IP Library Granted Patent US 9,369,275
Granted Patent B2
US 9,369,275 · App. 14/696,304 · Granted Jun 14, 2016

Key agreement in wireless networks with active adversaries

Inventors: Hongyi Yao (Pasadena, CA); Tracey C. Ho (Pasadena, CA); Cristina Nita-Rotaru (Chicago, IL)
Assignees: CALIFORNIA INSTITUTE OF TECHNOLOGY; PURDUE RESEARCH FOUNDATION
H04L9/0827H04L9/0802H04W12/04H04L2209/34H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,369,275
App. No.
14/696,304
Granted
Jun 14, 2016
Kind
B2
Abstract

A network and related methods for transmitting processes in a network secretly and securely is described. The network use keys, through path-key establishment and a key pool bootstrapping, to ensure that packets are transmitted and received properly and secretly in the presence of one or more adversarial nodes.

Claims (29)

1. A network of computers with error correction code configured to transmit keys secretly and securely comprising:

a first computer-based workstation operating as a source node and configured to encode a key into a plurality of distinct encoded source files, encoding being operatively implemented in one of: a) hardware, b) software, and c) a combination of a) and b);

a plurality of computer-based workstations operating as a plurality of intermediate nodes and configured to each receive a distinct encoded source file of the plurality of distinct encoded source files and transmit, to a receiver node, the distinct encoded source file when requested by the receiver; and

a second computer-based workstation operating as the receiver node and configured to decode the plurality of distinct encoded source files and retrieve the key, decoding being operatively implemented in one of: a) hardware, b) and/or software, and c) a combination of a) and b);

wherein the encoding, transmitting and decoding of the key comprise the following steps:

generating the key to be transmitted from the source node to the receiver node,

generating one or more random packets independently and uniformly within the source node,

generating a distinct encoded file for each intermediate node in the network, the encoded file comprising a linear combination of the key, the one or more random packets that were independently and uniformly generated and corresponding error detection information,

forwarding each of the distinct encoded files generated by the source node to each corresponding intermediate node of the plurality of intermediate nodes within the network via a first plurality of intermediate transmission links,

forwarding each of the distinct encoded files, upon request by the receiver node, from the corresponding intermediate node via a second plurality of intermediate transmission links, and

decoding the key from the plurality of encoded files, the error detection information used to determine if an error was present in either the intermediate transmission link and/or the intermediate node for a particular encoded file.

2. The network of computers of claim 1 , wherein the encoded source files comprise linearly independent combinations of the following:

one or more randomly generated packets, and

a source message, the source message comprising a set or subset of keys and corresponding error detection information.

3. The network of computers of claim 2 , wherein the error detection information comprises hash information from each of the other encoded files, the hash information being defined in terms of random parameters generated by the source node.

4. The network of computers of claim 1 , wherein the network is a distributed wireless network.

5. A network of computers with error correction code configured to transmit a key pool secretly and securely comprising:

(i) a plurality of computer-based workstations operating as a plurality of intermediate nodes and configured to each:

receive one or more, but not all, individual keys of the key pool, the key pool comprising a plurality of individual keys,

encode the one or more individual keys, encoding being operatively implemented in one of: a) hardware, b) software, and c) a combination of hardware and software, and

transmit the encoded one or more individual keys to a receiver node, when requested; and

(ii) a computer-based workstation operating as the receiver node and configured to decode encoded one or more individual keys received from a subset of the intermediate nodes, using a decoding algorithm to retrieve a specified subset of the key pool, decoding being operatively implemented in one of: a) hardware, b) software, and c) a combination of hardware and software;

wherein the decoding of the encoded keys to retrieve, the key pool in the receiver node comprises the following steps:

identifying two or more distinct groupings of intermediate nodes of the plurality of nodes, wherein each intermediate node within a particular distinct grouping of intermediate nodes shares a same set of individual keys of the key pool,

requesting each of the intermediate nodes of the two or more distinct groupings of intermediate nodes to forward their respective encoded files,

using error detection information to identify a number of compromised nodes within the two or more distinct grouping of intermediate nodes,

decoding each of the encoded files forwarded by each of the intermediate nodes,

determining a number of consistent decoded keys forwarded by the intermediate nodes within a particular grouping of the two or more distinct groupings of intermediate nodes, the number of consistent decoded keys is based on the number of compromised nodes, and

extracting the key pool by retrieving an error-free subset of the key pool from each of two or more distinct grouping of intermediate nodes.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2015
From: NITA-ROTARU, CRISTINA
To: PURDUE RESEARCH FOUNDATION
Reel/Frame 035550/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2015
From: YAO, HONGYI; HO, TRACEY C.
To: CALIFORNIA INSTITUTE OF TECHNOLOGY
Reel/Frame 035550/0956 →
CONFIRMATORY LICENSE Recorded Apr 29, 2015
From: CALIFORNIA INSTITUTE OF TECHNOLOGY
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 035522/0325 →
Continuity (3)
Continuation 13853881 · Mar 29, 2013
Provisional Application 61618203 · Mar 30, 2012
Related Publication 20150288516A1 · Oct 8, 2015