IP Library › Granted Patent US 12,261,835
Granted Patent B2
US 12,261,835 · App. 18/408,969 · Granted Mar 25, 2025

Authentication of networked devices having low computational capacity

Inventors: Kumaran Vijayasankar (Allen, TX); Oliver Shih (Pittsburgh, PA); Arvind K. Raghu (Dallas, TX); Ramanuja Vedantham (Allen, TX); Xiaolin Lu (Plano, TX)
Assignee: TEXAS INSTRUMENTS INCORPORATED
H04L63/0823H04L9/3268H04L63/0428H04L63/0435H04L63/0442H04L63/062H04L63/0884
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,261,835
App. No.
18/408,969
Granted
Mar 25, 2025
Kind
B2
Abstract

Authentication of a networked device with limited computational resources for secure communications over a network. Authentication of the device begins with the supplicant node transmitting a signed digital certificate with its authentication credentials to a proxy node. Upon verifying the certificate, the proxy node then authenticates the supplicant's credentials with an authentication server accessible over the network, acting as a proxy for the supplicant node. Typically, this verification includes decryption according to a public/private key scheme. Upon successful authentication, the authentication server creates a session key for the supplicant node and communicates it to the proxy node. The proxy node encrypts the session key with a symmetric key, and transmits the encrypted session key to the supplicant node which, after decryption, uses the session key for secure communications. In some embodiments, the authentication server encrypts the session key with the symmetric key.

Claims (40)

1. A method comprising:

receiving, by a first device and from a second device, an authentication credential;

determining, by the first device, that the authentication credential is associated with a third device that is different from the second device;

authenticating, by the first device, the third device using the authentication credential;

after authenticating the third device, creating, by the first device, a session key for the third device;

encrypting, by the first device, the session key using a symmetric key;

transmitting, by the first device, the encrypted session key to the second device; and

establishing a communication session between the first device and the third device based on the encrypted session key.

2. The method of claim 1 , further comprising receiving, by the first device and from the second device, a node identifier associated with the third device, wherein determining that the authentication credential is associated with the third device comprises determining that the node identifier is not associated with the second device based on the node identifier.

3. The method of claim 1 , further comprising:

receiving, by the first device and from the second device, a node identifier associated with the third device;

encrypting the node identifier using the symmetric key; and

transmitting, by the first device, the encrypted node identifier to the second device.

4. The method of claim 3 , further comprising:

receiving, by the first device and from the second device, a nonce;

encrypting the nonce using the symmetric key; and

transmitting, by the first device, the encrypted nonce to the second device.

5. The method of claim 1 , wherein the symmetric key is pre-stored in the first device.

6. The method of claim 1 , further comprising:

receiving, by the second device, the authentication credential;

verifying, by the second device, the authentication credential using asymmetric key cryptography; and

in response to verifying the authentication credential, transmitting, by the second device, the authentication credential to the first device.

7. The method of claim 6 , wherein receiving, by the second device, the authentication credential comprises receiving, by the second device, the authentication credential from the third device.

8. The method of claim 6 , wherein receiving, by the second device, the authentication credential comprises receiving, by the second device, a digital certificate that comprises the authentication credential.

9. The method of claim 8 , wherein verifying the authentication credential comprises verifying the digital certificate computing a hash of a first portion of the digital certificate.

10. The method of claim 8 , wherein the digital certificate comprises a nonce.

11. The method of claim 8 , wherein the digital certificate comprises an encrypted portion and an unencrypted portion, wherein the encrypted portion comprises the authentication credential.

12. The method of claim 11 , wherein the unencrypted portion comprises a node identifier associated with the third device.

13. The method of claim 11 , wherein verifying the authentication credential comprises decrypting the digital certificate using asymmetric key cryptography.

14. The method of claim 11 , further comprising comparing the encrypted portion with the unencrypted portion to verify the digital certificate.

15. The method of claim 8 , wherein receiving, by the second device, the digital certificate comprises receiving, by the second device, the digital certificate from the third device.

16. The method of claim 8 , wherein the digital certificate is a signed digital certificate.

17. The method of claim 16 , wherein the signed digital certificate is signed by a certificate authority.

18. The method of claim 17 , wherein the signed digital certificate is stored at the third device.

19. The method of claim 1 , wherein the third device has lower computational capacity than the second device.

20. The method of claim 1 , further comprising:

receiving, by the second device, the encrypted session key; and

forwarding, by the second device, the encrypted session key to the third device.

21. The method of claim 1 , wherein receiving, by the first device and from the second device, the authentication credential comprises using a wireless link according to an IEEE 802.11 protocol.

22. The method of claim 1 , wherein receiving, by the first device and from the second device, the authentication credential comprises using a wireless link according to a Bluetooth or Bluetooth Low Energy (BLE) protocol.

Continuity (6)
Continuation 17963411 · Oct 11, 2022
Continuation 17159016 · Jan 26, 2021
Continuation 16252262 · Jan 18, 2019
Continuation 15222524 · Jul 28, 2016
Provisional Application 62211507 · Aug 28, 2015
Related Publication 20240146717A1 · May 2, 2024
References Cited (21)
US 6856800B1 · Henry · 2005 [cited by examiner]
US 7159016B2 · Baker · 2007 [cited by applicant]
US 8327128B1 · Prince et al. · 2012 [cited by applicant]
US 9787668B1 · Marathe · 2017 [cited by examiner]
US 20030237004A1 · Okamura · 2003 [cited by applicant]
US 20060080545A1 · Bagley · 2006 [cited by examiner]
US 20070280482A1 · Yan et al. · 2007 [cited by applicant]
US 20080232595A1 · Pietrowicz et al. · 2008 [cited by applicant]
US 20100033300A1 · Brandin · 2010 [cited by applicant]
US 20130091353A1 · Zhang et al. · 2013 [cited by applicant]
US 20140331297A1 · Innes · 2014 [cited by examiner]
US 20150281278A1 · Gooding et al. · 2015 [cited by applicant]
US 20150381621A1 · Innes et al. · 2015 [cited by applicant]
Jun-Cheol Park and Ah-Hyun Jun, “A lightweight IPsec adaptation for small devices in IP-based mobile networks,” 2006 8th International Conference Advanced Communication Technology, Phoenix Park, 2006, pp. 5 pp.-302, doi… [cited by applicant]
Cheikhrouhou, O., Laurent, M., Abdallah, A.B. et al. “An EAP-EHash authentication method adapted to resource constrained terminals.” Ann. Telecommun. 65, 271-284 (2010). https://doi.org/10.1007/s12243-009-0135-9. [cited by applicant]
Bormann, et al., “Terminology for Constrained-Node Networks”, RFC 7228 (Internet Engineering Task Force, May 2014), 17 pages. [cited by applicant]
Kent, S., “Privacy Enhancement for Internet Electronic Mail: Part II: Certificate-Based Key Management”, RFC 1224 Network Working Group, Feb. 1993, 28 pages. [cited by applicant]
Bersani, et al., “The EAP-PSK Protocol: A Pre-Shared Key Extensible Authentication Protocol (EAP) Method”, RFC 4764 (Network Working Group, Jan. 2007), 64 pages. [cited by applicant]
D. S. Wong and A. H. Chan, “Mutual authentication and key exchange for low power wireless communications,” 2001 MILCOM Proceedings Communications for Network-Centric Operations: Creating the Information Force (Cat. No. … [cited by applicant]
R. Hummen, H. Shafagh, S. Raza, T. Voig and K. Wehrle, “Delegation-based authentication and authorization for the IP-based Internet of Things,” 2014 Eleventh Annual IEEE International Conference on Sensing, Communicatio… [cited by applicant]
L. Harn and J. Ren, “Generalized Digital Certificate for User Authentication and Key Establishment for Secure Communications,” in IEEE Transactions on Wireless Communications, vol. 10, No. 7, pp. 2372-2379, Jul. 2011, d… [cited by applicant]