US2003235309A1PendingUtilityA1
Local area network
Priority: Mar 8, 2002Filed: Mar 10, 2003Published: Dec 25, 2003
Est. expiryMar 8, 2022(expired)· nominal 20-yr term from priority
H04W 12/04H04L 63/08H04L 63/0876H04W 12/71H04L 9/0833H04W 84/18H04W 12/06H04L 63/104H04L 63/065H04L 9/0838H04L 63/0471H04L 9/006H04L 9/00H04L 63/061H04L 9/08H04L 63/0428
47
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method and system for distributed security for a plurality of devices in a communication network, each of the devices being responsible for generating, distributing and controlling its own keys for access to the communication network and using the keys to establish a trusted network, each device's membership to the communication network being checked periodically by other devices by using a challenge response protocol to establish which devices are allowed access to the communication network and the trusted network.
Claims
exact text as granted — not AI-modifiedThe embodiments of the invention in which an exclusive property or privilege is claimed are defined as follows:
1 . A method of establishing and maintaining distributed security between a plurality of devices in an ad hoc network, the method having the steps of;
associating each device with a unique device address; assigning to one of said devices a control function to control access by other devices to said network; each of said devices generating a public key for distribution to other devices; each of said devices authenticating itself periodically with said other devices in order to determine status of said other devices; arranging said devices into a plurality of trust groups, each group having a group key for distribution within said trust group; associating a trust level to each of said devices; each of said devices using said public key and said group key to perform key agreement in order to establish a secure communication channel with said other devices in said group; whereby each of said devices is responsible for its own security by generating, distributing its own keys to said other devices.
2 . The method of claim 1 wherein said device determines a source of said group key.
3 . The method of claim 2 wherein when said source is a device in said trust group then said group key is used for encryption and decryption of data transmitted between said devices.
4 . The method of claim 2 wherein when said source is a device excluded trust group then said group key is used decryption of data transmitted to said device.
5 . The method of claim 1 wherein step of determining status of said other devices includes a further step of determining which of said devices are active and capable of participating in said network.
6 . The method of claim 1 wherein step of determining status of said other devices includes a further step of using a challenge response protocol using said group key to establish whether said other devices are allowed access to said network in accordance with said control function.
7 . The method of claim 1 wherein said unique device address includes a device ID or a local ID.
8 . The method of claim 7 wherein said device ID is an IEEE MAC address and said local ID is an n-bit address unique to said group.
9 . A method of establishing and maintaining distributed security between one correspondent and another correspondent, said correspondents being members of different ad hoc networks and forming a group of communicating correspondents, the method having the steps of;
associating said one correspondent and said other correspondent with a unique device address; controlling access to said different ad hoc networks; each ad hoc network having a gateway and transferring traffic between said correspondents via said gateways; said one correspondent generating a public key for distribution to said other correspondent; said one correspondent authenticating itself periodically with said other correspondent in order to determine status of said other correspondent; determining a group key for distribution to said correspondents in accordance to said step of controlling access; associating a trust level to each of said correspondents; each of said correspondents using said public key and said group key for performing key agreement in order to establish secure communication within said group; whereby each of said correspondents is responsible for its own security by generating, distributing its own keys to said other devices.
10 . The method of claim 9 wherein said step of transferring traffic includes a further step of associating each of said correspondents with a router for storing routing information having instructions for routing traffic from said one correspondent to said other correspondent.
11 . The method of claim 10 wherein said routers query each other periodically in order to update and maintain said routing information.
12 . The method of claim 1 I wherein said step of determining said status of said other correspondent includes a further step of using a challenge response protocol to establish whether said other correspondent is allowed access to said different ad hoc network having said one correspondent, in accordance with said control function.
13 . A distributed security system for a plurality of devices in a communication network, each of said devices being responsible for generating, distributing and controlling its own keys for access to said communication network and using said keys to establish a trusted network, each device's membership to said communication network being checked periodically by other devices by using a challenge response protocol to establish which devices are allowed access to said communication network and said trusted network.
14 . The system of claim 13 wherein each device includes a security manager having the functions of generating said keys and distributing said keys to selected devices in said trusted network.
15 . The system of claim 14 wherein said trusted network is associated with a level of trust.
16 . The system of claim 14 wherein said security manager determines a source of said keys such that said keys from a device within said trusted network may be used for encryption and decryption of data, and said keys from a device excluded from said trusted network may be used decryption of said data.
17 . The system of claim 16 wherein said security manager foregoes decrypting said data when said keys are from a device excluded from said trusted network.
18 . The system of claim 15 wherein an outcome of said periodic checking is recorded by said security manager in order to maintain and update a membership list, and adjust said level of trust accordingly.
19 . The system of claim 17 wherein different trusted networks may be established within said network based on differing levels of trust.
20 . The system of claim 13 wherein said communication network includes a plurality of ad hoc networks and said distributed security system is established between devices in different ad hoc networks.
21 . The system of claim 19 wherein each ad hoc network includes a controller to controlling access to each of said ad hoc networks, each ad hoc network having a gateway for transferring traffic therebetween, and device having a router for storing routing information having instructions for routing traffic from said one device to another device via said gateways and other routers.Join the waitlist — get patent alerts
Track US2003235309A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.