US2003235309A1PendingUtilityA1

Local area network

Priority: Mar 8, 2002Filed: Mar 10, 2003Published: Dec 25, 2003
Est. expiryMar 8, 2022(expired)· nominal 20-yr term from priority
H04W 12/04H04L 63/08H04L 63/0876H04W 12/71H04L 9/0833H04W 84/18H04W 12/06H04L 63/104H04L 63/065H04L 9/0838H04L 63/0471H04L 9/006H04L 9/00H04L 63/061H04L 9/08H04L 63/0428
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and system for distributed security for a plurality of devices in a communication network, each of the devices being responsible for generating, distributing and controlling its own keys for access to the communication network and using the keys to establish a trusted network, each device's membership to the communication network being checked periodically by other devices by using a challenge response protocol to establish which devices are allowed access to the communication network and the trusted network.

Claims

exact text as granted — not AI-modified
The embodiments of the invention in which an exclusive property or privilege is claimed are defined as follows:  
     
         1 . A method of establishing and maintaining distributed security between a plurality of devices in an ad hoc network, the method having the steps of; 
 associating each device with a unique device address;    assigning to one of said devices a control function to control access by other devices to said network;    each of said devices generating a public key for distribution to other devices;    each of said devices authenticating itself periodically with said other devices in order to determine status of said other devices;    arranging said devices into a plurality of trust groups, each group having a group key for distribution within said trust group;    associating a trust level to each of said devices;    each of said devices using said public key and said group key to perform key agreement in order to establish a secure communication channel with said other devices in said group;    whereby each of said devices is responsible for its own security by generating, distributing its own keys to said other devices.    
     
     
         2 . The method of  claim 1  wherein said device determines a source of said group key.  
     
     
         3 . The method of  claim 2  wherein when said source is a device in said trust group then said group key is used for encryption and decryption of data transmitted between said devices.  
     
     
         4 . The method of  claim 2  wherein when said source is a device excluded trust group then said group key is used decryption of data transmitted to said device.  
     
     
         5 . The method of  claim 1  wherein step of determining status of said other devices includes a further step of determining which of said devices are active and capable of participating in said network.  
     
     
         6 . The method of  claim 1  wherein step of determining status of said other devices includes a further step of using a challenge response protocol using said group key to establish whether said other devices are allowed access to said network in accordance with said control function.  
     
     
         7 . The method of  claim 1  wherein said unique device address includes a device ID or a local ID.  
     
     
         8 . The method of  claim 7  wherein said device ID is an IEEE MAC address and said local ID is an n-bit address unique to said group.  
     
     
         9 . A method of establishing and maintaining distributed security between one correspondent and another correspondent, said correspondents being members of different ad hoc networks and forming a group of communicating correspondents, the method having the steps of; 
 associating said one correspondent and said other correspondent with a unique device address;    controlling access to said different ad hoc networks;    each ad hoc network having a gateway and transferring traffic between said correspondents via said gateways;    said one correspondent generating a public key for distribution to said other correspondent;    said one correspondent authenticating itself periodically with said other correspondent in order to determine status of said other correspondent;    determining a group key for distribution to said correspondents in accordance to said step of controlling access;    associating a trust level to each of said correspondents;    each of said correspondents using said public key and said group key for performing key agreement in order to establish secure communication within said group;    whereby each of said correspondents is responsible for its own security by generating, distributing its own keys to said other devices.    
     
     
         10 . The method of  claim 9  wherein said step of transferring traffic includes a further step of associating each of said correspondents with a router for storing routing information having instructions for routing traffic from said one correspondent to said other correspondent.  
     
     
         11 . The method of  claim 10  wherein said routers query each other periodically in order to update and maintain said routing information.  
     
     
         12 . The method of  claim 1  I wherein said step of determining said status of said other correspondent includes a further step of using a challenge response protocol to establish whether said other correspondent is allowed access to said different ad hoc network having said one correspondent, in accordance with said control function.  
     
     
         13 . A distributed security system for a plurality of devices in a communication network, each of said devices being responsible for generating, distributing and controlling its own keys for access to said communication network and using said keys to establish a trusted network, each device's membership to said communication network being checked periodically by other devices by using a challenge response protocol to establish which devices are allowed access to said communication network and said trusted network.  
     
     
         14 . The system of  claim 13  wherein each device includes a security manager having the functions of generating said keys and distributing said keys to selected devices in said trusted network.  
     
     
         15 . The system of  claim 14  wherein said trusted network is associated with a level of trust.  
     
     
         16 . The system of  claim 14  wherein said security manager determines a source of said keys such that said keys from a device within said trusted network may be used for encryption and decryption of data, and said keys from a device excluded from said trusted network may be used decryption of said data.  
     
     
         17 . The system of  claim 16  wherein said security manager foregoes decrypting said data when said keys are from a device excluded from said trusted network.  
     
     
         18 . The system of  claim 15  wherein an outcome of said periodic checking is recorded by said security manager in order to maintain and update a membership list, and adjust said level of trust accordingly.  
     
     
         19 . The system of  claim 17  wherein different trusted networks may be established within said network based on differing levels of trust.  
     
     
         20 . The system of  claim 13  wherein said communication network includes a plurality of ad hoc networks and said distributed security system is established between devices in different ad hoc networks.  
     
     
         21 . The system of  claim 19  wherein each ad hoc network includes a controller to controlling access to each of said ad hoc networks, each ad hoc network having a gateway for transferring traffic therebetween, and device having a router for storing routing information having instructions for routing traffic from said one device to another device via said gateways and other routers.

Join the waitlist — get patent alerts

Track US2003235309A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.