IP Library Granted Patent US 12,301,563
Granted Patent B2
US 12,301,563 · App. 18/139,508 · Granted May 13, 2025

System and method for pre-shared key (PSK) based wireless access point authentication

Inventor: Srinivas Kumar (Cupertino, CA)
Assignee: SYMMERA INC.
H04L63/0853H04L9/08H04L9/0819H04L9/083H04L9/085H04L9/088H04L9/0891H04L9/321H04L9/3242H04L9/3247H04L9/3268H04W12/0431H04W12/069H04W12/35H04W12/73
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,563
App. No.
18/139,508
Granted
May 13, 2025
Kind
B2
Abstract

The method provides an automated and scalable system for the generation, distribution, management of symmetric pre-shared keys (PSKs) to applications executing on headless and mobile devices. It helps achieve device protection, application security, and data protection with data authenticity and confidentiality in intra-device, inter-device, device-to-edge, and device-to-cloud communications. It helps Transport Layer Security (TLS) enabled applications dynamically acquire and renew PSKs and use identity hints for PSK based authentication ceremony during a TLS handshake. It helps manage and distribute API shared secrets and API access tokens required for authenticated API requests and API security. It helps applications (producers, brokers, and consumers of content) with PSKs for supply chain tamper resistance. It helps real-time low-latency applications with selective encryption of partial messages.

Claims (23)

1. A method of distributing a symmetric internal wireless access point (WAP) pre-shared key (IWAP-PSK) for secure wireless authentication by a device with a WAP in a production network including a supplicant program executing on the device, the WAP configured for multi-SSID (service set identifier) mode of operation, a key distribution service (KDS), a KDS proxy, a KDS interface, a symmetric KDS member PSK (M-PSK), a M-PSK identity hint, a tenant identifier, a device group identifier associated with the tenant identifier, a member domain associated with the device group identifier, an application identifier associated with the device group identifier, the IWAP-PSK identity hint, an internal WAP SSID (IWAP-SSID), a guest WAP pre-shared key (GWAP-PSK), a guest WAP SSID (GWAP-SSID), a key record, a dynamic host configuration protocol (DHCP) server, and a domain name system (DNS) server, the method comprising:

authenticating, by the supplicant program with the WAP, using the GWAP-SSID and GWAP-PSK, to establish initial wireless access for the device over the production network;

authenticating, with the KDS, by the supplicant program executing on the device, using the tenant identifier, the symmetric KDS member PSK (M-PSK) and the M-PSK identity hint, wherein the device is registered by a DNS hostname on the DNS server configured with the KDS or KDS proxy, and configured as a first member a device group on the KDS;

retrieving, by the supplicant program, the IWAP-PSK from the KDS, using at least the device group identifier and the IWAP-PSK identity hint, for use as a shared symmetric key for authentication with the wireless access point; and

authenticating, by the supplicant program with the WAP, using the IWAP-SSID and the retrieved IWAP-PSK to establish secure wireless access for the device over the production network to perform a switch-over from a guest SSID to an internal SSID wireless network.

2. The method of claim 1 , wherein the device member authentication handshake is performed by the KDS interface on the device using the tenant identifier, the device member PSK (M-PSK) and the M-PSK identity hint as a first factor of device authentication, and further wherein the session key is generated using a key exchange handshake between the KDS interface and the KDS or the KDS proxy, and further wherein a device member validation is performed as a second factor of device authentication:

performing, by the KDS or the KDS proxy, a DNS reverse lookup of a device member IP address to query for the DNS hostname;

retrieving, by the KDS or the KDS proxy, the DNS hostname from a resource record in a DNS response; and

comparing and matching, by the KDS or the KDS proxy, the retrieved DNS hostname with the device member identifier in the KDS requests.

3. The method of claim 2 , wherein a device authentication and a plurality of key exchange handshakes are performed over a connection-less User Datagram Protocol (UDP) or connection-oriented Transmission Control Protocol (TCP) transport protocol, without requiring a security transport protocol.

4. The method of claim 1 , wherein the KDS interface provides a plurality of application programming interfaces (APIs), wherein applications send a plurality of requests for key operations directly to the KDS and receive a plurality of responses for key operations directly from the KDS, or wherein the applications send a plurality of requests for key operations indirectly through the KDS proxy and receive a plurality of responses for key operations indirectly through the KDS proxy.

5. The method of claim 1 , wherein the device registered by a unique DNS hostname in the domain on a local DNS server with an IP address (A) record and a Pointer Record (PTR) record used in a DNS hostname reverse lookup.

6. The method of claim 1 , wherein on the KDS, the device is configured as a member of a tenancy associated with the tenant identifier and the device group associated with the tenant identifier, and further wherein the device group is configured with a key record that includes a key instance (IWAP-PSK) for secure wireless authentication.

7. The method of claim 1 , wherein a key record configured for the device group on the KDS includes a key expiration timestamp and a key status to manage automatic key renewal, key rotation, and key revocation operations on the KDS.

8. The method of claim 1 , wherein an authenticated member device's request for a key operation, based on the device group identifier and the IWAP-PSK identity hint, is processed by the KDS and permitted based on a match of a member domain with a domain derived from a plurality of resource records retrieved by a DNS reverse lookup for a member device DNS hostname.

9. The method of claim 1 , wherein the GWAP-SSID, the GWAP-PSK, the IWAP-SSID, the M-PSK, and the M-PSK identity hint are factory configured attributes on an executable application image or a system firmware on a real time operating system (RTOS) platform or specified through a configuration file on a general purpose operating system (GPOS) platform.

10. The method of claim 1 , wherein the primary and secondary KDS/KDS proxy URLs, the tenant identifier, and the device group identifier and identity hints associated with the production WAP for secure access are discovered using network characteristics based on custom attributes configured on a DHCP server, or a DNS server, associated with the member device LAN.

11. The method of claim 1 , wherein an authenticated member device's request for a key operation, based on the device group identifier, the IWAP-PSK identity hint, and the application identifier, is processed by the KDS and permitted based on a match with an application identifier associated with the device group identifier to allow or deny the key operation.

12. The method of claim 1 , wherein device specific information configured as extended custom attributes for a member device is retrieved from the DHCP server using a plurality of extended KDS interfaces to automate local device configuration and export vendor specific member device information to the KDS.

13. The method of claim 1 , wherein an authenticated member device's request for a key operation, based on the device group identifier and the IWAP-PSK identity hint, is processed by the KDS and permitted based on a match of the member device tenant identifier with an associated license owner identifier retrieved from the DHCP server as a vendor specific member device information.

14. The method of claim 1 , wherein the supplicant program detects a change in the IWAP-PSK based on failure to authenticate with the WAP using the IWAP-SSID and last retrieved and stored IWAP-PSK, and automatically switch-over to a guest wireless network using the GWAP-SSID and the GWAP-PSK, authenticate with the KDS, retrieve a IWAP-PSK from the KDS, and authenticate with the WAP using the IWAP-SSID and retrieved IWAP-PSK to switch-over to a secure wireless network.

15. The method of claim 1 , wherein the supplicant program, for security reasons, does not store a last retrieved IWAP-PSK locally on the device, and dynamically at power cycle or application restart, authenticate with a guest wireless network using the GWAP-SSID and the GWAP-PSK, authenticate with the KDS, retrieve an IWAP-PSK from the KDS, and authenticate with the WAP using the IWAP-SSID and retrieved IWAP-PSK to switch-over to a secure wireless network.

16. The method of claim 1 , wherein the supplicant program is a Wi-Fi supplicant, or a Wi-Fi supplicant function implemented within a production application or system firmware.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2024
From: KUMAR, SRINIVAS
To: SYMMERA INC.
Reel/Frame 068326/0742 →
Continuity (2)
Provisional Application 63454612 · Mar 24, 2023
Related Publication 20240323686A1 · Sep 26, 2024
References Cited (116)
US 6226618B1 · Downs et al. · 2001 [cited by applicant]
US 6574609B1 · Downs et al. · 2003 [cited by applicant]
US 6587837B1 · Spagna et al. · 2003 [cited by applicant]
US 6859791B1 · Spagna et al. · 2005 [cited by applicant]
US 6983371B1 · Hurtado et al. · 2006 [cited by applicant]
US 7110984B1 · Spagna et al. · 2006 [cited by applicant]
US 7228437B2 · Spagna et al. · 2007 [cited by applicant]
US 7346580B2 · Lisanke et al. · 2008 [cited by applicant]
US 7487128B2 · Spagna et al. · 2009 [cited by applicant]
US 8180708B2 · Hurtado et al. · 2012 [cited by applicant]
US 9565172B2 · Ståhl · 2017 [cited by applicant]
US 10057243B1 · Kumar et al. · 2018 [cited by applicant]
US 10162968B1 · Kumar et al. · 2018 [cited by applicant]
US 10250383B1 · Kumar et al. · 2019 [cited by applicant]
US 10326797B1 · Murray et al. · 2019 [cited by applicant]
US 10341321B2 · Kumar et al. · 2019 [cited by applicant]
US 10469480B2 · Kumar et al. · 2019 [cited by applicant]
US 10492069B2 · Gupta · 2019 [cited by examiner]
US 10505920B2 · Kumar et al. · 2019 [cited by applicant]
US 10587586B2 · Kumar et al. · 2020 [cited by applicant]
US 10657261B2 · Kumar et al. · 2020 [cited by applicant]
US 10764040B2 · Kumar et al. · 2020 [cited by applicant]
US 10979419B2 · Kumar et al. · 2021 [cited by applicant]
US 11025627B2 · Li et al. · 2021 [cited by applicant]
US 11134379B2 · Shi et al. · 2021 [cited by applicant]
US 11153344B2 · Hayton · 2021 [cited by applicant]
US 11206134B2 · Kumar et al. · 2021 [cited by applicant]
US 11303616B2 · Kumar et al. · 2022 [cited by applicant]
US 11349675B2 · Kim et al. · 2022 [cited by applicant]
US 11403402B2 · Kumar et al. · 2022 [cited by applicant]
US 11444753B1 · Williams et al. · 2022 [cited by applicant]
US 11451959B2 · Windsor · 2022 [cited by examiner]
US 11595217B2 · Kumar et al. · 2023 [cited by applicant]
US 11627464B2 · Ficara · 2023 [cited by examiner]
US 11716622B2 · Sloane · 2023 [cited by examiner]
US 20020002468A1 · Spagna et al. · 2002 [cited by applicant]
US 20020107803A1 · Lisanke et al. · 2002 [cited by applicant]
US 20030110130A1 · Pelletier · 2003 [cited by applicant]
US 20030185395A1 · Lee et al. · 2003 [cited by applicant]
US 20050251491A1 · Medina et al. · 2005 [cited by applicant]
US 20060089912A1 · Spagna et al. · 2006 [cited by applicant]
US 20070195960A1 · Goldman et al. · 2007 [cited by applicant]
US 20080172747A1 · Hurtado et al. · 2008 [cited by applicant]
US 20090185685A1 · DeRoberts · 2009 [cited by applicant]
US 20100008500A1 · Lisanke et al. · 2010 [cited by applicant]
US 20100293370A1 · Xiao et al. · 2010 [cited by applicant]
US 20120042160A1 · Nakhjiri et al. · 2012 [cited by applicant]
US 20130159724A1 · Kim et al. · 2013 [cited by applicant]
US 20150180662A1 · Cui et al. · 2015 [cited by applicant]
US 20160156626A1 · Roth · 2016 [cited by applicant]
US 20160364553A1 · Smith et al. · 2016 [cited by applicant]
US 20170041296A1 · Ford et al. · 2017 [cited by applicant]
US 20170272944A1 · Link, II · 2017 [cited by applicant]
US 20180082083A1 · Smith et al. · 2018 [cited by applicant]
US 20180123784A1 · Gehrmann · 2018 [cited by applicant]
US 20180367506A1 · Ford et al. · 2018 [cited by applicant]
US 20190149989A1 · Moriya · 2019 [cited by examiner]
US 20190222560A1 · Ford et al. · 2019 [cited by applicant]
US 20190320477A1 · Korber · 2019 [cited by examiner]
US 20190327209A1 · Seferiadis et al. · 2019 [cited by applicant]
US 20200008029A1 · Cao · 2020 [cited by applicant]
US 20200059469A1 · Chellappa et al. · 2020 [cited by applicant]
US 20200145409A1 · Pochuev et al. · 2020 [cited by applicant]
US 20200162917A1 · Anantha · 2020 [cited by examiner]
US 20200186365A1 · Kumar et al. · 2020 [cited by applicant]
US 20200295933A1 · Link, II · 2020 [cited by applicant]
US 20200382957A1 · Johnson · 2020 [cited by applicant]
US 20200396067A1 · Barker · 2020 [cited by applicant]
US 20200396604A1 · Olshansky · 2020 [cited by examiner]
US 20210050999A1 · Huang · 2021 [cited by examiner]
US 20210099873A1 · Windsor · 2021 [cited by examiner]
US 20210194681A1 · Nix · 2021 [cited by applicant]
US 20210240536A1 · Brazeau et al. · 2021 [cited by applicant]
US 20210350009A1 · Freundlich et al. · 2021 [cited by applicant]
US 20210377252A1 · Monro et al. · 2021 [cited by applicant]
US 20220006652A1 · Mishra et al. · 2022 [cited by applicant]
US 20220045930A1 · Williams · 2022 [cited by applicant]
US 20220060899A1 · Harding · 2022 [cited by examiner]
US 20220103578A1 · Srivastav et al. · 2022 [cited by applicant]
US 20220294609A1 · Williams et al. · 2022 [cited by applicant]
US 20220376898A1 · Kaliski, Jr. et al. · 2022 [cited by applicant]
US 20220393865A1 · Williams et al. · 2022 [cited by applicant]
US 20220393866A1 · Williams et al. · 2022 [cited by applicant]
US 20220407688A1 · Childe et al. · 2022 [cited by applicant]
US 20220417742A1 · Dey · 2022 [cited by examiner]
US 20230020193A1 · Williams et al. · 2023 [cited by applicant]
US 20230057469A1 · Hoole et al. · 2023 [cited by applicant]
US 20230163958A1 · Sheng et al. · 2023 [cited by applicant]
US 20230229758A1 · Terpstra et al. · 2023 [cited by applicant]
US 20230269099A1 · Medvinsky et al. · 2023 [cited by applicant]
US 20240214802A1 · Gupta · 2024 [cited by examiner]
US 20240349052A1 · Madappa · 2024 [cited by examiner]
US 20240406726A1 · Yang · 2024 [cited by examiner]
CN 114745170A · 2023 [cited by applicant]
WO 2023022724A1 · 2023 [cited by applicant]
WO 2023034121A1 · 2023 [cited by applicant]
Arqit announces QuantumCloud powered b AWS, Dec. 9, 2022, 4 pps. [cited by applicant]
Raza et al, “Security Considerations for the WirelessHART Protocol”, IEEE, 2009, 8 pps. [cited by applicant]
Raza et al, “S3K: Scalable Security with Symmetric Keys—DTLS Key Establishment for the Internet of Things”, Jun. 1, 2015, 11 pps. [cited by applicant]
Siddiqa et al, “Scalable Asymmetric Security Mechanism for Internet of Things”, International Journal of Advanced Computer Science and Applications, vol. 11, No. 8, 2020, pp. 365-373. [cited by applicant]
Vohra, Meenakshi “Internet key exchange (IKE) based secure wireless and mobile networks” [online] San Jose State University, May 2004 [retrieved Jul. 5, 2023]. Retrieved from the Internet: URL: https://scholarworks.sjsu… [cited by applicant]
“Symmetric Identity Based Device Attestation” [online] TrustedComputing Group, Jan. 2020 [retrieved Jul. 5, 2023]. Retrieved from the Internet: URL: https://trustedcomputinggroup.org/wp-content/uploads/TCG_DICE_SymIDAtt… [cited by applicant]
Eronen, Ed et al. “R.F.C. 4279: Pre-Shared Key Ciphersuites for Transport Layer Security (TLS)” [online] R.F.C., Dec. 2005 [retrieved Jul. 5, 2023] Retrieved from the Internet: URL: https://www.rfc-editor.org/rfc/rfc427… [cited by applicant]
Raza, Shahid et al. “S3K: Scalable Security With Symmetric Keys—DTLS Key Establishment for the Internet of Things” [online] IEEE, Jan. 2016 [retrieved Jul. 5, 2023]. Retrieved from the Internet: URL: https://ieeexplore.… [cited by applicant]
Non-Final Office Action, dated Aug. 17, 2023, issued in U.S. Appl. No. 18/206,426, 17 pgs. [cited by applicant]
Notice of Allowance, dated Aug. 17, 2023, issued in U.S. Appl. No. 18/206,399, 17 pgs. [cited by applicant]
S. Maksuti et al., “Automated and Secure Onboarding for System of Systems,” in IEEE Access, vol. 9, pp. 111095-111113, 2021. ( Year: 2021). [cited by applicant]
Boskov, Ivana Arsen et al. “Time-to-Provision Evaluation of IoT Devices Using Automated Zero-Touch Provisioning.” GLOBECOM 2020—2020 IEEE Global Communications Conference (2020): pp. 1-7. (Year: 2020). [cited by applicant]
Notice of Allowance, dated Jan. 24, 2024, issued in corresponding U.S. Appl. No. 18/377,866, 48 pages. [cited by applicant]
Non-Final Office Action issued on Dec. 4, 2024, in corresponding U.S. Appl. No. 18/139,486 (32 pages). [cited by applicant]
Non-Final Office Action issued on Feb. 27, 2025 in corresponding U.S. Appl. No. 18/438,586 (48 pages). [cited by applicant]
C. Malathi, I. Naga Padmaja, Identification of cyber attacks using machine learning in smart IoT networks, Materials Today: Proceedings, vol. 80, Part 3, pp. 2518-2523 (Year: 2023) 6 pages. [cited by applicant]
Notice of Allowance mailed Feb. 5, 2025 in copending U.S. Appl. No. 18/139,498 (15 pages). [cited by applicant]
R. Housley, Guidance for External Pre-Shared Key (PSK) Usage in TLS (RFC9257), Original Publication Date: Jul. 1, 2022 IP.com No. IPCOM000271272D, IP.com Electronic Publication Date: Nov. 19, 2022, 14 pages (Year: 2022). [cited by applicant]
Diogo Domingues Regateiro, “Supporting Pre-shared Keys in Closed Implementations of TLS”, academia.edu, 8 pages (Year: 2017). [cited by applicant]
Notice of Allowance issued Mar. 3, 2025 in corresponding U.S. Appl. No. 18/139,494 (16 pages). [cited by applicant]