Cryptographic messaging apparatus
By combining a cryptographic message transmission device with a hardware security module, the security problem of encrypted communication in sensitive team collaborations was solved, achieving end-to-end encrypted communication, preventing message interception, and improving collaboration efficiency and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- AMAZON TECH INC
- Filing Date
- 2024-06-26
- Publication Date
- 2026-06-02
AI Technical Summary
In sensitive areas, due to security concerns, existing technologies cannot effectively utilize devices such as mobile phones for reliable encrypted communication during team collaboration, leading to delays and wasted resources.
Design a cryptographic message transmission device that couples with internet access devices such as mobile phones, uses a hardware security module for encrypted communication, ensures that messages do not pass through the mobile phone's operating system in their unencrypted form, employs end-to-end encryption technology, and creates and manages secure channels through the provider's network.
It enables secure communication without relying on the mobile phone operating system, avoids the risk of message interception, and improves the efficiency and security of team collaboration.
Smart Images

Figure CN121420299B_ABST
Abstract
Description
Background Technology
[0001] Client companies working in sensitive areas experience a lack of visibility, delays, and team stress when responding to unplanned, time-sensitive issues. For example, a team wanting to discuss details of a sensitive operational issue might need to meet in a physical location. Waiting for team members to arrive at that location delays problem resolution. Because some details cannot be shared over public networks due to security concerns, it is difficult to determine who has relevant insights into the issue at hand. Consequently, more team members are often requested to be present than actually needed.
[0002] Delays and wasted effort can be avoided if leaders exchange a few lines of sensitive information with the team before determining who needs to collaborate in-person and who can contribute remotely. Wise decisions about who needs to travel and who can contribute remotely optimize team efficiency and increase team member satisfaction.
[0003] Distributed teams have readily embraced mobile-based text messaging as an effective collaboration tool. However, unfortunately, security-sensitive customers distrust mobile hardware, system software, and applications. Attached Figure Description
[0004] Various examples according to this disclosure will be described with reference to the accompanying drawings, in which:
[0005] Figure 1 An example of a cryptographic messaging device is shown.
[0006] Figure 2 An example of a screen for a cryptographic messaging device is shown.
[0007] Figure 3 An example of using a cryptographic messaging device is shown.
[0008] Figure 4 An example of using a cryptographic messaging device is shown.
[0009] Figure 5 An example of a provider network and its device messaging service is shown.
[0010] Figure 6 This is a flowchart illustrating the operation of a method for using a cryptographic device, based on some examples.
[0011] Figure 7 This is a flowchart illustrating the operation of a method for registering a password messaging device, based on some examples.
[0012] Figure 8 This is a flowchart illustrating the operations of a method for generating a message to be received, based on some examples.
[0013] Figure 9 This is a flowchart illustrating the operations of methods for handling messages, based on some examples.
[0014] Figure 10 The example provider network environment is shown based on some examples.
[0015] Figure 11 This is a block diagram of an example provider network that offers storage services and hardware virtualization services to customers, based on some examples.
[0016] Figure 12 This is a block diagram illustrating an example computer system that can be used in some examples. Detailed Implementation
[0017] This disclosure relates to methods, apparatus, systems, and non-transitory computer-readable storage media for secure communications. In some examples, a mobile phone (or other Internet access device) is used minimally to relay secure communications to / from coupled cryptographic communication devices.
[0018] Existing solutions for sending and receiving encrypted communications typically rely on software applications running on general-purpose machines (telephones, tablets, PCs, etc.). For example, a popular method of encrypted communication is using encrypted messaging programs installed and running on smartphones. These applications often make their cryptographic libraries available in open source and provide client and server implementations. These resources guide device design and foster trust in security certification authorities. Unfortunately, these software solutions still require operation on devices that are not always secure by default. That is, messages are entered unencrypted into software accessible to the device's operating system. If malware or other rogue software is present on the device, these messages could be intercepted and used by malicious actors.
[0019] The examples described in detail in this article refer to cryptographic communication devices isolated from their external communication means. That is, the device is coupled (e.g., using a cable) to a mobile phone (or other internet access device), and the networking capabilities of the mobile phone (or other internet access device) are used to transmit messages encrypted before being provided to the mobile phone (or other internet access device). Therefore, the operating system or other software on the mobile phone (or other internet access device) can never access any unencrypted data from the cryptographic communication device.
[0020] Cryptographic communication devices allow users to compose, display, send, and / or receive cryptographic messages (message content can be text, audio, video, images, combinations thereof, etc.). For example, a cryptographic communication device can receive plaintext from its own dedicated keyboard (hardware or virtual keyboard), encrypt the plaintext as part of an encrypted message, and use the phone's internet connectivity to transmit the encrypted message. Similarly, the encrypted message is received via the phone's internet connectivity, decrypted by the cryptographic communication device, and then displayed on the cryptographic communication device's screen. Plaintext messages never pass through the phone, nor are they transmitted or received over public networks. Cryptographic communication devices use paired, end-to-end cryptographic techniques. In some examples, encrypted audio, images, and / or audio / video including messages are supported. Similar to text messages, these messages do not pass through the phone unencrypted.
[0021] In some examples, the cryptographic communication device is attached to the back of the phone as a protective case and provides a separate physical interface for composing and displaying text messages. The cryptographic communication device includes the cryptographic capability to create a secure channel between communicating users. The cryptographic communication device receives power and / or internet access, and nothing else. It can be connected via a cable such as a Universal Serial Bus (USB) or a Lightning® cable.
[0022] In some examples, each cryptographic communication device registers with a service (e.g., a provider network service) to register the device and / or user. If it is desired to isolate user communications, users can be assigned to one or more groups. For example, groups can be used to enforce isolation or to bind communications to specific classification levels such as confidential or secret. Cryptographic materials are used to irrevocably associate a user's name, biometric characteristics, and / or authorized group with each cryptographic communication device.
[0023] Figure 1 An example of a cryptographic messaging device is shown. Cryptographic messaging device 100 allows a user to send and receive encrypted and signed messages via insecure mobile phones, networks, devices, servers, and services. Only the receiving device can decrypt and verify the message's signature, thus protecting the integrity and confidentiality of the message's content.
[0024] The cryptographic messaging apparatus 100 includes computing resources 130, such as one or more processors 131, for executing a messaging application 136 running on an operating system 134 stored in memory 132. The messaging application 136 utilizes one or more hardware security modules (HSMs) 120 to send and receive encrypted and signed messages. In some examples, the messaging application 136 is stored in secure storage 126 of the HSM 120 when not in use. In some examples, the messaging application 136 is executed in a secure enclave. In some examples, messages handled by the messaging application 136 are temporary and erased once read. In some examples, messages can be manually deleted.
[0025] Cryptographic operations are performed internally by the HSM 120, which uses and protects the private key used to sign messages. The recipient's public key is used to generate a shared key, which is used to encrypt the signed message. In some examples, one or more cryptographic engines 124 generate the key. Examples of supported cryptographic algorithms may include, but are not limited to, elliptic curve cryptography (ECC), ECDSA, ECDH, AES-256, SHA256, SHA3 (KECCAK), and / or post-quantum cryptography algorithms. In some examples, one or more cryptographic engines 124 utilize physically unclonable functions (PUFs). In some examples, the public key is provided offline (e.g., without using a messaging service).
[0026] HSM 120 uses key management 128 to generate and store keys (e.g., private keys and shared keys) in secure storage 126 in a tamper-proof manner. In some examples, the generated keys are never exposed outside the HSM.
[0027] In some examples, a secure microcontroller 122 is used to oversee device multi-factor authentication and / or physical security, run key management 128, and / or isolate secure elements (key management 128, secure storage 126) from computing resources 130.
[0028] In some examples, HSM 120 is used with physical intrusion detection system 170 to monitor signs of physical tampering, which may perform one or more of the following: monitoring power quality to detect anomalies such as undervoltage events, using one or more accelerometers to detect impact and orientation change events, and / or using peripheral integrity circuitry to detect interruptions in defined line loops / grids. In some examples, biometric security 190, such as a fingerprint reader, is used to access password messaging device 100.
[0029] The cryptographic messaging device 100 is locked, preventing it from communicating wirelessly (via Wi-Fi®, Bluetooth®, etc.) and restricting its access to its host device via cable. However, messages are encrypted upon leaving the cryptographic messaging device 100 and are transmitted in encrypted form until they reach their destination device, which contains a unique private key capable of decrypting the messages. Furthermore, the cryptographic messaging device locks itself if its operating system 134 or an application such as messaging application 136 is modified or tampered with.
[0030] In some examples, the password messaging device 100 includes one or more screens 110 to allow a user to use a messaging application 136 and / or other applications. In some examples, the one or more screens 110 are touchscreens. In some examples, the one or more screens 110 provide a virtual keyboard for input. In some examples, a physical keyboard 160 is used for input.
[0031] In some examples, the ciphertext messaging device 100 includes one or more of a microphone, a camera (still and / or video camera), and / or a speaker. The microphone and / or camera can be used as input to the messaging application 136.
[0032] In some examples, the cryptographic messaging device 100 includes a power management component 140 for controlling power to computing resources 130, HSM 120, etc. In some examples, when the cryptographic messaging device 100 is coupled to a network support device 180, it uses one or more input / output (I / O) ports 150 to obtain power. That is, the cryptographic messaging device 100 may not have its own power supply 142 and may draw power from an external power supply 188. The I / O port 150 may be one or more of a Universal Serial Bus (USB) port, a Lightning® port, etc.
[0033] In some examples, one or more system buses and / or interconnects 152 are used to couple various aspects of the cryptographic messaging apparatus 100.
[0034] In some examples, network support device 180 provides power (via power manager 186 and power supply 188) and / or network access (via networking hardware 184, such as cellular or satellite communication hardware). It should be noted that the network can be any network other than the Internet. In some examples, computing resources 182 include one or more processors, memory, and an operating system. In some examples, the operating system controls network access, and this aspect of the operating system can be accessed by cryptographic messaging device 100. In other examples, cryptographic messaging device 100 bypasses the operating system to use networking hardware 184.
[0035] Figure 2 An example screen of a password messaging device, such as password messaging device 100, is shown. As shown, a graphical user interface (GUI) 201 allows the user to "converse" 211 with another party who also has a password messaging device. In this example, the conversation is between Alice and Bob. Each message in the conversation is encrypted on the user's password messaging device and then sent to the other party for decryption and display. In some examples, a virtual keyboard 221 allows for text input, file sharing, etc.
[0036] Figure 3 An example using a cryptographic messaging device is shown. As illustrated, cryptographic messaging device 100(A) (user "Alice") sends encrypted messages to cryptographic messaging device 100(B) (user "Bob") and cryptographic messaging device 100(C) (user "Caleb") via coupled network support device 180(A), through network support devices 180(B) and 180(C), respectively. In this example, encrypted messages are sent directly without any intermediate messaging service. In some examples, elliptic curve Diffie-Hellman techniques are used to create a unique, secure channel between all communicator pairs. That is, Alice has a completely separate and independently derived set of keys for her exchanges with Bob and Caleb. Bob and Caleb use at least partially their internally stored keys to decrypt the messages.
[0037] Figure 4 An example using a cryptographic messaging device is shown. As illustrated, cryptographic messaging device 100(A) (user "Alice") sends encrypted messages to cryptographic messaging device 100(B) (user "Bob") and cryptographic messaging device 100(C) (user "Caleb") via coupled network support device 180(A), through network support devices 180(B) and 180(C), respectively. In this example, the encrypted messages are sent via an intermediate messaging service. In some examples, elliptic curve Diffie-Hellman (ECDH) technology is used to create a unique, secure channel between all communicator pairs. That is, Alice has a completely separate and independently derived key set for her exchanges with Bob and Caleb. Bob and Caleb use at least partially their internally stored keys to decrypt the messages.
[0038] In some examples, the Secure Hypertext Transfer Protocol (HTTPS) is used to send messages to / from the provider's network 400. In other examples, MQ Telemetry Transport (MQTT) is used to send messages. MQTT uses a publish / subscribe communication model where the client sending (publishing) a message is decoupled from the receiving (subscriber) device via a third party. When the connection from the subscribing client to the intermediary is broken, the intermediary buffers the message and pushes it to the subscriber when it becomes online again. When the connection from the publishing client to the intermediary is broken without notification, the intermediary can close the connection and send a cached message with instructions from the publisher to the subscriber. The MQTT intermediary acts as a medium between the clients sending messages and the subscribers receiving those messages.
[0039] In some examples, different transport protocols such as Constrained Application Protocol (CoAP), Advanced Message Queuing Protocol (AMQP), Simple / Streaming Text Directed Messaging Protocol (STOMP), Mosquito, and Simple Media Control Protocol (SMCP) are used to send / receive messages.
[0040] In some examples, provider network 400 includes a device messaging service for handling messages. Provider network 400 (or “cloud” provider network) provides users with the ability to use one or more of various types of compute-related resources, such as compute resources (e.g., executing virtual machine (VM) instances and / or containers, executing batch jobs, executing code without server provisioning), data / storage resources (e.g., object storage, block-level storage, data archive storage, databases and database tables, etc.), network-related resources (e.g., configuring virtual networks that include groups of compute resources, content delivery networks (CDNs), domain name services (DNS)), application resources (e.g., databases, application build / deployment services), access policies or roles, identity policies or roles, machine images, routers, and other data processing resources. These and other compute resources may be provided as services, such as hardware virtualization services that can execute compute instances, storage services that can store data objects, etc. Users of provider network 400 (or “customers”) may use one or more user accounts associated with a customer account; however, these terms may be used interchangeably to some extent depending on the use case. Users can interact with provider network 400 across one or more intermediate networks (e.g., the Internet) via one or more interfaces, such as through application programming interface (API) calls, via a console implemented as a website or application, etc. An API is an interface and / or communication protocol between a client and a server, such that if a client makes a request in a predefined format, the client should receive a response in a specific format or initiate a defined action. In a cloud provider network scenario, an API provides a gateway for customers to access cloud infrastructure by allowing customers to obtain data from or initiate actions within the cloud provider network, thereby enabling the development of applications that interact with resources and services hosted within the cloud provider network. APIs can also enable different services within the cloud provider network to exchange data with each other. Interfaces can be part of the provider network 400's control plane or act as the front end of the control plane, which includes "back-end" services that support and enable services that can be provided more directly to customers.
[0041] As described in this article, one type of service that a provider network can offer may be referred to as a "managed computing service," which executes code or provides computing resources for its users within a managed configuration. Examples of managed computing services include, for example, on-demand code execution services, hardware virtualization services, container services, etc.
[0042] On-Demand Code Execution Service (referred to in various examples as Function Compute Service, Function Service, Cloud Function Service, Function as a Service, or Serverless Compute Service) enables users of Provider Network 400 to execute their code on cloud resources without having to select or manage the underlying hardware resources used to execute that code. For example, a user can use On-Demand Code Execution Service by uploading their code and using one or more APIs to request the service to identify, provision, and manage any resources required to run the code. Therefore, in various examples, “serverless” functionality can include on-demand executable code provided by a user or other entity—such as the Provider Network itself. Serverless functionality is maintained within the Provider Network through On-Demand Code Execution Service and can be associated with a specific user or account or can typically be accessed by multiple users / accounts. Serverless functionality can be associated with a Uniform Resource Locator (URL), Uniform Resource Identifier (URI), or other reference that can be used to invoke the serverless functionality. Serverless functionality can be executed via computing resources such as virtual machines or containers when triggered or invoked. In some examples, serverless functionality can be invoked via Application Programming Interface (API) calls or specially formatted Hypertext Transfer Protocol (HTTP) request messages. Therefore, users can define serverless functions that can be executed on demand without requiring them to maintain dedicated infrastructure for executing serverless functions. Alternatively, resources maintained by the provider's network 400 can be used to execute serverless functions on demand. In some examples, these resources can be maintained in a "ready" state (e.g., with a pre-initialized runtime environment configured to execute serverless functions), thereby allowing serverless functions to be executed almost in real time.
[0043] Figure 5 An example of a provider network and its device messaging service is shown. Device messaging service 501 allows user devices to communicate with each other, allows users and devices to register, stores public keys and provides public keys to registered cryptographic devices, and provides infrastructure for devices to send and retrieve (encrypted) messages.
[0044] The device and / or user registry 511 stores information about the cryptographic device, such as identification information, owner (user), contact information, etc. In some examples, the user is registered and verified by a trusted human agent. If verified, a unique user identifier is generated. In some examples, the trusted agent obtains the user's biometric data, and the biometrics, customer contact information, and user ID are added to the secure user directory of registry 511. In some examples, the public key for each device (e.g., a public key generated by certificate service 509) is stored in registry 511.
[0045] The user's ID is associated with a unique serial number for the password messaging device. In some examples, registering the password messaging device results in an encrypted operating system image being loaded into the device. A key used to decrypt the operating system image is loaded into the device's HSM. This key is used to decrypt the operating system image each time the device boots. The customer's biometrics (at the time of use) are entered into the device's HSM.
[0046] The HSM is triggered to generate a private key set. If the HSM detects an attempt to physically leak the device, the private key cannot be extracted from the HSM and will be erased by the HSM along with all identifying information such as biometrics. Authentication (e.g., biometrics, camera, PIN, password, etc.) combined with HSM physical leak detection mitigates the risk of smash-and-grab attacks. Furthermore, no customer message data is retained at rest. When the device is powered off, only the keys stored in the HSM and the encrypted operating system image are retained.
[0047] Users can opt out voluntarily or involuntarily. At any time and for any reason, the administrator of Device Messaging Service 501 can revoke privileges granted to a specific device and delete the user's information from Registry 511. This isolates the device from Device Messaging Service 501 and all other user devices, as needed in the event of a lost or stolen password-messaging device. For planned user opt-out, a trusted human agent will collect the device and isolate it from all other users and Device Messaging Service 501. The trusted agent can reclaim the device by zeroing out the device's HSM, checking the device for signs of physical tampering, and then re-registering the device with a new user.
[0048] The authentication / authorization component 503 verifies the identity of the device. This authentication can be server authentication (allowing devices to ensure they are communicating with the correct service) and / or client authentication where the device authenticates itself. In some examples, X.509 certificates are used. Authorization determines whether the device is allowed to access messages, etc.
[0049] Device gateway 505 handles device connections and communications. In some examples, device gateway 505 acts as a message intermediary in a publish / subscribe model. Messages to be distributed are stored in message store 513. In some examples, the store is encrypted (therefore the messages themselves are encrypted multiple times). In some examples, device messaging service 501 generates out-of-band messages to notify receiving devices of the existence of messages stored for that receiving device.
[0050] The rules engine 507 allows the device to interact with other services in the provider network 400, analyze rules, and execute actions.
[0051] Certificate Services 509 allows the generation of keys / certificates to be used.
[0052] In some examples, the device messaging service 501 does not have the ability to decrypt any messages. In some examples, the device messaging service 501 stores messages until a cryptographic messaging device connects to the service and receives the message, but does not retain them for longer than that (if configured to do so). The device messaging service 501 supports multiple organizations, each with an isolated set of cryptographic devices.
[0053] To send a message using Device Messaging Service 501, the user looks up the recipient in Registry 511. The sending device connects to the receiving device via Device Messaging Service 501. Once connected, the sending and receiving devices derive unique cryptographic material for secure, post-disclosure secure (e.g., using a double-ratchet algorithm), paired conversations. This ensures that Device Messaging Service 501, eavesdroppers, and man-in-the-middle attackers cannot observe or leak the conversation.
[0054] Figure 6 This is a flowchart illustrating operations for using cryptographic devices according to some examples. Some or all of the operations (or other processes, variations, and / or combinations thereof described herein) are executed under the control of one or more computer systems configured with executable instructions and are implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) that commonly execute on one or more processors. The code is stored, for example, on a computer-readable storage medium in the form of a computer program including instructions executable by one or more processors. The computer-readable storage medium is non-transitory. In some examples, one or more of the operations are performed by one or more of the cryptographic messaging devices, messaging services, etc., shown in the other figures.
[0055] In some examples, at position 602, the cryptographic messaging device is registered with the provider's network service. This registration allows the cryptographic messaging device to send and / or receive messages.
[0056] Figure 7This is a flowchart illustrating the operation of a method for registering a cryptographic messaging apparatus according to some examples. Some or all of the operations (or other processes, variations, and / or combinations thereof described herein) are executed under the control of one or more computer systems configured with executable instructions and are implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) that commonly executes on one or more processors. The code is stored, for example, on a computer-readable storage medium in the form of a computer program including instructions executable by one or more processors. The computer-readable storage medium is non-transitory. In some examples, one or more of the operations are performed by one or more of the cryptographic messaging apparatuses, messaging services, etc., as shown in the other figures.
[0057] At point 702, an identifier is assigned to the cryptographic messaging device. This identifier is used to uniquely identify the device and is associated with a specific user. Therefore, messages destined for a user can be routed to the correct device. However, even if a message is routed incorrectly, the wrong receiving device will not have the necessary information to decrypt the message.
[0058] At 704, the hardware security module of the cryptographic messaging device is used to generate and store private keys, and in some examples, to generate certificate service requests corresponding to the device's and / or the user's public keys.
[0059] At position 706, a certificate service request is received, and the certificate authority is instructed to create and sign the certificate. For example, a certificate service call is made at position 509.
[0060] At point 708, the certificate is attached to the cryptographic messaging device. That is, the device that attaches the certificate to the registry 511. At point 710, the certificate is also sent to the cryptographic messaging device for storage. Therefore, the cryptographic messaging device has a unique certificate used to authenticate its identity.
[0061] At point 712, at least one security policy is attached to the certificate (and the device). This policy allows the device to send and receive messages.
[0062] At point 604, an encrypted message is received from the cryptographic messaging device at some point in time. In some examples, this occurs at least after the sending cryptographic messaging device has been authenticated at point 603. The message is then to be sent to the intended recipient. Figure 8This is a flowchart illustrating operations for generating a message to be received, according to some examples. Some or all of the operations (or other processes, variations, and / or combinations thereof described herein) are executed under the control of one or more computer systems configured with executable instructions and are implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) that commonly execute on one or more processors. The code is stored, for example, on a computer-readable storage medium in the form of a computer program including instructions executable by one or more processors. The computer-readable storage medium is non-transitory. In some examples, one or more of the operations are performed by one or more of the cryptographic messaging apparatus, messaging services, etc., as shown in the other figures.
[0063] At 802, the system receives a selection or input of a recipient identifier. For example, a user ID is selected. The selection of the recipient establishes a communication channel. In some examples, ECDH key exchange technology is used to create the channel. For example, this selection causes each user device to generate a random ECC pair from its public and private keys, exchange the public key via a messaging service, and the device calculates a shared key based on the user's private key and the received public key. The shared key is the same key for both users. In some examples, each device's certificate contains the device's public key.
[0064] At point 804, the ciphertext messaging device receives the message (text, image, audio, video, etc.) to be sent. At point 806, the ciphertext messaging device uses its HSM to sign the message with its private key.
[0065] At position 812, the signed message is then encrypted using a secret shared key. It should be noted that the message may also include a "new" public key that the sender will use in the future. That is, a ratchet effect process can be followed, ensuring that the leakage of one key will not reveal all messages.
[0066] At point 814, the encrypted, signed message is sent to the messaging service for distribution to the recipient.
[0067] At 606, the encrypted message from the cryptographic messaging device is routed to the receiving device. In some examples, this occurs at least after the receiving cryptographic messaging device has been authenticated at 605. This could happen when the receiving device connects to the messaging service, or at a scheduled time, etc. Figure 9This is a flowchart illustrating operations for handling messages according to some examples. Some or all of the operations (or other processes, variations, and / or combinations thereof described herein) are executed under the control of one or more computer systems configured with executable instructions and are implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) that commonly execute on one or more processors. The code is stored, for example, on a computer-readable storage medium in the form of a computer program including instructions executable by one or more processors. The computer-readable storage medium is non-transitory. In some examples, one or more of the operations are performed by one or more of the cryptographic messaging apparatus, messaging services, etc., as shown in the other figures.
[0068] At position 902, the message is received by a cryptographic messaging device. For example, a message is received from a messaging service described in detail herein. In some examples, this is a Transport Layer Security (TLC) socket for a message listening messaging service.
[0069] At position 904, the shared key is calculated. Specifically, the HSM of the cryptographic messaging device calculates the shared key from its stored private key and the sender's public key, which is part of the message or provided by the messaging service. Note that the ratchet effect can also be used.
[0070] At point 906, the shared key is used to decrypt the message, and at point 908, the signature of the decrypted message is verified to prove the sender's identity. At point 910, once the identity is verified and the message has not been altered, the message content is presented to the user of the messaging service. Note that in some examples, the message is deleted from the messaging service once it is received.
[0071] Figure 10 An example provider network (or “service provider system”) environment is illustrated according to some examples. Provider network 1000 may provide resource virtualization to customers via one or more virtualization services 1010, which allow customers to purchase, lease, or otherwise obtain instances 1012 of virtualized resources (including, but not limited to, compute and storage resources) implemented on devices within one or more provider networks in one or more data centers. A local Internet Protocol (IP) address 1016 may be associated with resource instance 1012; the local IP address is the internal network address of resource instance 1012 on provider network 1000. In some examples, provider network 1000 may also provide public IP addresses 1014 and / or ranges of public IP addresses (e.g., Internet Protocol version 4 (IPv4) or Internet Protocol version 6 (IPv6) addresses) available to customers from provider 1000.
[0072] Typically, provider network 1000 may allow service provider customers (e.g., customers operating one or more customer networks 1050A to 1050C (or “client networks”) including one or more client devices 1052) to dynamically associate at least some public IP addresses 1014 assigned to the customer with specific resource instances 1012 assigned to the customer via virtualization service 1010. Provider network 1000 may also allow customers to remap public IP addresses 1014 previously mapped to a virtualized computing resource instance 1012 assigned to the customer to another virtualized computing resource instance 1012 also assigned to the customer. Using the virtualized computing resource instances 1012 and public IP addresses 1014 provided by the service provider, service provider customers—such as operators of customer networks 1050A to 1050C—may implement customer-specific applications and present the customer’s applications on an intermediate network 1040 such as the Internet. Then, other network entities 1020 on intermediate network 1040 can generate traffic destined for public IP address 1014 published by customer networks 1050A to 1050C; this traffic is routed to the service provider data center, and at the data center, it is routed via network substrate to the local IP address 1016 of the virtualized computing resource instance 1012 currently mapped to the destination public IP address 1014. Similarly, response traffic from virtualized computing resource instance 1012 can be routed back to the intermediate network 1040 via network substrate to reach the source entity 1020.
[0073] As used herein, a local IP address refers to an internal or “private” network address of a resource instance within, for example, a provider network. Local IP addresses may be within an address block reserved by the Internet Engineering Task Force (IETF) Request for Comments (RFC) 1918 and / or have an address format specified by IETF RFC 4193, and may vary within the provider network. Network traffic originating outside the provider network is not directly routed to a local IP address; instead, traffic uses a public IP address mapped to the local IP address of the resource instance. Provider networks may include networking devices or apparatuses that provide Network Address Translation (NAT) or similar functionality to perform mappings from public IP addresses to local IP addresses and from local IP addresses to public IP addresses.
[0074] A public IP address is a variable network address on the Internet assigned to a resource instance by a service provider or customer. For example, traffic routed to a public IP address via 1:1 NAT translation is used to forward the traffic to the appropriate local IP address of the resource instance.
[0075] Some public IP addresses may be assigned to specific resource instances by the provider's network infrastructure; these public IP addresses may be referred to as standard public IP addresses, or simply standard IP addresses. In some examples, the mapping of standard IP addresses to the local IP addresses of resource instances is the default startup configuration for all resource instance types.
[0076] At least some public IP addresses can be assigned to or obtained by customers of Provider Network 1000; customers can then assign their assigned public IP addresses to specific resource instances assigned to them. These public IP addresses may be referred to as customer public IP addresses, or simply customer IP addresses. Instead of being assigned to resource instances by Provider Network 1000 as in the case of standard IP addresses, customer IP addresses can be assigned to resource instances by the customer, for example, via an API provided by the service provider. Unlike standard IP addresses, customer IP addresses are assigned to customer accounts and can be remapped to other resource instances by the relevant customer as needed. Customer IP addresses are associated with customer accounts, not specific resource instances, and the customer controls the IP address until the customer chooses to release it. Unlike regular static IP addresses, customer IP addresses allow customers to mask resource instance or availability zone failures by remapping their public IP addresses to any resource instance associated with their account. For example, customer IP addresses enable customers to resolve resource instance or software issues by remapping their public IP addresses to alternative resource instances.
[0077] Figure 11 This is a block diagram of an example provider network environment that provides storage services and hardware virtualization services to customers, based on some examples. Hardware virtualization service 1120 provides customers with multiple computing resources 1124 (e.g., compute instances 1125 such as VMs). Computing resources 1124 may be provided as a service to customers of provider network 1100 (e.g., customers implementing customer network 1150). Each computing resource 1124 may be configured with one or more local IP addresses. Provider network 1100 may be configured to route packets from the local IP addresses of computing resources 1124 to public internet destinations, and to route packets from public internet sources to the local IP addresses of computing resources 1124.
[0078] Provider network 1100 may provide a client network 1150, for example, coupled to intermediate network 1140 via local network 1156, with the ability to implement virtual computing systems 1192 via hardware virtualization service 1120 coupled to intermediate network 1140 and provider network 1100. In some examples, hardware virtualization service 1120 may provide one or more APIs 1102, such as web service interfaces, through which client network 1150 may access the functionality provided by hardware virtualization service 1120, for example, via console 1194 of client device 1190 (e.g., web-based applications, standalone applications, mobile applications, etc.). In some examples, each virtual computing system 1192 at provider network 1100 and client network 1150 may correspond to computing resources 1124 that are leased, rented, or otherwise provided to client network 1150.
[0079] Clients can access the functionality of the storage service 1110 from an instance of the virtual computing system 1192 and / or another client device 1190 (e.g., via console 1194), for example, via one or more APIs 1102, to access and store data from storage resources 1118A to 1118N of the virtual data storage area 1116 (e.g., folders or "buckets," virtualized volumes, databases, etc.) provided by the provider network 1100. In some examples, a virtualized data storage gateway (not shown) may be located at the client network 1150, which may locally cache at least some data (e.g., frequently accessed data or critical data) and may communicate with the storage service 1110 via one or more communication channels to upload new or modified data from the local cache, thereby maintaining the main data storage area (virtualized data storage area 1116). In some examples, a user can install and access volumes of virtual data storage 1116 via a storage service 1110 that acts as a storage virtualization service, through a virtual computing system 1192 and / or another client device 1190, and these volumes may appear to the user as local (virtualized) storage 1198.
[0080] Although Figure 11 Not shown, but virtualization services can also be accessed from resource instances within provider network 1100 via API 1102. For example, a customer, device service provider, or other entity can access virtualization services from within a corresponding virtual network on provider network 1100 via API 1102 to request the allocation of one or more resource instances within that virtual network or another virtual network.
[0081] Explanatory System
[0082] In some examples, systems implementing some or all of the techniques described herein may include general-purpose computer systems, such as Figure 12 The illustrated computer system 1200 (also referred to as a computing device or electronic device) includes or is configured to access one or more computer-accessible media. In the illustrated example, computer system 1200 includes one or more processors 1210 coupled to system memory 1220 via input / output (I / O) interface 1230. Computer system 1200 further includes a network interface 1240 coupled to I / O interface 1230. Although Figure 12 Computer system 1200 is shown as a single computing device, but in various examples, computer system 1200 may include a single computing device or any number of computing devices configured to work together as a single computer system 1200.
[0083] In various examples, computer system 1200 may be a single-processor system including one processor 1210 or a multiprocessor system including several processors 1210 (e.g., two, four, eight, or another suitable number). Processor 1210 may be any suitable processor capable of executing instructions. For example, in various examples, processor 1210 may be a general-purpose or embedded processor implementing any of a variety of instruction set architectures (ISAs) (such as x86, ARM, PowerPC, SPARC, or MIPS ISA or any other suitable ISA). In a multiprocessor system, each processor in processor 1210 may often, but not necessarily, implement the same ISA.
[0084] System memory 1220 may store instructions and data accessible by processor 1210. In various examples, system memory 1220 may be implemented using any suitable memory technology, such as random access memory (RAM), static RAM (SRAM), synchronous dynamic RAM (SDRAM), non-volatile / flash memory, or any other type of memory. In the illustrated example, program instructions and data implementing one or more desired functions such as those methods, techniques, and data described above are shown stored within system memory 1220 as message passing service code 1225 (e.g., executable to fully or partially implement message passing service 501) and data 1226.
[0085] In some examples, I / O interface 1230 may be configured to coordinate I / O traffic between processor 1210, system memory 1220, and any peripheral devices (including network interface 1240 and / or other peripheral interfaces (not shown)) within the device. In some examples, I / O interface 1230 may perform any necessary protocol, timing, or other data transformations to convert data signals from one component (e.g., system memory 1220) into a format suitable for use by another component (e.g., processor 1210). In some examples, for instance, I / O interface 1230 may include devices that support attachment via various types of peripheral buses (such as variants of the Peripheral Component Interconnect (PCI) bus standard or the Universal Serial Bus (USB) standard). In some examples, for instance, the functionality of I / O interface 1230 may be split into two or more separate components, such as a northbridge and a southbridge. Additionally, in some examples, some or all of the functionality of I / O interface 1230 (such as an interface to system memory 1220) may be directly incorporated into processor 1210.
[0086] For example, network interface 1240 may be configured to allow computer system 1200 to communicate with other devices 1260 attached to one or more networks 1250 (such as, Figure 1 The network interface 1240 may exchange data with other computer systems or devices shown. In various examples, for instance, the network interface 1240 may support communication via any suitable wired or wireless general-purpose data network—such as various types of Ethernet networks. Additionally, the network interface 1240 may support communication via telecommunications / telephone networks such as analog voice networks or digital fiber optic communication networks, via storage area networks (SANs) such as Fibre Channel SANs, and / or via any other suitable type of network and / or protocol.
[0087] In some examples, computer system 1200 includes one or more offload cards 1270A or 1270B (including one or more processors 1275 and possibly one or more network interfaces 1240), which are connected using I / O interface 1230 (e.g., a bus implementing a version of the Peripheral Component Interconnect Fast (PCI-E) standard or another interconnect such as Fast Path Interconnect (QPI) or Hyper Path Interconnect (UPI). For example, in some examples, computer system 1200 may act as a host electronic device hosting computing resources such as compute instances (e.g., operating as part of a hardware virtualization service), and one or more offload cards 1270A or 1270B act as a virtualization manager that manages the compute instances running on the host electronic device. As an example, in some examples, offload card 1270A or 1270B may perform compute instance management operations such as pausing and / or unpausing compute instances, starting and / or terminating compute instances, performing memory transfer / copy operations, etc. In some examples, these management operations may be performed by the offload card 1270A or 1270B in cooperation with a hypervisor (e.g., upon request from the hypervisor) executed by other processors 1210A to 1210N of the computer system 1200. However, in some examples, the virtualization manager implemented by the offload card 1270A or 1270B may adapt to requests from other entities (e.g., from the computing instance itself) and may not cooperate with (or serve) any single hypervisor.
[0088] In some examples, system memory 1220 may be an example of a computer-accessible medium configured to store program instructions and data as described above. However, in other examples, program instructions and / or data may be received, transmitted, or stored on different types of computer-accessible media. Generally, computer-accessible media may include any non-transitory storage medium or memory medium, such as magnetic or optical media, for example, a disk or DVD / CD coupled to computer system 1200 via I / O interface 1230. Non-transitory computer-accessible storage media may also include any volatile or non-volatile medium that may be included as system memory 1220 or another type of memory in some examples of computer system 1200, such as RAM (e.g., SDRAM, Double Data Rate (DDR) SDRAM, SRAM, etc.), read-only memory (ROM), etc. Furthermore, computer-accessible media may include transmission media or signals transmitted via communication media such as networks and / or wireless links, such as electrical signals, electromagnetic signals, or digital signals, which may be implemented via network interface 1240.
[0089] The various examples discussed or presented herein can be implemented in a wide variety of operating environments, in some cases of which may include one or more user computers, computing devices, or processing devices that can be used to operate any of many applications. User devices or client devices may include any of many general-purpose personal computers, such as desktop or laptop computers running standard operating systems, and cellular, wireless, and handheld devices running mobile software and capable of supporting many networking and messaging protocols. Such systems may also include numerous workstations running any of a variety of commercially available operating systems and other known applications for purposes such as development and database management. These devices may also include other electronic devices, such as virtual terminals, thin clients, gaming systems, and / or other devices capable of communicating via a network.
[0090] Most examples use at least one network familiar to those skilled in the art to support communication using any of a wide range of widely available protocols such as Transmission Control Protocol / Internet Protocol (TCP / IP), File Transfer Protocol (FTP), Universal Plug and Play (UPnP), Network File System (NFS), Public Internet File System (CIFS), Extensible Messaging and Field Protocol (XMPP), AppleTalk, etc. The network may include, for example, a Local Area Network (LAN), a Wide Area Network (WAN), a Virtual Private Network (VPN), the Internet, an intranet, an extranet, the Public Switched Telephone Network (PSTN), an infrared network, a wireless network, and any combination thereof.
[0091] In examples using a web server, the web server can run any of a variety of server or middleware applications, including HTTP servers, File Transfer Protocol (FTP) servers, Common Gateway Interface (CGI) servers, data servers, Java servers, business application servers, etc. The server can also respond to requests from user devices, such as by executing one or more web applications that can be implemented as one or more scripts or programs written in any programming language (such as Java®, C, C#, or C++) or any scripting language (such as Perl, Python, PHP, or TCL) and combinations thereof. The server may also include a database server, including but not limited to commercially available database servers from Oracle®, Microsoft®, Sybase®, IBM®, etc. The database server can be relational or non-relational (e.g., "NoSQL"), distributed or non-distributed, etc.
[0092] The environment disclosed herein may include a variety of data storage areas and other memories and storage media as discussed above. These may reside in a variety of locations, such as on (and / or in) storage media local to one or more computers in a computer, or on storage media of any or all computers remotely on a network. In a particular example set, information may reside in a storage area network (SAN) familiar to those skilled in the art. Similarly, any necessary files for performing functions belonging to a computer, server, or other network device may be stored locally and / or remotely as appropriate. Where the system includes computerized devices, each such device may include hardware elements electrically coupled via a bus, including, for example, at least one central processing unit (CPU), at least one input device (e.g., mouse, keyboard, controller, touchscreen, or keypad), and / or at least one output device (e.g., display device, printer, or speaker). Such a system may also include one or more storage devices, such as hard disk drives, optical storage devices, and solid-state storage devices such as random access memory (RAM) or read-only memory (ROM), as well as removable media devices, memory cards, flash memory cards, etc.
[0093] Such devices may also include computer-readable storage medium readers, communication devices (e.g., modems, (wireless or wired) network interface cards, infrared communication devices, etc.), and working memory as described above. A computer-readable storage medium reader may be connected to or configured to receive a computer-readable storage medium, which represents a remote, local, fixed, and / or removable storage device and storage medium for temporarily and / or more permanently accommodating, storing, transmitting, and retrieving computer-readable information. Systems and various devices will also typically include numerous software applications, modules, services, or other elements, including operating systems and applications such as client applications or web browsers, residing within at least one working memory device. It should be understood that alternative examples may have many variations different from those described above. For example, custom hardware may also be used, and / or specific elements may be implemented in hardware, software (including portable software such as applets), or both. Furthermore, connections to other computing devices, such as network input / output devices, may be employed.
[0094] Storage media and computer-readable media used to contain code or code portions may include any suitable media known or used in the art, including storage media and communication media, such as, but not limited to, volatile and non-volatile media, removable and non-removable media implemented in any way or technology to store and / or transmit information (such as computer-readable instructions, data structures, program modules or other data), including RAM, ROM, electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, optical disc-read-only memory (CD-ROM), digital universal disc (DVD) or other optical storage, magnetic tape cassettes, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible by system devices. Based on this disclosure and the teachings provided herein, those skilled in the art will appreciate other ways and / or methods for implementing the various examples.
[0095] In the foregoing description, various examples have been described. Specific configurations and details have been elaborated for illustrative purposes to provide a thorough understanding of the examples. However, it will also be apparent to those skilled in the art that the examples can be practiced without these specific details. Furthermore, well-known features may be omitted or simplified to avoid obscuring the described examples.
[0096] In this document, parenthesized text and boxes with dashed borders (e.g., large dashes, small dashes, dot dashes, and dots) are used to illustrate optional aspects for adding additional features to some examples. However, this notation should not be interpreted as implying that these are the only options or optional operations, and / or that in some examples, boxes with solid borders are not optional.
[0097] The suffix letters in the reference numerals can be used to indicate that one or more instances of the mentioned entity may exist in various examples, and when multiple instances exist, each instance need not be identical, but may share some general characteristics or function in a common manner. Furthermore, unless explicitly indicated to the contrary, the use of a particular suffix does not imply the existence of a specific number of entities. Therefore, in various examples, two entities using the same or different suffix letters may have or not have the same number of instances.
[0098] References to "an example," "example," etc., indicate that the described example may include a particular feature, structure, or characteristic, but each example may not necessarily include that particular feature, structure, or characteristic. Furthermore, such phrases do not necessarily refer to the same example. Additionally, when a particular feature, structure, or characteristic is described in conjunction with an example, it should be assumed that, whether explicitly described or not, implementing such a feature, structure, or characteristic in conjunction with other examples is within the knowledge of those skilled in the art.
[0099] Furthermore, in the various examples described above, unless otherwise specifically indicated, the disjunctive linguistic intent of phrases such as “at least one of A, B, or C” is understood to mean A, B, or C, or any combination thereof (e.g., A, B, and / or C). Similarly, the linguistic intent of phrases such as “at least one or more of A, B, and C” (or “one or more of A, B, and C”) is understood to mean A, B, or C, or any combination thereof (e.g., A, B, and / or C). Therefore, disjunctive language is neither intended nor should be understood to imply that a given example requires the existence of at least one of A, at least one of B, and at least one of C.
[0100] As used herein, the term "based on" (or similar) is an open-ended term used to describe one or more factors that influence a determination or other action. It should be understood that this term does not exclude additional factors that may influence a determination or action. For example, a determination may be based solely on the listed factors or on said factors and one or more additional factors. Therefore, if action A is "based on" B, it should be understood that B is a factor influencing action A, but this does not preclude the action from also being based on one or more other factors, such as factor C. However, in some cases, action A may be entirely based on B.
[0101] Unless otherwise expressly stated, articles such as “a / an” should generally be interpreted as including one or more of the described items. Therefore, phrases such as “a device configured to…” or “computing device” are intended to include one or more of the described devices. Such one or more described devices may be collectively configured to perform the described operations. For example, “a processor configured to perform operations A, B, and C” may include a first processor configured to perform operation A working in conjunction with a second processor configured to perform operations B and C.
[0102] Furthermore, the words “may” or “may” are used in a permissive sense (i.e., implying a possibility) rather than a mandatory sense (i.e., implying a requirement). The words “include,” “including,” and “includes” are used to indicate an open relationship and therefore imply, including but not limited to. Similarly, the words “have,” “having,” and “has” also indicate an open relationship and therefore imply, having but not limited to. Terms such as “first,” “second,” “third,” etc., as used herein, serve as markers for the nouns that follow them and do not imply any type of ordering (e.g., spatial, temporal, logical, etc.) unless otherwise explicitly indicated. Similarly, the values of such numerical markers are generally not used to indicate the required quantity of a particular noun in a claim set forth herein, and therefore, the element “fifth” generally does not imply the presence of four other elements unless those elements are explicitly included in the claim or their presence is otherwise sufficiently clear.
[0103] At least some embodiments of the disclosed technology may be described in light of the following terms:
[0104] 1. A computer-implemented method, comprising:
[0105] At the second cryptographic messaging device, encrypted messages are received from the first cryptographic messaging device via an attached network support device from a messaging service of the provider network, wherein the second cryptographic messaging device does not include networking capabilities.
[0106] The shared key is calculated from the public key of the first cryptographic messaging device and the private key of the second cryptographic messaging device using the hardware security module (HSM) of the second cryptographic messaging device;
[0107] The shared key is used to decrypt the encrypted message;
[0108] Verify the signature of the decrypted message; and
[0109] Display the contents of the decrypted message.
[0110] 2. The computer-implemented method as described in Clause 1, wherein the private key of the second cryptographic messaging device is stored in the hardware security module of the second cryptographic messaging device.
[0111] 3. The computer-implemented method as described in any one of Clauses 1 to 2, wherein the public key is managed by the messaging service of the provider network.
[0112] 4. An apparatus comprising:
[0113] Input / output ports, configured to receive encrypted messages from coupled external devices;
[0114] A hardware security module (HSM) configured to decrypt the encrypted message, wherein the HSM includes storage for storing at least one private key to be used for decrypting the encrypted message; and
[0115] A screen used to display the content of a decrypted message.
[0116] 5. The device as described in Clause 4, wherein the power for the device is supplied from the external device.
[0117] 6. The device as described in any one of Clauses 4 to 5, wherein the encrypted message is removed from the message distribution service of the provider network after the device receives the encrypted message.
[0118] 7. The device as described in any one of Clauses 4 to 6, wherein the device is to exchange elliptic curve Diffie-Hellman keys with the transmitting device.
[0119] 8. The device as described in any one of Clauses 4 to 7, wherein the encrypted message is received directly from the sending device.
[0120] 9. The device as described in any one of Clauses 4 to 8, wherein the encrypted message is received from a message distribution service of a provider network.
[0121] 10. The device as described in any one of Clauses 4 to 9, wherein the HSM shall include at least one cryptographic engine, and the storage is secure storage.
[0122] 11. The equipment as described in any one of Clauses 4 to 10, further comprising:
[0123] A physical intrusion detection system, the physical intrusion detection system being used to monitor signs of physical tampering with the device.
[0124] 12. The equipment as described in any one of Clauses 4 to 11, further comprising:
[0125] Processor; and
[0126] A memory coupled to the processor, the memory being used to store at least the operating system and messaging applications.
[0127] 13. The device as described in any one of Clauses 4 to 12, wherein the encrypted message comprises one or more of text, documents, images, video files, or audio files.
[0128] 14. The equipment as described in any one of Clauses 4 to 13, further comprising:
[0129] A physical keyboard used for inputting messages.
[0130] 15. The device as described in any one of Clauses 4 to 14, wherein the encrypted message is deleted from the device after a period of time has expired.
[0131] 16. The equipment as described in any one of Clauses 4 to 15, further comprising:
[0132] User authentication mechanism.
[0133] 17. A system comprising:
[0134] A first or more electronic devices, the first or more electronic devices being configured to implement network support devices; and
[0135] A second or more electronic device, the second or more electronic devices being used to implement a cryptographic message transmission device, the cryptographic message transmission device comprising:
[0136] An input / output port, wherein the input / output port is used to receive encrypted messages using the network support device, wherein the network support device provides network capabilities to the cryptographic messaging device.
[0137] A hardware security module (HSM) for decrypting the encrypted message, wherein the HSM includes storage for storing at least one private key to be used for decrypting the encrypted message, and
[0138] A screen used to display the content of a decrypted message.
[0139] 18. The system as described in Clause 17, wherein the network support device is a cellular device having an operating system and networking hardware for coupling to a telecommunications network.
[0140] 19. The system as described in any one of Clauses 17 to 18, further comprising:
[0141] A third or more electronic devices are configured to implement a messaging service of a provider network, the messaging service being configured to provide the encrypted message to the cryptographic messaging device via the network support device.
[0142] 20. The system of any one of Clauses 17 to 19, wherein the cryptographic messaging device is to exchange elliptic curve Diffie-Hellman keys with the sending device.
[0143] The specification and drawings should therefore be considered illustrative rather than restrictive. However, it will be apparent that various modifications and alterations may be made therein without departing from the broader scope of this disclosure as set forth in the claims.
Claims
1. A computer-implemented method, comprising: The second cryptographic messaging device receives an encrypted message initiated by the first cryptographic messaging device, wherein the encrypted message is received by the second cryptographic messaging device via an attached network-supported cellular device, the attached network-supported cellular device itself receiving the encrypted message via a wireless interface, and wherein the second cryptographic messaging device is attachable to the network-supported cellular device via an input / output interface and is detachable from the network-supported cellular device, the second cryptographic messaging device includes a second display, and the second cryptographic messaging device does not include wireless networking capability; The second cryptographic messaging device uses its hardware security module to calculate a shared key from the public key of the first cryptographic messaging device and the private key of the second cryptographic messaging device. The second cryptographic message passing device uses the shared key to decrypt the encrypted message; The signature of the decrypted message is verified by the second cryptographic message transmission device; as well as The content of the decrypted message is displayed by the second cryptographic message transmission device via the second display.
2. The computer-implemented method of claim 1, wherein the private key of the second cryptographic message passing device is stored in the hardware security module of the second cryptographic message passing device.
3. The computer-implemented method of claim 1, wherein the public key is managed by a messaging service of the provider network.
4. An apparatus comprising: Input / output ports, configured to receive encrypted messages obtained by the separate cellular device via a network via a physical attachment to another input / output port of the separate cellular device; A hardware security module (HSM) configured to decrypt the encrypted message, wherein the HSM includes a storage device for storing at least one private key to be used for decrypting the encrypted message; as well as The screen is used to display the content of the decrypted message. The device described herein does not include any cellular or wireless communication hardware. The HSM is further configured to encrypt user-provided messages delivered via a virtual keyboard presented by the device or a physical keyboard of the device, and The input / output port is further configured to send encrypted user-provided messages to the separate cellular device, so that the separate cellular device can send the encrypted user-provided messages to a destination via the network.
5. The device of claim 4, wherein power for the device is supplied from the separate cellular device via the input / output port.
6. The device of claim 4, wherein the encrypted message is received by the separate cellular device from a message distribution service of a provider network, and wherein the encrypted message is removed from the message distribution service after the device receives the encrypted message.
7. The device of claim 4, wherein the device uses an elliptic curve Diffie-Hellman key to perform key exchange with the transmitting device.
8. The device of claim 4, wherein the encrypted message is initiated by a sending device, the sending device comprising another cellular device which is itself attached to a cryptographic messaging device that created the encrypted message.
9. The device of claim 4, wherein the encrypted message is initiated by a message distribution service of a provider network, and wherein the message itself is initiated by another cellular device that is attached to the cryptographic messaging device.
10. The device of claim 4, wherein the HSM includes at least one cryptographic engine, and the storage device is a secure storage device.
11. The device of claim 4, further comprising: A physical intrusion detection system, the physical intrusion detection system being used to detect signs of physical tampering with the device.
12. The device of claim 4, further comprising: processor; as well as A memory coupled to the processor, the memory being used to store at least the operating system and messaging applications.
13. The device of claim 4, wherein the encrypted message comprises one or more of text, documents, images, video files, or audio files.
14. The device of claim 4, further comprising: The physical keyboard is used for inputting messages.
15. The device of claim 4, wherein the encrypted message is to be deleted from the device after a period of time.
16. The device of claim 4, further comprising: User authentication module.
17. A system comprising: The network supports cellular devices, which include a processor, memory, display, physical input / output ports, and a wireless network interface; as well as A cryptographic messaging device, separate from the cellular device and physically and communicatively coupled to the cellular device, the cryptographic messaging device comprising: An input / output port is provided for physically and communicatively coupling to a physical input / output port of the cellular device, the input / output port being used to receive encrypted messages from the cellular device, the cellular device itself receiving the encrypted messages via its wireless network interface, wherein the cellular device is used to provide network capabilities for the encrypted messaging device. A hardware security module (HSM) for decrypting the encrypted message, wherein the HSM includes a storage device for storing at least one private key to be used for decrypting the encrypted message, and The screen is used to display the content of the decrypted message. The cryptographic messaging device described herein does not include any cellular or wireless communication interface. The HSM is further used to encrypt user-provided messages provided by a virtual keyboard presented via the cryptographic messaging device or the physical keyboard of the cryptographic messaging device, and The input / output port is further configured to enable the cellular device to send encrypted user-provided messages to a destination via the wireless network interface.
18. The system of claim 17, wherein the wireless network interface of the network-supported cellular device is a cellular device for coupling to a telecommunications network.
19. The system of claim 17, further comprising: One or more third electronic devices are used to implement a messaging service of a provider network for transmitting the encrypted message to the cellular device.
20. The system of claim 17, wherein the cryptographic messaging device uses an elliptic curve Diffie-Hellman key to perform key exchange with the sending device.