Network device and method of operation of a device in a network
A method for operating a parent device, such as a coordinator or router, in a ZigBee network includes monitoring a network for a potential network attack and changing an operating mode from a first mode of operation to a second mode of operation if a potential network attack is detected. In the first mode of operation the parent device is configured to accept unsecured rejoin requests. In the second mode of operation the parent device is configured not to accept unsecured rejoin requests during a first time interval and to accept unsecured rejoin requests during a second time interval.
1 . A method for operating a parent device in a ZigBee network, the method comprising:
monitoring a network for a potential network attack;
in response to detecting a potential network attack, changing an operating mode from a first mode of operation to a second mode of operation;
in the first mode of operation the parent device is configured to accept unsecured rejoin requests;
in the second mode of operation the parent device is configured to not accept unsecured rejoin requests during a first time interval and to accept unsecured rejoin requests during a second time interval; and
in response to not detecting a potential network attack, changing an operating mode from the second mode of operation to the first mode of operation.
2 . A method for operating a parent device in a ZigBee network, the method comprising:
monitoring a network for a potential network attack;
in response to detecting a potential network attack, changing an operating mode from a first mode of operation to a second mode of operation;
in the first mode of operation the parent device is configured to accept unsecured rejoin requests;
in the second mode of operation the parent device is configured to not accept unsecured rejoin requests during a first time interval and to accept unsecured rejoin requests during a second time interval, wherein the second time interval is a rejoin time interval; and
in response to detecting a potential network attack broadcasting a signal including the rejoin time interval.
3 . A method for operating a parent device in a ZigBee network, the method comprising:
monitoring a network for a potential network attack;
in response to detecting a potential network attack, changing an operating mode from a first mode of operation to a second mode of operation;
in the first mode of operation the parent device is configured to accept unsecured rejoin requests; and
in the second mode of operation the parent device is configured to not accept unsecured rejoin requests during a first time interval and to accept unsecured rejoin requests during a second time interval, wherein the second time interval is a rejoin time interval, wherein the rejoin time interval is randomly generated.
4 . The method of claim 1 , wherein monitoring the network for a potential network attack comprises monitoring a rate of unsecured rejoin requests.
5 . The method of claim 4 , further comprising: detecting a potential network attack if the rate of unsecured rejoin requests is greater than or equal to a rejoin request rate threshold value.
6 . A method for operating a parent device in a ZigBee network, the method comprising:
monitoring a network for a potential network attack;
in response to detecting a potential network attack, changing an operating mode from a first mode of operation to a second mode of operation;
in the first mode of operation the parent device is configured to accept unsecured rejoin requests;
in the second mode of operation the parent device is configured to not accept unsecured rejoin requests during a first time interval and to accept unsecured rejoin requests during a second time interval, wherein the second time interval is a rejoin time interval; and
wherein monitoring the network for a potential network attack comprises monitoring a rate of fill of a neighbor table.
7 . The method of claim 6 further comprising: detecting a potential network attack if the rate of fill of the neighbor table is greater than or equal to a rate of fill threshold value.
8 . A method for operating a parent device in a ZigBee network, the method comprising:
monitoring a network for a potential network attack;
in response to detecting a potential network attack, changing an operating mode from a first mode of operation to a second mode of operation;
in the first mode of operation the parent device is configured to accept unsecured rejoin requests;
in the second mode of operation the parent device is configured to not accept unsecured rejoin requests during a first time interval and to accept unsecured rejoin requests during a second time interval, wherein the second time interval is a rejoin time interval;
in the first mode of operation, transmitting a private network parameter to a child device joining the network; and
in the second mode of operation, transmitting a publicly disclosable parameter comprising a network key protected by the private network parameter.
9 . A parent device for a ZigBee network, the parent device comprising:
a processor;
a memory coupled to the processor; and
a transceiver coupled to the processor; wherein the processor is configured to:
monitor a network for a potential network attack;
in response to detecting a potential network attack, change an operating mode from a first mode of operation to a second mode of operation;
in the first mode of operation accept unsecured rejoin requests;
in the second mode of operation not accept unsecured rejoin requests during a first time interval, and accept unsecured rejoin requests during a second time interval, and
in response to not detecting a potential network attack, change the operating mode from the second mode of operation to the first mode of operation.
10 . A parent device for a ZigBee network, the parent device comprising:
a processor;
a memory coupled to the processor; and
a transceiver coupled to the processor; wherein the processor is configured to:
monitor a network for a potential network attack;
in response to detecting a potential network attack, change an operating mode from a first mode of operation to a second mode of operation;
in the first mode of operation accept unsecured rejoin requests; and
in the second mode of operation not accept unsecured rejoin requests during a first time interval, and accept unsecured rejoin requests during a second time interval;
wherein the parent device is further configured to:
in the first mode of operation, transmit a private network parameter to a child device joining the network; and
in the second mode of operation, transmit a publicly disclosable parameter comprising a network key protected by the private network parameter.
11 . A ZigBee network comprising the parent device of claim 10 and a child device.
12 . The ZigBee network of claim 11 wherein the parent device is one of a ZigBee Coordinator and ZigBee Router and the child device is one of a ZigBee Router and ZigBee End Device.
13 . A parent device for a ZigBee network, the parent device comprising:
a processor;
a memory coupled to the processor; and
a transceiver coupled to the processor; wherein the processor is configured to:
monitor a network for a potential network attack;
in response to detecting a potential network attack, change an operating mode from a first mode of operation to a second mode of operation;
in the first mode of operation accept unsecured rejoin requests; and
in the second mode of operation not accept unsecured rejoin requests during a first time interval, and accept unsecured rejoin requests during a second time interval, wherein the second time interval is a rejoin time interval.
14 . The parent device of claim 13 , further configured to: in response to detecting a potential network attack broadcasting a signal including the rejoin time interval.
15 . A ZigBee network comprising the parent device of claim 13 and a child device.
16 . The ZigBee network of claim 15 wherein the parent device is one of a ZigBee Coordinator and ZigBee Router and the child device is one of a ZigBee Router and ZigBee End Device.
17 . A parent device for a ZigBee network, the parent device comprising:
a processor;
a memory coupled to the processor; and
a transceiver coupled to the processor; wherein the processor is configured to:
monitor a network for a potential network attack;
in response to detecting a potential network attack, change an operating mode from a first mode of operation to a second mode of operation;
in the first mode of operation accept unsecured rejoin requests; and
in the second mode of operation not accept unsecured rejoin requests during a first time interval, and accept unsecured rejoin requests during a second time interval;
wherein the memory comprises a neighbor table and wherein the processor is further configured to monitor the network for a potential network attack by monitoring a rate of fill of the neighbor table.
18 . A ZigBee network comprising the parent device of claim 9 and a child device.
19 . The ZigBee network of claim 18 wherein the parent device is one of a ZigBee Coordinator and ZigBee Router and the child device is one of a ZigBee Router and ZigBee End Device.
20 . A ZigBee network comprising the parent device of claim 17 and a child device.
21 . The ZigBee network of claim 20 wherein the parent device is one of a ZigBee Coordinator and ZigBee Router and the child device is one of a ZigBee Router and ZigBee End Device.