IP Library Granted Patent US 8,340,301
Granted Patent B2
US 8,340,301 · App. 12/375,990 · Granted Dec 25, 2012

Method for establishing a secret key between two nodes in a communication network

Assignee: NEC Europe, Ltd.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,340,301
App. No.
12/375,990
Granted
Dec 25, 2012
Kind
B2
Abstract

A method for establishing a secret key between two nodes in a communication network, in particular in a wireless local area network (WLAN), includes concealment of the fact that a key exchange occurs, one of the nodes—first node (B)—broadcasts one or more packets (P i ) that can be received by the other node—second node (A)—, wherein the packets (P i ) contain each a first key (K i ) and wherein the packets (P i ) are each encrypted with a second key (k i ) before being sent, the second node (A) randomly chooses one packet (P m ) from the packets (P i ) received and breaks the encryption of the chosen packet (P m ) in order to obtain the first key (K m ), and the second node (A) initiates a key exchange protocol, wherein the second node (A) encrypts the message to be sent for initiating the key exchange protocol with the revealed key (K m ).

Claims (19)

1. Method for establishing a secret key between two nodes in a communication network, in particular in a wireless local area network (WLAN), comprising:

first node (B) broadcasting one or more packets (P i ) that can be received by second node (A), wherein the packets (P i ) contain each a first key (K i ) and wherein the packets (P i ) are each encrypted with a second key (k i ) before being sent,

the second node (A) randomly choosing one packet (P m ) from the packets (P i ) received and breaks the encryption of the chosen packet (P m ) in order to obtain the first key (K m ), and

the second node (A) initiating a key exchange protocol, wherein the second node (A) encrypts the message to be sent for initiating the key exchange protocol with the revealed first key (K m ),

wherein the encryption of the packets (P i ) with the second (k i ) is an encryption that is broken by a brute force attack comprising a multiplicity of decryption attempts, and

wherein the second node (A) breaks the encryption of the chosen packet (P m ) in order to obtain the first key (K m ) without having the second key (k i ).

2. Method according to claim 1 , wherein between sending the packets (P i ) by the first node (B) and breaking the encryption or initiating the key exchange by the second node, a pre-configurable duration is provided for.

3. Method according to claim 1 , wherein the first node (B) stores a list of the sent first keys (K i ).

4. Method according to claim 3 , wherein the first node (B) tests the stored first keys (K i ) in order to decrypt the message of the second node (A) initiating the key exchange protocol.

5. Method according to claim 4 , wherein the first node (B) encrypts its message of the key exchange protocol with the found first key (K m ).

6. Method according to claim 1 , wherein a length of the second key (k i ) is set according to an encryption breakable with a multiplicity of decryption attempts.

7. Method according to claim 1 , wherein a RC5 encryption is employed for encrypting the packets (P i ).

8. Method according to claim 1 , wherein the first key (K i ) transported with the packet (P i ) and the second key (k i ) used to encrypt the packet (P i ) are identical.

9. Method according to claim 1 , wherein one of the nodes (A, B) is an access point (AP) of a network, and that the other of the nodes (B, A) is a node associated with said access point (AP).

10. Method according to claim 1 , wherein the packets (P i ) are sent periodically.

11. Method according to claim 1 , wherein the packets (P i ) are beacons broadcast at defined times.

12. Method according to claim 1 , wherein the initiated key exchange protocol is a Diffie-Hellman key exchange.

13. Method according to claim 2 , wherein the first node (B) stores a list of the sent first keys (K i ).

14. Method according to claim 2 , wherein a length of the second key (k i ) is set according to an encryption breakable with a multiplicity of decryption attempts.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 17, 2014
From: NEC EUROPE LTD.
To: NEC CORPORATION
Reel/Frame 033329/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2009
From: GIRAO, JOAO; ARMKNECHT, FREDERIK; MATOS, ALFREDO; AGUIAR, RUI LUIS
To: NEC EUROPE, LTD.
Reel/Frame 022600/0099 →
Priority Claims (1)
DE 10 2006 036 165 · Aug 1, 2006 · national
Continuity (1)
Related Publication 20100008508A1 · Jan 14, 2010