IP Library Granted Patent US 7,133,526
Granted Patent B2
US 7,133,526 · App. 11/280,507 · Granted Nov 7, 2006

System and method for providing WLAN security through synchronized update and rotation of WEP keys

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,133,526
App. No.
11/280,507
Granted
Nov 7, 2006
Kind
B2
Abstract

A system and method are disclosed that overcome deficiencies of prior art IEEE 802.11 WEP key management schemes. Preferred embodiments of the present system and method update WEP keys and rotate transmission key indices in a synchronized manner and on a frequent basis making it impractical for a hacker to gather sufficient network traffic using any one WEP key to decrypt that key and without disrupting communications. Preferred embodiments of the present system and method do not require changes in access point or mobile unit hardware, radio drivers, or firmware and are therefore compatible with existing or legacy network infrastructure or components. The disclosed system and method may be used to facilitate secure communications between one or more access points and one or more mobile units and/or groups of two or more mobile units engaging in peer-to-peer associations.

Claims (34)

1. A system for improved security for wireless local area networks, and comprised of:

a wireless local area network providing wireless communications links for the transmission of data between the two or more communicating entities;

one or more generators for creating pseudorandom encryption keys for the communicating entities; and

one or more controllers for selecting a transmission encryption key index on a rotating basis to point to a pseudorandom encryption key from a set of active pseudorandom encryption keys, and updating the set of active pseudorandom encryption keys for each communicating entity;

wherein the step of selecting the transmission encryption key index and the step of updating are not required to be precisely synchronous.

2. The system of claim 1 , wherein the communicating entities comprise two or more mobile units associating on a peer-to-peer basis.

3. The system of claim 2 , wherein the communicating entities comprising one or more access points associating with one or more wired sub-networks; and one or more mobile units select encryption keys for transmission in a staggered manner.

4. The system of claim 1 , wherein a reconnecting mobile unit performs a systematic search to identify correct encryption keys based on a key update and rotation algorithm.

5. The system of claim 4 , wherein the reconnecting mobile unit performs the systematic search based on time.

6. The system of claim 5 , wherein synchronization is maintained by one or more of (i) time stamp messages; (ii) a time offset; (iii) exchange of time synchronization messages; (iv) prompts for key rotation; (v) prompts for key generation; and (vi) detection of the next key being in use.

7. The system of claim 1 , wherein one or more of (i) a key seed file, and (ii) a list of two or more encryption keys is distributed to at least one mobile unit and at least one access point.

8. The system of claim 7 , wherein the key seed file is used to generate new pseudorandom encryption keys in the set of pseudorandom encryption keys.

9. The system of claim 1 , wherein an index key and key control client manages a static encryption key list and a transmission encryption key index on a mobile unit.

10. The system of claim 1 , wherein an automatic key generator creates lists of pseudorandomly generated encryption keys that are then managed by an index and key scheduler.

11. A mobile unit providing improved security in communications with a wireless local area network, and comprised of:

one or more generators for creating pseudorandom encryption keys for the communicating entities; and

one or more controllers for selecting a transmission encryption key index on a rotating basis to point to a pseudorandom encryption key from a set of active pseudorandom encryption keys, and updating the set of active pseudorandom encryption keys; and

wherein the step of selecting the transmission encryption key index and the step of updating are not required to be precisely synchronous; and

wherein synchronization with the wireless local area network is maintained by one or more of (i) time stamp messages; (ii) a time offset; (iii) exchange of time synchronization messages; (iv) prompts for key rotation; (v) prompts for key generation; and (vi) detection of the next key being in use.

12. A method for providing improved security for wireless local area networks, comprising:

creating pseudorandom encryption keys for at least one of a plurality of communicating entities adapted to communicate via a wireless local area network;

selecting a transmission encryption key index on a rotating basis to point to a pseudorandom encryption key from a set of active pseudorandom encryption keys for the at least one of a plurality of communicating entities; and

updating the set of active pseudorandom encryption keys; and

wherein the step of selecting the transmission encryption key index and the step of updating are not required to be precisely synchronous.

13. The method of claim 12 , wherein the communicating entities comprise:

one or more access points associating with one or more wired sub-networks; and

one or more mobile units.

14. The method of claim 12 , wherein the communicating entities comprise two or more mobile units associating on a peer-to-peer basis.

15. The method of claim 13 further comprising selecting encryption keys for transmission in a staggered manner.

16. The method of claim 12 further comprising systematically searching, at a mobile unit, in response to reconnecting to a network to identify correct encryption keys based on a key update and rotation algorithm.

17. The method of claim 16 , wherein the systematic searching is based on time.

18. The method of claim 17 further comprising maintaining synchronization by one or more of (i) time stamp messages; (ii) a time offset; (iii) exchange of time synchronization messages; (iv) prompts for key rotation; (v) prompts for key generation; and (vi) detection of the next key being in use.

19. The method of claim 12 further comprising distributing one or more of (i) a key seed file, and (ii) a list of two or more encryption keys.

20. The method of claim 19 further comprising generating a new encryption key in the set of pseudorandom encryption keys with the assistance of the key seed file.

Assignments (24)
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41052/0762 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054560/0857 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41459/0387 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054637/0161 →
MERGER Recorded Apr 19, 2018
From: CRIMSON CORPORATION
To: IVANTI, INC.
Reel/Frame 045983/0075 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40183/0506 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0457 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40182/0345 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0581 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041052/0762 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041459/0387 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040183/0506 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040182/0345 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 031029/0849 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0307 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 032333/0637 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0037 →
SECURITY AGREEMENT Recorded Feb 25, 2014
From: LANDESK SOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC
Reel/Frame 032333/0637 →
SECURITY AGREEMENT Recorded Aug 16, 2013
From: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; CRIMSON ACQUISITION CORP.; LANDESKSOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 031029/0849 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2013
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: CRIMSON CORPORATION
Reel/Frame 030993/0644 →
ARTICLES OF CORRECTION FOR CERTIFICATE OF MERGER. THE EFFECTIVE DATE OF THE MERGER IS JUNE 29, 2012. Recorded Nov 15, 2012
From: WAVELINK CORPORATION
To: WAVELINK SOFTWARE LLC
Reel/Frame 029309/0177 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2012
From: WAVELINK SOFTWARE LLC
To: CRIMSON CORPORATION
Reel/Frame 029213/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2012
From: WAVELINK SOFTWARE LLC
To: CRIMSON CORPORATION
Reel/Frame 029092/0559 →
MERGER Recorded Oct 8, 2012
From: WAVELINK CORPORATION
To: WAVELINK SOFTWARE LLC
Reel/Frame 029092/0548 →
PATENT SECURITY AGREEMENT Recorded Jul 26, 2012
From: CRIMSON CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 028643/0847 →
RELEASE OF SECURITY INTEREST Recorded Jun 20, 2012
From: SILICON VALLEY BANK
To: WAVELINK CORPORATION
Reel/Frame 028413/0021 →
RELEASE OF SECURITY INTEREST Recorded Jun 14, 2012
From: SILICON VALLEY BANK
To: WAVELINK CORPORATION
Reel/Frame 028407/0024 →