IP Library Granted Patent US 8,670,749
Granted Patent B2
US 8,670,749 · App. 13/209,572 · Granted Mar 11, 2014

Enhancing security in a wireless network

Inventors: Wallace A. Pratt, Jr. (Pflugerville, TX); Mark J. Nixon (Round Rock, TX); Eric D. Rotvold (West St. Paul, MN); Robin S. Pramanik (Karlsruhe, DE); Thomas L. Phinney (Glendale, AZ); Tomas P. Lennvall (Vasteras, SE); Yuri Zats (Menlo Park, CA); Frederick Enns (Menlo Park, CA)
Assignee: Hart Communication Foundation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,670,749
App. No.
13/209,572
Granted
Mar 11, 2014
Kind
B2
Abstract

A method of enhancing security in a wireless mesh communication network operating in a process control environment and including a plurality of wireless network devices includes processing a join request from a wireless device wishing to join the wireless mesh communication network, providing a limited network functionality to the wireless device if the join request is granted, requesting a complete approval of the wireless device; and granting a full network functionality to the wireless device if the complete approval of the wireless device is received.

Claims (25)

1. A method of enhancing security of a wireless communication protocol servicing a plurality of wireless network devices in a mesh communication network, wherein the mesh communication network operates in a process control environment, the method comprising:

defining a communication timeslot of a predetermined duration;

generating a network schedule including at least one superframe having repeating superframe cycles, each having a number of communication timeslots; wherein each of the plurality of wireless network devices transmits and receives data according to the network schedule;

maintaining an absolute slot number indicative of a number of communication timeslots scheduled since a start time of the mesh communication network; and

sending a data packet associated with one of a plurality of layers associated with the wireless communication protocol from one of the plurality of wireless network devices to another one of the plurality of wireless network devices, including:

updating a network key at a time based on the absolute slot number (ASN), wherein a respective copy of the ASN is maintained at each wireless network device and the respective copy of the ASN is synchronized with a master ASN maintained at a network manager; and

generating a message integrity code for the data packet using the updated network key.

2. A method of enhancing security of a wireless communication protocol servicing a plurality of wireless network devices in a mesh communication network, wherein the mesh communication network operates in a process control environment, the method comprising:

defining a communication timeslot of a predetermined duration;

generating a network schedule including at least one superframe having repeating superframe cycles, each having a number of communication timeslots; wherein each of the plurality of wireless network devices transmits and receives data according to the network schedule;

maintaining an absolute slot number indicative of a number of communication timeslots scheduled since a start time of the mesh communication network; and

sending a data packet associated with one of a plurality of layers associated with the wireless communication protocol from one of the plurality of wireless network devices to another one of the plurality of wireless network devices, including: generating a message integrity code for the data packet based on the absolute slot number, wherein generating the message integrity code includes:

forming a nonce value from the absolute slot number;

supplying the nonce value to a message integrity code generator; and

supplying a network key to the message integrity code generator, wherein the network key is shared by each fully operational wireless network device in the plurality of wireless network devices.

3. The method of claim 2 , wherein the data packet is associated with a data link layer included in the plurality of layers associated with the wireless communication protocol; and wherein generating the message integrity code further includes:

supplying a payload of the data packet to a non-enciphering input of the message integrity code generator; and

supplying an empty string to the enciphering input of the message integrity code generator.

4. The method of claim 1 , wherein the message integrity code is a first message integrity code, and wherein sending a data packet associated with one of a plurality of layers associated with the wireless communication protocol further includes:

enciphering the data packet on another one of the plurality of layers associated with the wireless communication protocol, including generating a second message integrity code associated with the another one of the plurality of layers based on a session-specific nonce counter.

5. A method of enhancing security of a wireless communication protocol servicing a plurality of wireless network devices in a mesh communication network, wherein the mesh communication network operates in a process control environment, the method comprising:

defining a communication timeslot of a predetermined duration;

generating a network schedule including at least one superframe having repeating superframe cycles, each having a number of communication timeslots; wherein each of the plurality of wireless network devices transmits and receives data according to the network schedule;

maintaining an absolute slot number indicative of a number of communication timeslots scheduled since a start time of the mesh communication network; and

sending a data packet associated with one of a plurality of layers associated with the wireless communication protocol from one of the plurality of wireless network devices to another one of the plurality of wireless network devices, including: generating a message integrity code for the data packet based on the absolute slot number, wherein generating the message integrity code for the data packet based on the absolute slot number includes merging the absolute slot number with a source address associated with the data packet.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2017
From: FIELDBUS FOUNDATION; HART COMMUNICATION FOUNDATION
To: FIELDCOMM GROUP, INC.
Reel/Frame 042822/0065 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2013
From: ENNS, FREDERICK
To: DUST NETWORKS, INC.
Reel/Frame 031652/0522 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2013
From: ZATS, YURI
To: DUST NETWORKS, INC.
Reel/Frame 031653/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2013
From: PRATT, WALLACE A., JR.; NIXON, MARK J.; ROTVOLD, ERIC D.; PRAMANIK, ROBIN S.; PHINNEY, THOMAS L.; LENNVALL, TOMAS P.
To: HART COMMUNICATION FOUNDATION
Reel/Frame 031633/0934 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2013
From: PRATT, WALLACE A., JR.; NIXON, MARK J.; ROTVOLD, ERIC D.; PRAMANIK, ROBIN S.; PHINNEY, THOMAS L.; LENNVALL, TOMAS P.
To: HART COMMUNICATION FOUNDATION
Reel/Frame 030400/0497 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2012
From: DUST NETWORKS, INC.
To: HART COMMUNICATIONS FOUNDATION
Reel/Frame 028098/0278 →
Continuity (3)
Division 12101021 · Apr 10, 2008
Provisional Application 60911795 · Apr 13, 2007
Related Publication 20110302635A1 · Dec 8, 2011