IP Library Granted Patent US 8,281,133
Granted Patent B1
US 8,281,133 · App. 12/350,649 · Granted Oct 2, 2012

Predictive real-time pairwise master key identification (PMKID) generation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,281,133
App. No.
12/350,649
Granted
Oct 2, 2012
Kind
B1
Abstract

A device receives, from a wireless access point, a pairwise master key identification (PMKID) based on a known pairwise master key (PMK), and determines whether the received PMKID matches one of multiple PMKIDs stored in a cache associated with the device. The device dynamically generates a PMKID based on the known PMK when the received PMKID does not match one of the multiple PMKIDs stored in the cache, and performs a fast four-way handshake to establish a secure connection between the device and the wireless access point when the dynamically generated PMKID matches the received PMKID.

Claims (62)

1. A device, comprising:

a memory to store a plurality of instructions; and

a processor to execute instructions in the memory to:

receive, from a wireless access point, a pairwise master key identification (PMKID) based on a known pairwise master key (PMK),

determine whether the received PMKID matches one of a plurality of PMKIDs stored in a cache associated with the memory,

dynamically generate a PMKID based on the known PMK when the received PMKID does not match one of the plurality of PMKIDs stored in the cache,

determine whether the dynamically generated PMKID matches the received PMKID,

perform a fast four-way handshake to establish a secure connection between the device and the wireless access point when the dynamically generated PMKID matches the received PMKID, and

perform a full authentication to establish a secure connection between the device and the wireless access point when the dynamically generated PMKID does not match the received PMKID.

2. The device of claim 1 , where, when receiving, from the wireless access point, the pairwise master key identification, the processor further executes instructions in the memory to:

perform a full authentication to establish a secure connection between the device and another wireless access point,

generate the known PMK based on the full authentication, and

generate, based on the known PMK, a PMKID associated with the other wireless access point.

3. The device of claim 2 , where, when receiving, from the wireless access point, the pairwise master key identification, the processor further executes instructions in the memory to:

provide, via the other wireless access point, the known PMK to a network device, where the network device provides the PMKID based on the known PMK to the wireless access point.

4. The device of claim 2 , where, when receiving, from the wireless access point, the pairwise master key identification, the processor further executes instructions in the memory to:

store the known PMK and the PMKID associated with the other wireless access point in the cache associated with the memory.

5. The device of claim 1 , where the device comprises one or more of:

a radiotelephone,

a personal communications system (PCS) terminal,

a personal digital assistant (PDA),

a laptop computer,

a personal computer, or

a network device.

6. A computing device-implemented method, the method comprising:

generating, by a processor associated with the computing device, a plurality of encryption key identifications based on a known encryption key, each of the plurality of encryption key identifications being associated with a wireless access point of a plurality of wireless access points;

storing the plurality of encryption key identifications in a memory associated with the computing device;

receiving, from a wireless access point of the plurality of wireless access points and at the processor, an encryption key identification based on the known encryption key;

determining, by the processor, whether the received encryption key identification matches one of the plurality of encryption key identifications stored in the memory;

dynamically generating, by the processor, another encryption key identification based on the known encryption key when the received encryption key identification does not match one of the plurality of encryption key identifications stored in the memory; and

performing, by the processor, a fast authentication to establish a secure connection between the computing device and the wireless access point when the dynamically generated encryption key identification matches the received encryption key identification.

7. The computing device-implemented method of claim 6 , where:

the encryption key identification comprises a pairwise master key identification (PMKID),

the known encryption key comprises a known PMK,

the dynamically generated encryption key identification comprises a dynamically generated PMKID, and

the fast authentication comprises a fast four-way handshake between the computing device and the wireless access point.

8. The computing device-implemented method of claim 7 , further comprising:

determining, by the processor, whether the dynamically generated PMKID matches the received PMKID; and

performing, by the processor, a full authentication to establish the secure connection between the computing device and the wireless access point when the dynamically generated PMKID does not match the received PMKID.

9. The computing device-implemented method of claim 7 , further comprising:

performing, by the processor, a full authentication to establish a secure connection between the computing device and another wireless access point;

generating, by the processor, the known PMK based on the full authentication; and

generating, by the processor and based on the known PMK, a PMKID associated with the other wireless access point.

10. The computing device-implemented method of claim 9 , further comprising:

providing, by the processor and via the other wireless access point, the known PMK to a network device, whether the network device provides the PMKID based on the known PMK to the wireless access point.

11. The computing device-implemented method of claim 10 , further comprising:

storing the known PMK and the PMKID associated with the other wireless access point in the memory.

12. The computing device-implemented method of claim 6 , where the computing device comprises one or more of:

a radiotelephone,

a personal communications system (PCS) terminal,

a personal digital assistant (PDA),

a laptop computer,

a personal computer, or

a network device.

13. A device, comprising:

a processor to:

receive, from a wireless access point, a pairwise master key identification (PMKID) based on a known pairwise master key (PMK);

determine whether the received PMKID matches one of a plurality of PMKIDs stored in a cache associated with a memory associated with the device;

dynamically generate a PMKID based on the known PMK when the received PMKID does not match one of the plurality of PMKIDs stored in the cache;

determine whether the dynamically generated PMKID matches the received PMKID;

perform a full authentication to establish a secure connection between the device and the wireless access point when the dynamically generated PMKID does not match the received PMKID; and

perform a fast four-way handshake to establish the secure connection between the device and the wireless access point when the dynamically generated PMKID matches the received PMKID.

Assignments (16)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: PULSE SECURE LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0027 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 053638-0220 Recorded Dec 1, 2020
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: PULSE SECURE, LLC
Reel/Frame 054559/0368 →
SECURITY INTEREST Recorded Aug 29, 2020
From: PULSE SECURE, LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053638/0220 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 042380/0859 Recorded Aug 29, 2020
From: CERBERUS BUSINESS FINANCE, LLC, AS AGENT
To: PULSE SECURE, LLC
Reel/Frame 053638/0259 →
RELEASE OF SECURITY INTEREST Recorded Jul 21, 2020
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
Reel/Frame 053271/0307 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL 037338, FRAME 0408 Recorded May 1, 2017
From: US BANK NATIONAL ASSOCIATION
To: PULSE SECURE, LLC
Reel/Frame 042381/0568 →
GRANT OF SECURITY INTEREST PATENTS Recorded May 1, 2017
From: PULSE SECURE, LLC
To: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
Reel/Frame 042380/0859 →
SECURITY INTEREST Recorded Dec 21, 2015
From: PULSE SECURE, LLC
To: U.S BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037338/0408 →
SECURITY INTEREST Recorded Dec 30, 2014
From: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
To: JUNIPER NETWORKS, INC.
Reel/Frame 034713/0950 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2014
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 034045/0717 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2009
From: TKAL, ERIK
To: JUNIPER NETWORKS, INC.
Reel/Frame 022077/0555 →