IP Library Granted Patent US 7,734,052
Granted Patent B2
US 7,734,052 · App. 11/470,921 · Granted Jun 8, 2010

Method and system for secure processing of authentication key material in an ad hoc wireless network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,734,052
App. No.
11/470,921
Granted
Jun 8, 2010
Kind
B2
Abstract

A method and system for secure processing of authentication key material in an ad hoc wireless network enables secure distribution of the authentication key material between a mesh authenticator ( 110 ) and a mesh key distributor ( 115 ), which may be separated by multiple wireless links. The method includes deriving a pairwise transient key for key distribution (PTK-KD) using a mesh key holder security information element (MKHSIE). A mesh authenticator pairwise master key (PMK-MA) is then requested using a first mesh encrypted key information element (MEKIE) that includes data origin information. Using the pairwise transient key for key distribution (PTK-KD), a second mesh encrypted key information element (MEKIE) is then decrypted to obtain the mesh authenticator pairwise master key (PMK-MA).

Claims (34)

1. A method for secure processing of authentication key material in an ad hoc wireless network, the method comprising:

deriving a pairwise transient key for key distribution using a mesh key holder security information element;

requesting a mesh authenticator pairwise master key using a first mesh encrypted key information element that includes data origin information; and

decrypting, using the pairwise transient key for key distribution, a second mesh encrypted key information element to obtain the mesh authenticator pairwise master key.

2. The method of claim 1 , further comprising:

completing a supplicant security exchange using the mesh authenticator pairwise master key.

3. The method of claim 1 , wherein the mesh key holder security information element includes a message integrity check value.

4. The method of claim 1 , wherein deriving the pairwise transient key for key distribution comprises processing a three message handshake with a mesh key distributor.

5. The method of claim 4 , wherein the three message handshake comprises a mesh key holder security association request message, a mesh key holder security association response message, and a mesh key holder security association confirm message.

6. The method of claim 1 , wherein deriving the pairwise transient key for key distribution comprises confirming that a mesh key distributor has correctly derived the pairwise transient key for key distribution.

7. The method of claim 1 , wherein the pairwise transient key for key distribution comprises both a key encrypting key and a key confirmation key.

8. The method of claim 7 , wherein the data origin information is computed using the key confirmation key and the second mesh encrypted key information element is decrypted using the key encrypting key.

9. The method of claim 1 , wherein the pairwise transient key for key distribution is based on a master key generated during a mesh authenticator extensible authentication protocol authentication process.

10. The method of claim 1 , wherein the mesh key holder security information element comprises an information count value that indicates a number of information elements protected by a message integrity check value.

11. The method of claim 1 , wherein the mesh encrypted key information element comprises a replay counter.

12. The method of claim 1 , wherein the data origin information comprises a message integrity check value.

13. The method of claim 1 , wherein the second mesh encrypted key information element comprises encrypted contents, including the mesh authenticator pairwise master key, which are encrypted using an advanced encryption standard key wrap.

14. A system for secure processing of authentication key material in an ad hoc wireless network, the system comprising:

a mesh authenticator operating to derive a pairwise transient key for key distribution using a mesh key holder security information element;

the mesh authenticator operating to request a mesh authenticator pairwise master key using a first mesh encrypted key information element that includes data origin information; and

the mesh authenticator operating to decrypt, using the pairwise transient key for key distribution, a second mesh encrypted key information element to obtain the mesh authenticator pairwise master key.

15. The system of claim 14 , further comprising:

the mesh authenticator operating to complete a supplicant security exchange using the mesh authenticator pairwise master key.

16. The system of claim 14 , wherein the mesh key holder security information element includes a message integrity check value.

17. The system of claim 14 , wherein deriving the pairwise transient key for key distribution comprises processing a three message handshake with a mesh key distributor.

18. The system of claim 17 , wherein the three message handshake comprises a mesh key holder security association request message, a mesh key holder security association response message, and a mesh key holder security association confirm message.

19. The system of claim 14 , wherein deriving the pairwise transient key for key distribution comprises confirming that a mesh key distributor has correctly derived the pairwise transient key for key distribution.

20. The system of claim 14 , wherein the pairwise transient key for key distribution comprises both a key encrypting key and a key confirmation key.

21. The system of claim 20 , wherein the data origin information is computed using the key confirmation key and the second mesh encrypted key information element is decrypted using the key encrypting key.

22. The system of claim 14 , wherein the pairwise transient key for key distribution is based on a master key generated during a mesh authenticator extensible authentication protocol authentication process.

23. The system of claim 14 , wherein the mesh key holder security information element comprises an information count value that indicates a number of information elements protected by a message integrity check value.

24. The system of claim 14 , wherein the mesh encrypted key information element comprises a replay counter.

25. The system of claim 14 , wherein the data origin information comprises a message integrity check value.

26. The system of claim 14 , wherein the second mesh encrypted key information element comprises encrypted contents, including the mesh authenticator pairwise master key, which are encrypted using an advanced encryption standard key wrap.

Assignments (8)
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2017
From: MOTOROLA SOLUTIONS, INC.
To: ARRIS ENTERPRISES LLC
Reel/Frame 044806/0900 →
CHANGE OF NAME Recorded Apr 6, 2011
From: MOTOROLA, INC
To: MOTOROLA SOLUTIONS, INC.
Reel/Frame 026081/0001 →