CA2371329C

Method and apparatus for initializing secure communications among, and for exclusively pairing wireless devices

Abstract

A method and system for efficiently establishing secure communications between mobile devices in a radio network.The present invention utilizes public key cryptography and unique hardware identifiers to enable authorizations for access to wirelessnetworks, such as picocells. The present invention prevents the mobile user from maintaining a plurality of secrets such as useridentifier/password pairs, PINs, or encryption keys, for access to each device to which he might require access. Wireless devicesdistributed throughout an enterprise are enabled to be efficiently initialized for secure communications. Well-known public keycryptography and machine unique identifiers are utilised to establish a secure channel and initialize the wireless devices. Wirelessdevices are enabled to be paired or permanently associated by a user or a network administrator. Well known public key cryptographyand machine unique identifiers are utilised to establish a secure channel and associate the devices with each other. This is extremelyuseful for associating a wireless headset with a telephone or associating a wireless mouse with a computer.

CA2371329C, drawing sheet 1
Sheet 1 of 13

Term

Term ended

Expired 22 May 2020, 6.3 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

70 claims: 25 independent, 45 dependent

  1. 1
    CA 02371329 2005-03-29 RSW990033 CLAIMS 1. A method for initializing secure communications between a first device and a second device, said first and second devices each having a public key of a Certificate Authority and a device certificate, said device certificate having a unique hardware identifier associated with said respective device, and a public key associated with said respective device, said method comprising the steps of:establishing a session between said first device and said second device;negotiating two-way session encryption and mutual authentication requirements between said first and said second device;exchanging device certificates of said first device and said second device ;cryptographically verifying the received certificate using the public key of said Certificate Authority;exchanging challenges created by each of said first and second devices;responding to a respective challenge by signing said received challenge, using a receiving device's private key, said private keys residing in a respective protected storage in each said device;returning said signed challenges;cryptographically verifying that said received challenge signature is of the challenge previously sent by said receiving device;establishing a key agreement between said first and said second devices;and, establishing secure communications if all of said prior verifying steps succeed.
  2. 2
    A method as is non-secure. claimed in claim i wherein said first established session
  3. 3
    A method as claimed in claim is an authenticated connection. wherein said established session
  4. 7
    8. A method for initializing a first device distributed with an embedded 10 radio module using a server, said server having an embedded radio module, said method comprising the steps of:sending an inquiry from said server to said first device using said embedded radio modules;returning, from said first device, a unique device identifier of said 15 first device, to said server;creating, at said server, a public key, private key pair for said first device;creating, at said server, a device certificate for said first device, said device certificate having a unique hardware identifier associated with 20 said first device and a public key associated with said first device;transmitting said private key, and said device certificate, and a public key of a Certificate Authority which signed said device certificate, to said first device;and, storing said private key in non-removable protected storage at said 25 first device.
  5. 8
    9. A method as claimed in claim 8 wherein a copy of said certificate is stored in an enterprise database. 30
  6. 10
    11. A method for initializing a first device distributed with an embedded radio module using a server, said server having an embedded radio module, 35 said method comprising the steps of:sending an inquiry from said server to said first device using said embedded radio modules;creating, at said first device, a public key, private key pair for said first device;CA 02371329 2005-03-29 RSW990033 storing, at said first device, said private key in non-removable protected storage;returning, from said first device, a unique device identifier and said public key of said first device, to said server;creating, at said server, a device certificate for said first device, said device certificate having said device identifier and said public key;and transmitting said device certificate and a public key of a Certificate Authority which signed said device certificate to said first device.
  7. 12
    13. A method for establishing a security relationship between a first device and a second device, said first and second devices each having an associated device certificate, each of said device certificates having a unique device identifier for said corresponding device, said method comprising the steps cf:initiating a pairing request one of said devices to the other of said devices;sending, from said first device, the device certificate of said first device to said second device;cryptographically verifying, by said second device, said received device certificate of said first device;outputting, at said second device, the device identifier of said first device contained in said first device certificate;verifying, by a user, that said output device identifier matches the unique identifier of said first device, said unique identifier being known to said user;and, accepting, by said user, the security relationship between said first device and said second device if said output device identifier is verified.
  8. 13
    14. A method as claimed in claim 13 wherein said sending and verifying steps are accomplished by establishing an authenticated secure session between said first device and said second device.
  9. 15
    16. A method as claimed in claim 15 wherein said indicator is the device identifier.
  10. 19
    20. A method as claimed in claim 19 wherein said automatic detection is accomplished by means of electromagnetic signal transmission from one of said devices and reception of said electromagnetic signal at the other of said devices.
  11. 25
    26. A computer program product for initializing secure communications between a first device and a second device, said first and second devices each having a public key of a Certificate Authority and a device certificate, said device certificate having a unique hardware identifier associated with said respective device, and a public key associated with said respective device, said computer program product comprising a computer usable medium CA 02371329 2005-03-29 RSW990033 embodying computer executable program code said computer executable program code comprising:computer executable program code for establishing a session between said first device and said second device;computer executable program code for negotiating two-way session encryption and mutual authentication requirements between said first and said second device;computer executable program code for exchanging device certificates of said first device and said second device;computer executable program code for cryptographically verifying the received certificate using the public key of said Certificate Authority;computer executable program code for exchanging challenges created by each of said first and second devices;computer executable program code for responding to a respective challenge by signing said received challenge, using a receiving device's private key, said private keys residing in a respective protected storage in each said device;computer executable program code for returning said signed challenges;computer program code means for cryptographically verifying that said received challenge signature is of the challenge previously sent by said receiving device;computer executable program code for establishing a key agreement between said first and said second devices;and, computer executable program code for establishing secure communications if all of said prior verifying steps succeed.
  12. 26
    27. The computer program product as claimed in claim 26 wherein said first established session is non- secure.
  13. 27
    28. The computer program product as claimed in claim 26 wherein. said first established session is an authenticated connection.
  14. 28
    29. The computer program product as claimed in claim 26 wherein said first established session is an encrypred connection.
  15. 33
    34. A computer program product for initializing a first device distributed with an embedded radio module using a server, said server having an embedded radio module, said computer program product comprising a computer usable medium embodying computer executable program code said computer executable program code comprising:computer executable program code for sending an inquiry from said server to said first device using said embedded radio modules;computer executable program code for returning, from said first device, a unique device identifier of said first device, to said server;computer executable program code for creating, at said server, a public key, private key pair for said first device;computer executable program code for creating, at said server, a device certificate for said first device, said device certificate having a unique hardware identifier associated with said first device and a public key associated with said first device;computer executable program code for transmitting said private key, and said device certificate, and a public key of a Certificate Authority which signed said device certificate, to said first device;and, computer executable program code for storing said private key in non-removable protected storage at said first device.
  16. 34
    35. The computer program product as claimed in claim 34 wherein a copy of said certificate is stored in an enterprise database.
  17. 36
    37. A computer program product for initializing a first device distributed with an embedded radio module using a server, said server having an embedded radio module, said computer program product comprising a computer usable medium embodying computer executable program code said computer executable program code comprising:computer executable program code for sending an inquiry from said server to said first device using said embedded radio modules;computer executable program code for creating, at said first device, a public key, private key pair for said first device;computer executable program code for storing, at said first device, said private key in non-removable protected storage;computer executable program code for returning, from said first device, a unique device identifier and said public key of said first device, to said server;computer executable program code for creating, at said server, a device certificate for said first device, said device certificate having said device identifier and said public key;and computer executable program code for transmitting said device certificate and a public key of a Certificate Authority which signed said device certificate to said first device.
  18. 38
    39. A computer program product for establishing a security relationship between a first device and a second device, said first and second devices each having an associated device certificate, each of said device certificates having a unique device identifier for said corresponding device, said computer program product comprising a computer usable medium embodying computer executable program code said computer executable program code comprising :computer executable program code for initiating a pairing request one of said devices to the other of said devices;computer executable program code for sending, from said first device, the device certificate of said first device to said second device;computer executable program code for cryptographically verifying, by said second device, said received device certificate of said first device;CA 02371329 2005-03-29 RSW990033 computer executable program code for outputting, at said second device, the device identifier of said first device contained in said first device certificate;computer executable program code for verifying, by a user, that said output device identifier matches the unique identifier of said first device, said unique identifier being known to said user;and, computer executable program code for accepting, by said user, the security relationship between said first device and said second device if said output device identifier is verified.
  19. 39
    40. The computer program product as claimed in claim 39 wherein said sending and verifying are accomplished by establishing an authenticated secure session between said first device and said second device.
  20. 40
    41. The computer program product as claimed in claim 39 wherein an indicator of the association of said first and said second device is placed in long-ti srm storage.
  21. 41
    42. The computer program product as claimed in claim 41 wherein said indicator is the device identifier.
  22. 42
    43. The computer program product as claimed in claim 41 wherein said indicator is key material.
  23. 43
    44. The computer program product as claimed in any one of claims 39 to 42 wherein the initiating of said pairing request is accomplished by making an input selection on one of said devices.
  24. 44
    45. The computer program product as claimed in any one of claims 39 to 42 wherein the initiating of said pairing request is accomplished by one of said devices automatically detecting the other of said devices.
  25. 45
    46. The computer program product as claimed in claim 45 wherein said automatic detection is accomplished by means of electromagnetic signal transmission from one of said devices and reception of said electromagnetic signal at the other of said devices. CA 02371329 2005-03-29 RSW990033
  26. 47
    48 . The computer program product as claimed in claim 44 or claim 46 wherein said input selection is accomplished by depressing a button.
  27. 48
    49. The computer program product as claimed in claim 44 or claim 46 wherein said input selection is accomplished by verbal command.
  28. 49
    50 . The computer program product as claimed in claim 39 wherein said output means is a visual display.
  29. 50
    51. The computer program product as claimed in claim 39 wherein said output means is auditory.
  30. 51
    52. A system for initializing secure communications between a first device and a second device, said first and second devices each having a public key of a Certificate Authority and a device certificate, said device certificate having a unique hardware identifier associated with said respective device, and a public key associated with said respective device, said system comprising:a communications mechanism for establishing a session between said first device and said second device, negotiating two-way session encryption and mutual authentication requirements between said first and said second device, and exchanging device certificates of said first device and said second device;a verifier for cryptographically verifying the received certificate using the public key of said Certificate Authority;a negotiation mechanism for exchanging challenges created by each of said first and second devices, responding to a respective challenge by signing said received challenge, using a receiving device's private key, said private keys residing in a respective protected storage in each said device, returning said signed challenges, cryptographically verifying that said received challenge signature is of the challenge previously sent by said receiving device, establishing a key agreement between said first and said second devices;and, establishing secure communications if all of said prior verifying steps succeed. CA 02371329 2005-03-29 RSW990033 53. is A system as claimed in claim non- secure. 52 wherein said first established session 54 . A system as claimed in claim 52 wherein said first established session is an authenticated connection. 55. A system as claimed in claim 52 wherein said first established session is an encrypted connection. 56, A system as claimed in claim 52 wherein said unique hardware identifier is a machine (MAC) address for said associated device .
  31. 52
    57 . A system as claimed in claim 52 wherein said protected storage is read-write storage wherein the read capacity of said storage is accessible only by means of a shared secret.
  32. 54
    59. A system for initializing a first device distributed with an embedded radio module using a server, said server having an embedded radio module, said system comprising:a communications mechanism for sending an inquiry from said server to said first device using said embedded radio modules, and returning, from said first device, a unique device identifier of said first device, to said server ;a processor at said server for creating a public key, private key pair for said first device;a device certificate, created at said server, for said first device, said device certificate having a unique hardware identifier associated with said first device and a public key associated with said first device;wherein said communications mechanism transmits said private key, and said device certificate, and a public key of a Certificate Authority which signed said device certificate, to said first device;and, said processor stores said private key in non-removable protected storage at said first device. CA 02371329 2005-03-29 RSW990033
  33. 57
    62. An initialization system, said system comprising:a first device, said first device having an embedded radio module;a server, said server having an embedded radio module;a communications mechanism, said communications mechanism sending an inquiry from said server to said first device using said embedded radio modules ;wherein said first device creates a public key, private key pair for said first device, stores said private key in non-removable protected storage, and returns a unique device identifier and said public key of said first device, to said server;said server creates a device certificate for said first device, said device certificate having said device identifier and said public key;and transmits said device certificate and a public key of a Certificate Authority which signed said device certificate to said first device.
  34. 59
    64. A system for a user to establish a security relationship, said system, comprising :a first device;a second device;a device certificate with each of said first and second devices, each of said device certificates having a unique device identifier for said corresponding device, wherein one of said first and second devices initiates a pairing request to the other of said devices, sends said device certificate of said first device from said first device to said second device, wherein said second device cryptographically verifies said received device certificate of said first device, outputs the device identifier of said first device contained in said first device certificate;wherein said user verifies that said output device identifier matches the unique identifier of said first device, said unique identifier being known to said CA 02371329 2005-03-29 RSW990033 user;and accepts the security relationship between said first device and said second device if said output device identifier is verified.
  35. 64
    69. A system as claimed in any one of claim 64 to claim 67 wherein the initiating of said pairing request is accomplished by making an input selection on one of said devices.
Independent claims35