IP Library Granted Patent US 8,681,993
Granted Patent B2
US 8,681,993 · App. 12/390,030 · Granted Mar 25, 2014

Local area network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,681,993
App. No.
12/390,030
Granted
Mar 25, 2014
Kind
B2
Abstract

A method and system for distributed security for a plurality of devices in a communication network, each of the devices being responsible for generating, distributing and controlling its own keys for access to the communication network and using the keys to establish a trusted network, each device's membership to the communication network being checked periodically by other devices by using a challenge response protocol to establish which devices are allowed access to the communication network and the trusted network.

Claims (28)

1. A method performed by a first communication device in an ad-hoc network, the method comprising:

the first communication device identifying a first trust group associated with a first level of trust, the first trust group including a first subset of communication devices in the ad-hoc network;

the first communication device identifying a second trust group associated with a second, lower level of trust, the second trust group including a second subset of communication devices in the ad-hoc network;

the first communication device receiving, from a second communication device in the first trust group, a first cryptographic group key generated by the second communication device;

the first communication device receiving, from a third communication device in the second trust group, a second cryptographic group key generated by the third communication device;

based on the first level of trust associated with the first trust group, the first communication device designating the first cryptographic group key to be used for both encrypting and decrypting communications with the second communication device; and

based on the second, lower level of trust associated with the second trust group, the first communication device designating the second cryptographic group key not to be used for encrypting communications with the third communication device.

2. The method according to claim 1 , wherein the ad-hoc network includes a master device configured to activate an access controller using identifiers of devices in the ad-hoc network.

3. The method according to claim 2 , wherein the master device uses an access control list to admit only devices that have been positively authenticated to the ad-hoc network.

4. The method according to claim 2 , wherein the master device further comprises a traffic controller to regulate data flow within the ad-hoc network.

5. The method according to claim 4 , wherein the master device allocates a time slot to each of the devices for message distribution.

6. The method according to claim 1 , further comprising the first communication device determining which other devices are presently active in the ad-hoc network.

7. The method according to claim 6 , wherein the determining comprises re-authenticating each of the other devices at a predetermined time.

8. The method according to claim 7 , wherein the re-authenticating comprises performing a challenge-response protocol with each of the other devices to determine which of the other devices are present in the ad-hoc network.

9. A communication device comprising a processor and memory, the memory comprising computer executable instructions that when executed by the processor, perform operations for communicating in an ad-hoc network, the operations comprising:

identifying a first trust group associated with a first level of trust, the first trust group including a first subset of communication devices in the ad-hoc network;

identifying a second trust group associated with a second, lower level of trust, the second trust group including a second subset of communication devices in the ad-hoc network;

receiving, from a second communication device in the first trust group, a first cryptographic group key generated by the second communication device;

receiving, from a third communication device in the second trust group, a second cryptographic group key generated by the third communication device;

based on the first level of trust associated with the first trust group, designating the first cryptographic group key to be used for both encrypting and decrypting communications with the second communication device; and

based on the second, lower level of trust associated with the second trust group, designating the second cryptographic group key not to be used for encrypting communications with the third communication device.

10. The communication device according to claim 9 , wherein the ad-hoc network comprises a master device configured to activate an access controller using identifiers of devices in the ad-hoc network.

11. The communication device according to claim 10 , wherein the master device uses an access control list to admit only devices that have been positively authenticated to the ad-hoc network.

12. The communication device according to claim 10 , wherein the master device further comprises a traffic controller to regulate data flow within the ad-hoc network.

13. The communication device according to claim 12 , wherein the master device allocates a time slot to each of the devices for message distribution.

14. The communication device according to claim 9 , the operations further comprising determining which other devices are presently active in the ad-hoc network.

15. The communication device according to claim 14 , wherein the determining comprises re-authenticating each of the other devices at a predetermined time.

16. The communication device according to claim 15 , wherein the re-authenticating comprises performing a challenge-response protocol with each of the other devices to determine which of the other devices are presently included in the ad-hoc network.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2009
From: STRUIK, MARINUS; VANSTONE, SCOTT A.
To: CERTICOM CORP.
Reel/Frame 022936/0113 →