IP Library Granted Patent US 9,794,731
Granted Patent B2
US 9,794,731 · App. 13/012,057 · Granted Oct 17, 2017

Method and apparatus for providing secure communication in a self-organizing network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,794,731
App. No.
13/012,057
Granted
Oct 17, 2017
Kind
B2
Abstract

A communication system provides secure communication between two nodes in a self-organizing network without the need for a centralized security or control device. A first node of the two nodes is provisioned with one or more security profiles, auto-discovers a second node of the two nodes, authenticates the second node based on a security profile of the one or more security profiles, selects a security profile of the one or more security profiles to encrypt a communication session between the two nodes, and encrypts the communication session between the two nodes based on the selected security profile. The second node also is provisioned with the same one or more security profiles, authenticates the first node based on a same security profile as is used to authenticate the second node, and encrypts the communication session based on the same security profile as is used for encryption by the first node.

Claims (54)

1. A computer-implemented method comprising:

obtaining, by a processor at a first network node of a distributed, self-organizing network, a value of a security profile selection parameter based at least on a physical communication link type, a channel type, a channel characteristic, a network interface type, a physical communication link identifier, or an endpoint identifier;

discovering, by a processor at a second network node of the distributed, self-organizing network, the first network node of the distributed, self-organizing network;

selecting, by the processor at the first network node, a particular security profile that (i) is associated with the value of the security profile selection parameter in a table of one or more security profiles respectively associated with one or more security profile selection parameters and (ii) is used to encrypt a communication session that is being initiated between the first network node and the second network node of the distributed, self-organizing network, from among one or more security profiles that were stored on a memory device of the first network node before the first network node was discovered by the second network node;

generating, by the processor at the first network node in response to selecting the particular security profile with which to encrypt the communication session that is being initiated between the first network node and the second network node, an authentication challenge message that includes (i) an encrypted portion that is encrypted based on the selected particular security profile that is associated with the value of the security profile selection parameter in the table, and (ii) an unencrypted portion that identifies the selected particular security profile that is associated with the value of the security profile selection parameter in the table;

transmitting, by the processor at the first network node, the authentication challenge message from the first network node to the second network node; and

in response to receiving the encrypted authentication challenge message at the second network node, decrypting, by the processor at the second network node, the authentication challenge message based on the particular security profile that was selected by the processor at the first network node, and in response, authenticating the first network node of the distributed, self-organizing network.

2. The computer-implemented method of claim 1 , further comprising in response to discovering, by the processor at the second network node of the distributed, self-organizing network, the first network node of the distributed, self-organizing network, transmitting, by the processor at the second network node of the distributed, self-organizing network, a communication session initiation message to the first network node of the distributed, self-organizing network.

3. The computer-implemented method of claim 2 , wherein the communication session initiation message transmitted, by the processor at the second network node, to the first network node includes one or more of: (i) a type of communication session being initiated between the second network node of the distributed, self-organizing network and the first network node of the distributed, self-organizing network, (ii) a port number assigned to the communication session, (iii) or a medium access control (MAC) layer address assigned to the communication session.

4. The computer-implemented method of claim 1 , further comprising:

receiving, by the second network node, the one or more security profiles; and

storing, by the second network node, the received one or more security profiles.

5. The computer-implemented method of claim 1 , further comprising:

receiving, by the first network node, an authentication response to the authentication challenge message from the second network node, wherein the authentication response is encrypted based on the particular security profile that was selected by the processor at the first network node.

6. The computer-implemented method of claim 5 , further comprising:

decrypting, by the first network node, the authentication response to the authentication challenge message that was received, by the first network node, from the second network node, based on the particular security profile, and in response, authenticating the second network node.

7. The computer-implemented method of claim 6 , further comprising:

after authenticating the second network node, establishing, by the first network node, a secure communication link between the first network node and the second network node.

8. The computer-implemented method of claim 7 , further comprising

in response to establishing the secure communication link, providing, by the first network node, an application layer communication to the second network node.

9. The computer-implemented method of claim 1 , wherein obtaining the value of the security profile selection parameter by the processor at the first network node comprises:

obtaining, by the processor at the first network node of the distributed, self-organizing network, a value of a security profile selection parameter based at least on a physical communication link type.

10. The computer-implemented method of claim 1 , wherein obtaining the value of the security profile selection parameter by the processor at the first network node comprises:

obtaining, by the processor at the first network node of the distributed, self-organizing network, a value of a security profile selection parameter based at least on a characteristic of a channel to be used in a communication session between the first network node and second network node.

11. The computer-implemented method of claim 10 , wherein the characteristic of the channel is associated with frequencies, time slots, or channel coding to be employed in the communication session between the first network node and second network node.

12. A system comprising:

one or more computers and one or more storage devices storing instructions that are operable, when executed by the one or more computers, to cause the one or more computers to perform operations comprising:

obtaining, by a processor at a first network node of a distributed, self-organizing network, a value of a security profile selection parameter based at least on a physical communication link type, a channel type, a channel characteristic, a network interface type, a physical communication link identifier, or an endpoint identifier;

discovering, by a processor at a second network node of the distributed, self-organizing network, the first network node of the distributed, self-organizing network;

selecting, by the processor at the first network node, a particular security profile that (i) is associated with the value of the security profile selection parameter in a table of one or more security profiles respectively associated with one or more security profile selection parameters and (ii) is used to encrypt a communication session that is being initiated between the first network node and the second network node of the distributed, self-organizing network, from among one or more security profiles that were stored on a memory device of the first network node before the first network node was discovered by the second network node;

generating, by the processor at the first network node in response to selecting the particular security profile with which to encrypt the communication session that is being initiated between the first network node and the second network node, an authentication challenge message that includes (i) an encrypted portion that is encrypted based on the selected particular security profile that is associated with the value of the security profile selection parameter in the table, and (ii) an unencrypted portion that identifies the selected particular security profile that is associated with the value of the security profile selection parameter in the table;

transmitting, by the processor at the first network node, the authentication challenge message from the first network node to the second network node; and

in response to receiving the encrypted authentication challenge message at the second network node, decrypting, by the processor at the second network node, the authentication challenge message based on the particular security profile that was selected by the processor at the first network node, and in response, authenticating the first network node of the distributed, self-organizing network.

13. The system of claim 12 , the operations further comprising:

receiving, by the first network node, an authentication response to the authentication challenge message from the second network node, wherein the authentication response is encrypted based on the particular security profile that was selected by the processor at the first network node.

14. The system of claim 13 , the operations further comprising:

decrypting, by the first network node, the authentication response to the authentication challenge message that was received, by the first network node, from the second network node, based on the particular security profile, and in response, authenticating the second network node.

15. The system of claim 14 , the operations further comprising:

after authenticating the second network node, establishing, by the first network node, a secure communication link between the first network node and the second network node.

16. A non-transitory computer-readable medium storing software comprising instructions executable by one or more computers which, upon such execution, cause the one or more computers to perform operations comprising:

obtaining, by a processor at a first network node of a distributed, self-organizing network, a value of a security profile selection parameter based at least on a physical communication link type, a channel type, a channel characteristic, a network interface type, a physical communication link identifier, or an endpoint identifier;

discovering, by a processor at a second network node of the distributed, self-organizing network, the first network node of the distributed, self-organizing network;

selecting, by the processor at the first network node, a particular security profile that (i) is associated with the value of the security profile selection parameter in a table of one or more security profiles respectively associated with one or more security profile selection parameters and (ii) is used to encrypt a communication session that is being initiated between the first network node and the second network node of the distributed, self-organizing network, from among one or more security profiles that were stored on a memory device of the first network node before the first network node was discovered by the second network node;

generating, by the processor at the first network node in response to selecting the particular security profile with which to encrypt the communication session that is being initiated between the first network node and the second network node, an authentication challenge message that includes (i) an encrypted portion that is encrypted based on the selected particular security profile that is associated with the value of the security profile selection parameter in the table, and (ii) an unencrypted portion that identifies the selected particular security profile that is associated with the value of the security profile selection parameter in the table;

transmitting, by the processor at the first network node, the authentication challenge message from the first network node to the second network node; and

in response to receiving the encrypted authentication challenge message at the second network node, decrypting, by the processor at the second network node, the authentication challenge message based on the particular security profile that was selected by the processor at the first network node, and in response, authenticating the first network node of the distributed, self-organizing network.

17. The non-transitory computer-readable medium of claim 16 , the operations further comprising:

receiving, by the first network node, an authentication response to the authentication challenge message from the second network node, wherein the authentication response is encrypted based on the particular security profile that was selected by the processor at the first network node.

18. The non-transitory computer-readable medium of claim 17 , the operations further comprising:

decrypting, by the first network node, the authentication response to the authentication challenge message that was received, by the first network node, from the second network node, based on the particular security profile, and in response, authenticating the second network node.

19. The non-transitory computer-readable medium of claim 18 , further comprising:

after authenticating the second network node, establishing, by the first network node, a secure communication link between the first network node and the second network node.

20. The non-transitory computer-readable medium of claim 19 , further comprising

in response to establishing the secure communication link, providing, by the first network node, an application layer communication to the second network node.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2014
From: MOTOROLA MOBILITY LLC
To: GOOGLE TECHNOLOGY HOLDINGS LLC
Reel/Frame 034244/0014 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2012
From: MOTOROLA MOBILITY, INC.
To: MOTOROLA MOBILITY LLC
Reel/Frame 028829/0856 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2011
From: MOTOROLA INC.
To: MOTOROLA MOBILITY INC.
Reel/Frame 026561/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2011
From: MAHIDHARA, SHRAVAN; RAGHURAM, VASANTHI
To: MOTOROLA, INC.
Reel/Frame 025683/0159 →