Methods, devices and systems for repeating secure wireless connections
A method can include, by operation of a first wireless device, executing a hash operation on a first portion of a received authentication value to generate a hash result. In response to determining that a connection is to be refreshed, an authentication validate can be validated by decrypting a second portion of the authentication value to generate a decryption result and comparing the hash result to the decryption result. The decryption result can be stored. In response to determining that a connection is not to be refreshed, an authentication value can be validated by comparing the hash result to a previously stored decryption result. Corresponding devices and systems are also disclosed.
1 . A method, comprising:
by operation of a wireless device,
executing a hash operation on a first portion of a received authentication value to generate a hash result,
in response to determining that a connection is to be refreshed, the determining that the connection is to be refreshed comprising determining if the authentication value corresponds to a previous wireless connection made within a predetermined time period, validate the authentication value by
decrypting a second portion of the authentication value to generate a decryption result,
comparing the hash result to the decryption result, and
storing the decryption result, and
in response to determining that the connection is not to be refreshed, validate the authentication value by comparing the hash result to a previously stored decryption result.
2 . The method of claim 1 , wherein the received authentication value comprises a server digital certificate.
3 . The method of claim 1 , wherein decrypting the second portion of the authentication value includes accessing a decryption key included in a local digital certificate stored by the wireless device.
4 . The method of claim 1 , wherein the authentication value is included in a message of a transport layer security (TLS) handshake.
5 . The method of claim 4 , further including completing the TLS handshake in response to at least validating the authentication value.
6 . The method of claim 1 , wherein the authentication value is received in at least one data frame compatible with at least one IEEE 802.11 wireless standard.
7 . The method of claim 1 , further including:
storing a decryption key in memory circuits of the wireless device; and
decrypting the second portion with the decryption key.
8 . A device, comprising:
wireless circuits configured to transmit and receive wireless messages, including receiving an authentication value;
controller circuits configured to
execute a hash operation on a first portion of the authentication value to generate a hash result,
in response to determining that a connection is to be refreshed, the determining that the connection is to be refreshed comprising determining if the authentication value corresponds to a previous wireless connection made within a predetermined time period, validate the authentication value by decrypting a second portion of the authentication value to generate a decryption result and comparing the hash result to the decryption result,
store the decryption result, and
in response to determining that the connection is not to be refreshed, validate the authentication value by comparing the hash result to a previously stored decryption result; and
memory circuits configured to store at least the previously stored decryption result.
9 . The device of claim 8 , wherein the wireless circuits are compatible with at least one IEEE 802.11 wireless standard.
10 . The device of claim 8 , wherein:
the authentication value comprises a host device certificate;
the memory circuits are configured to store a client device certificate that includes a decryption key; and
the controller circuits are configured to decrypt the second portion of the authentication value with the decryption key.
11 . The device of claim 10 , wherein:
the device certificate comprises a root certificate from a certificate authority; and
the decryption key comprises a public key of a public key infrastructure.
12 . The device of claim 8 , wherein the authentication value is included in a message of a transport layer security handshake.
13 . The device of claim 8 , wherein the controller circuits are further configured to determine if the authentication value corresponds to a previous wireless connection.
14 . A system, comprising:
a wireless device configured to
execute a hash operation on a first portion of a received authentication value to generate a hash result,
in response to determining that a connection is to be refreshed, the determining that the connection is to be refreshed comprising determining if the authentication value corresponds to a previous wireless connection made within a predetermined time period, validate the authentication value by decrypting a second portion of the authentication value to generate a decryption result and comparing the hash result to the decryption result,
store the decryption result, and in response to determining that the connection is not to be refreshed, validate the authentication value by comparing the hash result to a stored previous decryption result; and
an antenna system coupled to the wireless device.
15 . The system of claim 14 , wherein the wireless device is configured to determine if the authentication value corresponds to a previous wireless connection.
16 . The system of claim 14 , further including:
the wireless device is further configured to wirelessly transmit a first message; and
a remote device configured to transmit at least a second message in response to the first message that includes the authentication value.
17 . The system of claim 16 , wherein the first and second messages are part of a transport layer security (TLS) handshake.
18 . The system of claim 17 , further including the wireless device is configured to complete the TLS handshake in response to at least validating the authentication value.