Methods and systems for communication-session arrangement on behalf of cryptographic endpoints

    公开(公告)号:US10356059B2

    公开(公告)日:2019-07-16

    申请号:US14730807

    申请日:2015-06-04

    申请人: NAGRAVISION S.A.

    摘要: In an embodiment, a communication device receives a request to establish a media session with a remote endpoint. In response to receiving the request, the communication device exchanges media-session control data with the remote endpoint on behalf of a local endpoint to establish the requested media session between the local endpoint and the remote endpoint. The communication device is communicatively connected to the local endpoint via a Personal Area Network (PAN) communication link. The communication device relays media-session payload data between the local and remote endpoints. The media-session payload data (i) is associated with the media session and (ii) is encrypted based on at least one payload-data cryptographic key that is not accessible to the communication device.

    Systems and methods for conducting secure VOIP multi-party calls

    公开(公告)号:US10122767B2

    公开(公告)日:2018-11-06

    申请号:US14726108

    申请日:2015-05-29

    申请人: NAGRAVISION S.A.

    摘要: System and method for establish secure conference calls. In one example system, a central conference call server establishes point-to-point connections with accessory devices comprising a secure element and connected to corresponding participant devices. The conference call server includes an interface to a plurality of secure elements configured to perform scrambling and unscrambling of media signals communicated to and from the accessory devices. In another example, one of the participant devices operates as the central conference call server. In other examples, participant devices communicate on a conference call via point-to-point connections between all accessory devices connected to the participant devices. The accessory devices include secure elements for decryption and encryption of media signals communicated between the accessory devices.

    Method and system for smart card chip personalization

    公开(公告)号:US09729322B2

    公开(公告)日:2017-08-08

    申请号:US15093044

    申请日:2016-04-07

    申请人: NAGRAVISION S.A.

    摘要: Method and system for personalizing a chip, intended to be integrated into a smart card, comprising a tester associated to an FPGA device connected to the chip, the chip being part of a wafer comprising a plurality of chips and a disposable hardware module for verifying presence of the chip on the wafer. The tester sends a first secret code to the FPGA device, which commands the chip to initiate a test mode activation. The FPGA device encrypts a second secret code by using a secret encryption algorithm parameterized with a random number received from the chip and the first secret code to obtain a first cryptogram which is sent to the chip. The chip determines a second cryptogram by carrying out a Boolean function over a result obtained by decryption of the first cryptogram using the inverse algorithm parameterized with the random number and the first secret code. The second cryptogram is compared with a result obtained by carrying out the Boolean function over the second secret code temporarily stored on the chip. The FPGA device personalizes the chip only if the second cryptogram matches the calculated result.

    METHODS AND SYSTEMS FOR COMMUNICATION-SESSION ARRANGEMENT ON BEHALF OF CRYPTOGRAPHIC ENDPOINTS
    4.
    发明申请
    METHODS AND SYSTEMS FOR COMMUNICATION-SESSION ARRANGEMENT ON BEHALF OF CRYPTOGRAPHIC ENDPOINTS 审中-公开
    通讯会议安排方法和系统

    公开(公告)号:US20160359814A1

    公开(公告)日:2016-12-08

    申请号:US14730807

    申请日:2015-06-04

    申请人: NAGRAVISION S.A.

    IPC分类号: H04L29/06 H04W4/00

    摘要: In an embodiment, a communication device receives a request to establish a media session with a remote endpoint. In response to receiving the request, the communication device exchanges media-session control data with the remote endpoint on behalf of a local endpoint to establish the requested media session between the local endpoint and the remote endpoint. The communication device is communicatively connected to the local endpoint via a Personal Area Network (PAN) communication link. The communication device relays media-session payload data between the local and remote endpoints. The media-session payload data (i) is associated with the media session and (ii) is encrypted based on at least one payload-data cryptographic key that is not accessible to the communication device.

    摘要翻译: 在一个实施例中,通信设备接收与远程端点建立媒体会话的请求。 响应于接收到请求,通信设备代表本地端点与远程端点交换媒体会话控制数据,以在本地端点和远程端点之间建立所请求的媒体会话。 通信设备经由个人局域网(PAN)通信链路与本地端点通信地连接。 通信设备在本地和远程端点之间中继媒体会话有效负载数据。 媒体会话有效载荷数据(i)与媒体会话相关联,并且(ii)基于通信设备不可访问的至少一个有效载荷数据密码密钥进行加密。

    METHOD AND SYSTEM FOR SMART CARD CHIP PERSONALIZATION
    5.
    发明申请
    METHOD AND SYSTEM FOR SMART CARD CHIP PERSONALIZATION 有权
    智能卡芯片个性化方法与系统

    公开(公告)号:US20150270962A1

    公开(公告)日:2015-09-24

    申请号:US14432426

    申请日:2013-10-08

    申请人: NAGRAVISION S.A.

    IPC分类号: H04L9/08 H04L9/14

    摘要: Method and system for personalizing a chip, intended to be integrated into a smart card, comprising a tester associated to an FPGA device connected to the chip, the chip being part of a wafer comprising a plurality of chips and a disposable hardware module for verifying presence of the chip on the wafer. The tester sends a first secret code to the FPGA device, which commands the chip to initiate a test mode activation. The FPGA device encrypts a second secret code by using a secret encryption algorithm parameterized with a random number received from the chip and the first secret code to obtain a first cryptogram which is sent to the chip. The chip determines a second cryptogram by carrying out a Boolean function over a result obtained by decryption of the first cryptogram using the inverse algorithm parameterized with the random number and the first secret code. The second cryptogram is compared with a result obtained by carrying out the Boolean function over the second secret code temporarily stored on the chip. The FPGA device personalizes the chip only if the second cryptogram matches the calculated result.

    摘要翻译: 用于个性化芯片的方法和系统,旨在集成到智能卡中,包括与连接到芯片的FPGA器件相关联的测试器,该芯片是包括多个芯片的晶片的一部分,以及用于验证存在的一次性硬件模块 的晶片上的芯片。 测试仪向FPGA设备发送第一个密码,命令芯片启动测试模式激活。 FPGA设备通过使用由从芯片接收的随机数参数化的秘密加密算法和第一密码来加密第二密码,以获得发送到芯片的第一密码。 芯片通过对使用使用随机数和第一秘密码参数化的逆算法对第一密码进行解密获得的结果执行布尔函数来确定第二密码。 将第二密码与通过临时存储在芯片上的第二密码执行布尔函数获得的结果进行比较。 仅当第二个密码符合计算结果时,FPGA器件才会对芯片进行个性化设置。

    Cryptographic key configuration using physical unclonable function

    公开(公告)号:US11985236B2

    公开(公告)日:2024-05-14

    申请号:US17256673

    申请日:2019-06-21

    申请人: NAGRAVISION S.A.

    IPC分类号: H04L9/08 H04L9/32

    摘要: The disclosure relates to a method of obtaining a cryptographic key in a chipset (1). An initial configuration message may be generated using a physical unclonable function (hereinafter: PUF) (22) of the chipset (1). Said PUF (22) may generate a predetermined value when using the initial configuration message as input to the PUF (22). The initial configuration message may be transmitted to a client access server (31). An altered configuration message may be received from the client access server (31), wherein the altered configuration message is generated by the client access server (31) based on the initial configuration message. The cryptographic key may be obtained from the PUF (22) using the altered configuration message as input to the PUF (22).

    Systems and methods for conducting secure VOIP multi-party calls

    公开(公告)号:US11606398B2

    公开(公告)日:2023-03-14

    申请号:US16892886

    申请日:2020-06-04

    申请人: NAGRAVISION S.A

    摘要: System and method for establishing secure conference calls. In one example system, a central conference call server establishes point-to-point connections with accessory devices comprising a secure element and connected to corresponding participant devices. The conference call server includes an interface to a plurality of secure elements configured to perform scrambling and unscrambling of media signals communicated to and from the accessory devices. In another example, one of the participant devices operates as the central conference call server. In other examples, participant devices communicate on a conference call via point-to-point connections between all accessory devices connected to the participant devices. The accessory devices include secure elements for decryption and encryption of media signals communicated between the accessory devices.

    Systems and methods for conducting secure VOIP multi-party calls

    公开(公告)号:US10715557B2

    公开(公告)日:2020-07-14

    申请号:US16130828

    申请日:2018-09-13

    申请人: NAGRAVISION S.A.

    摘要: System and method for establishing secure conference calls. In one example system, a central conference call server establishes point-to-point connections with accessory devices comprising a secure element and connected to corresponding participant devices. The conference call server includes an interface to a plurality of secure elements configured to perform scrambling and unscrambling of media signals communicated to and from the accessory devices. In another example, one of the participant devices operates as the central conference call server. In other examples, participant devices communicate on a conference call via point-to-point connections between all accessory devices connected to the participant devices. The accessory devices include secure elements for decryption and encryption of media signals communicated between the accessory devices.

    Methods and systems for encrypting communications using a secure element

    公开(公告)号:US10237730B2

    公开(公告)日:2019-03-19

    申请号:US15151224

    申请日:2016-05-10

    申请人: NAGRAVISION S.A.

    摘要: Disclosed herein are methods and systems for encrypting communications using a secure element. An embodiment takes the form of a method including the steps of performing a key-exchange procedure with an endpoint via a voice-communication device to obtain a symmetric seed key for a secure voice session with the endpoint; generating first and second symmetric session keys for the secure voice session based on the obtained symmetric seed key; receiving outbound voice packets from the voice-communication device in connection with the secure voice session, each outbound voice packet including a header and an unencrypted payload; using a first symmetric encryption algorithm and the first symmetric session key, followed by a second symmetric encryption algorithm and the second symmetric session key to generate and output twice-encrypted outbound-voice-packet payloads to the voice-communication device for transmission to the endpoint in connection with the secure voice session.