IP Library › Granted Patent US 12,395,524
Granted Patent B2
US 12,395,524 · App. 17/968,310 · Granted Aug 19, 2025

Mitigation of a denial of service attack in a device provisioning protocol (DPP) network

Inventors: Amogh Guruprasad Deshmukh (Santa Clara, CA); Daniel N. Harkins (Santa Clara, CA); Zhijun Ren (Beijing, CN); Guangning Qin (Beijing, CN)
Assignee: Hewlett Packard Enterprise Development LP
H04L63/1458H04L63/0442H04L63/1416H04L2463/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,395,524
App. No.
17/968,310
Granted
Aug 19, 2025
Kind
B2
Abstract

Systems and methods are provided for mitigating denial-of-service attacks that can disrupt onboarding internet-of-things (IoT) devices onto a network and ensuring legitimate IoT devices are onboarded. Example implementations include receiving, at an access point (AP) from a device, a chirp signal comprising a hash of data including a first public key of an IoT device. Upon verification of the first public key, the AP generates a context based on a first public key received from the authenticator. The context comprises information for onboarding the IoT device without subsequent communications between the AP, configurator and the authenticator. The AP can use the context to create and transmit authentication authorization requests responsive to chirp signals. In some examples, a chirp table can be created by a configurator for tracking severing APs. The chirp table can be utilized in provisioning APs for future chirp signals as needed.

Claims (54)

1. A method comprising:

receiving, by an access point (AP) from a configurator, a message indicative that the AP is provisioned for onboarding an internet-of-things (IoT) device, the message comprising a hash of data including a first public key of the IoT device and the message is received based on receipt of another message by the configurator from the AP or another AP responsive to the AP or the other AP receiving a chirp signal comprising the hash of data including the first public key of the IoT device;

based on being provisioned for onboarding the IoT device, receiving, by the AP, verification of the first public key for the IoT device from an authentication server based on the hash of data including the first public key of the IoT device;

generating, by the AP, a context based on the first public key, wherein the context comprises information for onboarding the IoT device on to a network without subsequent communications between the AP and the configurator and the AP and the authenticator; and

transmitting, by the AP, an authentication request responsive to each of a first plurality chirp signals based on the context, the authorization request comprising the hash of the first public key;

receiving, by the AP, a one or more chirp signals of the first plurality of chirp signals from a device other than the IoT device;

receiving, by the AP, a chirp signal of the first plurality of chirp signals from the IoT device after receiving the first one or more chirp signals;

receiving, by the AP, an authentication response from the IoT device based on an authorization request that is responsive to the chirp signal from the IoT device; and

onboarding, by the AP, the IoT device onto the network based on the received authentication response.

2. The method of claim 1 , further comprising:

receiving, by the AP, an authentication response from the IoT device based on one of the authentication requests;

receiving, by the AP, a second plurality of chirp signals after receiving the authentication response; and

responsive to receiving the authentication response, ignoring the second plurality of chirp signals.

3. The method of claim 2 , further comprising:

onboarding, by the AP, the IoT device onto the network based on the received authentication response.

4. The method of claim 1 , wherein generating the context by the AP is in response to receiving, by the AP, the verification of the first public key for the IoT device from the authentication server.

5. The method of claim 1 , further comprising:

receiving, by the AP, a chirp signal comprising the hash of data including the first public key of the IoT device from a device other than the IoT device; and

responsive to receiving the chirp signal, reporting a chirping event to the configurator.

6. The method of claim 1 , further comprising:

after a timeout period has elapsed:

deleting the context;

reporting a subsequent chirping event to the configurator responsive to receiving a subsequent chirp signal;

receiving a chirping event reject message from the configurator; and

in response to the chirping event reject message, generating another context based on the first public key, wherein the other context comprises information for onboarding the IoT device on to the network.

7. The method of claim 1 , wherein the chirp signal and each of the a first plurality chirp signals are Device Provisioning Protocol (DPP) presence announcement messages.

8. The method of claim 1 , wherein the first public key is a public bootstrapping key.

9. An access point, comprising:

a memory storing instructions; and

one or more processors communicatively coupled to the memory and configured to execute the instructions stored in the memory to:

receive, from a device, a chirp signal comprising a hash of data including a first public key of an internet-of-things (IoT) device for onboarding the IoT device onto a network;

based on receiving the chirp signal, receive verification of the first public key for the IoT device from an authentication server based on the hash of data including the first public key of the IoT device;

generate a context based on the first public key, wherein the context comprises information for onboarding the IoT device on to the network without subsequent communications with the configurator and the authenticator; and

transmit an authentication request responsive to each of a first plurality chirp signals based on the context, the authorization request comprising the hash of the first public key;

receive a chirping event reject message from the configurator; and

in response to the chirping event reject message, generate another context based on the first public key, wherein the other context comprises information for onboarding the IoT device on to a network.

10. The access point of claim 9 , wherein the chirp signal and each of the a first plurality chirp signals are Device Provisioning Protocol (DPP) presence announcement messages.

11. The access point of claim 9 , wherein the chirp signal is received from a device other than the IoT device.

12. The access point of claim 9 , wherein the one or more processors are further configured to execute the instructions to:

transmit a chirping event to a configurator in response to receiving the chirp signal; and

based on a response to the chirping event received from the configurator, send a key authorization request to the authentication server,

wherein the verification of the first public key of the IoT device from the authentication server is responsive to the key authorization request.

13. The access point of claim 9 , wherein the one or more processors are further configured to execute the instructions to:

receive an authentication response from the IoT device based on one of the authentication requests;

receive a second plurality of chirp signals after receiving the authentication response; and

responsive to receiving the authentication response, ignore the second plurality of chirp signals.

14. The access point of claim 9 , wherein the one or more processors are further configured to execute the instructions to:

onboard the IoT device onto the network based on the received authentication response.

15. The access point of claim 9 , wherein the one or more processors are further configured to execute the instructions to:

receive a one or more chirp signals of the first plurality of chirp signals from a device other than the IoT device;

receive a chirp signal of the first plurality of chirp signals from the IoT device after receiving the first one or more chirp signals;

receive an authentication response from the IoT device based on an authorization request that is responsive to the chirp signals from the IoT device; and

onboard the IoT device onto the network based on the received authentication response.

16. The access point of claim 9 , wherein generating the context is in response to receiving the verification of the first public key for the IoT device from the authentication server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2022
From: DESHMUKH, AMOGH GURUPRASAD; HARKINS, DANIEL N.; REN, ZHIJUN; QIN, GUANGNING
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 061457/0338 →
Continuity (1)
Related Publication 20240129337A1 · Apr 18, 2024
References Cited (14)
US 9094445B2 · Moore et al. · 2015 [cited by applicant]
US 10116692B2 · Huston, III et al. · 2018 [cited by applicant]
US 10728280B2 · Reddy et al. · 2020 [cited by applicant]
US 10911300B2 · Stationwala et al. · 2021 [cited by applicant]
US 20140075567A1 · Raleigh et al. · 2014 [cited by applicant]
US 20160112406A1 · Bugrov · 2016 [cited by examiner]
US 20180109418A1 · Cammarota · 2018 [cited by examiner]
US 20190166495A1 · Goeringer et al. · 2019 [cited by applicant]
US 20190306710A1 · Cammarota · 2019 [cited by examiner]
US 20200162904A1 · Jiang et al. · 2020 [cited by applicant]
US 20200336898A1 · Jiang et al. · 2020 [cited by applicant]
US 20210385778A1 · Ahn · 2021 [cited by examiner]
US 20230164671A1 · Vig · 2023 [cited by examiner]
Wifi Alliance, “Wi-Fi Easy Connect™ Specification Version 2.0”, 2020, 226 pages. [cited by applicant]