IP Library Granted Patent US 12,452,044
Granted Patent B2
US 12,452,044 · App. 18/315,219 · Granted Oct 21, 2025

Securing network communications using dynamically and locally generated secret keys

Inventors: Ravisankar Jakkula (Telangana, IN); Kirankumar Anumolu (Telangana, IN)
Assignee: KIDDE FIRE PROTECTION, LLC
H04L9/085H04L9/0822H04L9/0869
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,044
App. No.
18/315,219
Granted
Oct 21, 2025
Kind
B2
Abstract

A communications network includes a bus communicatively coupled to a first device and a second device. The first device and the second device are operable to perform multiple iterations of a secret-key generation (SKG) process. Each of the multiple iterations of the SKG process includes the first device computing a first instance of a key seed; the second device computing a second instance of the key seed; the first device using the first instance of the key seed to generate a first instance of a secret key; and the second device using the second instance of the key seed to generate a second instance of the secret key.

Claims (77)

1. A communications network comprising:

a bus external to and electronically coupled to a first device and a second device;

wherein the first device and the second device are configured to perform multiple iterations of a secret-key generation (SKG) process;

wherein each of the multiple iterations of the SKG process comprises:

based at least in part on a determination that a prior time window has ended, the first device computing a first instance of a key seed associated with a current time window;

based at least in part on the determination that the prior time window has ended, the second device computing a second instance of the key seed associated with the current time window;

the first device using the first instance of the key seed to generate a first instance of a secret key associated with the current time window;

the second device using the second instance of the key seed to generate a second instance of the secret key associated with the current time window; and

based at least in part on a determination that the current time window has ended, initiating a next one of the multiple iterations of the SKG process, wherein the next one of the multiple iterations of the SKG process is associated with a new current time window.

2. The communications network of claim 1 , wherein the first device is further configured to:

use the first instance of the secret key associated with the current time window to encrypt communications from the first device to the second device over the bus during the current time window; and

discontinue using the first instance of the secret key associated with the current time window to encrypt communications from the first device to the second device over the bus after the current time window has ended.

3. The communications network of claim 2 , wherein the second device is further configured to:

use the second instance of the secret key associated with the current time window to decrypt the communications sent from the first device to the second device over the bus during the current time window; and

discontinue using the second instance of the secret key associated with the current time window to decrypt the communications sent from the first device to the second device over the bus after the current time window has ended.

4. The communications network of claim 3 , wherein the second device is further configured to:

use the second instance of the secret key associated with the current time window to encrypt communications from the second device to the first device over the bus during the current time window; and

discontinue using the second instance of the secret key associated with the current time window to encrypt communications from the second device to the first device over the bus after the current time window has ended.

5. The communications network of claim 4 , wherein the first device is further configured to:

use the first instance of the secret key associated with the current time window to decrypt the communications sent from the second device to the first device over the bus during the current time window; and

discontinue using the first instance of the secret key associated with the current time window to decrypt the communications sent from the second device to the first device over the bus after the current time window has ended.

6. The communications network of claim 5 , wherein:

the first instance of the secret key is not transmitted to or from the first device; and

the second instance of the secret key is not transmitted to or from the second device.

7. The communications network of claim 1 , wherein the next one of the multiple iterations of the SKG process generates a new version of the key seed associated with the new current time window.

8. The communications network of claim 1 , wherein:

the prior time window, the current time window, and the new current time window are each less than a second time window; and

the second time window defines a minimum time required by a third device to couple to the bus and determine the secret key without using the SKG process.

9. A communications network comprising:

a bus external to and electronically coupled to a first device and a second device;

wherein the first device and the second device are operable to perform multiple iterations of a secret-key generation (SKG) process;

wherein each of the multiple iterations of the SKG process comprises:

the first device computing a first instance of a key seed;

the second device computing a second instance of the key seed;

the first device using the first instance of the key seed to generate a first instance of a secret key; and

the second device using the second instance of the key seed to generate a second instance of the secret key;

wherein the key seed comprises a propagation delay over the bus and between the first device and the second device;

wherein the first device is configured to compute the first instance of the propagation delay while not performing any other operations;

wherein the first device computing the first instance of the propagation delay comprises the first device sending a first test message to the second device and the second device sending a second test message to the first device;

wherein the second device is configured to compute the second instance of the propagation delay while not performing any other operations; and

wherein the second device computing the second instance of the propagation delay comprises the second device sending a third test message to the first device and the first device sending a fourth test message to the first device.

10. The communications network of claim 9 , wherein:

each of the multiple iterations of the SKG process is spaced apart from one another by a first time window;

the first time window is less than a second time window; and

the second time window defines a minimum time required by a third device to couple to the bus and determine the secret key without using the SKG process.

11. A method of operating a communications network, the method comprising:

using a first device and a second device to perform multiple iterations of a secret-key generation (SKG) process, wherein each of the multiple iterations of the SKG process comprises:

based at least in part on a determination that a prior time window has ended, the first device computing a first instance of a key seed associated with a current time window;

based at least in part on the determination that the prior time window has ended, the second device computing a second instance of the key seed associated with the current time window;

the first device using the first instance of the key seed to generate a first instance of a secret key associated with the current time window;

the second device using the second instance of the key seed to generate a second instance of the secret key associated with the current time window; and

based at least in part on a determination that the current time window has ended, initiating a next one of the multiple iterations of the SKG process, wherein the next one of the multiple iterations of the SKG process is associated with a new current time window.

12. The method of claim 11 , wherein the first device is further configured to:

use the first instance of the secret key associated with the current time window to encrypt communications from the first device to the second device over the bus during the current time window; and

discontinue using the first instance of the secret key associated with the current time window to encrypt communications from the first device to the second device over the bus after the current time window has ended.

13. The method of claim 12 , wherein the second device is further configured to:

use the second instance of the secret key associated with the current time window to decrypt the communications sent from the first device to the second device over the bus during the current time window; and

discontinue using the second instance of the secret key associated with the current time window to decrypt the communications sent from the first device to the second device over the bus after the current time window has ended.

14. The method of claim 13 , wherein the second device is further configured to;

use the second instance of the secret key associated with the current time window to encrypt communications from the second device to the first device over the bus during the current time window; and

discontinue using the second instance of the secret key associated with the current time window to encrypt communications from the second device to the first device over the bus after the current time window has ended.

15. The method of claim 14 , wherein the first device is further configured to;

use the first instance of the secret key associated with the current time window to decrypt the communications sent from the second device to the first device over the bus during the current time window; and

discontinue using the first instance of the secret key associated with the current time window to decrypt the communications sent from the second device to the first device over the bus after the current time window has ended.

16. The method of claim 15 , wherein:

the first instance of the secret key is not transmitted to or from the first device; and

the second instance of the secret key is not transmitted to or from the second device.

17. The method of claim 11 , wherein the next one of the multiple iterations of the SKG process generates a new version of the key seed associated with the new current time window.

18. The method of claim 11 , wherein the key seed comprises a propagation delay over the bus and between the first device and the second device.

19. The method of claim 18 , wherein:

the first device is operable to compute the first instance of the propagation delay while not performing any other operations;

the first device computing the first instance of the propagation delay comprises the first device sending a first test message to the second device and the second device sending a second test message to the first device;

the second device is operable to compute the second instance of the propagation delay while not performing any other operations; and

the second device computing the second instance of the propagation delay comprises the second device sending a third test message to the first device and the first device sending a fourth test message to the first device.

20. The method of claim 11 , wherein:

the prior time window, the current time window, and the new current time window are each less than a second time window; and

the second time window defines a minimum time required by a third device electronically coupled to the bus to determine the secret key without using the SKG process.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2025
From: CARRIER CORPORATION; CARRIER GLOBAL CORPORATION; CARRIER FIRE & SECURITY EMEA; CARRIER FIRE & SECURITY, LLC; CARRIER CANADA CORPORATION; CLIMATE, CONTROLS & SECURITY ARGENTINA S.A.; KIDDE IP HOLDINGS , INC.; KIDDE LTD.; KIDDE PRODUCTS LTD.; CARRIER TRANSICOLD AUSTRIA GMBH; CARRIER TRANSICOLD FRANCE SCS
To: KIDDE FIRE PROTECTION, LLC
Reel/Frame 072829/0574 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2023
From: JAKKULA, RAVISANKAR; ANUMOLU, KIRANKUMAR
To: CARRIER TECHNOLOGIES INDIA LIMITED
Reel/Frame 063600/0288 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2023
From: CARRIER TECHNOLOGIES INDIA LIMITED
To: CARRIER CORPORATION
Reel/Frame 063600/0313 →
Continuity (2)
Provisional Application 63342749 · May 17, 2022
Related Publication 20230379146A1 · Nov 23, 2023
References Cited (28)
US 7209561B1 · Shankar et al. · 2007 [cited by applicant]
US 8356201B2 · Newald · 2013 [cited by applicant]
US 8542069B2 · Kelling et al. · 2013 [cited by applicant]
US 10037441B2 · Kaluzhny et al. · 2018 [cited by applicant]
US 10291403B2 · Ligatti et al. · 2019 [cited by applicant]
US 10523685B1 · Kostka · 2019 [cited by examiner]
US 10541833B2 · Andrews · 2020 [cited by applicant]
US 10970382B2 · Hofman · 2021 [cited by applicant]
US 20090245516A1 · Ravikiran · 2009 [cited by applicant]
US 20150033016A1 · Thornton et al. · 2015 [cited by applicant]
US 20180026962A1 · Kaladgi · 2018 [cited by examiner]
US 20180337938A1 · Kneib et al. · 2018 [cited by applicant]
US 20190013941A1 · Ligatti · 2019 [cited by examiner]
US 20190253439A1 · Payton · 2019 [cited by applicant]
US 20190327235A1 · Brickell · 2019 [cited by examiner]
US 20210029096A1 · Hart · 2021 [cited by examiner]
US 20210203682A1 · Bajpai · 2021 [cited by applicant]
US 20210377008A1 · Chien · 2021 [cited by applicant]
US 20220171832A1 · Gallagher · 2022 [cited by examiner]
CN 103746801A · 2014 [cited by examiner]
CN 106920357A · 2017 [cited by applicant]
EP 2748966A1 · 2014 [cited by applicant]
IE 20020742A1 · 2003 [cited by applicant]
KR 20160020866A · 2016 [cited by applicant]
WO 0191366A2 · 2001 [cited by applicant]
WO 2013042143A1 · 2013 [cited by applicant]
WO 2020208639A2 · 2020 [cited by applicant]
European Application No. 23174100.0 filed May 17, 2023; Extended European Search Report dated Feb. 5, 2024; 9 pages. [cited by applicant]