Method for secure communication over the internet - Patents.com

JP2025509135A5Pending Publication Date: 2026-01-26トルットマルティン +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024551552
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-03-10
Filing Date
2023-01-27
Publication Date
2026-01-26

AI Technical Summary

Technical Problem

Current communication technologies lack robust security measures, making them vulnerable to identity theft, eavesdropping, and data misuse, particularly over the Internet.

Method used

A method for proof-enabled anonymous and non-eavesdropping communication, which involves installing a computer program product on communication devices, sending security certificates, verifying proofs, and enabling direct, encrypted communication between devices without intermediaries.

Benefits of technology

This approach enhances data security by ensuring only identified users can communicate, preventing eavesdropping, and reducing the risk of data misuse, while also improving communication efficiency by eliminating reliance on central servers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

In one aspect, the present invention addresses a method for attestation-enabled anonymous and eavesdrop-proof communication. Furthermore, the present invention relates to a computer-implemented method for information-secure communication between at least a first communication partner and a second communication partner, the first communication partner having a first communication device and the second communication partner having a second communication device, comprising: a) installing a computer program product on a computing unit of the first communication device and a computing unit of the second communication device; b) sending an invitation from the first communication device to the second communication device, where a security certificate is sent to the second communication device when sending the invitation; c) accepting the invitation by the second communication device and verifying the security certificate; d) feeding back to an intermediate server when the verification of the security certificate is passed; and e) directly transmitting communication data between the first communication device and the second communication device. Furthermore, the present invention addresses both the communication device network and the computer program product.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] In one aspect, the present invention is directed to a method for attestation-enabled anonymous and eavesdrop-proof communication.

[0002] Furthermore, the present invention relates to a computer-implemented method for secure communication of information between at least a first communication partner and a second communication partner, the first communication partner having a first communication device and the second communication partner having a second communication device, a) installing a computer program product on computing units of a first communication device and a second communication device; b) sending an invitation from the first communication device to the second communication device, where a security certificate is sent to the second communication device when sending the invitation; c) accepting the invitation by the second communications device and verifying the security credentials; d) providing feedback to the intermediate server when the verification of the security proof is successful; e) transmitting communication data directly between the first communication device and the second communication device; Includes.

[0003] Additionally, the present invention addresses both a communication device network and a computer program product. [Background technology]

[0004] Today's communication is mainly carried out via the Internet. For example, an estimated billions of people use WhatsApp to send messages. However, other services such as social media platforms (e.g. Instagram, Facebook, etc.) are also used for communication. Furthermore, platforms that combine chat, meetings, notes and attachments, such as Microsoft® Teams® or Zoom, have also become increasingly important. Such services have become central for many people, especially after the Covid-19 pandemic, when it was initially undesirable and sometimes even impossible for people to have frequent and close contact with each other. In the era of modernization and globalization, software platforms for communication are becoming more and more important.

[0005] Most software systems in use today are based on so-called client-server solutions (see also Figure 1), where the operator of the software always has data sovereignty. The user of the software cannot understand in detail what the manufacturer does with the data distributed via its server. This problem applies both to software for e-mail traffic and to chats, social media accounts and / or video conferencing.

[0006] Furthermore, there are risks regarding data security when users use the software-based communication options mentioned above. In any case, the functionality of the software used also brings about the possibility of misuse by the users themselves, since they have the option of automatically generating topics, comments and / or responses. The current systems therefore show security-related weaknesses both on the part of the software providers (hosts) and on the part of the users of the individual software packages. In addition to the mentioned software platforms, these shortcomings are also present in systems such as Telegram, iMessage and / or other comparable software.

[0007] With the introduction of the General Data Protection Regulation (GDPR), various efforts have been made to protect data generated during communication over the Internet. Although companies such as Facebook face an ever-increasing number of regulations, real control over data flows, or the way in which they are handled, is still not possible. One of the reasons for this is that the data generated and collected can easily be processed across borders, meaning that national laws are often not enforceable.

[0008] Chat users, conferencing software users, and / or social media software users cannot determine whether a message sent to them was generated by a human, a software, and / or a robot. With the current means of the state of the art, users of modern Internet communication opportunities have no way of knowing who actually generated the data. It is also unclear what is done with the generated / sent data.

[0009] In particular, given the current state of the art, it is not possible to clearly identify the user with whom one is communicating via email or chat. Anyone can create a user account with any identifier and communicate through this user account. Fictitious communications can also be set up through identity theft. Given the current state of the art, this is a common way to obtain information or money. The current state of the art allows to communicate using a false identity or to flood the platform with messages from automated systems without people realizing that they are communicating with machines and not with people. According to the current state of the art, it is relatively easy to modify a message after it has been sent so that the recipient receives a message with altered content. To begin to counter this type of attack, further encryption systems must be installed in today's systems.

[0010] US 2013 / 0036308(A1) and [1] describe how communication over the Internet is established via the Session Initiation Protocol (SIP). Both disclosures discuss dealing with a SIP proxy through which data traffic is authorized and routed. The variant certificates described in US 2013 / 0036308(A1) are based on Secure / Multipurpose Internet Mail Extensions (SMIME) standards-based certificates, which are used to identify users and to encrypt the connection. Furthermore, the SIP protocol aims to connect individual users to each other as flexibly as possible. This includes the opportunity for each user to contact another user. The connection itself is also secured by encryption.

[0011] [2] essentially aims to connect users of 5G networks to each other as securely and flexibly as possible. This means that the functionality of all programs includes the use of 5G (or other standards) by which communication or data exchange can take place. The SIP protocol therefore allows the connection to other users, using this transmission technique disclosed in [2]. This technique also aims to allow as many users as possible to interact with each other as easily as possible.

[0012] Nevertheless, these methods require an application server to establish the connection, which provides the corresponding protocols (e.g. SIP) and services. Since mass communication is the main focus of this technology, significant resources must be allocated.

[0013] Yet this orientation also requires that, in principle, any user be able to contact another user, even if the two users do not know each other or have not previously agreed to communicate.

[0014] Known technologies demand significant resources, and these resources are used by multiple service providers. Microsoft, for example, does not build its own 5G network, but uses other 5G networks and relies on standards such as the SIP protocol to establish communication. Said standards always work according to the same rules / measures and safety standards. It is possible to guarantee that this communication works beyond the boundaries of individual service providers.

[0015] For example, a Telekom user can communicate with an O2 user (Figure 15). The main disadvantage is that all communications must still be processed using technologies from a wide range of providers. Maximum security measures are therefore always the obligation of the service provider offering the corresponding service. It is never really possible to guarantee that the service provider will not use the resulting data for its own purposes.

[0016] Therefore, there is a need for more secure communication options using the Internet. [Prior art documents] [Patent documents]

[0017] [Patent Document 1] US Patent No. 2013 / 0036308(A1) [Non-patent literature]

[0018] [Non-Patent Document 1] ROSENBERG J ET AL: "SIP:Session Initiation Protocol", Request for Comments:Network Working Group June 2002, Internet Engineering Task Force (IETF) Internet Society (ISOC) 4, rue des Falaises CH-1205 Geneva, Switzerland, RFC3261, June 1, 2002 (2002-06-01), pp. 1-269, XPO1 5009039 [Non-Patent Document 2] "3rd Generation Partnership Project; Technical Specification Group, Services and System Aspects; IP Multimedia Subsystem (IMS); Stage 2 (Release 17)", 3GPP(registered trademark) STANDARD; 3GPP(registered trademark) TS23.228, 3RD GENERATION PARTNERSHIP PROJECT (3GPP(registered trademark)), V17.3.0 December 23, 2021 (2021-12-23), pp. 1-354, XP052083247 Summary of the Invention [Problem to be solved by the invention]

[0019] The object of the present invention was to eliminate the shortcomings of the prior art, in particular to provide improved data security and communication options which ensure that the communication itself is protected against attacks. [Means for solving the problem]

[0020] The object according to the invention is achieved by means of the features of the independent claims. Advantageous embodiments of the invention are set forth in the dependent claims.

[0021] In a first aspect, the present invention relates to a method for attestation-enabled anonymous and eavesdrop-proof communication.

[0022] The present invention also relates to a method for certificate-based access control.

[0023] Additionally, the present invention addresses methods for certificate-enabled direct communication between PCs, and cluster-enabled load balancing of the individual PCs involved in the communication.

[0024] Another aspect of the invention is a method for intermediate servers and applications for registration and certificate-based invitation of additional anonymous users.

[0025] The present invention also relates to a method for load balancing during direct PC-enabled communication.

[0026] Additionally, the present invention addresses a method for load balancing in direct PC-based communications with integrated, legally secure communications security for businesses.

[0027] Furthermore, the present invention relates to a software-enabled method for controlling and certificate-enabled anonymous serverless communication between clients.

[0028] The invention also relates to a method for a certificate-enabled communication server for registration and for establishing anonymity of contacts.

[0029] Additionally, the present invention addresses methods for a certificate-enabled communication server for registration, contact establishment, and legally secure storage for a company.

[0030] In a further aspect, the present invention relates to a computer-implemented method for secure communication of information between at least a first communication partner and a second communication partner, the first communication partner having a first communication device and the second communication partner having a second communication device, a) installing a computer program product on computing units of a first communication device and a second communication device; b) sending an invitation from the first communication device to the second communication device, where a security certificate is sent to the second communication device when sending the invitation; c) accepting the invitation by the second communications device and verifying the security credentials; d) providing feedback to the intermediate server when the verification of the security proof is successful; e) transmitting communication data directly between the first communication device and the second communication device; Includes.

[0031] With the aid of the preferred method, in particular the computer program product (also referred to in the context of the present invention as PointOne or PointOne App), weaknesses present in the prior art during communication using the Internet are advantageously eliminated: false identities, identity theft, automated mass messages with arbitrary content or modifications to sent messages are advantageously no longer possible.

[0032] Advantageously, the computer program product and / or preferred method only permits communication between people who have clearly identified themselves. Automated mass messaging is not possible as the computer program product (Point One) is a self-contained system that does not support the opportunity to connect to third party software.

[0033] In particular, the functioning of the computer program product (Point One or Point One App) is based on the creation of a security certificate and on the encryption and connection data contained in the security certificate. Only clearly identified users can communicate. By registering as a user (synonym for communication partner) at the (Point One App) intermediate server, the user receives a unique identifier and a certificate, with which the software can be installed once. The user can preferably only establish a connection with other registered users of the Point One App or the computer program product if the user has been invited by another registered user or if the user has previously invited a communication partner. After an invitation has been accepted, the computer program products preferably exchange connection data such as IP addresses at regular intervals so as to be reachable by each other. Any form of transmission is preferably encrypted and sent directly from the communication device to the communication device (e.g. a PC). The server is preferably not involved in the communication. For the encryption, the security certificate previously exchanged and approved during the invitation is preferably used. This makes it impossible for a potential attacker to eavesdrop on or affect the communication.

[0034] Below, illustrative examples of communication methods and various types of communication data exchanges are illustrated (but are not limited to these).

[0035] Example of establishing a connection - Text message

[0036] A user of a computer program product (Point One App) sends a message to another user of the computer program product. The port on which the message arrives is monitored by the computer program product. When a data packet arrives at a monitored port, it is checked whether the data packet uses an approved identifier and appropriate encryption. Only if this is the case is the data packet processed by the computer program product. Data packets that do not meet the requirements regarding identifier or encryption are blocked. Data packets that meet the requirements of the computer program product are processed.

[0037] Connection Building Examples - Video Messages

[0038] Here too, the incoming data packets are first checked and only approved data packets are processed. If the data packet is accepted, a two-way connection is established. This is done via connection information exchanged between the users. Data transmitted during the connection is encrypted before being sent and can only be decrypted by the receiver, since only he has the corresponding key.

[0039] The actual process of recording images and / or sounds or creating text is preferably performed using current methods of the state of the art. The differences compared to the state of the art are mainly that communication takes place only with a unique identifier, only with a received proof, only encrypted, and only between the participating communication devices. Data generated during communication is only decrypted and stored on the participating systems.

[0040] The proposed combination of method steps leads to surprising synergistic effects resulting in the advantageous properties and associated overall success of the present invention. The individual features and / or method steps of the present invention interact with each other.

[0041] A particularly significant advantage of the preferred method is that a server-less transmission of communication data is made possible. According to the current state of the art, communication data would still be routed via the software provider's server. In the preferred method, the intermediate server is advantageously the point where the information for establishing the connection of the communication devices is set up. This advantageously prevents data, especially communication data, from being routed via the server provider's server. The preferred method therefore advantageously significantly increases the data security for the communication itself. This also means that a direct communication between the communication devices, i.e. avoiding the "detour" to the server, can be considered as a departure from the status quo.

[0042] By using the preferred method, communication partners can advantageously communicate with each other securely and directly against eavesdropping: Only by tracing the accessed IP addresses can it be determined whether the communication devices were in a data connection with each other.

[0043] The preferred steps of the preferred methods are particularly executable by means of a computer program product embodiment.

[0044] Preferably, communication between communication partners is only possible if all communication partners have installed the computer program product in the computing unit of a given communication device. This means that communication is restricted to the range of people who have installed the preferred computer program product. Advantageously, no unwanted contact is possible via the preferred computer program product, as opposed to, for example, calls and / or SMS messages. Thus, the preferred method advantageously improves security-related aspects for data exchange between people.

[0045] The technical features of the preferred method are given since the communication, in particular the communication via the internet, is carried out using a communication device, which advantageously prevents third parties from disrupting the communication, accessing the communication data and / or modifying said data.

[0046] The preferred communication between a first communication partner and a second communication partner is not limited to only two communication partners, which means that 3, 4, 5, 6, 7, 8, 9, 10, 50, 100, 1000 or even more communication partners can communicate with each other.

[0047] In particular, the following requirements are necessary for communication to take place: 1. Each communication device of the communication participants must have the computer program product available (see Figure 12). 2. A communication participant must send an invitation, and the invitation must be accepted. 3. Invitations can only be sent by communication participants who own a computer program product with this functionality (Point One App). Communication participants who own a computer program product that is only capable of accepting invitations (Point Zero App) are therefore not able to send invitations. Such communication participants are not able to organize meetings, but can only establish ad-hoc connections with users who have invited them.

[0048] When an invitation is sent from a first communications device to a second communications device, a security credential is preferably also sent to the second communications device.

[0049] The user identifier of the first communication device is preferably checked with the security credentials of the second communication device. The credentials of the first communication device (inviter) and the second communication device (invitee) must each have the appropriate user identifier so that connection information can be exchanged. Without this initial synchronization, the communication devices, and therefore the communication participants, cannot communicate with each other.

[0050] After verification of the certificate, a connection of the security certificate of the given communication participant is preferentially enabled. For this purpose, a part of the security certificate that manages the invited communication participant is used, and in the certificate management, the security certificate of the inviter is provided with an addition, thus confirming the acceptance of the invitation. This security certificate is then sent directly to the inviter. If the inviter now verifies this on his communication device, the certificate in the computer program product is expanded to include the information of the invitee. From this point on, the first communication partner (inviter) and the second communication partner (inviter) can communicate with each other via the computer program product.

[0051] The communication takes place directly between each other, i.e. without any "detours" to reach the software provider's server. In the context of the present invention, "direct communication" refers in particular to a serverless transmission of the communication data. In particular, direct communication means that there is no server to establish the communication, buffer and / or distribute the communication data. The data is preferably transmitted directly from one communication device to the other over the Internet. The Internet server which preferably transmits the data does not know what is being transmitted and simply forwards the data packets.

[0052] The intermediate server is in this case not comparable to a standard server of a current server provider of standard state of the art for communication software. The intermediate server is preferably an intermediary that does not store any data other than security certificates. According to the current state of the art, the communication should be routed through the software provider's server. Nevertheless, according to the invention, the intermediate server is merely a point that makes available to an authorized user the information for establishing a connection.

[0053] In the context of the present invention, information-secure communication refers to communication in which information is not processed, stored, and / or archived, thus achieving protection objectives such as confidentiality, availability, and / or integrity. In particular, information-secure communication serves to protect against dangers and threats, as well as to minimize risks regarding the sovereignty of information provided during communication over the Internet.

[0054] A communication device preferably refers to a device with which communication can be performed, in particular using the Internet. Thus, in the context of the present invention, a communication device can be a computer, a tablet, an iPad, a smartphone and / or a similar device.

[0055] A communication device preferably comprises a communication unit to be able to carry out the communication itself, where a communication unit refers to a sending and / or receiving unit adapted to send and / or receive data.

[0056] A computing unit preferably refers to any device that can be configured to perform computing operations. A computing unit is preferably a processor, a processor chip, a microprocessor, and / or a microcontroller. A computing unit may preferably be a programmable circuit board. A computing unit may preferably comprise a computer usable or computer readable medium, such as a hard disk, a random access memory (RAM), a read only memory (ROM), a flash memory, etc.

[0057] In a further preferred embodiment, the computer implemented method is characterized in that the security credentials are provided by installation of the computer program product.

[0058] Prior to installation of the computer program product on a communication device, the user of the computer program product is preferably registered as a potential communication participant. The registration is performed by the manufacturer of the computer program product. Each user of the computer program product is registered and receives a registration key made exclusively for him that can only be used by this user. The computer program product is preferably installable on up to three communication devices. For each additional installation, an additional registration key is preferably required.

[0059] On the one hand, the registration key allows the installation of a computer program product, and on the other hand, the registration key ensures the synchronization of each of the installed computer program products, which use the same registration key and / or belong to a group of computer program products, which registration keys can be assigned to the same user. The synchronization of the individual computer program products ensures that the internal database of the computer program products always has the same state of information on all communication devices of the user. The login to receive the registration key is preferably the only moment at which the user data is stored.

[0060] When installing the computer program product, the user preferably contacts the manufacturer to verify the registration key and an Internet connection is preferably required for this. Furthermore, the number of installations already performed is preferably verified. The installation preferably only continues if the registration key check is successful and the maximum number of installations has not yet been reached (see Figure 3).

[0061] When installing a computer program product, various information is requested from the communication device and / or computing unit on which the software is installed. This information is used on the one hand to create a security certificate that is used for subsequent encryption of communication data and on the other hand to ensure that the computer program product can only be installed on a maximum number of devices. Each installation with a unique registration key or one of the associated extended registration keys of the group allows an unambiguous identification as to how many communication devices the registration key has already been used on. The specific security certificate thus created comprises several parts. One part is preferably published as a public key on the manufacturer's server.

[0062] The public key advantageously does not allow any conclusions to be drawn about who generated this key. The public key is preferably used by the computer program product to provide the necessary information to establish a connection with an invited user having the rights of the account. This advantageously allows the computer program product to access the authorized user as soon as the authorized user is online, i.e. in particular when the communication device is connected to the Internet.

[0063] An intermediate server is preferably provided for this purpose. In the case of communication between multiple communication participants using a particular communication device, especially in the context of private communication, the intermediate server makes it possible to establish contact between the communication participants. The intermediate server acts as an intermediary and does not store any other data other than the security credentials, especially not the communication data.

[0064] Preferably, the certificate created during the first installation is also required for a second installation of the computer program product on the same communication device. This may be advantageously necessary if the communication device needs to be reset after a problem. Security certificates are also preferably requested to be able to synchronize data from other installations after a reinstallation.

[0065] Advantageously, the security certificate is not renewable, which also improves the security of the communications. After a one-time creation (per communications device), the computer program product can preferably only be installed on the particular communications device that has the associated security certificate. If the security certificate is damaged or lost, a new registration key preferably has to be created.

[0066] Preferably, the new registration key can only be assigned to the same group so that the existing installation can communicate and synchronize with the newly installed version. In particular, if a new communication device is purchased and an old communication device equipped with the computer program product is retired, a new registration will be required if the computer program product was already installed on the maximum number of communication devices.

[0067] When installing the communication device, a folder is preferably created that is accessible to the computer program product. The computer program product is preferably largely shielded from the operating system. This means that the transfer of data from the computer program product to the communication device can preferably only take place via the folder created by the computer program product. No access via the clipboard or another directory is possible here. Nevertheless, this folder is preferably not synchronized.

[0068] The computer program product preferably has a database in which the communication history, the contacts approved for communication and the data generated in this process are stored. This database is preferably the only one that is synchronized. The database, like the rest of the computer program product, is preferably encrypted and can only be decrypted and read with the associated certificate.

[0069] After preferred completion of the installation and entry of the user name and required password, the certificate for the new or additional installation is stored in the created folder. A registration key can only be used for a maximum number of installations. For additional installations, the registration key and certificate of an already installed computer program product must always be used. Each new installation generates a new device-specific security certificate.

[0070] The preferred method preferably operates on an IP basis and preferably interconnects communication devices in an IP-based network using current standards. In other words, there is preferably an IP-based connection between the first and second communication devices. The preferred method therefore also includes the provision of an IP-based connection. This IP-based connection makes it possible for the first time to exchange data, voice or images (including films) over these connections, for example using the SIP protocol. As with e-mail programs or social media platforms, the preferred method can also use GPS, 5G, WLAN, LAN and / or other methods for establishing an IP-based connection. The skilled person will recognize that an IP-based connection means a connection based on at least one Internet protocol.

[0071] The preferred method, or corresponding computer program product (Point One), does not require the SIP protocol or a proxy server to establish communication. The preferred method, and therefore also the corresponding computer program product, does not use the SIP protocol or certificates to validate the connection between the communicating devices. The preferred computer program product is preferably registered with a registration server. After registration, it is advantageously possible to conduct secure conversations in a public space (Internet) that do not rely on common standards such as the SIP protocol or servers, with connections buffered or stored from a service provider such as Microsoft.

[0072] The orientation of this aspect of the invention departs from the approach where anyone can communicate with anyone, and instead pursues an approach that allows only users who have clearly identified themselves with the intermediate server, and who have also previously agreed to contact the requesting communication partner, to come into contact with each other and / or exchange data. Thus, the preferred method involves the identification of communication partners at the intermediate server.

[0073] In contrast to the techniques known from the prior art, here the approach of the widest possible use is therefore not followed, but rather an approach of strongly restricted opportunities for contact with others (Figure 16).

[0074] Functionality previously provided in the prior art, for example by the SIP protocol and / or by proxy servers, is provided directly in the preferred computer program product, and computer-implemented methods designed therefor. The SIP protocol is able to meet the associated requirements because the preferred computer program product's orientation and functionality differ fundamentally from the prior art.

[0075] This and already previously negotiated communication authorization and the resulting encryption, in particular end-to-end encryption, secures the communication and requires only an existing Internet connection, which advantageously requires only the standards defined by the W3C Consortium to establish the communication.

[0076] Unlike SMIME / SSL certificates, the certificate used in the preferred method and / or provided by the preferred computer program product (those skilled in the art will recognize that when "method" is used in the context of the present invention, a preferred computer-implemented method is intended) does not have a public key. The initial certificate is preferably created when the user or communication partner logs into the intermediate server (see FIG. 17). The initial certificate is preferably used to send an invitation to the second communication partner. The initial certificate is preferably a security certificate. The invitation is preferably sent from the first communication device to the second communication device, and the initial certificate is sent to the second communication device when sending the invitation. The initial certificate comprises the key and preferably certified user data of the requester or the first communication partner and / or the first communication device (see FIG. 18). If the requester or first communication partner's invitation is accepted, the first communication partner or requester will preferably receive an acceptance confirmation. The acceptance confirmation is preferably created by the intermediate server. Through the authorization confirmation, the first communication partner or requester preferably receives a release certificate, preferably from the intermediate server. The release certificate preferably provides the certificates required for communication over the Internet and all data required for the communication. The aforementioned preferred steps are preferably performed after the invitation has been accepted. If the request is rejected, the requester preferably receives information, preferably from the intermediate server, that communication is not desired. Communication should therefore not be possible.

[0077] Using the information exchanged through the certificate, the computer program products of the first communication partner and the second communication partner are preferably automatically linked to each other, so that communication, and thus the exchange of encrypted data, is made possible.

[0078] The contact data is preferably periodically transmitted to authorized users in the user's communication network and to the intermediate server, which advantageously ensures that individual users can connect with each other at any time.

[0079] Preferably, the computer program product receives these data from the intermediate server if the user or communication partner has not been in the network for some time, therefore enabling integration back into the communication network. The comparison is also preferably performed directly between authorized users in the network. Preferably, the data of the intermediate server is therefore only requested if the user of the communication device on which the computer program product is installed is no longer connected to the Internet.

[0080] In the preferred method, and therefore also through the use of the preferred computer program, an initial certificate, a release certificate and a communication certificate are used. With the initial certificate, in particular a release process is created. The release certificate enables admission to the communication network to be granted. The communication certificate is in particular used to encrypt the communication data and preferably contains identification data and / or parameters of available resources. The communication certificate preferably also contains the communication data. The initial certificate, the release certificate and the communication certificate represent security certificates in the context of the present invention.

[0081] Therefore, in a further preferred embodiment the invention relates to a computer-implemented method for secure communication of information between at least a first communication partner and a second communication partner, the first communication partner comprising a first communication device and the second communication partner comprising a second communication device, a) installing a computer program product on computing units of a first communication device and a second communication device; b) sending an invitation from the first communication device to the second communication device, where an initial certificate is sent to the second communication device when sending the invitation; c) accepting the invitation by the second communications device and verifying the initial certificate; d) feeding back to the intermediate server when the initial proof passes validation; e) sending a release certificate from the intermediate server to the first communication device; f) exchanging communication credentials between the first communication device and the second communication device; Includes.

[0082] Preferably, the communication data is transmitted directly between the first communication device and the second communication device.

[0083] In a further preferred embodiment the invention relates to a computer program product for secure communication of information between a first communication device and a second communication device, the computer program product, when executed, comprising: a) sending an invitation from a first communication device to a second communication device, where an initial certificate is sent to the second communication device when sending the invitation; b) accepting the invitation by the second communications device and verifying the initial certificate; c) feeding back to the intermediate server when validation of the initial proof is successful; d) sending a release certificate from the intermediate server to the first communication device; e) exchanging communication credentials between the first communication device and the second communication device; is executed.

[0084] In a further preferred embodiment the invention relates to a communication device network for secure communication of information comprising at least a first communication device and a second communication device, each of the first communication device and the second communication device comprising a computing unit, wherein after installation of the computer program product: a) sending an invitation from a first communication device to a second communication device, where an initial certificate is sent to the second communication device when sending the invitation; b) accepting the invitation by the second communications device and verifying the initial certificate; c) feeding back to the intermediate server when validation of the initial proof is successful; d) sending a release certificate from the intermediate server to the first communication device; e) exchanging communication credentials between the first communication device and the second communication device; The apparatus is configured to execute the following steps:

[0085] The certificate (Fig. 20) generated by the preferred method preferably does not have a public key, as is the case for example in the prior art with SSL certificates. Preferably, in the sense of the present invention, the authentication and / or creation is performed by a preferred step in the sense of a release process via a preferred computer program product installed in the computing units of the first and second communication devices, in particular the first and second communication devices, i.e. the communication devices of the first and second communication partners or the requester and the requestee.

[0086] This advantageously ensures that data exchange is only possible between communication devices which have the corresponding computer program products installed when the release process (preferably steps including feeding back to the intermediate server when verification of the initial certificate has passed, sending a release certificate from the intermediate server to the first communication device and / or exchanging communication certificates between the first communication device and the second communication device) has been completed via the intermediate server. Since the two computer program products of the first communication device and the second communication device can establish contact directly, an intermediate proxy server or similar method is advantageously not required.

[0087] A preferred method, or a corresponding computer program product, allows for establishing a direct communication device to communication device communication, preferably where an invitation in the sense of a first communication request via an intermediate server is validated and the communication partners and / or communication devices are unambiguously identified.

[0088] Furthermore, the required resources, such as those required for communication in the sense of the disclosure of US 2013 / 0036308(A1), [1] or [2], are considerable and must be scaled with an increasing number of communication partners. The preferred computer program product advantageously uses the resources of the involved communication devices themselves, in particular the communication device to which the invitation was sent. Only the hardware capabilities of the first and / or second communication device impose a limit on the number of communication connections that may occur simultaneously.

[0089] Furthermore, the disclosures of U.S. Patent No. 2013 / 0036308(A1), [1] and [2] teach that different software products from different manufacturers can be developed in such a way that communication between the individual software products is possible.

[0090] The preferred computer-implemented method is designed and optimized in such a way that communication is only possible with authorized users or communication partners who have installed the corresponding computer program product. The preferred computer-implemented method is designed in such a way that each communication partner can set up its own communication network which can only be used by the authorized communication partner. It is therefore not possible purely architecturally, i.e. in particular due to the configuration of the computer program product, that third parties can provide their own solutions in the system to be able to participate in the communication.

[0091] The preferred method and corresponding computer program product are particularly suitable for users or communication partners with a particularly high need for security: after a preferred registration and installation on a registration server, the communication partners can advantageously communicate and exchange data securely.

[0092] Currently, users with high security needs have to take additional measures to secure their communications. Additional VPN connections, SMIME certificates, and / or other security technologies are now part of the basic equipment of any public entity or company. By using the preferred computer program product, additional measures to secure communications can advantageously be eliminated. This has positive effects affecting the IT infrastructure. Moreover, this is accompanied by advantageous economic efficiency, since additional costs that would be necessary for additional security measures, but which can nevertheless be omitted by the preferred computer program product, are avoided.

[0093] In a further preferred embodiment, the computer implemented method is characterized in that the communication data is encrypted for transmission, preferably using an asymmetric encryption method.

[0094] Preferably, PKI methods (PKI: Public Key Infrastructure, preferably a system capable of issuing, distributing and / or verifying digital certificates) as well as symmetric encryption are additionally implemented in the computer program product (Point One). Furthermore, preferably, unique hashes are created for data to be transmitted, in particular communication data, and also transmitted, allowing received data to be verified.

[0095] Advantageously, this makes it possible to achieve a particularly high security of the communication data transmitted between the communication partners.

[0096] Preferably, the computer program product encrypts the communication data prior to transmission.

[0097] In a further preferred embodiment the computer implemented method is characterized in that the data transmission rates and / or data capacities of the communication devices of the communication partners are determined.

[0098] Advantageously, by determining the data transmission rate and / or data capacity, the computer program product can utilize the capacity of the involved communication devices. In particular, the communication devices can advantageously be created in clusters, such that resources are advantageously distributed and balanced as needed. This means, for example, that the quality in the context of video communication depends on the communication device with the least resources. As this cluster is self-contained and encrypted, third parties are advantageously not accessible to the cluster.

[0099] The computer program product preferably determines during installation the speed at which communication data, such as video data, are decoded and processed. This information is preferably stored and is preferably used to negotiate the video quality to be received and processed. This verification can be repeated by the user if necessary and the values ​​can be saved again. The user preferably has an input into the settings to be made so that the determination of these values ​​results in an acceptable outcome for the user, and thus an optimal result corresponding to the performance can be achieved. To determine the existing transmission speed, generated verification data similar in nature to the communication data, for example video data, are preferably sent. Furthermore, these packets preferably contain the sender's requirements profile for the optimal video data. Using the data contained in the verification file, the computer program product is now preferably able to determine the time required for the data packets to be sent and what form of video data must be prepared for the receiver. This exchange is preferably performed for all participants of the video communication. Based on the determined performance data, expected transmission times are preferably assigned to the individual data packets. If packets from an individual user require an unexpectedly long time to be transmitted, the transmission quality of the associated users is adjusted, in particular with the aid of the preferred computer program product (or computer-implemented method), so that an optimized transmission and easier processing is made possible. In this way, the data to be transmitted, in particular communication data, is advantageously adapted to the recipient.

[0100] In the prior art, since all communication is performed through the service provider's server, occasional overloads on the service provider's server sometimes occur. When using the preferred computer-implemented method and / or the preferred computer program product, the performance of the individual participating computers is preferably decisive since there is preferably no server that has to process the data. According to the current state of the art, server-based solutions require not only high computing power but also maximum Internet connectivity since many different users may, for example, hold their own video conferences at the same time.

[0101] In order to prevent interference due to poorly performing communication devices, the computer program product and / or the corresponding communication device on which the computer program product is installed can advantageously be used as a repeater. This means that the computer program product functions as a communication server for individual participants, in particular those with weak performance and / or poor Internet connection. To allow the preferred computer program product to function in this way, the particular communication partner preferably has to activate the corresponding functionality, thereby allowing a balance between the resources of the individual communication participants. Here again, the preferred computer-implemented method, and thus the likewise preferred computer program product, is superior to the current status, since the computer program product and / or the communication device acting as a repeater is integrated as a direct participant of the communication and thus preferably contributes partly its own data to the communication, so that data security and data sovereignty are also guaranteed in this mode. Nevertheless, it is also preferred that these data are not automatically stored, but rather deleted after use. Participants are only able to store the communication that has occurred if all participants have preferably given their consent.

[0102] In a further preferred embodiment the computer implemented method is characterised in that the communication takes place between a plurality of communication partners each having a communication device and / or the communication takes place within a communication network.

[0103] Advantageously, the computer-implemented method is therefore suitable for both private use and for use within a communication network. In both examples of use, a secure and in particular eavesdrop-proof communication of information is advantageously made possible.

[0104] In a further preferred embodiment the computer implemented method is characterized in that the communication is performed between communication partners and that a computer program product installed on the first communication device and / or on a computing unit of the first communication device provides an intermediate server.

[0105] Preferably, the first communication partner acts as an inviter on his first communication device, while the second communication partner acts as an invitee on his second communication partner.

[0106] The inviter must preferably be reachable via a fixed IP address, and security credentials are preferably exchanged beforehand so that the invitee can log in to communicate, for example during the meeting. Advantageously, contact information is exchanged with the inviter's computer program product each time an authorized user connects to the Internet with his or her communication device and goes online.

[0107] Preferably, the user data of authorized communication partners is available on all approved devices. Any computer program product (PointOne App) can therefore advantageously be used as an intermediate server.

[0108] The security certificate already mentioned above comprises several parts, including a public key, which is preferably published (certified) on a server of the manufacturer of the computer program product.

[0109] The public key advantageously does not allow any conclusions to be drawn about who generated this key. Nevertheless, the public key is preferably used to use the information required to establish a connection with an invited user who has the rights to the account with which the connection will be established. In particular, the information required to establish the connection should be made available. The latter feature advantageously ensures that the computer program products are accessible to each other as soon as the communication partners are online with the computer program products, even if, for example, the individual devices change location frequently and / or have not been reachable for some time.

[0110] For this purpose, there are intermediate servers, especially for private use, that allow contacts to be established between communication partners. The intermediate servers are only intermediaries and do not store any data other than security credentials. According to the current state of the art, the communication should be routed through the software provider's server. In contrast, in the context of the present invention, it is defined that the intermediate server merely represents a point that makes available to an authorized user the information for establishing a connection.

[0111] In a communication network, the intermediate server can be installed on a separate server. Communication can therefore take place within the communication network and can also be enabled with external communication partners. In this context, external communication partners preferably mean communication partners that are not part of the communication network.

[0112] In a further preferred embodiment the computer implemented method is characterized in that the communication between the communication partners takes place within a communication network, and an intermediate server is preferably installed on a web server and serves as an exchange.

[0113] Communications with communication partners in a communication network are preferably established via an exchange, which is particularly distinct from private use. The actual communication continues to flow from communication device to communication device, but the exchange may authorize, record and / or store the communication. The exchange is preferably hosted by the particular communication network itself. Advantageously, third parties do not have access to the exchange, which allows a particularly secure communication even in the communication network.

[0114] Advantageously, the functional scope of the computer program product is extended by the preferred exchange to include functionality for legally secure storage of legally relevant (e.g. business critical) communications.

[0115] If the computer program product is preferably installed with the registration key of the communication network used by the exchange, then the computer program product is only capable of allowing contact via the appropriate exchange. A direct invitation, which is preferably feasible without an exchange, is therefore no longer possible.

[0116] In the preferred embodiment, the exchange performs the following tasks: 1. The exchange (see figures 11, 14) can only be installed once. A registration key is also required for this. This must be requested before installation. During installation, the administrator receives an operation certificate that allows the administrator to access and operate the exchange. If the user releases data for archiving and viewing, the administrator receives read and / or copy rights to this data. Nevertheless, the stored data can only be read and not modified. 2. To ensure that data remains GDPR (General Data Protection Regulation) compliant, prescriptive deletion and / or storage rules can be created for data in the exchange. For these rules to take effect, scheduled and / or complete communications must therefore be identified by the user. Several basic provisions of the GDPR are firmly established in the exchange and are automatically implemented. Contacts with which no contact has been made within the last 24 months will be automatically deleted. Users to whom a particular contact was assigned before the deletion will receive information enabling them to establish contact with the user so that the automation will start again at zero (months since the most recent establishment of contact). 2.2 Data is fully backed up automatically. Backup cycle and type of backup are preset by the administrator. 2.3. All backed-up data records are identified by the exchange in such a way that the administrator can also delete the data records in the backup. This does not apply to data identified as legally relevant. These data can only be deleted upon expiration of the specified retention period (in years). 3. Receiving and temporarily storing messages even if the recipient is currently offline (not reachable). This means that incoming messages are stored until they can be sent to the recipient. If data is to be stored for legal reasons and / or based on internal needs, the exchange can be configured so that the memory is kept and can be read by an administrator if necessary. To make this possible, each affected employee must agree that he or she activates this storage function via the computer program product. 4. Manage security credentials so that messages are still readable after an employee leaves. This still requires the authorization of the relevant employee. Authorization is granted via a setting in the computer program product. Authorization is revocable only for future data. Data created while authorization was granted is therefore no longer protectable by the user. 5. Storage of communication contacts of all external and internal users of the computer program product. When using the exchange, unlike in the case of private users, communication is established via the exchange and not via the computer program product. Communications via the exchange can be stored, so that data is generated here and can be viewed by third parties after authorization by the user. 6. Forwards communication requests to external and internal users. All contacts stored in the computer program product are managed in the exchange. Individual communication partners or groups can be blocked and / or approved by the administrator via the exchange. A blocked user is no longer contactable via the computer program product. Unlike in private use, a user cannot contact other users via the exchange without approval. This applies both to internal and external communication (with respect to a communication network). 7. Authorized users' address books for both internal and external contacts are managed by the exchange and are shareable within the communications network. Contacts can only be shared and approved for other people with the computer program product via the exchange. If an external user contact is to be approved for other internal users via the exchange, the external user must confirm the approval request before approval can take place. 8. The exchange stores all data encrypted so that the data is protected from unauthorized access. Administrators can obtain operational credentials via the exchange to ensure that data approved by individual users remains available. 9. Unlike a typical mailbox, the communication data is stored on the server but does not remain in active memory. Instead, the communication data is directly archived. The data can only be accessed directly within the computer program product to manipulate the data. If the data on the computer becomes corrupted or the user receives a computer from another company, the data can be restored from the backed-up server data. If the data is deleted by rules or pre-configured automation, the data is not recoverable. 10. Depending on the type of application and the amount of data that will be stored, the exchange must have sufficient resources. This applies both to storage space and performance of the servers employed.

[0117] In the current state of the art, all communication passes through an external service or software provider that has final control over the software and data. According to the present invention, this is prevented by enabling direct communication from communication device to communication device, in particular by the computer program product.

[0118] In a preferred use, the exchange sets up a cluster with connections of multiple communication devices and controls the load balancing so that peaks cannot occur at the server itself. With the current state of the art, it is always a problem when an unexpectedly large number of users access a server or server cluster at the same time, which often results in disruptions or communication breakdowns. Advantageously, this does not happen by using the preferred computer program product or computer-implemented method, since the burden is passed on by the communication partners involved in the communication.

[0119] The method of load balancing preferably follows the same method as already described in the preferred method of load balancing by a computer program product. The only difference is that the exchange acts as a relay rather than a computer program product or a corresponding communication device in which the computer program product (Point One) is installed. In the context of a communication network (e.g. a company, a school), thus various conferences with many users with stable connections can advantageously be set up simultaneously.

[0120] Advantageously, recordings of video conferences are not stored, for example, via the exchange, instead all recordings, such as audio and / or image recordings, are preferably always stored within a secure computer program product and can only be exported with the permission of the communication participants.

[0121] In the context of the present invention, a communication network refers to an organization striving to perform Internet-based communication. Communication can take place both within the communication network (internal) and with communication partners outside the communication network (external). For example, a communication network can be selected from the group including public institutions, educational institutions, medical facilities, and / or companies. Preferably, the communication network represents a company.

[0122] In a further preferred embodiment, the computer implemented method is characterized in that the communication data is selected from the group including a text message, a photo, a video, an audio message, and / or an attachment.

[0123] Advantageously, different types of communication data can thus be transmitted, and therefore there is no restriction on a particular type of communication data.

[0124] The current state of the art is not very secure when sending e-mails. E-mail addresses can be stolen, forged, and / or disguised, and therefore the recipient often cannot say who the actual sender is. Messages such as e-mails sent via the preferred computer program product are always clearly attributable to the sender. The exchanged certificate and unique registration advantageously prevent third parties from performing unauthorized sending of messages to the recipient.

[0125] The current state of email technology allows, for example, a person to write to any person with an email account. A preferred computer-implemented method using a preferred computer program product allows a person to, for example, send a message to another person only if the person has previously been authorized as a sender by an accepted invitation.

[0126] Furthermore, with the current state of the art, it is possible that attachments, such as documents, can be attached, in particular to e-mail and / or by other transmission channels. Nevertheless, without additionally guaranteed security measures, attachments are often transmitted unencrypted and thus can be read by third parties. Advantageously, the preferred computer program product allows attachments (such as documents) to be attached to messages. Advantageously, attachments are thus transmitted encrypted just like the rest of the message. Furthermore, the user can assign rights to the document, such that the user can specify what the recipient can do with the received document.

[0127] In a further aspect, the present invention relates to a communication device network for secure communication of information comprising at least a first communication device and a second communication device, each of the first communication device and the second communication device comprising a computing unit, wherein after installation of a computer program product: a) sending an invitation from a first communication device to a second communication device, where a security certificate is sent to the second communication device when sending the invitation; b) accepting the invitation by the second communication partner and verifying the security credentials; c) providing feedback to the intermediate server when the verification of the security proof is successful; d) transmitting communication data directly between the first communication device and the second communication device; The apparatus is configured to execute the following steps:

[0128] The preferred computer network advantageously leads to a secure, in particular eavesdrop-proof, communication between the communication partners. In this case, the communication data can advantageously be transmitted directly between the communication devices of the communication partners. Advantageously, the connection between the individual communication devices is not established via a server, but directly between the individual communication devices. In particular, the connection between the communication devices is advantageously encrypted.

[0129] A communication device network preferably refers to a network comprising a network comprising a plurality of communication devices for exchanging data. A communication device network thus creates the opportunity to carry out the exchange of data between the communication devices.

[0130] The communications device network is preferably available for private use, in particular by computer program products.

[0131] Therefore, in a further preferred embodiment the communication device network is characterized in that the communication takes place between communication partners and a computing unit of a first communication device and / or a computer program product installed in a computing unit of the first communication device is configured to provide an intermediate server.

[0132] In contrast to the embodiment of the communication network, since there is no exchange, the first communication device acting as the inviter preferably has a fixed IP address. Thus, the second communication device (invitee) can log in for communication so that direct transmission of communication data between the communication devices is enabled. Contact information is preferably exchanged between the first and second communication devices as soon as the user goes online on his / her communication device.

[0133] In the context of the communication network, it is also preferred that a communication device network is present. Therefore, in a further preferred embodiment, the communication device network is characterized in that the communication between the communication partners takes place within the communication network, and preferably an intermediate server is installed on the web server and serves as an exchange.

[0134] After installation of the intermediate server on the web server of the communication network, all communication partners using the computer program product are preferably created as users in the exchange. Authorizations for future communication are preferably stored via the exchange. Furthermore, contact information such as email addresses of authorized and blocked communication partners is preferably stored by the exchange. In particular, email addresses are preferably relevant information about communication partners in the context of the communication network.

[0135] The preferred invitation communicates to the particular computer program product the information required to establish communication and establish a connection with the exchange. Thus, in the future, the exchange will preferably pass the requested information to the particular computer program product upon request from the computer program product. This advantageously allows communication devices to connect directly to each other.

[0136] In a preferred embodiment, if an invitation is deleted at the exchange, no future data will be exchanged with the blocked or restricted user.

[0137] Preferably, a user (e.g., an employee of the communications network) and a one-time password are exchanged for initial set-up by the exchange. Transmission of communication data is preferably encrypted. Thus, all information required to establish a connection is preferably stored within the computer program product.

[0138] In a further aspect, the present invention relates to a computer program product for secure communication of information between a first communication device and a second communication device, the computer program product, when executed, comprising: a) sending an invitation from a first communication device to a second communication device, where a security certificate is sent to the second communication device when sending the invitation; b) accepting the invitation by the second communication partner and verifying the security credentials; c) providing feedback to the intermediate server when the verification of the security proof is successful; d) transmitting communication data directly between the first communication device and the second communication device; is executed.

[0139] Advantageously, the use of the preferred computer program product leads to an eavesdrop-proof communication of the communication data. In particular, the communication data is advantageously not sent to a server of the manufacturer of the computer program product. Instead, a direct and equally server-less exchange of the communication data is advantageously performed.

[0140] The preferred computer program product is preferably available in two preferred embodiments: In one preferred embodiment, the computer program product is configured such that invitations can be sent and received, and in a further preferred embodiment, the computer program product is configured such that invitations can be accepted but not sent.

[0141] In a further preferred embodiment the computer program product is characterized in that the computer program product provides a user interface by which invitations can be sent and / or accepted by operating the user interface.

[0142] The computer program product therefore comprises a network layer, a functional layer and a database. In particular the network layer comprises a function for sending invitations. The functional layer allows communication data to be transmitted and optimized so that chat, video, audio and / or general data exchange is made possible (relay layer). The database preferably contains information about the communication data to be transmitted, e.g. chat, as well as information about communication participants and about deleted communication participants. In particular, by using the user interface that can be provided it is possible to send invitations to communicate. It is also possible to accept the invitation.

[0143] The preferred computer program product preferably has a user interface (GUI, Graphical User Interface) by which the individual functions can be controlled. Advantageously, it is not possible to control the computer program product from the outside. The individual functions are optimized to ensure the highest level of security for its user. Advantageously, there is no automation available to automate processes such as sending messages or chats.

[0144] Nor is mass messaging possible. The computer program product is not intended to reach a large number of participants at once. Rather, everything is advantageously subordinated to aspects of security and harmonized and structured communication.

[0145] In a further preferred embodiment the computer program product is characterized in that the computer program product provides a user interface by which the invitation can be accepted by operating the user interface.

[0146] Thus, there are embodiments that have only a functional layer and a database, which allows an invitation to be accepted but not sent.

[0147] Those skilled in the art will recognize that the technical features, definitions and advantages of the preferred embodiments that apply to the computer-implemented method according to the present invention apply equally to the communication device network according to the present invention and the computer program product according to the present invention, and vice versa.

[0148] Furthermore, one of average skill in the art will preferably recognize that the steps, such as method steps, and / or capabilities of the aspects of the present invention may also preferably be directed to a preferred computer program product comprising instructions that may affect corresponding steps, such as corresponding method steps, and / or corresponding capabilities.

[0149] The concept according to the invention is explained in more detail below on the basis of illustrative examples, without being limited to these examples. [Brief description of the drawings]

[0150] [Figure 1] FIG. 1 is a schematic diagram of a communication method from the prior art. [Diagram 2] FIG. 1 is a schematic diagram of a preferred method of encrypted communication. [Diagram 3] FIG. 2 is a schematic diagram of data exchange between an intermediate server and a communication device. [Figure 4] FIG. 1 is a schematic diagram of proof-based communication. [Diagram 5] FIG. 2 is a schematic diagram of certificate-based access control. [Figure 6] FIG. 1 is a schematic diagram in which there is no intermediate server. [Figure 7] FIG. 13 illustrates an example of a client's behavior when an intermediate server is no longer accessible. [Figure 8] FIG. 1 illustrates a method for an intermediate server or application for registration and certificate-based invitation of additional anonymous users. [Figure 9] FIG. 1 is a schematic diagram of a method for load balancing. [Figure 10] FIG. 1 is a diagram of load balancing by inviting communication device. [Figure 11]FIG. 1 is a diagram of load balancing by inviting communication devices and exchanges. [Figure 12] FIG. 1 is an example diagram of serverless communication between clients. [Figure 13] FIG. [Figure 14] FIG. [Figure 15] FIG. 1 is a schematic diagram of a communication method from the prior art. [Figure 16] FIG. 1 is a schematic diagram of a preferred IP-based communication. [Figure 17] FIG. 1 is a schematic diagram of a preferred authorization method. [Figure 18] FIG. 1 is a schematic diagram of an initial proof. [Figure 19] FIG. 2 is a schematic diagram of a release certificate. [Figure 20] FIG. 2 is a schematic diagram of communication proof. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0151] FIG. 1 shows a method for communication used in the prior art.

[0152] Now PC1 sends messages to PC2, which forwards them to the software provider and from there to PC2. The software provider's server therefore receives all messages and can read or process these messages.

[0153] FIG. 2 illustrates the preferred method of communication.

[0154] The communication between the two PCs is established directly and encrypted, and the data is not buffered by any server. The communication is encrypted and transmitted directly between the two PCs via the computer program product (PointOne App) according to the invention.

[0155] FIG. 3 illustrates the data exchange between the intermediate server and the communication device.

[0156] After the user starts the installation of the computer program product and enters the registration key, communication with the registration server is established. After the server accepts the registration key, a security certificate is created on PC1.

[0157] Figure 4 shows the structure of the security proof.

[0158] After successful registration, the computer program creates a security certificate, the public portion of which contains data for establishing communications, and the communications information contains a unique user identifier.

[0159] User identifiers are assigned to computer program products, not to people, so it is not possible to determine which user belongs to which identifier. This security credential is updated at regular intervals and contains current information with which communication devices can be addressed.

[0160] The communication information includes the user identifier invited by the user of the communication device. When a contact is added, the security credentials on the intermediate server are instantly updated with the additional new contact information. These data are also not assignable to any person. The same happens if the user's location or IP changes. All this information is encrypted and does not allow any conclusions to be drawn about the user or his / her location.

[0161] It only determines which user identifiers match so that the users can exchange specific information and therefore communicate with each other.

[0162] FIG. 5 illustrates the certificate-based access control.

[0163] The user identifier of the inviter and the user identifier of the invited communication partner are compared to verify an authorized connection between individual users. The two certificates will be linked only if the certificate stored in the intermediate server contains the user identifier of the authorized user. Every time an invitation is accepted, the certificate is updated. This also applies if a user is removed from the contacts. This means that if the user identifier of a removed contact is deleted from the security certificate, a local modification of the certificate will trigger an update process that sends the modified certificate to the intermediate server, thus preventing future exchange of connection data with the former contact.

[0164] FIG. 6 is intended to illustrate how data exchange occurs in the absence of an intermediate server.

[0165] If the intermediate server (one of several) is not reachable, the computer program product independently contacts the other computer program product with which contact information has already been exchanged and thus directly exchanges the most recent connection information. Before the exchange takes place, it is checked whether the user identifier is already agreed by both sides. Only if the user identifier is present in the security certificate will the connection be established and information exchanged.

[0166] Figure 7 illustrates the behavior of a client immediately after an intermediate server becomes no longer reachable.

[0167] In the current state of the art, as soon as a communication server (e.g. Office365, Teams, Zoom, Skype, etc.) fails, it is no longer possible to communicate via normal Internet channels. According to the invention, the client initiates a direct exchange of connection information, so that communication opportunities are maintained despite the server failure.

[0168] Even if individual PCs were offline during the failure of the intermediate server, they are gradually reconnected to the network as soon as they come back online. The network is rebuilt as the PCs re-establish contact with each of their confirmed contacts.

[0169] Thus, it is sufficient that one user of the contact network is reachable at the time of failure. Through this one user, other users can gradually reconnect to the network. Each additional connected user exponentially increases the speed at which the network is rebuilt.

[0170] The main differences between an exchange and an intermediate server are:

[0171] Preferably, new users can be registered via the intermediate server, and exchanges must also register for installation in the intermediate server. Nevertheless, the intermediate server preferably does not store communication data and is not usable as a repeater. The intermediate server preferably only manages registration and certification data and preferably provides connection data.

[0172] The more contacts an individual user has authorized, the faster this user can be reintegrated into the network. New contacts or new installations of computer program products are not possible during the downtime of the communication server.

[0173] The same conditions apply to companies that use exchanges. These clients can also continue to communicate with each other. The difference lies in the expanded capabilities of the exchange. As long as the exchange is offline, it cannot store any data and any ongoing communication can only be tracked via a computer program on the computer.

[0174] FIG. 8 illustrates a method for an intermediate server or application to register a certificate-based invitation for an additional anonymous user.

[0175] Each security certificate is encrypted and has a security level that is generated when the certificate is created. An intermediate server checks the certificate for correctness and tampering. If this check reveals unauthorized access or the certificate shows an error, the certificate is rejected and the sender of the security certificate is blocked.

[0176] Since the user identifier does not allow any conclusions to be drawn about the person to whom this identifier was assigned, the affected user must first prove that there was no misuse and that there was a technical problem with the certificate refusal.

[0177] FIG. 9 shows load balancing for data exchange.

[0178] During communication setup, the computer program product determines the available Internet bandwidth and available computer capacity. The computers participating in the communication then negotiate how the load of data exchange should be distributed.

[0179] In addition to reducing the load on weaker devices or devices with weaker Internet connections, this also reduces the total amount of data to be ported. For companies that use exchanges, communications can also now be fully distributed and controlled.

[0180] The negotiation of resource distribution is done through the inviting computer, which is also responsible for distributing the data stream, since all invited users dial into communication through this computer.

[0181] FIG. 10 illustrates load balancing.

[0182] The inviting computer receives information about available resources. At the same time, it informs the connected computers about which computers are still involved in the communication and forwards the connection information to all participants in the meeting. These data are only stored temporarily and are used to determine the connection speed and reachability of each computer involved in the communication. In this way, the most efficient connection route between the participants is ascertained and established.

[0183] Connection routes and load balancing are negotiated between computers using the following rules or methods. 1. A communication profile will be automatically sent to each participant. The profile transmits previously determined data on computer performance and time stamps to determine transmission quality, desired type of communication and expected resource requirements. The communication profile preferably refers to a summary of information, e.g. about the processing speed of video data, determined downstream and upstream Internet speeds and / or time stamps including the start of data transmission, especially communication data. 2. Determine current resources The computer determines its own available resources and communicates the results to the inviter and all participants. 3. Determine communication channels In parallel, the computer determines the connection speed for each participant and the inviter. 4. Creating a configuration file Based on the incoming information, the inviting computer decides what quality level is possible on the computer with the least resources, creates a configuration file, and sends the configuration file to all participants. This configuration file also decides how the computers will be connected to each other. This also makes it possible to split up data packets and thus avoid peak loads. Each computer constantly reports its connection quality to the inviting PC. This makes the connection optimization process a dynamic process that runs continuously in the background.

[0184] FIG. 11 shows load balancing by exchanges.

[0185] For companies using an exchange, the exchange can be used as a center for collaboration and the ongoing optimization process. The PC making the invitation can specify that when its computer program product is linked to the exchange, the exchange will negotiate configuration files with the participants and control the ongoing optimization process for the meeting.

[0186] The communication itself continues to be direct between the individual computers.

[0187] FIG. 12 illustrates the preferred encryption.

[0188] The computer program product contains all the elements for independently establishing encrypted communication: a user wishing to invite another user sends a certificate together with an email address to the intermediate server of the user who wishes to invite.

[0189] The intermediate server checks if this user is already registered using the email address, which is also in the certificate in encrypted form and cannot be read in the clear.

[0190] If the email address is already registered, the intermediate server forwards this invitation in the form of an invitation certificate to the corresponding user. If this user accepts the invitation, the corresponding certificate is sent to the intermediate server and both users are linked to each other via their user certificate. The inviter is then informed via the intermediate server of the fact that the invitation has been accepted.

[0191] If the invitation is declined, the inviter will also be informed of the fact that the invitation was rejected. In the event of a rejection, there is still no link of proof.

[0192] If the email address is not yet verified, the inviter will be informed that the invitee has not yet used the computer program product.

[0193] FIG. 13 shows a schematic diagram of the functional principle of an intermediate server.

[0194] The intermediate server is used to register new users and compare user invitations. To protect against misuse, each user must clearly identify himself / herself to be able to register. The registration of a computer program product is the only time at which a user can be clearly identified.

[0195] The registration key required for installation is generated during registration. At the same time, a sequence that can be used to block suspects is created in the registration key. This code sequence becomes part of the security credentials after logging in to the intermediate server. Since the security credentials are encrypted, the sequence required to block an individual user, and the existing blocking code, cannot be assigned directly to the user.

[0196] The intermediate servers preferably comprise several levels or tiers:

[0197] 1.Security Management An intermediate server only accepts registration requests (registration credentials), user credentials, or invitation requests for communication (invitation credentials). Each credential is checked for authenticity and accuracy before processing. If the check cannot be completed successfully, the acceptance / processing will be rejected.

[0198] 2. Registration Database Only when the security administration approves the incoming certificate can it be processed by the registration database. If the processing ends with a negative result, a blocking code is created that prevents the final installation / launch. If a positive result is nevertheless generated during registration, a security certificate is created and the user is registered on the server with the security certificate. The user certificate is then sent to the applicant and the computer program product (Point One App) becomes available for use.

[0199] 3. Blocking Code A blocking code is always created. If the registration is successful, the blocking code will be stored in the database and will remain there. In case of misuse, the user can therefore be specifically blocked and no one needs to know which security credentials were assigned to the user. This allows a user to be blocked even if no security credentials were available to be assigned to the user.

[0200] This is a passive blocking, which means that the user is not excluded from the account, but rather a blocking code is only activated in the security control, which prevents any further communication with the intermediate server. At the same time, the computer program product is blocked for all of the user's devices via feedback of unauthorized proof. As a result, the communication devices also stop communicating with all authorized invited users or all accepted invitations from other users.

[0201] 4. Proof Creation A user certificate is created during registration to allow the final setup of the computer program product. This certificate is used when setting up the computer program product and is expanded with security features and expanded encryption on the computer. The actual security certificate is sent to the server address to which the registration data is sent and which is now integrated after the installation on the PC is completed.

[0202] 5. User and invitation matching When a user successfully registers, the user's email address is stored in a user database. If the user now invites another user, the invited user is informed of this via the registration server. This information is sent to the user via the registration certificate. If said user accepts the invitation, the security certificate in the computer program product is appended with this information and is then updated on the registration server.

[0203] 6. Certificate Management The invitation matching now creates a connection between the credentials of a particular user. For this purpose, a part of the credentials that manages the invited user is used, and in the credentials management, the inviter's credentials are provided with an addition that confirms the acceptance of the invitation. Immediately afterwards, this certificate is sent to the inviter. If said inviter now confirms this on his computer, the certificate in the computer program product is augmented to include the invitee's information. From this point on, the inviter and the invitee can communicate with each other via the computer program product.

[0204] 7. Connection and communication Here, the connected computer program products (Point One Apps) expose their communication data via their security certificates. A computer program product with the appropriate identifier can retrieve the corresponding certificate to communicate with other users. If the intermediate server is not reachable, the individual computer program products start comparing this data via their already integrated contacts.

[0205] FIG. 14 serves to illustrate the exchange.

[0206] An exchange for a communication network, particularly a company, replaces the intermediate servers and takes over their tasks. The exchange has an extended range of functions for storing communication data and for ensuring this storage in accordance with data protection requirements (GDPR).

[0207] The exchange itself is preferably registered via the company's own domain. A blocking code is also created when registering the exchange so that the exchange can also be blocked. If the exchange is blocked, all computer program products registered with it will be blocked at the same time. Since computer program products can only be registered with an intermediate server or with an exchange (for the company), further use of the computer program product is generally no longer possible after blocking of the exchange. Since it is not possible to register more than one installation on a computer, the company's computers connected to the blocked company account can no longer be used with computer program products. If this is still necessary, the company's registration (for the blocked account) must first be removed from the intermediate server. If a computer is sold, its registration must be removed from the exchange so that the corresponding computer program product can be reinstalled on that computer.

[0208] In contrast to private use, the company assigned to the registration certificate can be seen in the clear at the exchange. This is only at the moment when the exchange exchanges data with the intermediate server of the computer program product, so data security and data sovereignty are also guaranteed to the company. Only the areas at the exchange provided for blocking are still reachable by the intermediate server of the computer program product after registration.

[0209] FIG. 15 shows a schematic diagram of typical communication over the Internet as known from the prior art.

[0210] In the prior art, it is common for providers to oversee the functioning and control of communications, for example the SIP protocol controls, regulates and monitors communications carried out over the SIP protocol.

[0211] In particular, this leads hardware and software manufacturers to make greater efforts to prove that communications through their products are secure, yet as soon as the concerns of the producer diverge from those of the user, security can no longer be fully guaranteed.

[0212] Given the large number of service providers whose technology is used for communication, communication security can only be guaranteed through extensive additional measures on the part of the user.

[0213] FIG. 16 illustrates a schematic diagram of preferred IP-based communications in the context of the present invention.

[0214] The method, within the meaning of the context of the present invention, establishes a connection between communication devices using an IP-based network.

[0215] Using the data of approved communication partners stored in the computer program product and regularly updated, users can communicate directly with each other.

[0216] Other than the servers required for the network to operate (registry and intermediate servers), no additional service providers or their software are required. Communications can be encrypted so that no one else can view the data. This provides a level of security that is not achievable using state-of-the-art means.

[0217] FIG. 17 serves to illustrate a release process that can be implemented in a preferred embodiment of the present invention.

[0218] Upon request of the first communication partner or after an invitation from the first communication partner, the requested user, i.e. the second communication partner, can accept or reject the communication partner invitation. The computer program product has a corresponding configuration and / or corresponding instructions for this purpose.

[0219] Using the computer program product, it is advantageously not possible to simply write messages to random recipients. A user of the computer program product according to the invention is only able to communicate within his own network (authorized communication partners). Each communication is provided with a unique key valid between each of the two communication partners.

[0220] FIG. 18 illustrates a schematic of a preferred embodiment of the initial certification.

[0221] In addition to the communication request, the initial certificate also contains communication data in the sense of user data of the requesting user (first communication partner or first communication device), said data being stored in the computer program product by accepting the communication request and being periodically updated.

[0222] If authorization to communicate is revoked by one of the users, the security credentials, communication data, and user identifier of the blocked user, as well as the user data of the user who revoked authorization, shall be removed from both users.

[0223] FIG. 19 serves to illustrate diagrammatically a preferred embodiment of the release certificate.

[0224] The release certificate is sent to the requesting user (first communication partner) after approval by the requester (second communication partner).

[0225] This certificate is sent directly to the requester (first communication partner or first communication device). In this way, the two communication devices newly connected to each other now generate a certificate for exchanging not only encryption but also data for establishing contact. The certificate thus generated can only be used by the two users of this registration process. No one else can use this certificate.

[0226] FIG. 20 shows a schematic diagram of a preferred embodiment of communication authentication.

[0227] The Proof of Communication encrypts the transmission with end-to-end encryption and contains the necessary information for setup.

[0228] Since a communication certificate always allows communication only between two users (inviter and invitee), communication with multiple users is only possible if each user has completed the release process (invitation process) with all participants in the communication.

[0229] References [1] ROSENBERG JET AL: "SIP:Session Initiation Protocol", Request for Comments: Network Working Group June 2002, Internet Engineering Task Force (IETF) Internet Society (ISOC) 4, rue des Falaises CH-1205 Geneva, Switzerland, RFC3261, June 1, 2002 (2002-06-01), pp. 1-269, XPO1 5009039

[0230] [2] "3rd Generation Partnership Project; Technical Specification Group, Services and System Aspects; IP Multimedia Subsystem (IMS); Stage 2 (Release 17)", 3GPP(registered trademark) STANDARD; 3GPP(registered trademark) TS23.228, 3RD GENERATION PARTNERSHIP PROJECT (3GPP(registered trademark)), V17.3.0 December 23, 2021 (2021-12-23), pp. 1-354, XP052083247

Claims

1. 1. A computer-implemented method for secure communication of information between at least a first communication partner and a second communication partner, wherein the first communication partner has a first communication device and the second communication partner has a second communication device, a) installing a computer program product on computing units of the first communication device and the second communication device; b) sending an invitation from the first communication device to the second communication device, wherein a security credential is sent to the second communication device when sending the invitation; c) accepting the invitation by the second communications device and verifying the security credentials; d) providing feedback to the intermediate server when the verification of the security certificate is successful; e) transmitting communication data directly between the first communication device and the second communication device; 20. A computer-implemented method comprising:

2. the security certificate is provided by the installation of the computer program product 2. The computer-implemented method of claim 1.

3. The communication data is encrypted for transmission, preferably by asymmetric encryption methods.

3. A computer-implemented method according to claim 1 or 2.

4. The data transfer rate and / or data capacity of the communication devices of the communication partners can be determined 3. A computer-implemented method according to claim 1 or 2.

5. The communication takes place between a plurality of communication partners, each of which has a communication device, and / or the communication takes place within a communication network.

3. A computer-implemented method according to claim 1 or 2, characterized in that:

6. the communication is between communication partners, and the first communication device and / or the computer program product installed in the computing unit of the first communication device provides the intermediate server.

3. A computer-implemented method according to claim 1 or 2.

7. The communication between the communication partners takes place within a communication network. It is characterized by the fact that the intermediate server is installed on a web server and functions as an exchange; 3. A computer-implemented method according to claim 1 or 2.

8. The communication data is selected from the group including a text message, a photo, a video, an audio message, and / or an attachment.

3. A computer-implemented method according to claim 1 or 2.

9. 1. A communication device network for secure communication of information, comprising at least a first communication device and a second communication device, wherein the first communication device and the second communication device each comprise a computing unit, and after installation of a computer program product, the first communication device and the second communication device: a) sending an invitation from the first communication device to the second communication device such that security credentials are sent to the second communication device when the invitation is sent; b) accepting the invitation by the second communication partner and verifying the security credentials; c) providing feedback to an intermediate server when the verification of the security credentials is successful; d) a communications device network configured to transmit communications data directly between said first communications device and said second communications device.

10. the communication is between communication partners, and the computing unit of the first communication device and / or the computer program product installed on the computing unit of the first communication device is configured to provide the intermediate server.

10. A communication device network according to claim 9.

11. The communication between the communication partners takes place within a communication network. It is characterized by the fact that Preferably, the intermediate server is installed on a web server and functions as an exchange.

10. The communication device network of claim 9.

12. 1. A program for secure communication of information between a first communication device and a second communication device, comprising: a) sending an invitation from the first communication device to the second communication device, wherein security credentials are sent to the second communication device when sending the invitation; b) accepting said invitation by a second communication partner and verifying said security credentials; c) feeding back to an intermediate server when said verification of said security credentials is successful; d) transmitting communication data directly between the first communication device and the second communication device; A program that causes a computer to execute the following.

13. The method of claim 12, wherein at least one of sending the invitation and accepting the invitation is performed based on an operation of a user interface. The program according to claim 12 .

14. The invitation is accepted based on user interface activity. The program according to claim 12 .