IP Library Granted Patent US 7,480,939
Granted Patent B1
US 7,480,939 · App. 09/900,617 · Granted Jan 20, 2009

Enhancement to authentication protocol that uses a key lease

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,480,939
App. No.
09/900,617
Granted
Jan 20, 2009
Kind
B1
Abstract

A method and system for using a key lease in a secondary authentication protocol after a primary authentication protocol has been performed is described. In one embodiment, the primary authentication protocol comprises a strong, secure, computationally complex authentication protocol. Moreover, the secondary authentication protocol comprises a less complex (compared to the primary authentication protocol) and less secure (compared to the primary authentication protocol) authentication protocol which can be performed in a length of time that is shorter than a length of time required to perform the primary authentication protocol. In an embodiment, the key lease includes context information. Moreover, a new session encryption key is computed after each time a quick re-authentication is performed by executing the secondary authentication protocol using the key lease, whereas the session encryption key is used for encrypting communication traffic, providing a solution to the potential communication traffic replay threat.

Claims (18)

1. A method of re-authenticating and protecting wireless communication security comprising the steps of:

a) performing a secondary authentication protocol between a wireless client electronic system (client) and a wireless network access point electronic system (AP) using a key lease generated by performance of a primary authentication protocol, wherein said key lease includes a key lease period for indicating a length of time in which said key lease is valid for using said secondary authentication protocol instead of said primary authentication protocol, and wherein the secondary authentication protocol includes the steps of:

a(i) transmitting said key lease from said client to said AP;

a(ii) generating a first random number associated with said client and a second random number associated with said AP, wherein said key lease includes an encryption key for use in said secondary authentication protocol; and

a(iii) transmitting said first random number to said AP and said second random number to said client; and

b) if said secondary authentication protocol is successful, generating a session encryption key for encrypting communication traffic between said client and said AP, wherein the generating comprises:

b(i) applying a hash function and said encryption key to said first random number and said second random number to determine said session encryption key.

2. A method as recited in claim 1 wherein said hash function is a HMAC-MD5 algorithm and wherein said hash function and encryption key are applied to a concatenation of said first random number and said second random number to determine said session encryption key.

3. A method as recited in claim 1 wherein said hash function is a HMAC-SHA-1 algorithm and wherein said hash function and encryption key are applied to a concatenation of said first random number and said second random number to determine said session encryption key.

4. A method as recited in claim 1 wherein said step b) includes:

generating a first session encryption key for encrypting communication traffic from said client to said AP; and

generating a second session encryption key for encrypting communication traffic from said AP to said client.

5. A method as recited in claim 4 wherein said step b) includes:

using said encryption key, said first random number, said second random number, a first media access control (MAC) address associated with said client, a second media access control (MAC) address associated with said AP, and the hash function to determine said first and second session encryption keys.

6. A method as recited in claim 5 wherein said hash function is a HMAC-MDS algorithm and wherein said hash function and said encryption key are applied to a concatenation of said first random number, said second random number, said first media access control (MAC) address associated with said client, and said second media access control (MAC) address associated with said AP to determine said first session encryption key.

7. A method as recited in claim 5 wherein said hash function is a HMAC-SHA-1 algorithm and wherein said hash function and said encryption key are applied to a concatenation of said first random number, said second random number, said first media access control (MAC) address associated with said client, and said second media access control (MAC) address associated with said AP to determine said first session encryption key.

8. A method as recited in claim 5 wherein said hash function is a HMAC-MD5 algorithm and said hash function and said encryption key are applied to a concatenation of said first random number, said second random number, said second media access control (MAC) address associated with said AP, and said first media access control (MAC) address associated with said client to determine said second session encryption key.

9. A method as recited in claim 5 wherein said hash function is a HMAC-SHA-1 algorithm and said hash function and said encryption key are applied to a concatenation of said first random number, said second random number, said second media access control (MAC) address associated with said AP, and said first media access control (MAC) address associated with said client to determine said second session encryption key.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2021
From: OT PATENT ESCROW, LLC
To: VALTRUS INNOVATIONS LIMITED
Reel/Frame 055403/0001 →
PATENT ASSIGNMENT, SECURITY INTEREST, AND LIEN AGREEMENT Recorded Jan 26, 2021
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP; HEWLETT PACKARD ENTERPRISE COMPANY
To: OT PATENT ESCROW, LLC
Reel/Frame 055269/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →