IP Library › Granted Patent US 12,238,080
Granted Patent B2
US 12,238,080 · App. 17/325,972 · Granted Feb 25, 2025

Accelerated reconnection in authenticated networks

Inventors: Aparna Raghunath (Bangalore, IN); Dhanya Jalaja Ramachandran (Bangalore, IN)
Assignee: Zebra Technologies Corporation
H04L63/068G06F21/45H04L9/0897
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,238,080
App. No.
17/325,972
Granted
Feb 25, 2025
Kind
B2
Abstract

A method in a client computing device includes: establishing an association with a communications network in a first connection time period; via an authentication session with an authentication server of a communications network in an authentication time period following the first connection time period, obtaining at least one key value for use in accessing the communications network; storing reauthentication data associated with the at least one key value; responsive to disconnecting from the communications network, discarding the at least one key value and retaining the reauthentication data; responsive to a reconnection command: deriving the at least one key value from the reauthentication data, establishing a further association with the communications network in a second connection time period by sending an association request to the communications network, the association request containing the at least one key value, and accessing network resources via the communications network following the second connection time period.

Claims (51)

1. A method in a client computing device, the method comprising:

establishing an association with a communications network in a first connection time period;

via an authentication session with an authentication server of the communications network in an authentication time period following the first connection time period, obtaining at least one key value for use in accessing the communications network;

storing reauthentication data associated with the at least one key value;

responsive to disconnecting from the communications network, discarding the at least one key value from a memory of the client computing device and retaining the reauthentication data having an intermediate key value from a root key, where the intermediate key value is associated to a particular access point;

responsive to a reconnection command:

deriving the discarded at least one key value from the intermediate key value of the root key,

establishing a further association with the communications network in a second connection time period by sending an association request to the communications network, the association request containing the at least one key value, and

accessing network resources via the communications network following the second connection time period.

2. The method of claim 1 , wherein storing the reauthentication data includes storing the reauthentication data in a persistent storage device.

3. The method of claim 1 , further comprising storing an identifier of the communications network in association with the reauthentication data.

4. The method of claim 3 , wherein the reconnection command includes a reconnection network identifier; the method further comprising:

prior to retrieving the at least one key value, determining that the reconnection network identifier matches the identifier stored in association with the reauthentication data.

5. The method of claim 1 , further comprising:

after a time period, discarding the reauthentication data.

6. The method of claim 1 , further comprising:

receiving, in response to the association request, a reauthentication command from an access point;

repeating the authentication process to obtain at least one further key value; and

storing further reauthentication data associated with the at least one further key value.

7. A computing device, comprising:

a memory;

a communications interface; and

a controller configured to:

establish an association with a communications network in a first connection time period;

via an authentication session with an authentication server of the communications network in an authentication time period following the first connection time period, obtain at least one key value for use in accessing the communications network;

store, in the memory, reauthentication data associated with the at least one key value;

responsive to detecting a disconnection from the communications network, discard the at least one key value from the memory and retaining the reauthentication data having an intermediate key value from a root key, where the intermediate key value is associated to a particular access point;

responsive to a reconnection command:

derive the discarded at least one key value from the intermediate key value of the root key,

establish a further association with the communications network in a second connection time period by sending an association request to the communications network, the association request containing the at least one key value, and

access network resources via the communications network following the second connection time period.

8. The computing device of claim 7 , further comprising a secure memory;

wherein the controller is configured, to store the reauthentication data, to store the reauthentication data in a persistent storage device.

9. The computing device of claim 7 , wherein the controller is further configured to store an identifier of the communications network in association with the reauthentication data.

10. The computing device of claim 9 , wherein the reconnection command includes a reconnection network identifier; the controller further configured to:

prior to retrieving the at least one key value, determine that the reconnection network identifier matches the identifier stored in association with the reauthentication data.

11. The computing device of claim 7 , wherein the controller is further configured, after a time period, to discard the reauthentication data.

12. The computing device of claim 7 , wherein the controller is further configured to:

receive, in response to the association request, a reauthentication command from an access point;

repeat the authentication process to obtain at least one further key value; and

store further reauthentication data associated with the at least one further key value.

13. A non-transitory computer readable medium storing instructions executable by a controller of a computing device having a memory and a communications interface, to:

establish an association with a communications network in a first connection time period;

via an authentication session with an authentication server of the communications network in an authentication time period following the first connection time period, obtain at least one key value for use in accessing the communications network;

store, in the memory, reauthentication data associated with the at least one key value;

responsive to detecting a disconnection from the communications network, discard the at least one key value from the memory and retain the reauthentication data having an intermediate key value from a root key, where the intermedia key value is associated to a particular access point;

responsive to a reconnection command:

derive the discarded at least one key value from the intermediate key value of the root key,

establish a further association with the communications network in a second connection time period by sending an association request to the communications network, the association request containing the at least one key value, and

access network resources via the communications network following the second connection time period.

14. The non-transitory computer readable medium of claim 13 , wherein execution of the instructions configures the controller, to store the reauthentication data, to store the reauthentication data in a persistent storage device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 11, 2022
From: RAGHUNATH, APARNA; RAMACHANDRAN, DHANYA JALAJA
To: ZEBRA TECHNOLOGIES CORPORATION
Reel/Frame 059896/0249 →
Continuity (1)
Related Publication 20220377061A1 · Nov 24, 2022
References Cited (28)
US 1112869A · Tirrell · 1914 [cited by examiner]
US 20030188195A1 · Abdo · 2003 [cited by examiner]
US 20060242415A1 · Gaylor · 2006 [cited by examiner]
US 20100228982A1 · Zhu · 2010 [cited by examiner]
US 20140273958A1 · Messana · 2014 [cited by examiner]
US 20190044723A1 · Prakash · 2019 [cited by examiner]
US 20200274721A1 · Melo · 2020 [cited by examiner]
US 20220377061A1 · Raghunath · 2022 [cited by examiner]
FR 3042626A1 · 2017 [cited by examiner]
JP 2004242187A · 2004 [cited by examiner]
JP 2005346401A · 2005 [cited by examiner]
JP 2011101118A · 2011 [cited by examiner]
JP 2014013960A · 2014 [cited by examiner]
WO WO2005036857A1 · 2005 [cited by examiner]
WO WO2020052531A1 · 2020 [cited by examiner]
WO WO2020215272A1 · 2020 [cited by examiner]
WO WO2021094103A1 · 2021 [cited by examiner]
Li et al., “A Neighbor Caching Mechanism for Handoff in IEEE 802.11 Wireless Networks,” 2007 International Conference on Multimedia and Ubiquitous Engineering (MUE'07), 2007, pp. 48-53, doi: 10.1109/MUE.2007.32. (Year: … [cited by examiner]
Namal et al., “Lightweight authentication and key management on 802.11 with Elliptic Curve Cryptography,” 2013 IEEE Wireless Communications and Networking Conference (WCNC), 2013, pp. 1830-1835, doi: 10.1109/WCNC.2013.6… [cited by examiner]
Indra et al., “An ECC-Time Stamp Based Mutual Authentication and Key Management Scheme for WSNs,” 2013 27th International Conference on Advanced Information Networking and Applications Workshops, 2013, pp. 883-889, doi:… [cited by examiner]
Kim et al., “Enhancing Security Using the Discarded Security Information in Mobile WiMAX Networks,” IEEE Globecom 2008—2008 IEEE Global Telecommunications Conference, New Orleans, LA, USA, 2008, pp. 1-5, doi: 10.1109/GL… [cited by examiner]
Komarova et al., “Fast Re-Authentication Protocol for Inter-Domain Roaming,” 2007 IEEE 18th International Symposium on Personal, Indoor and Mobile Radio Communications, Athens, Greece, 2007, pp. 1-5, doi: 10.1109/PIMRC.… [cited by examiner]
Hoeper et al., “Distribution of EAP-Based Keys for Handover and ReAuthentication (RFC5749)”, IPCOM000193862D, Mar. 1, 2010, pp. 1-12. (Year: 2010). [cited by examiner]
Xu et al., “The Performance Analysis of Fast EAP Re-authentication Protocol,” 2008 International Symposium on Computer Science and Computational Technology, Shanghai, China, 2008, pp. 99-103, doi: 10.1109/ISCSCT.2008.16… [cited by examiner]
Clancy et al., “Handover Key Management and Re-Authentication Problem Statement (RFC5169)”, IPCOM000168869D, Mar. 1, 2008. (Year: 2008). [cited by examiner]
Kim et al., “An efficient and scalable re-authentication protocol over wireless sensor network,” in IEEE Transactions on Consumer Electronics, vol. 57, No. 2, pp. 516-522, May 2011, doi: 10.1109/TCE.2011.5955187. (Year:… [cited by examiner]
Hoeper et al. “Distribution of EAP-Based Keys for Handover and ReAuthentication (RFC5749),” IP.com, IPCOM000193862D, Mar. 1, 2010. (Year: 2010). [cited by examiner]
Rajagopal, “Security Enhancement Using Cache Based Reauthentication in WiMAX Based E-Learning System,” PubMed Central ID: 4553329, 10.1155/2015/878327, Jan. 1, 2015. (Year: 2015). [cited by examiner]
Cited By (1)
US 12,395,339