US2014215221A1PendingUtilityA1

Hitless manual cryptographic key refresh in secure packet networks

Assignee: ROCKSTAR CONSORTIUM US LPPriority: Dec 22, 2003Filed: Dec 18, 2013Published: Jul 31, 2014
Est. expiryDec 22, 2023(expired)· nominal 20-yr term from priority
H04L 9/3247H04L 9/0891
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In a hitless manual cryptographic key refresh scheme, a state machine is independently maintained at each network node. The state machine includes a first state, a second state, and a third state. In the first state, which is the steady state, a current cryptographic key is used both for generating signatures for outgoing packets and for authenticating signatures of incoming packets. In the second state, which is entered when a new cryptographic key is provisioned, the old (i.e. formerly current) key is still used for generating signatures for outgoing packets, however one or, if necessary, both of the old key and the newly provisioned key is used for authenticating signatures of incoming packets. In the third state, the new key is used for generating signatures for outgoing packets and either one or both of the old key and new key are used for authenticating signatures of incoming packets.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A packet data network, comprising at least a first node and a second node interconnected by at least one communication path:
 the first node being configured:
 (a) after being provisioned with a new cryptographic key:
 to include in packets transmitted to the second node a signature generated using a current cryptographic key; and 
 to treat as authentic packets received from the second node only if the received packets contain a signature generated using the current cryptographic key or a signature generated using the new cryptographic key; and 
 
 (b) after receipt from the second node of a packet containing a signature generated using the new cryptographic key:
 to include in packets transmitted to the second node a signature generated using the new cryptographic key; and 
 to treat as authentic packets received from the second node only if the received packets contain a signature generated using the new cryptographic key; and 
 
   the second node being configured:
 (a) after being provisioned with the new cryptographic key:
 to include in packets transmitted to the first node a signature generated using the current cryptographic key; and 
 to treat as authentic packets received from the first node only if the received packets contain a signature generated using the current cryptographic key or a signature generated using the new cryptographic key; and 
 
 (b) after receipt from the first node of a packet containing a signature generated using the new cryptographic key:
 to include in packets transmitted to the first node a signature generated using the new cryptographic key; and 
 to treat as authentic packets received from the first node only if the received packets contain a signature generated using the new cyptographic key. 
 
   
     
     
         2 . The network of  claim 1 , wherein the first node is configured:
 to start a delay period after being provisioned with the new cryptographic key; and   after expiry of the delay period and prior to receipt from the second node of a packet containing a signature generated using the new cryptographic key:
 to include in packets transmitted to the second node a signature generated using the new cryptographic key; and 
 to treat as authentic packets received from the second node only if the received packets contain a signature generated using the current cryptographic key or a signature generated using the new cryptographic key. 
   
     
     
         3 . The network of  claim 2 , wherein the second node is configured:
 to start a delay period after being provisioned with the new cryptographic key; and   after expiry of the delay period and prior to receipt from the first node of a packet containing a signature generated using the new cryptographic key:   to include in packets transmitted to the first node a signature generated using the new cryptographic key; and   to treat as authentic packets received from the first node only if the received packets contain a signature generated using the current cryptographic key or a signature generated using the new cryptographic key.   
     
     
         4 . The network of  claim 1 , wherein the first node is configured to include in packets transmitted to the second node a signature generated using the new cryptographic key conditionally on the elapsing of a predetermined time period after receipt from the second node of the packet containing a signature generated using the new cryptographic key. 
     
     
         5 . The network of  claim 4 , wherein the second node is configured to include in packets transmitted to the first node a signature generated using the new cryptographic key conditionally on the elapsing of a predetermined time period after receipt from the first node of the packet containing a signature generated using the new cryptographic key. 
     
     
         6 . The network of  claim 1 , wherein the first node is configured, after being provisioned with a further cryptographic key, to use the further cryptographic key as the new cryptographic key. 
     
     
         7 . The network of  claim 1 , wherein the second node is configured, after being provisioned with a further cryptographic key, to use the further cryptographic key as the new cryptographic key. 
     
     
         8 . The network of  claim 1 , wherein the first node is configured, before any cryptographic key is provisioned:
 to omit from packets transmitted to the second node any signature generated using a cryptographic key; and   to treat as authentic packets received from the second node lacking a signature generated using a cryptographic key.   
     
     
         9 . The network of  claim 8 , wherein the second node is configured, before any cryptographic key is provisioned:
 to omit from packets transmitted to the first node any signature generated using a cryptographic key; and   to treat as authentic packets received from the first node lacking a signature generated using a cryptographic key.   
     
     
         10 . The network of  claim 8 , wherein the first node is configured, after being provisioned with a first cryptographic key and until a first packet containing a signature generated using the first cryptographic key is received from the second node:
 to omit from packets transmitted to the second node any signature generated using a cryptographic key; and   to treat as authentic packets received from the second node lacking a signature generated using a cryptographic key and packets received from the second node containing a signature generated using the first cryptographic key.   
     
     
         11 . The network of  claim 9 , wherein the second node is configured, after being provisioned with a first cryptographic key and until a first packet containing a signature generated using the first cryptographic key is received from the first node:
 to omit from packets transmitted to the first node any signature generated using a cryptographic key; and   to treat as authentic packets received from the first node lacking a signature generated using a cryptographic key and packets received from the first node containing a signature generated using the first cryptographic key.   
     
     
         12 . The network of  claim 10 , wherein the first node is configured, after being provisioned with a first cryptographic key and after receiving from the second node a first packet containing a signature generated using the first cryptographic key:
 to include in packets transmitted to the second node a signature generated using the first cryptographic key; and   to treat as authentic packets received from the second node only if the received packets contain a signature generated using the first cryptographic key.   
     
     
         13 . The network of  claim 12 , wherein the second node is configured, after being provisioned with a first cryptographic key and after receiving from the first node a first packet containing a signature generated using the first cryptographic key:
 to include in packets transmitted to the first node a signature generated using the first cryptographic key; and   to treat as authentic packets received from the first node only if the received packets contain a signature generated using the first cryptographic key.   
     
     
         14 . The network of  claim 12 , wherein the first node is configured to include in packets transmitted to the second node a signature generated using the new cryptographic key conditionally on the elapsing of a predetermined time period after receipt from the second node of the first packet containing a signature generated using the first cryptographic key. 
     
     
         15 . The network of  claim 13 , wherein the second node is configured to include in packets transmitted to the first node a signature generated using the new cryptographic key conditionally on the elapsing of a predetermined time period after receipt from the first node of the first packet containing a signature generated using the first cryptographic key. 
     
     
         16 . The network of  claim 12 , wherein the first node is configured, after being provisioned with a further cryptographic key, to use the further cryptographic key as the new cryptographic key. 
     
     
         17 . The network of  claim 16 , wherein the second node is configured, after being provisioned with a further cryptographic key, to use the further cryptographic key as the new cryptographic key. 
     
     
         18 . In packet data network comprising at least a first node and a second node, the first and second nodes using a current cryptographic key to authenticate packets transmitted from the first node to the second node and to authenticate packets transmitted from the second node to the first node, a method of replacing the current cryptographic key with a new cryptographic key without disrupting the traffic between the two nodes, the method comprising:
 provisioning the first node with the new cryptographic key;   provisioning the second node with the new cryptographic key;   when receiving packets from the second node after being provisioned with the new cryptographic key, the first node treating the received packets as authentic only if the received packets contain a signature generated using the current cryptographic key or a signature generated using the new cryptographic key;   when receiving packets from the first node after being provisioned with the new cryptographic key, the second node treating the received packets as authentic only if the received packets contain a signature generated using the current cryptographic key or a signature generated using the new cryptographic key;   activating the new cryptographic key on the first node after the second node has been provisioned with the new cryptographic key;   activating the new cryptographic key on the second node after the first node has been provisioned with the new cryptographic key;   when transmitting packets to the second node after the new cryptographic key has been activated on the first node, the first node including in the packets a signature generated using the new cryptographic key;   when transmitting packets to the first node after the new cryptographic key has been activated on the second node, the second node including in the packets a signature generated using the new cryptographic key;   retiring the current cryptographic key on the first node after the new cryptographic key has been activated on the second node;   retiring the current cryptographic key on the second node after the new cryptographic key has been activated on the first no - de;   when receiving packets from the second node after the current cryptographic key has been retired on the first node, the first node treating the received packets as authentic only if the received packets contain a signature generated using the new cryptographic key; and   when receiving packets from the first node after the current cryptographic key has been retired on the second node, the second node treating the received packets as authentic only if the received packets contain a signature generated using the new cryptographic key.   
     
     
         19 . The method of  claim 18 , wherein before any cryptographic key is provisioned:
 the first node:
 omits from packets transmitted to the second node any signature generated using a cryptographic key; and 
 treats as authentic packets received from the second node lacking a signature generated using a cryptographic key; and 
   the second node:
 omits from packets transmitted to the first node any signature generated using a cryptographic key; and 
 treats as authentic packets received from the first node lacking a signature generated using a cryptographic key. 
   
     
     
         20 . The method of  claim 19 , wherein:
 the first node, after being provisioned with a first cryptographic key and until a first packet containing a signature generated using the first cryptographic key is received from the second node:
 omits from packets transmitted to the second node any signature generated using a cryptographic key; and 
 treats as authentic packets received from the second node lacking a signature generated using a cryptographic key and packets received from the second node containing a signature generated using the first cryptographic key; and 
   the second node, after being provisioned with a first cryptographic key and until a first packet containing a signature generated using the first cryptographic key is received from the first node:
 omits from packets transmitted to the first node any signature generated using a cryptographic key; and 
 treats as authentic packets received from the first node lacking a signature generated using a cryptographic key and packets received from the first node containing a signature generated using the first cryptographic key. 
   
     
     
         21 . The method of  claim 20 , wherein:
 the first node, after being provisioned with a first cryptographic key and after receiving from the second node a first packet containing a signature generated using the first cryptographic key:
 includes in packets transmitted to the second node a signature generated using the first cryptographic key; and 
 treats as authentic packets received from the second node only if the received packets contain a signature generated using the first cryptographic key; and 
   the second node, after being provisioned with a first cryptographic key and after receiving from the first node a first packet containing a signature generated using the first cryptographic key:
 includes in packets transmitted to the first node a signature generated using the first cryptographic key; and 
 treats as authentic packets received from the first node only if the received packets contain a signature generated using the first cryptographic key.

Join the waitlist — get patent alerts

Track US2014215221A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.