IP Library Granted Patent US 9,998,285
Granted Patent B2
US 9,998,285 · App. 14/979,336 · Granted Jun 12, 2018

Security hardening for a Wi-Fi router

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,998,285
App. No.
14/979,336
Granted
Jun 12, 2018
Kind
B2
Abstract

A method and system of securing the firmware of a router. Upon determining that a received digital message does not have integrity or the digital signature of the received digital message is not correct, the digital message is ignored or discarded. Otherwise the digital message is decrypted and a new firmware extracted therefrom. The existing firmware is then flashed with the new extracted firmware.

Claims (47)

1. A router comprising:

a processor;

at least one network interface coupled to the processor configured to enable communications via one or more communication networks;

a memory for content and programming;

a program stored in the memory, wherein execution of the program by the processor configures the router to perform acts comprising, during a provisioning stage:

receiving a provisioning digital message from a firmware server, the provisioning digital message comprising a digital certificate and an initial encrypted firmware that, when unencrypted and installed on the router, prevents unauthorized access to an existing firmware of the router;

the program being further executed by the processor to configure the router to perform acts comprising, during a maintenance stage:

receiving a digital message;

determining whether the digital message has integrity;

determining whether a digital signature of the digital message is correct;

upon determining that at least one of: (i) the digital message does not have integrity, or (ii) the digital signature of the digital message is not correct, ignoring or discarding the digital message; and

upon determining that (i) the digital message does have integrity, and (ii) the digital signature of the digital message is correct:

decrypting the digital message;

extracting a new firmware from the digital message; and

flashing the existing firmware of the router in the memory with the new firmware.

2. The router of claim 1 , wherein only firmware that prevents access via at least one of Telnet and SSH is used to flash the existing firmware in the memory with the new firmware.

3. The router of claim 1 , wherein the initial encrypted firmware has a symmetric key encryption.

4. The router of claim 1 , wherein execution of the program further configures the router to perform acts comprising, during a provisioning stage: receiving a decryption key operative to decrypt the provisioning digital message received from the firmware server.

5. The router of claim 4 , wherein upon determining that (i) the digital message does have integrity, and (ii) the digital signature of the digital message is correct, the decryption key is used to decrypt the digital message.

6. The router of claim 1 , wherein a new digital message is received by the router from the firmware server at predetermined intervals.

7. The router of claim 1 , further comprising a cellular broadband driver, and wherein a new digital message is received by the router from the firmware server via a cellular network.

8. The router of claim 1 , further comprising a security application stored in the memory, wherein the security application performs an act of at least one of (i) determining that the digital message has integrity, or (ii) determining that the digital signature of the digital message is correct.

9. The router of claim 1 , wherein execution of the program further configures the router to perform acts comprising:

determining that the digital message is in a format of a firmware update, and

wherein determining that the digital message has integrity, is based on the digital message being in the format of the firmware update.

10. The router of claim 1 , wherein determining whether the digital message has integrity comprises performing at least one of: (i) a cyclic redundancy check (CRC) or (ii) a message digest check.

11. The router of claim 1 , further comprising:

sending the digital message to a remote authentication server; and

receiving a confirmation from the remote authentication server that at least one of (i) the digital message does have integrity, or (ii) that the digital signature of the digital message is correct,

wherein, determining that at least one of (i) the digital message does have integrity, or (ii) that the digital signature of the digital message is correct, is based at least in part on receipt of the confirmation.

12. A non-transitory computer-readable medium having stored thereon a plurality of sequences of instructions which, when executed by one or more processors, cause the one or more processors to perform a method of securing a firmware of a router, the method comprising:

receiving a digital message;

sending the digital message to a remote authentication server;

in response to receiving, from the remote authentication server, a first confirmation that at least one of: (i) the digital message does not have integrity, or (ii) a digital signature of the digital message is not correct, ignoring or discarding the digital message;

in response to receiving, from the remote authentication server, a second confirmation that (i) the digital message does have integrity, and (ii) the digital signature of the digital message is correct:

decrypting the digital message;

extracting a new firmware from the digital message; and

flashing an existing firmware with the new firmware.

13. The method of claim 12 , further comprising:

receiving a provisioning digital message from a firmware server, the provisioning digital message including a digital certificate and an initial encrypted firmware that, when unencrypted and installed on the router, is operative to prevent unauthorized access to the firmware of the router.

14. The method of claim 13 , further comprising, in a provisioning stage receiving a decryption key operative to decrypt the provisioning digital message received from the firmware server.

15. The method of claim 14 , wherein upon receiving, from the remote authentication server, the second confirmation that (i) the digital message does have integrity, and (ii) the digital signature of the digital message is correct, decrypting the digital message with the decryption key.

16. The method of claim 13 , wherein a new digital message is received by the router from the firmware server via a cellular network.

17. The method of claim 12 , wherein, receiving the second confirmation that the digital message does have integrity, is based at least in part on the digital message being in a format of a firmware update.

18. The method of claim 12 , wherein, receiving the second confirmation that the digital message does have integrity is based at least in part on one of a (i) a cyclic redundancy check or a message digest check.

19. The method of claim 12 , wherein only firmware that prevents access via at least one of Telnet and SSH is used to flash the existing firmware with the new firmware.

20. The method of claim 13 , wherein the initial encrypted firmware has a symmetric key encryption.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
RELEASE OF SECURITY INTEREST Recorded Apr 1, 2020
From: DEUTSCHE TELEKOM AG
To: T-MOBILE USA, INC.; IBSV LLC
Reel/Frame 052969/0381 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 30, 2016
From: T-MOBILE USA, INC.
To: DEUTSCHE TELEKOM AG
Reel/Frame 041225/0910 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 26, 2015
From: HODROJ, SAMIR
To: T-MOBILE USA, INC.
Reel/Frame 037361/0098 →