US2016021063A1PendingUtilityA1

System for Efficiently Handling Cryptographic Messages Containing Nonce Values in a Wireless Connectionless Environment

Assignee: TELECOMM SYSTEMS INCPriority: Aug 21, 2001Filed: Jun 2, 2015Published: Jan 21, 2016
Est. expiryAug 21, 2021(expired)· nominal 20-yr term from priority
H04L 63/04H04L 63/1408H04L 9/321H04L 63/0876H04L 63/14H04W 12/04H04W 12/06H04W 12/041H04W 12/121H04W 12/02
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system for determining the validity of a received cryptographic message while ensuring for out-of-order messages is utilized to provide for secure communications among peers in a network. In particular, a secure communication module may be configured to accept the cryptographic message in response to a received nonce value of the received message is greater than the largest nonce value yet seen, the secure communication module may be configured to compare the received nonce value with a nonce value acceptance window. If the received nonce value falls outside the nonce acceptance window, the secure communication module may be further configured to reject the received message and assume that a replay attack has been detected. If the received nonce value fails within the nonce acceptance window, the secure communication module may be further configured to determine if the received nonce value has been seen before by comparing the received nonce value with a replay window mask. If the received nonce has been seen before, the secure communication module may be further configured to reject the received message and assume a replay attack. Otherwise, the secure communication module may be further configured to accept the message and add the received nonce value to the replay window mask.

Claims

exact text as granted — not AI-modified
1 - 43 . (canceled) 
     
     
         44 . A method of detecting a replay attack in a secure communication, comprising:
 accepting a cryptographic message in response to a received nonce value of a received message being greater than a largest nonce value yet seen, and otherwise comparing said received nonce value with a nonce acceptance window when said received nonce value is not a largest nonce value yet seen;   determining if said received nonce value has been seen before, when said received nonce value falls within said nonce acceptance window, otherwise, when said received nonce value falls outside said nonce acceptance window, rejecting said received message and indicating detection of a replay attack; and   rejecting said received message and indicating detection of said replay attack, when said received nonce has been seen before, otherwise, when said received nonce has not been seen before, accepting said received message and adding said received nonce value to a replay window mask.   
     
     
         45 . The method of detecting a replay attack in a secure communication according to  claim 44 , wherein said determining if said received nonce value has been seen before comprises:
 comparing said received nonce value with a replay window mask.   
     
     
         46 . The method of detecting a replay attack in a secure communication according to  claim 44 , further comprising:
 adjusting a size of said range of acceptable nonce values within said nonce acceptance window based on a reset largest nonce value.   
     
     
         47 . The method of detecting a replay attack in a secure communication according to  claim 44 , wherein:
 said largest nonce value is associated with a first session.   
     
     
         48 . The method of detecting a replay attack in a secure communication according to  claim 44 , wherein:
 said largest nonce value is associated with a second session.   
     
     
         49 . The method of detecting a replay attack in a secure communication according to  claim 44 , further comprising:
 generating a new cryptographic key.   
     
     
         50 . Apparatus for detecting a replay attack in a secure communication, comprising:
 means for accepting a cryptographic message in response to a received nonce value of a received message being greater than a largest nonce value yet seen, and otherwise for comparing said received nonce value with a nonce acceptance window when said received nonce value is not a largest nonce value yet seen;   means for determining if said received nonce value has been seen before, when said received nonce value falls within said nonce acceptance window, otherwise, when said received nonce value falls outside said nonce acceptance window, for rejecting said received message and indicating detection of a replay attack; and   means for rejecting said received message and indicating detection of said replay attack, when said received nonce has been seen before, otherwise, when said received nonce has not been seen before, for accepting said received message and adding said received nonce value to a replay window mask.   
     
     
         51 . The apparatus for detecting a replay attack in a secure communication according to  claim 50 , wherein said means for determining if said received nonce value has been seen before comprises:
 means for comparing said received nonce value with a replay window mask.   
     
     
         52 . The apparatus for detecting a replay attack in a secure communication according to  claim 50 , further comprising:
 means for adjusting a size of said range of acceptable nonce values within said nonce acceptance window based on a reset largest nonce value.   
     
     
         53 . The apparatus for detecting a replay attack in a secure communication according to  claim 50 , wherein:
 said largest nonce value is associated with a first session.   
     
     
         54 . The apparatus for detecting a replay attack in a secure communication according to  claim 50 , wherein:
 said largest nonce value is associated with a second session.   
     
     
         55 . The apparatus for detecting a replay attack in a secure communication according to  claim 50 , further comprising:
 means for generating a new cryptographic key.

Join the waitlist — get patent alerts

Track US2016021063A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.