IP Library › Granted Patent US 11,743,731
Granted Patent B2
US 11,743,731 · App. 17/271,621 · Granted Aug 29, 2023

Method and device to establish a wireless secure link while maintaining privacy against tracking

Inventor: Johannes Arnoldus Cornelis Bernsen (Eindhoven, NL)
Assignee: Koninklijke Philips N.V.
H04W12/50H04L9/088H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,743,731
App. No.
17/271,621
Granted
Aug 29, 2023
Kind
B2
Abstract

This application relates to devices and a method to establish a secure wireless link for communication between a first and a second device over a wireless physical channel, wherein a paring protocol requires sending over the wireless channel identifying information by the first device, identifying information being data suitable for identifying the device sending the identifying information or a user thereof wherein the first device encrypts and transmits the identifying information by using a public key information of the second device and random information, the second device receives the encrypted identifying information and using private key information associated with the public key information it extracts the identifying information. The devices use a secret uniquely related to the identifying information to derive a session key and then use the session key to establish the secure wireless link. For example, the wireless channel is Wi-Fi, the identifying information is an identifier for a password or passphrase and the secret is the password or passphrase and the authentication method is simultaneous authentication of equals (SAE). Alternatively the pairing protocol is DPP and the identifying information is a part of the DPP Connector. The public key information can be transmitted in a Beacon, DMG Beacon, Probe Response, Announce, or Information Response frame or be configured in the first device by a DPP Configurator using the DPP protocol adapted for transferring the public key information as part of the DPP Configuration response message.

Claims (77)

1. A method for establishing a secure wireless link for communication between a first device and a second device over a wireless physical channel,

wherein a paring protocol requires the first device send identifying information over the wireless physical channel, the identifying information identifying the device sending the identifying information or a user thereof,

wherein the pairing protocol is based upon a Device Provisioning Protocol and wherein the identifying information is a part of the Connector as defined in the Device Provisioning Protocol;

the method comprising:

generating random information;

encrypting, by the first device, a combination of the identifying information and the random information by using a public key information of the second device to provide encrypted identifying information;

transmitting, by the first device, the encrypted identifying information over the wireless physical channel;

receiving, by the second device, the encrypted identifying information and using private key information associated with the public key information to extract the identifying information;

using a secret uniquely related to the identifying information to derive a session key,

wherein a simultaneous authentication of equals' algorithm is used for deriving the session key and the secret is a password used for the simultaneous authentication of equals' algorithm,

using the session key to establish the secure wireless link, and

using the encrypted identifying information to restore the Connector and to verify the integrity of the Connector.

2. A device being a first device adapted to establish a secure wireless link for communication between the first device and a second device over a wireless physical channel,

wherein a Device Provisioning Protocol requires the first device send identifying information over the wireless physical channel,

wherein the identifying information is a part of a Connector as defined in the Device Provisioning Protocol,

wherein the identifying information uniquely determines the device sending the identifying information or a user thereof;

the device comprising:

a processor, wherein the processor is arranged to:

generate random information;

encrypt a combination of the identifying information and the random information by using a public key information of the second device to provide a modified Connector;

derive a session key using a secret that is uniquely related to the identifying information,

wherein a simultaneous authentication of equals' algorithm is used for deriving the session key and the secret is a password used for the simultaneous authentication of equals' algorithm; and

use the session key to establish the secure wireless link with the second device; and

a transmitter that is arranged to transmit the modified Connector over the wireless channel; and

wherein the modified Connector enables the second device to restore the original Connector and thereby verify the integrity of the Connector.

3. The device according to claim 2 , wherein the identifying information is an identifier for a password or passphrase and the secret is the password or passphrase.

4. The device according to claim 2 , wherein the device is adapted to receive and extract the public key information from a Beacon, DMG Beacon, Probe Response, Announce, or Information Response frame.

5. The device according to claim 2 , wherein the device is adapted to receive and extract the public key information from a DPP configurator.

6. The device according to claim 2 , wherein the 802.11 4-way handshake protocol is used to derive a key on which the security of the secure channel is based and the secret is the passphrase or the PSK to use in the 802.11 4-way handshake protocol.

7. A device being a second device adapted to establish a secure wireless link for communication between a first device and the second device over a wireless physical channel,

wherein a paring protocol requires the first device send identifying information over the wireless physical channel,

wherein the identifying information identifies the device sending the identifying information or a user thereof,

wherein the pairing protocol is based upon a Device Provisioning Protocol and

wherein the identifying information is a part of a Connector as defined in the Device Provisioning Protocol;

wherein the device has a public key information and a secret key information associated therewith,

the device comprising:

a receiver adapted to receive, over the wireless channel, encrypted identifying information,

wherein the encrypted identifying information comprises identifying information and random information encrypted by the public key information;

a processor adapted to:

use the private key information to decrypt the encrypted identifying information;

extract the identifying information;

use a secret uniquely related to the identifying information to derive a session key,

wherein a simultaneous authentication of equals' algorithm is used for deriving the session key and the secret is a password used for the simultaneous authentication of equals' algorithm; and

use the session key to establish the secure channel,

wherein the device is adapted to use the encrypted identifying information to restore the Connector and to verify the integrity of the Connector.

8. The device according to claim 7 , wherein the identifying information is an identifier for a password or passphrase and the secret is the password or passphrase.

9. The device according to claim 8 , wherein the device is adapted to receive and extract the public key information from a Beacon, DMG Beacon, Probe Response, Announce, or Information Response frame.

10. A device according to claim 8 , wherein the device is adapted to receive and extract the public key information from a DPP configurator.

11. A device according to claim 8 , wherein a 802.11 4-way handshake protocol is used to derive a key on which the security of the secure channel is based and the identifying information indicates the passphrase or PSK to use in the 802.11 4-way handshake protocol.

12. A method for a first device to establish a secure wireless link for communication between the first device and a second device over a wireless physical channel,

wherein a paring protocol requires the first device send identifying information over the wireless physical channel,

wherein the identifying information identifies the device sending the identifying information or a user thereof,

wherein the pairing protocol is based upon a Device Provisioning Protocol, and wherein the identifying information is a part of the Connector as defined in the Device Provisioning Protocol;

the method comprising:

generating random information;

encrypting a combination of the identifying information and the random information by using a public key information of the second device;

transmitting the encrypted identifying information over the wireless physical channel;

receiving, by the second device, the encrypted identifying information and using private key information associated with the public key information to extract the identifying information;

using a secret uniquely related to identifying information to derive a session key,

wherein a simultaneous authentication of equals' algorithm is used for deriving the session key and the secret is a password used for the simultaneous authentication of equals' algorithm;

using the session key to establish the secure wireless link, and

using the encrypted identifying information to restore the Connector and to verify the integrity of the Connector.

13. A method for a second device to establish a secure wireless link for communication between the second device and a first device over a wireless physical channel,

wherein a paring protocol requires the first device send identifying information over the wireless physical channel,

wherein the identifying information identifies the device sending the identifying information or a user thereof,

wherein the pairing protocol is based upon a Device Provisioning Protocol and wherein the identifying information is a part of the Connector as defined in the Device Provisioning Protocol;

wherein the first device generates random information and encrypts a combination of the identifying information and the random information by using a public key information of the second device to produce encrypted identifying information and transmits the encrypted identifying information over the wireless channel;

the method comprising:

receiving the encrypted identifying information and using private key information associated with the public key information to extract the identifying information;

using a secret uniquely related to identifying information to derive a session key,

wherein a simultaneous authentication of equals' algorithm is used for deriving the session key and the secret is a password used for the simultaneous authentication of equals' algorithm,

using the session key to establish the secure wireless link,

using the encrypted identifying information to restore the Connector and to verify the integrity of the Connector.

14. The method according to claim 12 , wherein the identifying information is an identifier for a password or passphrase and the secret is the password or passphrase.

15. The method according to claim 14 , wherein the first device is adapted to receive and extract the public key information from a Beacon, DMG Beacon, Probe Response, Announce, or Information Response frame.

16. The method according to claim 14 , wherein the first device is adapted to receive and extract the public key information from a DPP configurator.

17. The method according to claim 14 , wherein the 802.11 4-way handshake protocol is used to derive a key on which the security of the secure channel is based and the secret is the passphrase or the PSK to use in the 802.11 4-way handshake protocol.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2021
From: BERNSEN, JOHANNES ARNOLDUS CORNELIS
To: KONINKLIJKE PHILIPS N.V.
Reel/Frame 055418/0970 →
Priority Claims (1)
EP 18190900 · Aug 27, 2018 · regional
Continuity (1)
Related Publication 20210329462A1 · Oct 21, 2021
Cited By (1)
US 12,413,966