IP Library Granted Patent US 11,546,150
Granted Patent B2
US 11,546,150 · App. 17/031,395 · Granted Jan 3, 2023

Secure scalable link key distribution using bootsrapping

Inventors: Siby Mathew Tarigopla Pancras (San Jose, CA); Jari T. Malinen (Santa Clara, CA)
Assignee: ARRIS ENTERPRISES, LLC
H04L9/0869H04L9/0891H04L9/0894H04L9/3215H04L9/3226H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,546,150
App. No.
17/031,395
Filed
Sep 24, 2020
Granted
Jan 3, 2023
Kind
B2
Art Unit
2497
USPC
380/44
Abstract

An electronic device (such as an IoT controller) that distributes a link key is described. During operation, while an administrator is logged in, the electronic device may receive the link key using a secure widget, where the link key may facilitate secure communication via a link. Then, the electronic device may generate an access key, and may generate an encrypted version of the link key based at least in part on the access key and the link key, where the access key enables access to the link key based at least in part on the encrypted version of the link key. Next, the electronic device may store the link key, the access key and/or the encrypted version of the link key in a trusted envelope or partition in the memory with encryption. Moreover, when the administrator logs out, the electronic device may disable access to the trusted envelope.

Claims (60)

1. An electronic device configured to securely distribute a link key to a gateway, comprising:

a network node;

an interface circuit communicatively coupled to the network node;

a processor coupled to the interface circuit; and

memory, coupled to the processor, configured to store program instructions, wherein, when executed by the processor, the program instructions cause the electronic device to perform operations, comprising:

while an administrator is logged in via a computer that is different from the electronic device:

receiving, at the interface circuit and associated with a second computer, the link key using a secure widget, wherein the link key facilitates secure communication via a link;

after receiving the link key, creating, at the electronic device, an access key;

generating, at the electronic device, an encrypted version of the link key based at least in part on the access key and the link key, wherein the access key enables access to the link key based at least in part on the encrypted version of the link key; and

storing, at the electronic device, at least two of the link key, the access key and the encrypted version of the link key in a trusted envelope or partition in the memory with encryption;

when the administrator logs out, disabling access to the trusted envelope, wherein access to the stored at least two of the link key, the access key and the encrypted version of the link key in the trusted envelope or the partition in the memory with encryption is only enabled when the administrator is logged in;

when the administrator logs in via the computer again:

re-enabling access to the trusted envelope;

when the electronic device receives information that indicates that the gateway has joined a network, providing, from the interface circuit, the encrypted version of the link key addressed to the gateway; and

when the electronic device receives, at the interface circuit and associated with the gateway, an access request for the access key, providing, from the interface circuit, the access key addressed to the gateway, wherein the access request is associated with an authorized second electronic device that is associated with the gateway and an entity that is different than the administrator; and

when the administrator logs out again, disabling access to the trusted envelope.

2. The electronic device of claim 1 , wherein the operations comprise storing metadata with the link key, the access key and the encrypted version of the link key in the trusted envelope; and

wherein the metadata specifies when the access key was created and how long it is valid or when the access key expires.

3. The electronic device of claim 1 , wherein the access key is created based at least in part on an administrator login credential.

4. The electronic device of claim 3 , wherein the administrator credential comprises a password.

5. The electronic device of claim 1 , wherein the access key is a random or a pseudorandom number.

6. The electronic device of claim 1 , wherein the access key is created based at least in part on a policy or privilege associated with the administrator.

7. The electronic device of claim 1 , wherein the encrypted version of the link key and the access key are provided using different communication channels.

8. The electronic device of claim 1 , wherein the gateway comprises an access point or an eNodeB.

9. The electronic device of claim 1 , wherein the link is associated with a ZigBee communication protocol.

10. The electronic device of claim 1 , wherein the access key is further provided based at least in part on an authorization associated with the administrator, an identifier of the second electronic device or both.

11. A non-transitory computer-readable storage medium for use in conjunction with an electronic device, the computer-readable storage medium storing program instructions that, when executed by the electronic device, securely distributes a link key to a gateway by causing the electronic device to perform operations comprising:

while an administrator is logged in via a computer that is different from the electronic device:

receiving, at the electronic device and associated with a second computer, the link key using a secure widget, wherein the link key facilitates secure communication via a link;

after receiving the link key, creating, at the electronic device, an access key;

generating, at the electronic device, an encrypted version of the link key based at least in part on the access key and the link key, wherein the access key enables access to the link key based at least in part on the encrypted version of the link key; and

storing, at the electronic device, at least two of the link key, the access key and the encrypted version of the link key in a trusted envelope or partition in a memory of the electronic device with encryption;

when the administrator logs out, disabling access to the trusted envelope, wherein access to the stored at least two of the link key, the access key and the encrypted version of the link key in the trusted envelope or the partition in the memory with encryption is only enabled when the administrator is logged in;

when the administrator logs in via the computer again:

re-enabling access to the trusted envelope;

when the electronic device receives information that indicates that the gateway has joined a network, providing, from the electronic device, the encrypted version of the link key addressed to the gateway; and

when the electronic device receives, associated with the gateway, an access request for the access key, providing, from the electronic device, the access key addressed to the gateway, wherein the access request is associated with an authorized second electronic device that is associated with the gateway and an entity that is different than the administrator; and

when the administrator logs out again, disabling access to the trusted envelope.

12. The non-transitory computer-readable storage medium of claim 11 , wherein the operations comprise storing metadata with the link key, the access key and the encrypted version of the link key in the trusted envelope; and

wherein the metadata specifies when the access key was created and how long it is valid or when the access key expires.

13. The non-transitory computer-readable storage medium of claim 11 , wherein the encrypted version of the link key and the access key are provided using different communication channels.

14. A method for securely distributing a link key to a gateway comprising:

by an electronic device:

while an administrator is logged in via a computer that is different from the electronic device:

receiving, at the electronic device and associated with a second computer, the link key using a secure widget, wherein the link key facilitates secure communication via a link;

after receiving the link key, creating, at the electronic device, an access key;

generating, at the electronic device, an encrypted version of the link key based at least in part on the access key and the link key, wherein the access key enables access to the link key based at least in part on the encrypted version of the link key; and

storing, at the electronic device, at least two of the link key, the access key and the encrypted version of the link key in a trusted envelope or partition in a memory of the electronic device with encryption;

when the administrator logs out, disabling access to the trusted envelope, wherein access to the stored at least two of the link key, the access key and the encrypted version of the link key in the trusted envelope or the partition in the memory with encryption is only enabled when the administrator is logged in;

when the administrator logs in via the computer again:

re-enabling access to the trusted envelope;

when the electronic device receives information that indicates that the gateway has joined a network, providing, from the electronic device, the encrypted version of the link key addressed to the gateway; and

when the electronic device receives, associated with the gateway, an access request for the access key, providing, from the electronic device, the access key addressed to the gateway, wherein the access request is associated with an authorized second electronic device that is associated with the gateway and an entity that is different than the administrator; and

when the administrator logs out again, disabling access to the trusted envelope.

15. The method of claim 14 , wherein the method comprises storing metadata with the link key, the access key and the encrypted version of the link key in the trusted envelope; and

wherein the metadata specifies when the access key was created and how long it is valid or when the access key expires.

16. The method of claim 14 , wherein the access key is created based at least in part on a policy or privilege associated with the administrator.

17. The method of claim 14 , wherein the encrypted version of the link key and the access key are provided using different communication channels.

18. The method of claim 14 , wherein the access key is a random or a pseudorandom number.

19. The method of claim 14 , wherein the access key is further provided based at least in part on an authorization associated with the administrator, an identifier of the second electronic device or both.

Assignments (9)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 058843/0712 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC; COMMSCOPE NORTH CAROLINA, LLC (F/K/A COMMSCOPE, INC. OF NORTH CAROLINA); COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 074591/0389 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 058875/0449 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 069743/0057 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 066399/0561 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
ABL SECURITY AGREEMENT Recorded Nov 15, 2021
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 058843/0712 →
TERM LOAN SECURITY AGREEMENT Recorded Nov 15, 2021
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 058875/0449 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 2, 2021
From: PANCRAS, SIBY MATTHEW TARIGOPLA; MALINEN, JARI T.
To: ARRIS ENTERPRISES LLC
Reel/Frame 057371/0840 →
Continuity (2)
Provisional Application 62906063 · Sep 25, 2019
Related Publication 20210091941A1 · Mar 25, 2021