b> possessing the symmetric key <b>107</b>. The receiver <b>104</b> is configured to request to subscribe to the sender <b>102</b>'s symmetric keys. The key management service <b>118</b> is coupled to an escrow relay <b>117</b> that includes an escrow server <b>116</b>. Decrypted messages and keys are optionally stored on the escrow server <b>116</b> to comply with government and enterprise data retention policies.
0049Referring now to <figref idref="DRAWINGS">FIG. 2</figref>, the receiver <b>104</b> broadcasts or transmits the public key <b>108</b> to a selected audience in step <b>202</b>. The sender <b>102</b> retrieves the receiver <b>104</b>'s public key <b>108</b> in step <b>204</b>. The sender <b>102</b> encrypts the symmetric key <b>107</b> by using the public key <b>108</b> of the receiver <b>104</b> in step <b>208</b>. According to one aspect of the present invention, the sender <b>102</b> embeds the encrypted symmetric key <b>107</b> into a second image using steganography prior to transmitting the message to the receiver <b>104</b>. According to a further aspect of the present invention, the sender <b>102</b> does not embed the encrypted symmetric key <b>107</b> into an image prior to transmitting the message to the receiver <b>104</b>; the sender <b>102</b> transmitting the encrypted symmetric key <b>107</b> directly to the receiver <b>104</b> without embedding it in an image. The sender <b>102</b> transmits the communication including the encrypted symmetric key <b>107</b> to the receiver <b>104</b> in step <b>210</b> over the network <b>105</b>. The receiver <b>104</b> receives the encrypted communication from the sender <b>102</b> in step <b>212</b>. The receiver <b>104</b> includes the private key <b>110</b>. The receiver <b>104</b> uses the private key <b>110</b> to decrypt the symmetric key <b>107</b> in step <b>216</b>. The receiver <b>104</b> uses the symmetric key <b>107</b> shared between the sender <b>102</b> and the receiver <b>104</b> to decrypt communications from the sender <b>102</b> in step <b>217</b>. The receiver <b>104</b> uses the symmetric key <b>107</b> to encrypt future communications from the receiver <b>104</b> to other devices within the network <b>105</b> that have received or possess the symmetric key <b>107</b>.
0050The type of symmetric key <b>107</b> may be configured or selected based on preference and needs. The type of symmetric key <b>107</b> that is generated is based on a selected key generation service. The symmetic key <b>107</b> is an Advanced Encryption Standard (AES) 256 key, 128 bit AES, 256 bit AES, 256 bit TWOFISH, and the like.
0051The network, such as the unsecure network <b>105</b>, within which the sender <b>102</b> and the receiver <b>104</b> communicate may include the network server <b>112</b> where the encrypted messages are stored in step <b>214</b>.
0052In a further aspect of the present invention, the receiving device <b>104</b> includes a user interface for communicating the decrypted message to a user of the receiving device <b>104</b>. The decrypted messages and keys are stored in step <b>218</b> on an escrow server <b>116</b>.
0053According to a further aspect of the present invention, the client devices (such as the sender <b>102</b> and the receiver <b>104</b>) are configured to allow for complete erasure or “zeroization” of all the keys sent or received by any user (sender <b>102</b>, receiver <b>104</b>, and other users or devices in the network). This aspect is particularly useful in case of loss or compromise of the device associated with the sender <b>102</b>, the receiver <b>104</b>, or any other device that has sent or received private messages or received the symmetric key <b>107</b>. According to one aspect of the present invention, the keys are deleted to an un-restorable state.
0054The system <b>100</b> is configured to work seamlessly with several third party networking services, including TWITTER. The system <b>100</b> is configured to allow the users of the sender <b>102</b> and the receiver <b>104</b> to sign into the application for securely communicating in a network with their TWITTER (or other networking service) user names and passwords. The users are able to manage their account settings in the same manner as they would usually be able to with their TWITTER accounts. The TWITTER functionality and settings are directly accessible from within the application on the devices associated with the sender <b>102</b> and the receiver <b>104</b>.
0055The system <b>100</b> may be used in any circumstance or industry where two or more people need to share information in a private and confidential manner. The encryption software is configured to integrate into any third party communication platform for any industry or service as needed by the users. The systems <b>100</b> and <b>101</b> may be used in the medical, legal, financial, real estate, architectural, entertainment and lifestyle, media, security, education, clergy, military, food and drug, law enforcement, intelligence community, private investigation services, political campaigns, government, and other fields and industries to securely transmit information to an intended audience. The systems <b>100</b> and <b>101</b> may be used in the medical profession for secure and confidential communications between doctor and patient; in the legal profession for secure and confidential communications between lawyer and client; in the military to securely and timely share information or plans with remote or disparate users; in the context of research and development for any company to enable it to securely share information.
0056Referring now to <figref idref="DRAWINGS">FIG. 3</figref>, a subscription key model is illustrated. Clients or devices using the system for establishing secure communications according to the present invention may subscribe to other client's keys. Subscription is an exchange that occurs between users during a key exchange described in relation to <figref idref="DRAWINGS">FIGS. 1A and 1B</figref>. In order for the sender <b>102</b> to transmit secure data to the receiver <b>104</b>, the receiver <b>104</b> must have the sender <b>102</b>'s symmetric key <b>107</b>. As discussed above, the sender <b>102</b> encrypts the sender <b>102</b>'s symmetric key <b>107</b> with the receiver <b>104</b>'s public key <b>108</b> in step <b>208</b>. The receiver <b>104</b> is configured to request to subscribe to the symmetric key <b>107</b> associated with the sender. The sender <b>102</b> is configured to allow or deny the subscription request, or to simply give the receiver <b>104</b> the current symmetric key <b>107</b> and no other keys. The sender <b>102</b> is configured to roll over its symmetric key <b>107</b> over based on a predetermined criterion (such as expiration date) or by choosing to do so manually. According to one aspect of the present invention, in order for the sender <b>102</b> to transmit secure data to the receiver <b>104</b>, the receiver <b>104</b> must have the sender <b>102</b>'s symmetric key <b>107</b>. The receiver <b>104</b> may specifically request the symmetric key <b>107</b> associated with the sender <b>102</b> or the sender <b>102</b> may transmit to the receiver <b>104</b> the symmetric key <b>107</b> at any time based on a predetermined set of criteria.
0057When the sender <b>102</b> rolls its symmetric key <b>107</b> over, the new symmetric key <b>107</b> is encrypted (with a public key) separately for each registered subscriber. The sender <b>102</b> generates a new symmetric key <b>107</b> in step <b>420</b>. According to one aspect of the present invention, the sender <b>102</b> transmits a request or query to the key management service <b>118</b> indicating that the sender <b>102</b> would like to receive a new symmetric key <b>107</b>. The key management service <b>118</b> transmits a request to the key source <b>114</b> to generate a new symmetric key <b>107</b> for the sender <b>102</b>. The key source <b>114</b> generates a new symmetric key <b>107</b>. The key source <b>114</b> retrieves a public key associated with the sender <b>102</b>. The key source <b>114</b> encrypts the new symmetric key <b>107</b> with the public key associated with the sender <b>102</b>. The key source <b>114</b> then transmits the encrypted symmetric key <b>107</b> to the key management service <b>118</b>. The key management service <b>118</b> transmits the new symmetric key <b>107</b> to the sender <b>102</b>.
0058The sender <b>102</b> retrieves a first subscriber's public key <b>108</b> in step <b>422</b>. According to one aspect of the present invention, the public key <b>108</b> is steganographically embedded into an image associated with and broadcast by the first subscriber (such as the image <b>106</b> associated with the receiver <b>104</b>). According to a further aspect of the present invention, the first subscriber's public key <b>108</b> is stored on a public or private cloud. Selected users have access to the public key <b>108</b> stored on the public or private cloud. According to a further aspect of the present invention, the sender <b>102</b> transmits a specific request to receive the first subscriber's public key <b>108</b> or the first subscriber transmits the public key <b>108</b> to the sender <b>102</b> based on a predetermined criterion or trigger.
0059The sender <b>102</b> encrypts the new symmetric key <b>107</b> with the first subscriber's public key <b>108</b> for the first subscriber. This encryption is carried out using the public key <b>108</b> of the first subscriber (such as the receiver <b>104</b>). If there are multiple users or devices that subscribe to the sender <b>102</b>'s keys, the sender <b>102</b> retrieves a subsequent subscriber's (e.g., subscriber “n”) public key in step <b>426</b>. The sender <b>102</b> encrypts the symmetric key <b>107</b> for each subsequent subscriber with that subscriber's public key <b>108</b> in step <b>428</b>.
0060The sender <b>102</b> transmits or publishes a bundle of encrypted symmetric keys to the network <b>105</b> in step <b>430</b>. According to one aspect of the present invention, the sender <b>102</b> transmits or publishes the bundle of encrypted symmetric keys by transmitting an image including the steganographically embedded encrypted symmetric key bundle. According to a further aspect of the present invention, the sender <b>102</b> transmits the bundle of encrypted symmetric keys to the key management service <b>118</b> for download by the receiving devices in the network <b>105</b>. Each receiver in the network (such as the receiving device <b>104</b>) downloads his own corresponding encrypted symmetric key <b>107</b>. The bundle includes several encrypted keys, with a unique key being provided for each subscriber. Each subscriber checks the transmitted or published bundle for a personal encrypted symmetric key. The personal symmetric key for a given subscriber is encrypted with that subscriber's public key. Each subscriber retrieves the personal encrypted symmetric key in step <b>432</b>. Each subscriber locally decrypts the encoded symmetric key with each subscriber's unique private key <b>110</b> in step <b>434</b>. Each subscriber stores the decrypted symmetric key for subsequent usage in step <b>436</b>.
0061According to one aspect of the present invention, the sender <b>102</b> is configured to broadcast only a single message or image including the bundle of encrypted symmetric keys <b>107</b>. A separate message or image including steganographically embedded encrypted symmetric key does not need to be transmitted to each user, which significantly reduces the strain on the network <b>105</b>.
0062According to one embodiment of the present invention, each one of the sender <b>102</b> and the receiver <b>104</b> is coupled to the key source <b>114</b>. The key source <b>114</b> includes processing hardware configured to generate the symmetric key <b>107</b> and to roll over the symmetric key <b>107</b> based on predetermined criteria including passage of time and specific request by a network device. When the key source <b>114</b> rolls over the symmetric key <b>107</b>, the key source <b>114</b> is configured to determine which devices in the network <b>105</b> subscribe to the symmetric key <b>107</b>. The key source <b>114</b> is configured to retrieve the public keys associated with the devices in the network <b>105</b> that subscribe to the symmetric key <b>107</b>. The key source <b>114</b> includes processing hardware configured to encrypt the symmetric key <b>107</b> with the public key associated with each device in the network that subscribes to the symmetric key <b>107</b>. Accordingly, the key source <b>114</b> encrypts the symmetric key <b>107</b> individually for each subscriber with that subscriber's public key. The key source <b>114</b> combines all the encrypted symmetric keys <b>107</b> into a single message or bundle. According to one aspect of the present invention, the key source <b>114</b> transmits the bundle directly to the network <b>105</b>, such that each subscriber can download and decrypt their own corresponding encrypted symmetric key <b>107</b>. The corresponding encrypted symmetric key <b>107</b> is a symmetric key encrypted with the public key corresponding to the particular subscriber device. According to a further aspect of the present invention, the key source <b>114</b> includes processing hardware configured to steganographically embed the bundle of encrypted symmetric key <b>107</b> into an image. The key source <b>114</b> transmits or broadcasts the image to the network <b>105</b>. Each subscriber then searches the image for their corresponding encrypted symmetric key <b>107</b>. Each subscriber then decrypts the encrypted symmetric key with their own private key (e.g., private key <b>110</b> of the receiver <b>104</b>).
0063The following discussion is intended to provide a brief, general description of suitable computer processing environments in which the methods and apparatus described herein may be implemented. In one non-limiting example, the method and apparatus will be described in the general context of processor-executable instructions, such as program modules, being executed in a distributed computing environment in which tasks may be performed by remote and local processing devices linked via one or more networks. Those of ordinary skill in the art will appreciate that the method may be practiced with any number of suitable computer system configurations and is not limited to the described configurations.
0064The present invention includes systems having processors to provide various functionality to process information, and to determine results based on inputs. Generally, the processing may be achieved with a combination of hardware and software elements. The hardware aspects may include combinations of operatively coupled hardware components including microprocessors, logical circuitry, communication/networking ports, digital filters, memory, or logical circuitry. The processors may be adapted to perform operations specified by a computer-executable code, which may be stored on a computer readable medium.
0065The steps of the methods described herein may be achieved via an appropriate programmable processing device, such as an external conventional computer or an on-board field programmable gate array (FPGA) or digital signal processor (DSP), that executes software, or stored instructions. In general, physical processors and/or machines employed by embodiments of the present invention for any processing or evaluation may include one or more networked or non-networked general purpose computer systems, microprocessors, field programmable gate arrays (FPGA's), digital signal processors (DSP's), micro-controllers, and the like, programmed according to the teachings of the exemplary embodiments of the present invention, as is appreciated by those skilled in the computer and software arts. Appropriate software can be readily prepared by programmers of ordinary skill based on the teachings of the exemplary embodiments, as is appreciated by those skilled in the software arts. In addition, the devices and subsystems of the exemplary embodiments can be implemented by the preparation of application-specific integrated circuits or by interconnecting an appropriate network of conventional component circuits, as is appreciated by those skilled in the electrical arts. Thus, the exemplary embodiments are not limited to any specific combination of hardware circuitry and/or software.
0066Stored on any one or on a combination of computer readable media, the exemplary embodiments of the present invention may include software for controlling the devices and subsystems of the exemplary embodiments, for driving the devices and subsystems of the exemplary embodiments, for processing data and signals, for enabling the devices and subsystems of the exemplary embodiments to interact with a human user, and the like. Such software can include, but is not limited to, device drivers, firmware, operating systems, development tools, applications software, and the like. Such computer readable media further can include the computer program product of an embodiment of the present invention for performing all or a portion (if processing is distributed) of the processing performed in implementations. Computer code devices of the exemplary embodiments of the present invention can include any suitable interpretable or executable code mechanism, including but not limited to scripts, interpretable programs, dynamic link libraries (DLLs), Java classes and applets, complete executable programs, and the like. Moreover, parts of the processing of the exemplary embodiments of the present invention can be distributed for better performance, reliability, cost, and the like.
0067Common forms of computer-readable media may include, for example, a floppy disk, a flexible disk, hard disk, magnetic tape, any other suitable magnetic medium, a CD-ROM, CDRW, DVD, any other suitable optical medium, punch cards, paper tape, optical mark sheets, any other suitable physical medium with patterns of holes or other optically recognizable indicia, a RAM, a PROM, an EPROM, a FLASH-EPROM, any other suitable memory chip or cartridge, a carrier wave or any other suitable medium from which a computer can read.
0068While particular implementations and applications of the present disclosure have been illustrated and described, it is to be understood that the present disclosure is not limited to the precise construction and compositions disclosed herein and that various modifications, changes, and variations can be apparent from the foregoing descriptions without departing from the spirit and scope of the invention as defined in the appended claims.
Contents5
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US10116645B1 | Cited by | United States of America | Applicant |
| WO2023170454A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US9893885B1 | Cited by | United States of America | Applicant |
| CN111371546A | Cited by | China | Search report |
| DE102015210573A1 | Cited by | Germany | Search report |
| US11271715B2 | Cited by | United States of America | Applicant |
| US9794271B2 | Cited by | United States of America | Applicant |
| US11349646B1 | Cited by | United States of America | Search report |
| US2019030528A1 | Cited by | United States of America | Search report |
| US10110615B2 | Cited by | United States of America | Applicant |
| US9197408B2 | Cited by | United States of America | Search report |
| US2022006787A1 | Cited by | United States of America | Search report |
| US11611431B2 | Cited by | United States of America | Applicant |
| US9674162B1 | Cited by | United States of America | Search report |
| US2014344566A1 | Cited by | United States of America | Pre-grant |
| US2015347685A1 | Cited by | United States of America | Pre-grant |
| US10165444B2 | Cited by | United States of America | Search report |
| WO2017161616A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO2018147895A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US10154013B1 | Cited by | United States of America | Applicant |
| US11283778B2 | Cited by | United States of America | Search report |
| US2021234680A1 | Cited by | United States of America | Search report |
| US10785193B2 | Cited by | United States of America | Search report |
| US10735384B2 | Cited by | United States of America | Applicant |
| US2014337628A1 | Cited by | United States of America | Pre-grant |
| US10003467B1 | Cited by | United States of America | Applicant |
| US10841132B2 | Cited by | United States of America | Search report |
| US11330003B1 | Cited by | United States of America | Search report |
| US10985915B2 | Cited by | United States of America | Search report |
| US10462154B2 | Cited by | United States of America | Applicant |
| US11671412B2 | Cited by | United States of America | Search report |
| US11741221B2 | Cited by | United States of America | Applicant |
| US2006041762A1 | Cites | United States of America | Pre-grant |
| US2008033740A1 | Cites | United States of America | Pre-grant |
| US2008049942A1 | Cites | United States of America | Pre-grant |
| US2010261465A1 | Cites | United States of America | Pre-grant |
| US5850444A | Cites | United States of America | Pre-grant |
| US6424828B1 | Cites | United States of America | Pre-grant |
| US7039189B1 | Cites | United States of America | Pre-grant |
| US8130945B2 | Cites | United States of America | Pre-grant |
| US8458477B2 | Cites | United States of America | Pre-grant |
| US8554176B2 | Cites | United States of America | Pre-grant |
| US8726009B1 | Cites | United States of America | Pre-grant |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 201213586487 | United States of America | A | |
| US201213586487 | – | – | – |
32 transactions on the USPTO file
Abandoned after 1 non-final rejection.
- Non-final rejections
- 1
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Email NotificationEML_NTR | EML_NTR | |
| Mail Abandonment for Failure to Respond to Office ActionAbandonedMABN2 | MABN2 | |
| Aband. for Failure to Respond to O. A.AbandonedABN2 | ABN2 | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Application Is Now CompleteCOMP | COMP | |
| Sent to Classification ContractorPGPC | PGPC | |
| Filing Receipt - UpdatedFLRCPT.U | FLRCPT.U | |
| Additional Application Filing FeesADDFLFEE | ADDFLFEE | |
| A statement by one or more inventors satisfying the requirement under 35 USC 115, Oath of the ApplicOATHDECL | OATHDECL | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Notice Mailed--Application Incomplete--Filing Date AssignedINCD | INCD | |
| Cleared by L&R (LARS)L128 | L128 | |
| Referred to Level 2 (LARS) by OIPE CSRL198 | L198 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Initial Exam Team nnIEXX | IEXX |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Information on status: application discontinuationABANDONED -- FAILURE TO RESPOND TO AN OFFICE ACTIONSTCB | STCB | |
| AssignmentAS | AS |
Numbers
- Publication
- 20140052989
- Publication, DOCDB
- 2014052989
- Publication, EPODOC
- US2014052989
- Application
- 13586487
- Application, DOCDB
- 201213586487
- Application, EPODOC
- US201213586487
Titles
- English
- SECURE DATA EXCHANGE USING MESSAGING SERVICE
Classification
- CPC, 8
- H04L63/062
- H04L9/0819
- H04L9/0822
- H04L9/0825
- H04L2209/601
- G06F21/72
- G06F21/85
- H04L2463/062
- IPC, 1
- H04L9 00
- USPC, 1
- 713171000