Security in smart configuration for WLAN based IOT device

US10659442B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-10659442-B1
Application numberUS-201615378276-A
CountryUS
Kind codeB1
Filing dateDec 14, 2016
Priority dateDec 21, 2015
Publication dateMay 19, 2020
Grant dateMay 19, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Provided is a method in a device under configuration (DUC) for communicating with a remote device over a wireless local area network. The method comprises transmitting a beacon to a remote device, providing a first security key to the remote device using first security measures, authenticating the remote device using second security measures, receiving encrypted secrets from the remote device, and obtaining network access using the secrets. Also, provided is a method of providing network access information over a wireless network. The method comprises identifying a device under configuration (DUC) from information contained in a beacon transmitted by the DUC, retrieving a public KEY from the DUC, authenticating the DUC using first security measures, encrypting secrets, and transmitting encrypted commands to the DUC.

First claim

Opening claim text (preview).

What is claimed is: 1. A method in a device under configuration (DUC) for communicating with a remote device over a wireless local area network, the method comprising: providing a first security key to a remote device using a first out of band (OOB) communication of the wireless network, wherein the first OOB communication comprises light emitting diode signals emitted in a visible light spectrum and modulated in a binary pattern; authenticating the remote device using a probe request frame, wherein the probe request frame is transmitted over the wireless local area network in a radio spectrum; receiving encrypted secrets from the remote device; and obtaining network access using the encrypted secrets. 2. The method of claim 1 wherein the providing the first security key to the remote device using the first security measures comprises providing the first security key in response to a request by the remote device. 3. The method of claim 1 wherein authenticating the remote device using the probe request frame comprises: receiving an authentication command through the probe request frame sent from the remote device within a predetermined period of time; and providing an acknowledgement of the authentication command using a second out of band (OOB) communication. 4. The method of claim 3 further comprising: refusing to authenticate the remote device when it is detected that more than one remote device has attempted authentication during the predetermined period of time. 5. The method of claim 1 wherein receiving encrypted secrets comprises receiving credentials for logging onto a network. 6. The method of claim 5 wherein receiving the credentials for logging onto the network comprises receiving a service set identifier (SSID) for the network and/or a passphrase for the network. 7. The method of claim 1 wherein receiving the encrypted secrets comprises receiving a second security key for use in communicating with the remote device. 8. The method of claim 7 wherein receiving encrypted secrets comprises receiving secrets encrypted using the second key. 9. The method of claim 1 wherein receiving encrypted secrets comprises receiving secrets encrypted using the first security key. 10. A method of providing network access information over a wireless network, comprising: identifying a device under configuration (DUC) from information contained in a beacon that is received over a wireless network; in response to the received beacon, sending to the DUC, a request for a first security key of the device under configuration; retrieving a public key from the DUC using a first communication out of band (OOB) of the wireless network, wherein the first OOB communication comprises light emitting diode signals in a visible light spectrum modulated in a binary pattern; transmitting an authentication command to the DUC using a probe request frame wherein the probe request frame is transmitted over the wireless network in a radio spectrum; encrypting secrets using a second security key; and transmitting the encrypted secrets to the DUC, wherein the encrypted secrets are transmitted over the wireless network in the radio spectrum. 11. The method of claim 10 , wherein retrieving the public key comprises transmitting a request to the DUC to generate and transmit the public key. 12. The method of claim 10 further comprising: receiving an acknowledgement of the authentication command using a second out of band (OOB) communication. 13. The method of claim 12 wherein the second OOB communication comprises a message on a display of the DUC or LED lights blinking in a predefined pattern. 14. The method of claim 10 wherein receiving the encrypted secrets comprises receiving credentials for logging onto a network. 15. The method of claim 14 wherein receiving the credentials comprises receiving a service set identifier (SSID) for the network and/or a passphrase for the network. 16. The method of claim 10 wherein the receiving encrypted secrets comprises receiving a second security key for use in communicating with the DUC. 17. The method of claim 10 wherein encrypting the secrets using the second security key comprises encrypting the first security key using the second security key. 18. A system for communicating with a remote device over a wireless local area network, the system comprising: control circuitry coupled to a receiver, the control circuitry configured to: providing a first security key to a remote device using a first out of band (OOB) communication of the wireless network, wherein the first OOB communication comprises light emitting diode signals emitted in a visible light spectrum and modulated in a binary pattern; authenticating the remote device using a probe request frame, wherein the probe request frame is transmitted over the wireless local area network in a radio spectrum; and obtaining network access using the encrypted secrets; and the receiver configured to: receive encrypted secrets from the remote device. 19. The system of claim 18 , wherein the control circuitry is configured to provide the first security key to the remote device using the first security measures by providing the first security key in response to a request by the remote device. 20. The system of claim 18 , wherein the control circuitry is configured to authenticate the remote device using the probe request frame by: receiving an authentication command through the probe request frame sent from the remote device within a predetermined period of time; and providing an acknowledgment of the authentication command using a second out of band (OOB) communication.

Assignees

Inventors

Classifications

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

  • H04L63/062Primary

    for key distribution, e.g. centrally by trusted party (cryptographic mechanisms or cryptographic arrangements for key distribution involving a central third party H04L9/0819) · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • for controlling access to devices or network resources · CPC title

  • Access security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10659442B1 cover?
Provided is a method in a device under configuration (DUC) for communicating with a remote device over a wireless local area network. The method comprises transmitting a beacon to a remote device, providing a first security key to the remote device using first security measures, authenticating the remote device using second security measures, receiving encrypted secrets from the remote device, …
Who is the assignee on this patent?
Marvell Int Ltd
What technology area does this patent fall under?
Primary CPC classification H04L63/062. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 19 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 6 related publications on this page (citations in our corpus or others sharing the same primary CPC).