IP Library Granted Patent US 9,071,438
Granted Patent B2
US 9,071,438 · App. 13/902,074 · Granted Jun 30, 2015

System for efficiently handling cryptographic messages containing nonce values in a wireless connectionless environment

Inventors: Todd Lagimonier (Delray Beach, FL); Jim Voris (Cockeysville, MD)
Assignee: TeleCommunication Systems, Inc.
H04L9/321H04L63/04H04L63/14H04L63/1408H04W12/02H04W12/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,071,438
App. No.
13/902,074
Granted
Jun 30, 2015
Kind
B2
Abstract

A secure communication module that accepts a cryptographic message if a nonce value for the received message is greater than the largest nonce value yet seen. If the received nonce value is not the largest nonce value yet seen, the secure communication module compares the received nonce value with a nonce acceptance window. If the nonce value falls outside the nonce acceptance window, the secure communication module rejects the received message and assumes a replay attack. Alternatively, if the nonce value falls within the nonce acceptance window, the secure communication module compares the received nonce value with a replay window mask. If comparison with the replay window mask indicates that the received nonce value has been seen before, the secure communication module rejects the received message and assumes a replay attack. Otherwise, the secure communication module accepts the message and adds the received nonce value to the replay window mask.

Claims (32)

1. A method of processing out-of-order data packets, comprising:

obtaining a largest nonce value from among a plurality of nonce values of previous data packets;

adjusting, at a receiving device, a size of a range of acceptable nonce values within an acceptance window based around said largest nonce value;

accepting, at said receiving device, a newly received out-of-order data packet including a newly received nonce value when said newly received nonce value is within said acceptance window; and

resetting said largest nonce value to said newly received nonce value when said accepted, newly received nonce value exceeds said largest nonce value.

2. The method of processing out-of-order data packets according to claim 1 , further comprising:

adjusting said size of said range of acceptable nonce values within said acceptance window based on said reset largest nonce value.

3. The method of processing out-of-order message packets according to claim 1 , wherein:

said largest nonce value is associated with a first session.

4. The method of processing out-of-order message packets according to claim 1 , wherein:

said largest nonce value is associated with a second session.

5. The method of processing out-of-order message packets according to claim 1 , further comprising:

generating a new cryptographic key.

6. A method of processing out-of-order data packets, comprising:

obtaining a largest nonce value from among a plurality of nonce values of previous data packets;

adjusting, at a receiving device, a size of a range of acceptable nonce values within an acceptance window based around said largest nonce value;

accepting, at said receiving device, a newly received out-of-order data packet including a newly received nonce value when said newly received nonce value is within said acceptance window; and

adjusting said size of said range of acceptable nonce values within said acceptance window when said accepted, newly received nonce value exceeds said largest nonce value.

7. The method of processing out-of-order data packets according to claim 6 , further comprising:

resetting said largest nonce value to said newly received nonce value when said accepted, newly received nonce value exceeds said largest nonce value.

8. The method of processing out-of-order message packets according to claim 6 , wherein:

said largest nonce value is associated with a first session.

9. The method of processing out-of-order message packets according to claim 6 , wherein:

said largest nonce value is associated with a second session.

10. The method of processing out-of-order message packets according to claim 6 , further comprising:

generating a new cryptographic key.

11. A method of rejecting a replay attack in out-of-order data packets, comprising:

obtaining a largest nonce value from among a plurality of nonce values of previous data packets;

adjusting, at a receiving device, a size of a range of acceptable nonce values within an acceptance window based around said largest nonce value; and

rejecting, at said receiving device, a newly received out-of-order data packet including a newly received nonce value when said newly received nonce value is outside of said acceptance window.

12. The method of rejecting a replay attack in out-of-order data packets according to claim 11 , further comprising:

designating said newly received out-of-order data packet as a replay attack.

Assignments (5)
SECURITY AGREEMENT Recorded Mar 3, 2016
From: COMTECH EF DATA CORP.; COMTECH XICOM TECHNOLOGY, INC.; COMTECH MOBILE DATACOM CORPORATION; TELECOMMUNICATION SYSTEMS, INC.
To: CITIBANK N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037993/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2013
From: LAGIMONIER, TODD; VORIS, JIM
To: AETHER SYSTEMS, INC.
Reel/Frame 030482/0904 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2013
From: AETHER SYSTEMS, INC.
To: TSYS ACQUISITION CORP.
Reel/Frame 030482/0970 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2013
From: TELECOMMUNICATION SYSTEMS CORPORATION OF MARYLAND
To: TELECOMMUNICATION SYSTEMS, INC.
Reel/Frame 030483/0080 →
CHANGE OF NAME Recorded May 24, 2013
From: TSYS ACQUISITION CORP.
To: TELECOMMUNICATION SYSTEMS CORPORATION OF MARYLAND
Reel/Frame 030490/0429 →
Continuity (4)
Continuation 13447902 · Apr 16, 2012
Continuation 12926840 · Dec 13, 2010
Continuation 09932982 · Aug 21, 2001
Related Publication 20130339737A1 · Dec 19, 2013