IP Library Granted Patent US 10,348,489
Granted Patent B2
US 10,348,489 · App. 15/339,864 · Granted Jul 9, 2019

Internet of things (IOT) method for updating a master key

Inventors: Alexander Medvinsky (San Diego, CA); Tat Keung Chan (San Diego, CA)
Assignee: ARRIS Enterprises LLC
H04L9/083H04L9/0631H04L9/0643H04L9/0822H04L9/0833H04L9/0866H04L63/166H04L2209/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,348,489
App. No.
15/339,864
Granted
Jul 9, 2019
Kind
B2
Abstract

A method is provided for providing a new master key to devices in a Thread network for an Internet of Things (IOT). To provide the new master key, Device Provisioning Key (DPK) is generated from a Network Seed Key (NSK) known to a Commissioner and Leader in a local network. The Commissioner provides the DPK as a unique per-device key to each device in the network to establish a secure session. The DPK is derived from the NSK as follows: DPK=OWF(NSK, ID), wherein OWF is a One Way Function, and ID is a unique device identifier for each device. The new master key can then be sent from the commissioner to the new devices to establish a secure session created using the DPK.

Claims (63)

1. A method for providing a new master key to devices in a network comprising:

deriving a Device Provisioning Key (DPK) from a Network Seed Key NSK known to a Commissioner and Leader in the local network,

providing a unique per-device key comprising the DPK from the Commissioner to each device in the network to establish a secure session;

wherein the DPK is derived from the NSK as follows: DPK=OWF(NSK, ID), and

wherein OWF is a One Way Function, and ID is a unique device identifier; sending the new master key from the Commissioner to each of the devices, wherein the new master key is protected using the DPK;

broadcasting by the commissioner a message to every device in the network that they can start using the New Master Key; and

providing a new commissioner and updating the NSK with a new NSK (NNSK) using the new Commissioner with a method comprising the following steps:

generating a parameter a using the new commissioner;

generating the new NSK (NNSK) using the new commissioner, wherein the devices can determine the NNSK from a;

broadcasting a from the commissioner encrypted using the new master key;

replacing NSK with NNSK in the new commissioner; and

broadcasting from the new commissioner a command to start using a new DPK (NDPK) that can be calculated from the NNSK in the devices.

2. The method of claim 1 , wherein the unique device identifier is an IEEE 48-bit or 64-bit MAC Address.

3. The method of claim 1 , wherein the OWF can be a SHA-1 or a SHA-256 hash or an AES encrypt or decrypt.

4. The method of claim 1 , wherein alpha is a random large integer value, and NNSK=α*NSK.

5. The method of claim 1 , wherein after broadcast of alpha from the commissioner, each device in the network can derive a New Elliptic Curve point Q called NQ as follows: NQ=αQ,

wherein the NQ can then be used to derive the NDPK using the formula for the DPK with the NNSK substituted for NSK.

6. A method for providing a new master key to devices in a network comprising:

deriving a Device Provisioning Key (DPK) from a Network Seed Key NSK known to a Commissioner and Leader in the local network,

providing a unique per-device key comprising the DPK from the Commissioner to each device in the network to establish a secure session;

wherein the DPK is derived from the NSK as follows: DPK=OWF(NSK, ID), and

wherein OWF is a One Way Function, and ID is a unique device identifier;

sending the new master key from the Commissioner to each of the devices, wherein the new master key is protected using the DPK−; and

broadcasting by the commissioner a message to every device in the network that they can start using the New Master Key,

wherein prior to the step of deriving the DPK from the NSK, the following steps are performed:

triggering the commissioner by an event to generate the new master key;

broadcasting from the commissioner a message to all devices in the network that the commissioner intends to change to the new master key;

receiving requests at the commissioner from the devices in the network to change the master key to the new master key;

wherein deriving within the commissioner the new Device Provisioning Key (DPK) is then performed for each separate one of the requesting devices, and

wherein sending the new master key to the requesting devices is performed by establishing a new secure session between the Commissioner and each one of the requesting devices using the specific new DPK for the requesting device as a common pre-shared key, and wherein the new master key is sent by the commissioner to the requesting devices, protected with the new secure session.

7. The method of claim 6 , further comprising:

receiving at a later time a request from a device in the network for the new master key that did not provide a request for transmission of the new master key during initial broadcast of the new master key;

deriving at the commissioner a further DPK specific to the later requesting device;

establishing a secure session using the further DPK specific to the later requesting device; and transmitting the new master key to the later requesting device during the secure session.

8. The method of claim 6 , wherein the network is an IOT network.

9. The method of claim 6 , wherein prior to the steps of claim 1 , the following steps are performed:

establishing an initial secure session with a commissioning PIN provided from a commissioner device;

deriving within the commissioner an initial DPK unique to a new device in a network based on an identifier for the new device; and

sending both an initial Master Key and the DPK to the new device under the initial secure session,

wherein the initial Master Key is used to encrypt/decrypt communications in the network.

10. The method of claim 9 , wherein the secure session is Datagram Transport Layer Security (DTLS).

11. The method of claim 9 , wherein the identifier for the new device is a MAC Address.

12. A method for providing a new master key to devices in a network comprising:

deriving a Device Provisioning Key (DPK) from a Network Seed Key NSK known to a Commissioner and Leader in the local network,

providing a unique per-device key comprising the DPK from the Commissioner to each device in the network to establish a secure session;

wherein the DPK is derived from the NSK as follows: DPK=OWF(NSK, ID), and

wherein OWF is a One Way Function, and ID is a unique device identifier;

sending the new master key from the Commissioner to each of the devices, wherein the new master key is protected using the DPK−; and

broadcasting by the commissioner a message to every device in the network that they can start using the New Master Key,

wherein prior to the step of deriving the DPK from the NSK, the following steps are performed:

triggering the commissioner by an event to generate the new master key;

broadcasting from the commissioner a message to all devices in the network that the commissioner intends to change to the new master key;

receiving requests at the commissioner from the devices in the network to change the master key to the new master key,

wherein deriving within the commissioner, the new Device Provisioning Key (DPK) is then performed for each separate one of the requesting devices, and

wherein sending the new master key to the requesting devices is performed by sending by the commissioner the new master key to the requesting devices, encrypted and authenticated with the new DPK.

13. The method of claim 12 , further comprising:

receiving at a later time a request from a device in the network for the new master key that did not provide a request for transmission of the new master key during initial broadcast of the new master key;

deriving at the commissioner a further DPK specific to the later requesting device; and

transmitting the new master key to the later requesting device encrypted and authenticated either directly with the further DPK or indirectly using keys derived from the further DPK.

14. The method of claim 12 , wherein prior to the steps of claim 1 , the following steps are performed:

establishing an initial secure session with a commissioning PIN provided from a commissioner device;

deriving within the commissioner an initial DPK unique to a new device in a network based on an identifier for the new device;

sending both an initial Master Key and the DPK to the new device under the initial secure session; wherein the initial Master Key is used to encrypt/decrypt communications in the network.

Assignments (8)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2016
From: MEDVINSKY, ALEXANDER; CHAN, TAT KEUNG
To: ARRIS ENTERPRISES LLC
Reel/Frame 040334/0096 →
Continuity (2)
Provisional Application 62248339 · Oct 30, 2015
Related Publication 20170126402A1 · May 4, 2017