IP Library Granted Patent US 10,212,141
Granted Patent B2
US 10,212,141 · App. 15/297,332 · Granted Feb 19, 2019

Autonomous key update mechanism with blacklisting of compromised nodes for mesh networks

Inventors: Andrei Catalin Frincu (Pascani, RO); George Bogdan Alexandru (Bucharest, RO)
Assignee: NXP USA, Inc.
H04L63/061H04L63/101H04L63/126
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,212,141
App. No.
15/297,332
Granted
Feb 19, 2019
Kind
B2
Abstract

Various embodiments described herein relate to network key manager which is configured to manage keys in nodes in the network, wherein the network key manager including a memory configured to store an update data structure; a processor configured to: determine which nodes are blacklisted; generate the update data structure of volatile private keys for each node that is not blacklisted, wherein the volatile private key is based upon secret information associated with the node and an index, wherein the volatile private key is used for the index th key update; determine a neighbor node of the network key manager; remove the volatile private key for the neighbor node from the update data structure; encrypt the resulting update data structure and a new network key with the private key for the neighbor node to produce an encrypted message; and send the encrypted message to the neighbor node.

Claims (73)

1. A network key manager which is configured to manage keys in nodes in the network, wherein the network key manager comprises:

a memory configured to store an update data structure;

a processor configured to:

determine which nodes are blacklisted;

generate the update data structure of volatile private keys for each node that is not blacklisted, wherein the volatile private key is based upon secret information associated with the node and an index, wherein the volatile private key is used for the indexth key update;

determine a neighbor node of the network key manager;

remove the volatile private key for the neighbor node from the update data structure;

encrypt the resulting update data structure and a new network key with the private key for the neighbor node to produce an encrypted message; and

send the encrypted message to the neighbor node.

2. The network key manager according to claim 1 , wherein the processor is further configured to:

provision a new network node including:

generating secret information for the new network node;

sending the secret information, a current index, and a current network key to the new network node; and

storing the secret information for the new network node in the memory.

3. The network key manager according to claim 1 ,

wherein generating the update data structure of volatile private keys for each node that is not blacklisted includes generating the volatile private key by running a cryptographic hash on the secret information associated with the node and the index.

4. The network key manager according to claim 1 ,

wherein the processor is further configured to increment the index.

5. The network key manager according to claim 1 ,

wherein the secret information for the nodes is stored in a secret information data structure.

6. A network node which is configured to receive a network key update, comprising:

a memory configured to store a secret information associated with the network node;

a processor configured to:

receive an encrypted message including an update data structure and a new network key from a network key manager;

generate a decryption key based upon the secret information and a current index;

decrypt the encrypted message with the decryption key;

determine a neighbor node of the network node;

remove the volatile private key for the neighbor node from the update data structure;

encrypt the resulting update data structure and the new network key with the private key for the neighbor node to produce an encrypted neighbor message; and

send the encrypted neighbor message to the neighbor node.

7. The network node according to claim 6 ,

wherein the processor is further configured to receive a provisioning message including the secret information, a current index, and current network key.

8. The network node according to claim 6 ,

wherein the processor is further configured to increment the index.

9. The network node according to claim 6 , wherein the processor is if further configured to:

encrypt an acknowledgment message using the new network key identifying the network node; and

broadcast the encrypted acknowledgment message to the network.

10. The network node according to claim 6 , wherein the processor is if further configured to:

receive an encrypted acknowledgment message key identifying the network node;

decrypt the encrypted acknowledgement message using the new network key; and

remove the volatile private key for the identified node from the update data structure.

11. A method of managing keys in nodes in a network by a network key manager, the method comprising:

determining which nodes are blacklisted;

generating an update data structure of volatile private keys for each node that is not blacklisted, wherein the volatile private key is based upon secret information associated with the node and an index, wherein the volatile private key is used for the indexth key update;

determining a neighbor node of the network key manager;

removing the volatile private key for the neighbor node from the update data structure;

encrypting the resulting update data structure and a new network key with the private key for the neighbor node to produce an encrypted message; and

sending the encrypted message to the neighbor node.

12. The method claim 11 , wherein the further method comprises:

provisioning a new network node including:

generating secret information for the new network node;

sending the secret information, a current index, and a current network key to the new network node; and

storing the secret information for the new network node in the memory.

13. The method claim 11 ,

wherein generating the update data structure of volatile private keys for each node that is not blacklisted includes generating the volatile private key by running a cryptographic hash on the secret information associated with the node and the index.

14. The method claim 11 ,

wherein the further method comprises incrementing the index.

15. The method claim 11 ,

wherein the secret information for the nodes is stored in a secret information data structure.

16. A method of updating a network key in a network node, comprising:

receiving an encrypted message including an update data structure and a new network key from a network key manager;

generating a decryption key based upon a secret information associated with the network node and a current index;

decrypting the encrypted message with the decryption key;

determining a neighbor node of the network node;

removing the volatile private key for the neighbor node from the update data structure;

encrypting the resulting update data structure and the new network key with the private key for the neighbor node to produce an encrypted neighbor message; and

sending the encrypted neighbor message to the neighbor node.

17. The method according to claim 16 ,

wherein the processor is further configured to receive a provisioning message including the secret information, a current index, and current network key.

18. The method according to claim 16 , further comprising incrementing the index.

19. The method according to claim 16 , further comprising:

encrypting an acknowledgment message using the new network key identifying the network node; and

broadcasting the encrypted acknowledgment message to the network.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 040626 FRAME: 0683. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER AND CHANGE OF NAME EFFECTIVE NOVEMBER 7, 2016. Recorded Jan 12, 2017
From: NXP SEMICONDUCTORS USA, INC. (MERGED INTO); FREESCALE SEMICONDUCTOR, INC. (UNDER)
To: NXP USA, INC.
Reel/Frame 041414/0883 →
CHANGE OF NAME Recorded Nov 16, 2016
From: FREESCALE SEMICONDUCTOR INC.
To: NXP USA, INC.
Reel/Frame 040626/0683 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2016
From: FRINCU, ANDREI CATALIN; ALEXANDRU, GEIRGEL BOGDAN
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 040059/0856 →
Priority Claims (1)
RO A2016-00314 · May 4, 2016 · national
Continuity (1)
Related Publication 20170324716A1 · Nov 9, 2017