EP1337087A2

Security key distribution using key rollover strategies for wireless networks

Abstract

Security key distribution techniques using key rollover strategies for wireless networks are described. A number of keys are generated, usually by an access point. The present invention allows a standard mode and a mixed mode. In standard mode, each device on the network supports automatic key updates. In mixed mode, one or more devices on the wireless network require fixed keys. In both modes, a predetermined number of keys are determined and communicated to client devices that are accessing the wireless network. The predetermined number is determined so that a client device can miss a certain number of authentication periods without losing communication with the wireless network. Preferably, transmit keys used by an access point are different than the transmit keys used by the client devices that support automatic key updates.

EP1337087A2, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Projected expiry passed 12 July 2022, 4.2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

10 claims: 3 independent, 7 dependent

  1. 1
    A method to improve security in a wireless network, the method comprising:determining a time period, the time period indicating when at least one new key is to be generated;loading a number of keys in a controller, the number set so that a device connected to the wireless network can miss being re-authenticated for a predetermined number of the time periods and still communicate in a secure manner on the wireless network;and communicating the keys from the controller to the device.
  2. 9
    A method to improve security in a wireless network, the method comprising:loading a time period, the time period indicating when at least one new key is to be generated;loading a plurality of keys;selecting one of the keys as a local transmit key;selecting the other keys as receive keys;performing the following steps every time period: (i) generating at least one new key;(ii) using the at least one new key to replace, for each of the at least one keys, one key of the plurality of keys, the at least one new key and any keys not replaced comprising a new plurality of keys;and (iii) selecting a key of the new plurality of keys as a local transmit key, the local transmit key for a current time period selected to be different than the local transmit key for an immediately proceeding time period.
  3. 10
    An apparatus for controlling access to a wireless network, the apparatus comprising:a memory that stores computer-readable code;and a processor operatively coupled to the memory, said processor configured to implement the computer-readable code, said computer-readable code configured to: determine a time period, the time period indicating when at least one new key is to be generated;load a number of keys, the number set so that a device connected to the wireless network can miss being re-authenticated for a predetermined number of the time periods and still communicate in a secure manner on the wireless network;and communicate the keys from the controller to the device.