IP Library Granted Patent US 12,063,580
Granted Patent B2
US 12,063,580 · App. 18/159,085 · Granted Aug 13, 2024

Method and apparatus for providing a secure communication in a self-organizing network

Inventors: Shravan Mahidhara (Palatine, IL); Vasanthi Raghuram (Palatine, IL)
Assignee: Google Technology Holdings LLC
H04W4/80H04L63/0428H04L63/08H04W28/18H04W48/16H04W76/00H04W84/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,063,580
App. No.
18/159,085
Granted
Aug 13, 2024
Kind
B2
Abstract

A communication system provides secure communication between two nodes in a self-organizing network without the need for a centralized security or control device. A first node of the two nodes is provisioned with one or more security profiles, auto-discovers a second node of the two nodes, authenticates the second node based on a security profile of the one or more security profiles, selects a security profile of the one or more security profiles to encrypt a communication session between the two nodes, and encrypts the communication session between the two nodes based on the selected security profile. The second node also is provisioned with the same one or more security profiles, authenticates the first node based on a same security profile as is used to authenticate the second node, and encrypts the communication session based on the same security profile as is used for encryption by the first node.

Claims (46)

1. A computer-implemented method that, when executed by data processing hardware of a first network node of a self-organizing network, causes the data processing hardware to perform operations comprising:

obtaining a first table of security profiles stored at a first memory device of the first network node;

after obtaining the first table of security profiles;

discovering a second network node of the self-organizing network; and

receiving, from the second network node, an authentication challenge message comprising:

an encrypted portion encrypted based on a respective one of the security profiles selected by the second network node from a second table of security profiles stored at a second memory device of the second network node prior to the first network node discovering the second network node, the second table comprising the same security profiles as the first table, the respective one of the security profiles associated with a value of a security profile selection parameter in the second table of security profiles; and

an unencrypted portion identifying the respective one of the security profiles selected by the second network node;

selecting, from the first table of security profiles, based on the unencrypted portion of the authentication challenge message, the respective one of the security profiles selected by the second network node;

decrypting the encrypted portion of the authentication challenge message using the selected respective one of the security profiles; and

based on decryption of the encrypted portion, authenticating the second network node.

2. The method of claim 1 , wherein the operations further comprise transmitting, to the second network node, a communication session initiation message.

3. The method of claim 2 , wherein the communication session initiation message comprises at least one of:

a type of a communication session being initiated between the first network node and the second network node;

a port number assigned to the communication session; or

a medium access control (MAC) layer address assigned to the communication session.

4. The method of claim 1 , wherein the operations further comprise transmitting, to the second network node, an authentication response to the authentication challenge message, the authentication response encrypted based on the selected respective one of the security profiles.

5. The method of claim 4 , wherein, in response to the authentication response, the second network node authenticates the first network node.

6. The method of claim 5 , wherein the operations further comprise, after the second network node authenticates the first network node, establishing a secure communication link between the first network node and the second network node.

7. The method of claim 6 , wherein the operations further comprise, in response to establishing the secure communication link, providing an application layer communication to the second network node.

8. The method of claim 1 , wherein the value of the security profile selection parameter is based on a physical communication link type.

9. The method of claim 1 , wherein the value of the security profile selection parameter is based on a characteristic of a channel to be used in a communication session between the first network node and the second network node.

10. The method of claim 9 , wherein the characteristic of the channel is associated with frequencies, time slots, or channel coding for the communication session between the first network node and the second network node.

11. A system comprising:

data processing hardware of a first network node of a distributed, self-organizing network; and

memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:

obtaining a first table of security profiles stored at a first memory device of the first network node;

after obtaining the first table of security profiles;

discovering a second network node of the self-organizing network; and

receiving, from the second network node, an authentication challenge message comprising:

an encrypted portion encrypted based on a respective one of the security profiles selected by the second network node from a second table of security profiles stored at a second memory device of the second network node prior to the first network node discovering the second network node, the second table comprising the same security profiles as the first table, the respective one of the security profiles associated with a value of a security profile selection parameter in the second table of security profiles; and

an unencrypted portion identifying the respective one of the security profiles selected by the second network node;

selecting, from the first table of security profiles, based on the unencrypted portion of the authentication challenge message, the respective one of the security profiles selected by the second network node;

decrypting the encrypted portion of the authentication challenge message using the selected respective one of the security profiles; and

based on decryption of the encrypted portion, authenticating the second network node.

12. The system of claim 11 , wherein the operations further comprise transmitting, to the second network node, a communication session initiation message.

13. The system of claim 12 , wherein the communication session initiation message comprises at least one of:

a type of a communication session being initiated between the first network node and the second network node;

a port number assigned to the communication session; or

a medium access control (MAC) layer address assigned to the communication session.

14. The system of claim 11 , wherein the operations further comprise transmitting, to the second network node, an authentication response to the authentication challenge message, the authentication response encrypted based on the selected respective one of the security profiles.

15. The system of claim 14 , wherein, in response to the authentication response, the second network node authenticates the first network node.

16. The system of claim 15 , wherein the operations further comprise, after the second network node authenticates the first network node, establishing a secure communication link between the first network node and the second network node.

17. The system of claim 16 , wherein the operations further comprise, in response to establishing the secure communication link, providing an application layer communication to the second network node.

18. The system of claim 11 , wherein the value of the security profile selection parameter is based on a physical communication link type.

19. The system of claim 11 , wherein the value of the security profile selection parameter is based on a characteristic of a channel to be used in a communication session between the first network node and the second network node.

20. The system of claim 19 , wherein the characteristic of the channel is associated with frequencies, time slots, or channel coding for the communication session between the first network node and the second network node.

Continuity (5)
Continuation 17446177 · Aug 27, 2021
Continuation 15783244 · Oct 13, 2017
Continuation 13012057 · Jan 24, 2011
Provisional Application 61429001 · Dec 31, 2010
Related Publication 20230164533A1 · May 25, 2023