Set of servers for “machine-to-machine” communications using public key infrastructure

Patent No. US9118464 (titled "Set of servers for “machine-to-machine” communications using public key infrastructure") on Oct 28, 2013. The application was issued on Aug 25, 2015.

What is this patent about?

’464 is related to the field of Machine-to-Machine (M2M) communications, specifically addressing the challenges of maintaining secure and energy-efficient links between remote modules and application servers. In typical M2M environments, devices frequently enter sleep states to conserve battery, causing intermediate firewalls to tear down connection states. The background context involves the need for a robust Public Key Infrastructure (PKI) that can handle dynamic IP addresses and the secure rotation of cryptographic keys without requiring manual intervention like swapping SIM cards.

The underlying idea behind ’464 is the use of an intermediate server set that acts as a secure bridge, managing the asymmetric cryptographic lifecycle of remote modules while shielding them from the overhead of complex server-side protocols. The core insight is to allow a module to internally derive new public/private key pairs based on server-provided parameters and then authenticate these new keys using a previously established trust anchor. This enables the system to update security postures and rotate keys over the air while ensuring that instructions from an application server are only delivered when the module is active and reachable.

The claims of ’464 focus on a multi-step handshake and key derivation sequence performed by a set of servers to manage a module located behind a firewall. The process involves verifying a module's identity via an initial public key, providing specific cryptographic parameters to the module for the generation of a new key pair, and then authenticating a second module public key derived from those parameters. The independent claims specifically cover the logic of receiving a module instruction from an application server and waiting to transmit it until the module reconnects from a new, different source IP:port number, ensuring the data is encrypted with the newly verified key.

In practice, the invention operates by utilizing a shared module database and a module controller that monitors for incoming UDP datagrams. When a module wakes from a dormant state, it may have a different network-assigned address; the server detects this change and uses the most recent source IP:port to bypass firewall restrictions. The server set manages two distinct security layers: a secure connection (such as TLS) with the application server using one set of keys, and a more efficient, potentially ECC-based encryption layer with the module using the derived keys. This dual-layer approach allows the module to remain low-power while the application interface remains compatible with enterprise standards.

’464 differs from prior approaches by eliminating the need for persistent, high-overhead security tunnels like IPSec or standard TLS between the module and the final application. Instead of requiring the module to re-negotiate complex handshakes after every sleep cycle, the server set maintains the stateful association between the module identity and its current cryptographic keys. By allowing the module to derive its own keys and authenticating them through a shared secret or prior key, the system provides a scalable way to refresh security without the logistical burden of physical credential management or the energy drain of traditional session establishment.

How does this patent fit in bigger picture?

Technical Landscape

In the early 2010s when ’464 was filed, machine-to-machine (M2M) communications were typically implemented using wireless wide-area networking standards originally optimized for mobile telephony, where systems commonly relied on continuous network attachment rather than power-efficient sleep cycles. At a time when hardware constraints made the implementation of resource-intensive security protocols like TLS or IPSec non-trivial for small-form-factor sensors, secure data exchange often required significant packet overhead and frequent re-negotiation of encrypted tunnels. Furthermore, cryptographic management in these systems was typically static, relying on pre-shared secret keys embedded in physical modules, which made the remote update of security credentials or the transition to modern public key infrastructure (PKI) difficult without manual intervention.

Prosecution Position

The disclosed invention represents a meaningful technical advancement through an architectural shift that decouples the secure communication requirements of an application from the resource constraints of an M2M module. By utilizing an intermediate server to perform protocol and cryptographic translation—such as converting between UDP-based ECC communications used by the module and TCP-based RSA communications used by the application—the system enables high energy efficiency and reduced bandwidth consumption without compromising end-to-end security. A key capability enabled is the secure, remote derivation of new module public/private key pairs using server-provided cryptographic parameters, allowing modules to update their security posture autonomously. This integration overcomes the technical constraint of network-layer connection teardowns during module dormancy, as the server can buffer application instructions and manage secure handshakes independently of the module’s power state.

Claims

The patent contains 17 claims, consisting of independent claims 1 and 11, which focus on a method and a system for supporting machine-to-machine communications by managing secure data transmissions between a server set and a module located behind a firewall through the dynamic derivation of cryptographic key pairs and the tracking of changing source IP addresses and port numbers. The dependent claims generally serve to specify particular cryptographic parameters, define the use of symmetric and asymmetric encryption algorithms such as RSA and elliptic curve cryptography, detail the hardware components like eUICCs and mobile phones, and refine the messaging protocols and authentication steps used during the communication process.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Cryptographic parameters
(Claim 1, Claim 11)
Cryptographic parameters input into key pair generation algorithms can include the type of asymmetric ciphering algorithms used, the key length in bits, an elliptic curve utilized for ECC, and a time-to-live for a public key. They can include values to define an equation for an elliptic curve, such as constants and variables, allowing the module to calculate a new, potentially non-standard elliptic curve. Parameters may also include a supported point formats extension (uncompressed or compressed) as specified in standards like ANSI X-9.62.A set of values or settings used by a module to define the characteristics of a cryptographic algorithm or key pair, such as elliptic curve equations, key lengths, or base points, enabling the module to derive a new public and private key pair.
Module identity
(Claim 1, Claim 11)
The server can receive a message that includes a module identity and a module encrypted data. The use of a pre-shared secret key can ensure a submitted module public key is validly associated with the module and module identity. The server can poll a shared module database using the module identity to retrieve recorded instructions or cryptographic settings.A unique identifier for a machine-to-machine (M2M) device that allows a server to associate incoming messages, public keys, and instructions with a specific physical module recorded in a database.
Module instruction
(Claim 1, Claim 11)
The module instruction can include an actuator setting and also optionally an actuator identity. Since the module can transition between periods of sleep and active states, the server can wait until a next message is received from the module before sending the module instruction in a response. Examples include turning on or off a power switch, locking or unlocking a door, or adjusting a motor speed.Command data originated by an application server and intended for a specific module, such as an actuator setting or configuration update, which is buffered by an intermediate server until the module wakes from a sleep state.
Server encrypted data
(Claim 1)
The server can send the module instruction to the module in a server encrypted data using a second server public key. The server encrypted data could be processed using any of a first module public key, a symmetric key, or a shared secret key. This ensures that an observer along the flow of data could not observe the contents of the instruction or the parameters being used.Plaintext data, such as a module instruction, that has been ciphered by the server using the module's specific public key (e.g., the second module public key) to ensure secure delivery to the module.
Shared module database
(Claim 11)
The set of servers can record and query data from a shared module database. The shared module database can return the module instruction that was recorded by the application server. It can also authoritatively record the derived module public key with the module identity to ensure the key is validly associated with the device.A centralized repository accessible by a set of servers that stores and manages module-specific security credentials, including identities, public keys, pre-shared secret keys, and pending instructions.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
2:25-cv-00667Jun 27, 2025Network-1 Technologies, Inc. v. SAMSUNG ELECTRONICS CO., LTD. et al

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US9118464

Application Number
US14064618A
Filing Date
Oct 28, 2013
Publication Date
Aug 25, 2015
External Links
Slate, USPTO , Google Patents