IP Library Granted Patent US 9,198,033
Granted Patent B2
US 9,198,033 · App. 11/862,561 · Granted Nov 24, 2015

Method and apparatus for authenticating nodes in a wireless network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,198,033
App. No.
11/862,561
Granted
Nov 24, 2015
Kind
B2
Abstract

The invention includes a method and apparatus for authenticating a wireless node requesting to join a network. A method includes receiving an authentication request from the wireless node, negotiating at least one authentication parameter with the wireless node, deriving a first encryption key using the at least one authentication parameter, encrypting a second encryption key using the first encryption key, and propagating the encrypted second encryption key toward the wireless node, wherein the wireless node independently derives the first encryption key for use in decrypting the encrypted second encryption key received from the authentication server node. The wireless node decrypts the encrypted second encryption key and stores the second encryption key for use to securely communicate with other wireless nodes of the network. In one embodiment, the present invention may be implemented using a modified version of the EAP-TLS protocol, in which rather than a Pairwise Master Key (PMK) being sent from the authentication server node to the wireless node, the authentication server node and the wireless node each derive the PMK and the authentication server node securely provides a group encryption key to the wireless node by encrypting the group encryption key using the PMK.

Claims (51)

1. A method for authenticating a wireless node requesting to join a wireless network, the method comprising:

receiving, at an authentication server node, an authentication request from the wireless node;

negotiating at least one authentication parameter with the wireless node;

receiving, from the wireless node, a first encryption key derived using the at least one authentication parameter;

deriving a second encryption key using the first encryption key and the at least one authentication parameter, wherein the second encryption key is independently derived at the wireless node;

encrypting a third encryption key using the second encryption key to form an encrypted third encryption key; and

propagating the encrypted third encryption key toward the wireless node.

2. The method of claim 1 , wherein the second encryption key comprises an Extensible Authentication Protocol (EAP) Pairwise Master Key (PMK).

3. The method of claim 1 , wherein the third encryption key comprises one of a unicast encryption key, a multicast encryption key, and a broadcast encryption key.

4. The method of claim 1 , wherein negotiating the at least one authentication parameter with the wireless node is performed using an Extensible Authentication Protocol (EAP) method.

5. The method of claim 1 , further comprising:

after receiving the authentication request and prior to negotiating the at least one authentication parameter, establishing a secure tunnel between the wireless node and the authentication server node; and

negotiating the at least one authentication parameter with the wireless node using the secure tunnel.

6. The method of claim 5 , wherein the secure tunnel is established using one of Extensible Authentication Protocol-Tunneled Transport Layer Security (EAP-TTLS) or Protected Extensible Authentication Protocol (PEAP).

7. The method of claim 1 , wherein the wireless node comprises an access node portion and a supplicant node portion, wherein the supplicant node portion is adapted to derive the second encryption key for use in decrypting the encrypted third encryption key.

8. An apparatus for authenticating a wireless node requesting to join a wireless network, comprising:

a processor and a memory communicatively connected to the processor, the processor configured to:

receive, at an authentication server node, an authentication request from the wireless node;

negotiate at least one authentication parameter with the wireless node;

receive, from the wireless node, a first encryption key derived using the at least one authentication parameter;

derive a second encryption key using the first encryption key and the at least one authentication parameter, wherein the second encryption key is independently derived at the wireless node;

encrypt a third encryption key using the second encryption key to form an encrypted third encryption key; and

propagate the encrypted third encryption key toward the wireless node.

9. A method for authenticating a wireless node requesting to join a wireless network, comprising:

negotiating at least one authentication parameter with an authentication server node;

providing, from the wireless node toward the authentication server node, a first encryption key derived using the at least one authentication parameter;

deriving, at the wireless node, a second encryption key using the first encryption key and the at least one authentication parameter, wherein the second encryption key is independently derived at the authentication server node; and

receiving, at the wireless node from the authentication server node, a message including an encrypted third encryption key, wherein the encrypted third encryption key is an encrypted version of a third encryption key, wherein the third encryption key is encrypted using the second encryption key to form the encrypted third encryption key, wherein the third encryption key is adapted for use by the wireless node in communicating with at least one other node of the wireless network.

10. The method of claim 9 , further comprising:

receiving a packet from a wireless user device;

retrieving the third encryption key from the memory;

encrypting the packet using the third encryption key to form an encrypted packet; and

transmitting the encrypted packet toward another node.

11. The method of claim 9 , further comprising:

receiving an encrypted packet from another node;

retrieving the third encryption key from the memory;

decrypting the encrypted packet using the third encryption key to recover a packet; and

transmitting the packet toward a wireless user device for which the packet is intended.

12. The method of claim 9 , wherein the second encryption key comprises an Extensible Authentication Protocol (EAP) Pairwise Master Key (PMK).

13. The method of claim 9 , wherein the third encryption key comprises one of a unicast encryption key, a multicast encryption key, and a broadcast encryption key.

14. The method of claim 9 , wherein negotiating the at least one authentication parameter with the authentication node is performed using an Extensible Authentication Protocol (EAP) method.

15. The method of claim 9 , further comprising:

prior to negotiating the at least one authentication parameter with the authentication server node, establishing a secure tunnel between the wireless node and the authentication server node; and

negotiating the at least one authentication parameter with the authentication server node using the secure tunnel.

16. The method of claim 15 , wherein the secure tunnel is established using one of Extensible Authentication Protocol-Tunneled Transport Layer Security (EAP-TTLS) or Protected Extensible Authentication Protocol (PEAP).

17. An apparatus for authenticating a wireless node requesting to join a wireless network, comprising:

a processor and a memory communicatively connected to the processor, the processor configured to:

negotiate at least one authentication parameter with an authentication server node;

provide, from the wireless node toward the authentication server node, a first encryption key derived using the at least one authentication parameter;

derive, at the wireless node, a second encryption key using the first encryption key and the at least one authentication parameter, wherein the second encryption key is independently derived at the authentication server node; and

receive, at the wireless node from the authentication server node, a message including an encrypted third encryption key, wherein the encrypted third encryption key is an encrypted version of a third encryption key, wherein the third encryption key is encrypted using the second encryption key to form the encrypted third encryption key, wherein the third encryption key is adapted for use by the wireless node in communicating with at least one other node of the wireless network.

Assignments (13)
PATENT SECURITY AGREEMENT Recorded Apr 22, 2023
From: RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 063429/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: PROVENANCE ASSET GROUP LLC
To: RPX CORPORATION
Reel/Frame 059352/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: NOKIA US HOLDINGS INC.
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058363/0723 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: CORTLAND CAPITAL MARKETS SERVICES LLC
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058983/0104 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 14, 2019
From: NOKIA USA INC.
To: NOKIA US HOLDINGS INC.
Reel/Frame 048370/0682 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP LLC
To: NOKIA USA INC.
Reel/Frame 043879/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: NOKIA TECHNOLOGIES OY; NOKIA SOLUTIONS AND NETWORKS BV; ALCATEL LUCENT SAS
To: PROVENANCE ASSET GROUP LLC
Reel/Frame 043877/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP, LLC
To: CORTLAND CAPITAL MARKET SERVICES, LLC
Reel/Frame 043967/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2015
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 037007/0829 →
MERGER AND CHANGE OF NAME Recorded Nov 3, 2015
From: ALCATEL USA MARKETING, INC.; ALCATEL USA SOURCING, INC.; LUCENT TECHNOLOGIES INC.; LUCENT TECHNOLOGIES INC.
To: ALCATEL-LUCENT USA INC.
Reel/Frame 036946/0995 →
RELEASE OF SECURITY INTEREST Recorded Oct 9, 2014
From: CREDIT SUISSE AG
To: ALCATEL-LUCENT USA INC.
Reel/Frame 033949/0016 →
SECURITY INTEREST Recorded Mar 7, 2013
From: ALCATEL-LUCENT USA INC.
To: CREDIT SUISSE AG
Reel/Frame 030510/0627 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2007
From: BUDDHIKOT, MILIND MADHAV; PAYETTE, CHARLES
To: LUCENT TECHNOLOGIES INC.
Reel/Frame 019975/0184 →