IP Library Granted Patent US 7,788,703
Granted Patent B2
US 7,788,703 · App. 11/788,371 · Granted Aug 31, 2010

Dynamic authentication in secured wireless networks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,788,703
App. No.
11/788,371
Granted
Aug 31, 2010
Kind
B2
Abstract

Systems and methods for authentication using paired dynamic secrets in secured wireless networks are provided. Each authenticated user is assigned a random secret generated so as to be unique to the user. The secret is associated with a wireless interface belonging to the user, so that no other wireless interface may use the same secret to access the network. The secret may be updated either periodically or at the request of a network administrator, and reauthentication of the wireless network may be required.

Claims (29)

1. A method for pairing secrets in a secured wireless network, the method comprising:

receiving an access request from a wireless interface device, the access request regarding access to the secured wireless network;

identifying that the wireless interface device belongs to an authenticated user having an access profile in the secured wireless network, wherein identification is based on the access request;

determining that the wireless interface device is associated with a valid security key derived from a secret, the secret associated with the access profile belonging to the authenticated user, wherein determining that the wireless interface device is associated with the valid security key comprises:

initially identifying that the wireless interface device is associated with at least one invalid security key, wherein the secret associated with the invalid security key is identified as being expired,

updating the expired secret associated with the access profile by:

generating a new random secret unique to the authenticated user, wherein the new secret is associated with the access profile belonging to the authenticated user;

deriving one or more security keys from the new secret; and

updating a table of unassociated security keys with the one or more security keys derived from the new secret;

obtaining the valid security key from the table of unassociated security keys, and

providing the valid security key to the wireless interface device, wherein execution of an executable on the wireless interface device configures the wireless interface device to access the secured wireless network using the access profile and the valid security key; and

permitting use of the valid security key to access the secured wireless network, wherein the use of the valid security key is restricted to the wireless interface device belonging to the user as identified by the access profile.

2. The method of claim 1 , wherein initially identifying that the wireless interface device is not associated with the valid security key includes determining that the wireless interface device is not associated with any security keys derived from the secret associated with the access profile of the authenticated user.

3. The method of claim 1 , wherein one or more valid security keys are stored to the table, wherein the table comprises information concerning each key, whether each key is associated with a wireless interface device, and which wireless interface device is associated with each key.

4. The method of claim 1 , wherein expiration of the secret occurs after a predefined period of time.

5. The method of claim 1 , wherein expiration of the secret occurs upon request by a system administrator.

6. The method of claim 1 , wherein requiring the wireless interface device to be re-authenticated comprises terminating the wireless connection between the wireless interface device and the wireless network.

7. A system for pairing secrets in a secured wireless network comprising:

an authentication module stored in memory and executable by a processor to authenticate a user of a wireless interface device, the authenticated user having an access profile in the secured wireless network;

a secret database for storing information concerning an updated secret, the secret database including a table concerning at least one valid security key derived from the updated secret, the updated secret associated with the access profile belonging to the authenticated user;

a secret generation module stored in memory and executable by a processor to update a secret when the secret is identified as being expired, wherein updating the secret comprises:

generating a new random secret unique to the authenticated user, wherein the new secret is associated with the access profile belonging to the authenticated user, and

deriving one or more security keys from the new secret, wherein the table is updated with the one or more security keys derived from the new secret;

an executable generation module stored in memory and executable by the processor to generate an executable for using the access profile and the updated secret to configure the wireless interface device to access the secured wireless network; and

an interface that receives requests to access the secured wireless network, wherein use of the valid security key to access the secured wireless network is restricted to the wireless interface device belonging to the user as identified by the access profile.

8. The system of claim 7 , further comprising an access profile generation module executable by a processor to update an access profile for the authenticated user, the update concerning the updated secret.

9. The system of claim 7 , wherein the secret generation module is further executable to update the secret after a predefined period of time.

10. The system of claim 7 , wherein the secret generation module is further executable to update the secret upon request by a system administrator.

11. The system of claim 8 , further comprising a binding module stored in memory and executable by a processor to associate the wireless interface device with the updated secret.

Assignments (16)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 066399/0561 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 8, 2019
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: RUCKUS WIRELESS, INC.
Reel/Frame 048817/0832 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2018
From: RUCKUS WIRELESS, INC.
To: ARRIS ENTERPRISES LLC
Reel/Frame 046730/0854 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2018
From: RUCKUS WIRELESS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 046379/0431 →
RELEASE OF SECURITY INTEREST Recorded Mar 17, 2017
From: SILICON VALLEY BANK; GOLD HILL VENTURE LENDING 03, LP
To: RUCKUS WIRELESS, INC.
Reel/Frame 042038/0600 →
RELEASE OF SECURITY INTEREST Recorded Jan 26, 2017
From: SILICON VALLEY BANK
To: RUCKUS WIRELESS, INC.
Reel/Frame 041513/0118 →
SECURITY AGREEMENT Recorded Oct 14, 2011
From: RUCKUS WIRELESS, INC.
To: GOLD HILL VENTURE LENDING 03, LP; SILICON VALLEY BANK
Reel/Frame 027063/0412 →
SECURITY AGREEMENT Recorded Oct 14, 2011
From: RUCKUS WIRELESS, INC.
To: SILICON VALLEY BANK
Reel/Frame 027062/0254 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 17, 2007
From: JOU, TYAN-SHU; SHEU, MING; YANG, BO-CHIEH; LIN, TIAN-YUAN; KUO, TED TSEI
To: RUCKUS WIRELESS, INC.
Reel/Frame 019567/0825 →