IP Library Granted Patent US 7,461,253
Granted Patent B2
US 7,461,253 · App. 11/561,443 · Granted Dec 2, 2008

Method and apparatus for providing a key for secure communications

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,461,253
App. No.
11/561,443
Granted
Dec 2, 2008
Kind
B2
Abstract

A method and apparatus for providing a key for secure communications is provided herein. During operation a node wishing to join a network, will authenticate with an authentication server and then derive a pairwise key (e.g., a Pair-wise Transient Key (PTK)) used for encryption of unicast traffic. The node will also create its own group transient key (GTK) for use in encrypting multicast or broadcast traffic. Once the GTK is generated, it will be provided to an authenticator as part of an association request message.

Claims (25)

1. A method for mutual authentication of a first and a second node in a peer-to-peer network, the method comprising the steps of:

sending a first authentication message to the second node containing information needed to authenticate the first node;

receiving a second authentication message from the second node echoing at least some of the information transmitted in the first authentication message;

determining responsive to the contents of the received second authentication message whether authentication is needed;

deriving a pair-wise transient key (PTK) used for encryption of unicast traffic from a pair-wise master key created during authentication;

sending an association message to the second node, the association message comprising both information needed by the second node to validate the PTK, and a group transient key (GTK) used by the first node in encrypting multicast or broadcast traffic; and

receiving an association message from the second node, the association message comprising information needed by the first node to validate the PTK, and a GTK used by the second node, wherein the first authentication message comprises a nonce created by the first node and the second authentication message comprises a nonce created by the second node.

2. The method of claim 1 wherein the association message sent to the second node is an association request message.

3. The method of claim 1 wherein the association message received from the second node is an association response message.

4. The method of claim 1 wherein the first authentication message comprises information needed for the second node to authenticate the first node.

5. The method of claim 4 wherein the second authentication message comprises information needed by the first node for the first node to be authenticated by the second node.

6. The method of claim 1 wherein the information in the association message needed by the second node to validate the PTK comprises a Robust Security Network (RSN) information element identifying the pair-wise master key used for deriving the PTK, and a message integrity check value calculated using the PTK.

7. The method of claim 1 wherein the information in the association message needed by the first node to validate the PTK comprises an RSN information element identifying the pair-wise master key used for deriving the PTK, and a message integrity check value calculated using the PTK.

8. An apparatus for performing mutual authentication, the apparatus comprising:

a transmitter sending a first authentication message to a second node containing information needed to authenticate a first node;

a receiver receiving a second authentication message from the second node echoing at least some of the information transmitted in the first authentication message;

a logic unit determining responsive to the contents of the received second authentication message whether authentication is needed and deriving a pair-wise transient key (PTK) used for encryption of unicast traffic from a pair-wise master key created during authentication; and

wherein the transmitter additionally transmits an association message to the second node, the association message comprising both information needed by the second node to validate the PTK, and a group transient key (GTK) used by a first node in encrypting multicast or broadcast traffic; and

the receiver additionally receives an association message from the second node, the association message comprising information needed by the first node to validate the PTK and a GTK used by the second, wherein the first authentication message comprises a nonce created by the first node and the second authentication message comprises a nonce created by the second node.

9. The apparatus of claim 8 wherein the association message sent to the second node is an association request message.

10. The apparatus of claim 8 wherein the association message received from the second node is an association response message.

11. The apparatus of claim 8 wherein the first authentication message comprises information needed for the second node to authenticate the first node.

12. The apparatus of claim 11 wherein the second authentication message comprises information needed by the first node for the first node to be authenticated by the second node.

13. The apparatus of claim 8 wherein the information in the association message needed by the second node to validate the PTK comprises a Robust Security Network (RSN) information element identifying the pair-wise master key used for deriving the PTK, and a message integrity check value calculated using the PTK.

14. The apparatus of claim 8 wherein the information in the association message needed by the first node to validate the PTK comprises an RSN information element identifying the pair-wise master key used for deriving the PTK, and a message integrity check value calculated using the PTK.

Assignments (9)
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2017
From: MOTOROLA SOLUTIONS, INC.
To: ARRIS ENTERPRISES LLC
Reel/Frame 044806/0900 →
CHANGE OF NAME Recorded Apr 6, 2011
From: MOTOROLA, INC
To: MOTOROLA SOLUTIONS, INC.
Reel/Frame 026081/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2007
From: BRASKICH, ANTHONY J.; EMEOTT, STEPHEN P.
To: MOTOROLA, INC.
Reel/Frame 018950/0194 →