IP Library › Granted Patent US 12,273,717
Granted Patent B2
US 12,273,717 · App. 17/898,357 · Granted Apr 8, 2025

Secure sniffing of wireless connections with forward secrecy

Inventors: Yedidya Yechiel Vachnish (Revava, IL); Barak Cherches (Ramat Ha'Kovesh, IL); Avi Sammy Berkovich (Herzeliya, IL)
Assignee: TEXAS INSTRUMENTS INCORPORATED
H04W12/121H04L9/0819H04L9/30H04L9/3247H04L9/3268H04W12/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,717
App. No.
17/898,357
Granted
Apr 8, 2025
Kind
B2
Abstract

In at least one example, a method includes establishing, by a sniffer provisioning server (SPS) of a first wireless device, a trusted relationship between the first wireless device and a sniffer tool using a public key of the sniffer tool. An out-of-band (OOB) key exchange provisions the public key of the sniffer tool to the wireless device. The method further includes obtaining, by the SPS, key material uniquely related to a communication session established between the first wireless device and a second wireless device using a shared password. The key material excludes the shared password and a session key uniquely related to the communication session. The method further includes publishing, by the SPS, the key material over a channel to the sniffer tool based on the trusted relationship. The channel is secured using the public key of the sniffer tool.

Claims (31)

1. A method comprising:

establishing a secure communication channel between a server of a first wireless device and a sniffer device using a public key of the sniffer device;

obtaining, by the server, key material uniquely related to a communication session established between the first wireless device and a second wireless device, wherein the communication session is established using a shared password, wherein the key material excludes the shared password and a session key uniquely related to the communication session; and

transmitting, by the server, the key material over the secure communication channel to the sniffer device, wherein the secure communication channel is secured using the public key of the sniffer device.

2. The method of claim 1 , further comprising authenticating, by the server, the public key of the sniffer device using a root-of-trust or a certificate catalog that is signed by the root-of-trust.

3. The method of claim 1 , further comprising:

receiving, by the first wireless device, a command to transition the server from a disabled state to an enabled state prior to the server transmitting the key material.

4. The method of claim 2 ,

further comprising verifying, by the server, a digital signature of a certificate that includes the public key of the sniffer device.

5. The method of claim 1 , wherein transmitting the key material comprises:

encrypting, by the server, the key material using the public key of the sniffer device to generate encrypted key material; and

transmitting, by the server, the encrypted key material to a sniffer provisioning client of the sniffer device.

6. The method of claim 3 , wherein the server automatically returns from the enable state to the disable state by default.

7. The method of claim 1 , further comprising receiving, by the server, the shared password from an entity that is external to the first wireless device.

8. The method of claim 1 , further comprising updating, by the server, a trusted peer list of the first wireless device to include the sniffer device based on the establishing of the secure communication channel.

9. The method of claim 1 , wherein the shared password is specific to and access point of a wireless network, and the second wireless device is the access point.

10. The method of claim 5 , further comprising decrypting, by the sniffer provisioning client, the key material using a private key of the sniffer device.

11. The method of claim 1 , wherein an out-of-band (OOB) key exchange provisions the public key of the sniffer device to the first wireless device.

12. The method of claim 1 , further comprising:

receiving, by the server, a first message from the sniffer device, wherein the first message comprises the public key of the sniffer device; and

encrypting, by the server, the key material using the public key of the sniffer device to generate encrypted key material, wherein transmitting the key material over the secure communication channel to the sniffer device comprises transmitting, by the server, the encrypted key material.

13. The method of claim 12 , wherein the communications session is established between the first and second wireless devices in a wireless local area network (WLAN), and wherein the first message is received by the server via an out-of-band (OOB) channel that excludes the WLAN.

14. The method of claim 1 , further comprising receiving, by the server, the key material via an in-band channel that is secured using the public key of the sniffer device.

15. The method of claim 1 , wherein the first wireless device or the second wireless device is an access point (AP) of a wireless local area network (WLAN).

16. The method of claim 1 , further comprising:

intercepting, by the sniffer device, a packet transmitted between the first and second wireless devices; and

decrypting, by the sniffer device, a payload of the packet using the session key.

17. The method of claim 16 , wherein the payload is encrypted according to a simultaneous Authentication of Equals (SAE) protocol.

18. The method of claim 16 , wherein a header of the packet is unencrypted.

19. The method of claim 1 , further comprising generating, by the sniffer device, the session key using the shared password and the key material.

20. The method of claim 1 , wherein the key material comprises first and second random numbers associated with the first wireless device, and third and fourth random numbers associated with the second wireless device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 26, 2024
From: VACHNISH, YEDIDYA YECHIEL; CHERCHES, BARAK; BERKOVICH, AVI SAMMY
To: TEXAS INSTRUMENTS INCORPORATED
Reel/Frame 069411/0086 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2022
From: VACHNISH, YEDIDYA YECHIEL; CHERCHES, BARAK; BERKOVICH, AVI SAMMY
To: TEXAS INSTRUMENTS INCORPORATED
Reel/Frame 060932/0858 →
Continuity (1)
Related Publication 20240073693A1 · Feb 29, 2024
References Cited (8)
US 20180062854A1 · Kancharla · 2018 [cited by examiner]
US 20180278419A1 · Higgins · 2018 [cited by examiner]
US 20190068564A1 · Putatunda · 2019 [cited by examiner]
US 20240381053A1 · Liu · 2024 [cited by examiner]
Harkins, Dan., “Dragonfly Key Exchange,” Aruba Networks, Nov. 2015, 18 p. [Online] https://www.rfc-editor.org/rfc/rfc7664.html. [cited by applicant]
IEEE Computer Society, “IEEE Standard for Information Technology,” Jul. 23, 2004, 190 p. [cited by applicant]
IEEE Computer Society, “Port-Based Network Access Control,” IEEE Standard for Local and Metropolitan Area Networks, Jan. 30, 2020, 289 p. [cited by applicant]
Wi-Fi Alliance, “WPA3™ Specification Version 3.0,” ©2020 Wi-Fi Alliance, 30 p. [cited by applicant]