IP Library Granted Patent US 12,418,530
Granted Patent B2
US 12,418,530 · App. 17/976,212 · Granted Sep 16, 2025

Automatic periodic pre-shared key update

Inventor: Wei Kao (Taipei, TW)
Assignee: Ruckus IP Holdings LLC
H04L63/0892H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,530
App. No.
17/976,212
Granted
Sep 16, 2025
Kind
B2
Abstract

During operation, the computer may obtain an access acceptance message, where the access acceptance message indicates that the electronic device has been authenticated and allowed to securely access a network, and where the authentication is based at least in part on a passphrase associated with a user of an electronic device. For example, the computer may receive the acceptance message from the computer network device or a second computer (such as a controller). Alternatively, the computer may obtain the access acceptance message while performing the authentication. Then, the computer may automatically provide a second passphrase addressed to a computer network device and the electronic device, where the second passphrase replaces the passphrase during a current session of the electronic device in the network. Moreover, when the current session ends, the computer may automatically revert to the passphrase for subsequent authentication of the user.

Claims (50)

1. A computer, comprising:

an interface circuit configured to communicate with a computer network device and an electronic device;

a processor coupled to the interface circuit; and

memory, coupled to the processor, configured to store program instructions, wherein, when executed by the processor, the program instructions cause the computer to perform operations comprising:

obtaining an access acceptance message, wherein the access acceptance message indicates that the electronic device has been authenticated and allowed to securely access a network, and wherein the authentication is based at least in part on a passphrase associated with a user of the electronic device;

automatically providing a second passphrase addressed to the computer network device and the electronic device, wherein the second passphrase replaces the passphrase during a current session of the electronic device in the network; and

when the current session ends, automatically reverting to the passphrase for subsequent authentication of the user, wherein the passphrase comprises a dynamic pre-shared key (DPSK) of the electronic device; and

wherein the authentication is compatible with Wi-Fi Protected Access (WPA) WPA3 and is based at least in part on a binding between the passphrase and the network.

2. The computer of claim 1 , wherein the operations comprise receiving, associated with the computer network device or a second computer, the acceptance message.

3. The computer of claim 2 , wherein the second computer comprises a controller of the computer network device or an authentication, authorization, and accounting (AAA) server.

4. The computer of claim 1 , wherein obtaining the access acceptance message comprises:

receiving an access request associated with the electronic device and via the computer network device, wherein the access request comprises passphrase parameters corresponding to the passphrase, and the passphrase parameters comprise inputs to a cryptographic calculation and an output of the cryptographic calculation;

calculating one or more second outputs of the cryptographic calculation based at least in part on the inputs and one or more stored passphrases; and

when there is a match between one of the one or more second outputs and the output, selectively providing, addressed to the electronic device and via the computer network device, the access acceptance message, wherein the access acceptance message includes information for establishing the secure access of the electronic device to the network.

5. The computer of claim 4 , wherein the passphrase parameters comprise one or more of: a random number associated with the electronic device, a random number associated with the computer network device, the output of the cryptographic calculation, the identifier of the electronic device, or an identifier of the computer network device.

6. The computer of claim 1 , wherein the second passphrase is automatically provided after a predefined time interval has elapsed after successful authentication of the electronic device.

7. The computer of claim 1 , wherein the automatic providing of the second passphrase comprises:

generating the second passphrase; or

selecting the second passphrase from a set of predefined or predetermined second passphrases.

8. The computer of claim 1 , wherein the computer network device comprises an access point, a router or a switch.

9. The computer of claim 1 , wherein the network comprises a wireless local area network (WLAN) or a virtual network that may be associated with a location.

10. The computer of claim 1 , wherein the authentication is compatible with one or more of: Wi-Fi Protected Access (WPA), WPA2 or WPA3.

11. A non-transitory computer-readable storage medium for use in conjunction with a computer, the computer-readable storage medium storing program instructions that, when executed by the computer, cause the computer to perform operations comprising:

obtaining an access acceptance message, wherein the access acceptance message indicates that an electronic device has been authenticated and allowed to securely access a network, and wherein the authentication is based at least in part on a passphrase associated with a user of the electronic device;

automatically providing a second passphrase addressed to a computer network device and the electronic device, wherein the second passphrase replaces the passphrase during a current session of the electronic device in the network; and

when the current session ends, automatically reverting to the passphrase for subsequent authentication of the user, wherein the passphrase comprises a dynamic pre-shared key (DPSK) of the electronic device; and

wherein the authentication is compatible with Wi-Fi Protected Access (WPA) WPA3 and is based at least in part on a binding between the passphrase and the network.

12. The non-transitory computer-readable storage medium of claim 11 , wherein the second passphrase is automatically provided after a predefined time interval has elapsed after successful authentication of the electronic device.

13. The non-transitory computer-readable storage medium of claim 11 , wherein the automatic providing of the second passphrase comprises:

generating the second passphrase; or

selecting the second passphrase from a set of predefined or predetermined second passphrases.

14. The non-transitory computer-readable storage medium of claim 11 , wherein obtaining the access acceptance message comprises:

receiving an access request associated with the electronic device and via the computer network device, wherein the access request comprises passphrase parameters corresponding to the passphrase, and the passphrase parameters comprise inputs to a cryptographic calculation and an output of the cryptographic calculation;

calculating one or more second outputs of the cryptographic calculation based at least in part on the inputs and one or more stored passphrases; and

when there is a match between one of the one or more second outputs and the output, selectively providing, addressed to the electronic device and via the computer network device, the access acceptance message, wherein the access acceptance message includes information for establishing the secure access of the electronic device to the network.

15. A method for automatically updating a passphrase, comprising:

by a computer:

obtaining an access acceptance message, wherein the access acceptance message indicates that an electronic device has been authenticated and allowed to securely access a network, and wherein the authentication is based at least in part on the passphrase associated with a user of the electronic device;

automatically providing a second passphrase addressed to a computer network device and the electronic device, wherein the second passphrase replaces the passphrase during a current session of the electronic device in the network; and

when the current session ends, automatically reverting to the passphrase for subsequent authentication of the user, wherein the passphrase comprises a dynamic pre-shared key (DPSK) of the electronic device; and

wherein the authentication is compatible with Wi-Fi Protected Access (WPA) WPA3 and is based at least in part on a binding between the passphrase and the network.

16. The method of claim 15 , wherein the second passphrase is automatically provided after a predefined time interval has elapsed after successful authentication of the electronic device.

17. The method of claim 15 , wherein the automatic providing of the second passphrase comprises:

generating the second passphrase; or

selecting the second passphrase from a set of predefined or predetermined second passphrases.

18. The method of claim 15 , wherein obtaining the access acceptance message comprises:

receiving an access request associated with the electronic device and via the computer network device, wherein the access request comprises passphrase parameters corresponding to the passphrase, and the passphrase parameters comprise inputs to a cryptographic calculation and an output of the cryptographic calculation;

calculating one or more second outputs of the cryptographic calculation based at least in part on the inputs and one or more stored passphrases; and

when there is a match between one of the one or more second outputs and the output, selectively providing, addressed to the electronic device and via the computer network device, the access acceptance message, wherein the access acceptance message includes information for establishing the secure access of the electronic device to the network.

19. The method of claim 15 , wherein the second computer comprises a controller of the computer network device or an authentication, authorization, and accounting (AAA) server.

Assignments (8)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067620/0675 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 074593/0001 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067620/0717 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 069743/0220 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2024
From: KAO, WEI
To: ARRIS ENTERPRISES LLC
Reel/Frame 068504/0711 →
PATENT SECURITY AGREEMENT (TERM) Recorded Jun 4, 2024
From: RUCKUS IP HOLDINGS LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067620/0717 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jun 4, 2024
From: RUCKUS IP HOLDINGS LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067620/0675 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 066399/0561 →
Continuity (1)
Related Publication 20240146732A1 · May 2, 2024
References Cited (15)
US 7882349B2 · Cam-Winget · 2011 [cited by examiner]
US 8290163B2 · Chang · 2012 [cited by examiner]
US 11627464B2 · Ficara · 2023 [cited by examiner]
US 12047240B2 · Hansen · 2024 [cited by examiner]
US 20040168054A1 · Halasz · 2004 [cited by examiner]
US 20100071043A1 · Babula · 2010 [cited by examiner]
US 20110047607A1 · Chen · 2011 [cited by examiner]
US 20140025497A1 · Jha · 2014 [cited by examiner]
US 20160066181A1 · Henry · 2016 [cited by examiner]
US 20170041859A1 · Martin · 2017 [cited by examiner]
US 20190356482A1 · Nix · 2019 [cited by examiner]
US 20210075618A1 · Stephenson · 2021 [cited by examiner]
US 20230195876A1 · Keret · 2023 [cited by examiner]
US 20230319564A1 · Mohammed · 2023 [cited by examiner]
US 20240098492A1 · Hsu · 2024 [cited by examiner]