IP Library Granted Patent US 11,576,023
Granted Patent B2
US 11,576,023 · App. 17/446,177 · Granted Feb 7, 2023

Method and apparatus for providing a secure communication in a self-organizing network

Inventors: Shravan Mahidhara (Palatine, IL); Vasanthi Raghuram (Palatine, IL)
Assignee: Google Technology Holdings LLC
H04W4/80H04L63/0428H04L63/08H04W28/18H04W48/16H04W76/00H04W84/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,576,023
App. No.
17/446,177
Granted
Feb 7, 2023
Kind
B2
Abstract

A communication system provides secure communication between two nodes in a self-organizing network without the need for a centralized security or control device. A first node of the two nodes is provisioned with one or more security profiles, auto-discovers a second node of the two nodes, authenticates the second node based on a security profile of the one or more security profiles, selects a security profile of the one or more security profiles to encrypt a communication session between the two nodes, and encrypts the communication session between the two nodes based on the selected security profile. The second node also is provisioned with the same one or more security profiles, authenticates the first node based on a same security profile as is used to authenticate the second node, and encrypts the communication session based on the same security profile as is used for encryption by the first node.

Claims (52)

1. A computer-implemented method that when executed by data processing hardware of a first network node of a distributed, self-organizing network, causes the data processing hardware to perform operations comprising:

obtaining a value of a security profile selection parameter;

receiving, from a second network node, a request to establish a communication session;

in response to receiving the request to establish the communication session, selecting, from a first table of security profiles, a security profile uniquely associated with the value of the security profile selection parameter, the first table stored at a memory device at the first network node prior to the second network node discovering the first network node;

generating an authentication challenge message comprising:

an encrypted portion encrypted based on the selected security profile associated with the value of the security profile selection parameter in the first table; and

an unencrypted portion identifying the selected security profile associated with the value of the security profile selection parameter in the first table; and

transmitting the authentication challenge message to the second network node, wherein the authentication challenge message when received by the second network node causes the second network node to:

select, from a second table of security profiles, based on the unencrypted portion of the authentication challenge, the same security profile selected by the data processing hardware of the first network node, the second table stored at a memory device of the second network node prior to the second network node discovering the first network node;

decrypt the encrypted portion of the authentication challenge message using the selected security profile; and

in response to decryption of the encrypted portion, authenticate the first network node.

2. The method of claim 1 , wherein the operations further comprise receiving, from the second network node, a communication session initiation message.

3. The method of claim 2 , wherein the communication session initiation message comprises at least one of:

a type of communication session being initiated between the second network node and the first network node;

a port number assigned to the communication session; or

a medium access control (MAC) layer address assigned to the communication session.

4. The method of claim 1 , wherein the operations further comprise receiving, from the second network node, an authentication response to the authentication challenge message, the authentication response encrypted based on the selected security profile.

5. The method of claim 4 , wherein the operations further comprise:

decrypting the authentication response based on the selected security profile; and

in response to decrypting the authentication response, authenticating the second network node.

6. The method of claim 5 , wherein the operations further comprise, after authenticating the second network node, establishing a secure communication link between the first network node and the second network node.

7. The method of claim 6 , wherein the operations further comprise, in response to establishing the secure communication link, providing an application layer communication to the second network node.

8. The method of claim 1 , wherein obtaining the value of the security profile selection parameter is based on a physical communication link type.

9. The method of claim 1 , wherein obtaining the value of the security profile selection parameter is based on a characteristic of a channel to be used in a communication session between the first network node and second network node.

10. The method of claim 9 , wherein the characteristic of the channel is associated with frequencies, time slots, or channel coding for the communication session between the first network node and second network node.

11. A system comprising:

data processing hardware of a first network node of a distributed, self-organizing network; and

memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:

obtaining a value of a security profile selection parameter;

receiving, from a second network node, a request to establish a communication session;

in response to receiving the request to establish the communication session, selecting, from a first table of security profiles, a security profile uniquely associated with the value of the security profile selection parameter, the first table stored at a memory device at the first network node prior to the second network node discovering the first network node;

generating an authentication challenge message comprising:

an encrypted portion encrypted based on the selected security profile associated with the value of the security profile selection parameter in the first table; and

an unencrypted portion identifying the selected security profile associated with the value of the security profile selection parameter in the first table; and

transmitting the authentication challenge message to the second network node, wherein the authentication challenge message when received by the second network node causes the second network node to:

select, from a second table of security profiles, based on the unencrypted portion of the authentication challenge, the same security profile selected by the data processing hardware of the first network node, the second table stored at a memory device of the second network node prior to the second network node discovering the first network node;

decrypt the encrypted portion of the authentication challenge message using the selected security profile; and

in response to decryption of the encrypted portion, authenticate the first network node.

12. The system of claim 11 , wherein the operations further comprise receiving, from the second network node, a communication session initiation message.

13. The system of claim 12 , wherein the communication session initiation message comprises at least one of:

a type of communication session being initiated between the second network node and the first network node;

a port number assigned to the communication session; or

a medium access control (MAC) layer address assigned to the communication session.

14. The system of claim 11 , wherein the operations further comprise receiving, from the second network node, an authentication response to the authentication challenge message, the authentication response encrypted based on the selected security profile.

15. The system of claim 14 , wherein the operations further comprise:

decrypting the authentication response based on the selected security profile; and

in response to decrypting the authentication response, authenticating the second network node.

16. The system of claim 15 , wherein the operations further comprise, after authenticating the second network node, establishing a secure communication link between the first network node and the second network node.

17. The system of claim 16 , wherein the operations further comprise, in response to establishing the secure communication link, providing an application layer communication to the second network node.

18. The system of claim 11 , wherein obtaining the value of the security profile selection parameter is based on a physical communication link type.

19. The system of claim 11 , wherein obtaining the value of the security profile selection parameter is based on a characteristic of a channel to be used in a communication session between the first network node and second network node.

20. The system of claim 19 , wherein the characteristic of the channel is associated with frequencies, time slots, or channel coding for the communication session between the first network node and second network node.

Continuity (4)
Continuation 15783244 · Oct 13, 2017
Continuation 13012057 · Jan 24, 2011
Provisional Application 61429001 · Dec 31, 2010
Related Publication 20210392484A1 · Dec 16, 2021