IP Library Granted Patent US 7,669,232
Granted Patent B2
US 7,669,232 · App. 12/339,688 · Granted Feb 23, 2010

Dynamic authentication in secured wireless networks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,669,232
App. No.
12/339,688
Granted
Feb 23, 2010
Kind
B2
Abstract

Systems and methods for authentication using paired dynamic secrets in secured wireless networks are provided. Each authenticated user is assigned a random secret generated so as to be unique to the user. The secret is associated with a wireless interface belonging to the user, so that no other wireless interface may use the same secret to access the network. The secret may be updated either periodically or at the request of a network administrator, and reauthentication of the wireless network may be required.

Claims (41)

1. A method for pairing dynamic secrets in a secured wireless network, the method comprising:

identifying an access profile belonging to an authenticated user, the user having been authenticated as being authorized to access the secured wireless network, the access profile being specific to the authenticated user;

randomly generating a secret for the authenticated user, wherein the secret is unique to the authenticated user;

storing the secret in memory, the secret being stored in association with the identified access profile belonging to the authenticated user;

deriving one or more security keys from the secret;

saving the one or more derived security keys to a table in memory, the table including information concerning the security keys and whether each security key is associated with a wireless interface device;

generating an executable for configuring the wireless interface device to access the secured wireless network;

downloading the executable and at least one of the security keys as a part of the access profile to a wireless interface device belonging to the authenticated user, wherein executing the transferred executable on the wireless interface device configures the wireless interface device to access the secured wireless network using the security key and the access profile belonging to the authenticated user; and

updating the table to include the association between the security key and the wireless interface device belonging to the authenticated user and further associated with the access profile, wherein use of the security key to access the secured wireless network is restricted to the associated wireless interface device belonging to the authenticated user as identified by the associated access profile.

2. The method of claim 1 , wherein updating the table includes storing the association between the security key and an identification of the wireless interface.

3. The method of claim 1 , wherein updating the table includes storing the association between the security key and a radio of the wireless interface device.

4. The method of claim 1 , further comprising updating the secret.

5. The method of claim 2 , wherein the wireless interface identification includes a MAC address.

6. The method of claim 4 , wherein updating the secret occurs after a predefined period of time.

7. The method of claim 4 , wherein updating the secret occurs upon request by a system administrator.

8. The method of claim 4 , wherein updating the secret comprises:

generating a new random secret unique to the authenticated user;

storing the new secret in memory with the access profile belonging to the user; and

requiring that the wireless interface be reauthenticated by the authenticated user before associating the new secret to the wireless interface.

9. The method of claim 8 , wherein requiring the wireless interface to be re-authenticated comprises terminating the wireless connection between the wireless interface and the secured wireless network.

10. A system for pairing dynamic secrets in a secured wireless network, the system comprising:

a secret generation module stored in memory and executable by a processor to:

randomly generate a secret unique to an authenticated user, the user having been authenticated as being authorized to access the secured wireless network, and

derive one or more security secrets from the secret;

a secret database configured to store information concerning the secret in association with an access profile identified as belonging to the authenticated user, the access profile being specific to the authenticated user, the secret database comprising a table including information concerning the re security keys and whether each security key is associated with a wireless interface device;

an access profile generation module executable by the processor to generate an access profile for the authenticated user;

an executable generation module executable by the processor to generate an executable for using the access profile and the security key to configure the wireless interface to access the secured wireless network; and

a binding module stored in memory and executable by the processor to download the executable and at least one of the security keys as part of the access profile to a wireless interface device belonging to the authenticated user,

wherein executing the transferred executable on the wireless interface device configures the wireless interface device to access the secured wireless network using the security key and the access profile belonging to the authenticated user, and

wherein the table is updated to include the association between the security key and the wireless interface device belonging to the authenticated user and further associated with the access profile, wherein use of the security key to access the secured wireless network is restricted to the associated wireless interface device belonging to the authenticated user as identified by the associated access profile.

11. The system of claim 10 , wherein the secret generation module is further executable by the processor to update the secret by generating a new random secret unique to the user.

12. A computer-readable storage medium having embodied thereon a program, the program being executable by a computer processor to perform a method for pairing dynamic secrets in a secured wireless network, the method comprising:

identifying an access profile belonging to an authenticated user, the user having been authenticated as being authorized to access the secured wireless network, the access profile being specific to the authenticated user;

randomly generating a secret for the authenticated user, wherein the secret is unique to the authenticated user;

storing the secret in memory, the secret being stored in association with the identified access profile belonging to the authenticated user, the access profile;

deriving one or more security keys from the secret;

saving the one or more derived security keys to a table in memory, the table including information concerning the security keys and whether each security key is associated with a wireless interface device;

generating an executable for configuring the wireless interface device to access the secured wireless network;

downloading the executable and at least one of the security keys as a part of the access profile to a wireless interface device belonging to the authenticated user, wherein executing the transferred executable on the wireless interface device configures the wireless interface device to access the secured wireless network using the security key and the access profile belonging to the authenticated user; and

updating the table to include the association between the security key and the wireless interface belonging to the authenticated user, wherein use of the security key to access the secured wireless network is restricted to the associated wireless interface belonging to the authenticated user as identified by the associated access profile.

13. The computer-readable storage medium of claim 12 , wherein the program is further executable by the processor to update the secret, wherein the wireless interface must be reauthenticated by the user.

Assignments (16)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 066399/0561 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 8, 2019
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: RUCKUS WIRELESS, INC.
Reel/Frame 048817/0832 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2018
From: RUCKUS WIRELESS, INC.
To: ARRIS ENTERPRISES LLC
Reel/Frame 046730/0854 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2018
From: RUCKUS WIRELESS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 046379/0431 →
RELEASE OF SECURITY INTEREST Recorded Mar 17, 2017
From: SILICON VALLEY BANK; GOLD HILL VENTURE LENDING 03, LP
To: RUCKUS WIRELESS, INC.
Reel/Frame 042038/0600 →
RELEASE OF SECURITY INTEREST Recorded Jan 26, 2017
From: SILICON VALLEY BANK
To: RUCKUS WIRELESS, INC.
Reel/Frame 041513/0118 →
SECURITY AGREEMENT Recorded Oct 14, 2011
From: RUCKUS WIRELESS, INC.
To: GOLD HILL VENTURE LENDING 03, LP; SILICON VALLEY BANK
Reel/Frame 027063/0412 →
SECURITY AGREEMENT Recorded Oct 14, 2011
From: RUCKUS WIRELESS, INC.
To: SILICON VALLEY BANK
Reel/Frame 027062/0254 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2009
From: JOU, TYAN-SHU; SHEU, MING; YANG, BO-CHIEH; LIN, TIAN-YUAN; KUO, TED TSEI
To: RUCKUS WIRELESS, INC.
Reel/Frame 023383/0757 →