EP3403386A2

Key establishment for communications within a group

Abstract

This record has no abstract on file.

Term

10.2 yearsto projected expiry

Projected expiry 12 December 2036, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

1 claim: 1 independent, 0 dependent

  1. 1
    Claims of equivalent WO 2017123362 A2 CLAIMSWhat is claimed is:1. A method for wireless communication comprising: creating, by a managing device of a group of devices, a first group security configuration for a first device of the group of devices, the first group security configuration comprising a group security parameter associated with the group of devices and a device- specific security parameter associated with the first device;creating, by the managing device, a second group security configuration for a second device of the group of devices, the second group security configuration comprising the group security parameter and a device-specific security parameter associated with the second device;and providing the first group security configuration to the first device and the second group security configuration to the second device, wherein the first group security configuration and the second group security configuration are configured to be used to establish a secure connection for communications between the first device and the second device. 2. The method of claim 1 wherein the first group security configuration and the second group security configuration are configured to be used to establish the secure connection without additional communications with the managing device during the establishment of the secure connection. 3. The method of claim 1, further comprising: determining a group security level for the group of devices based at least in part on a maximum number of devices in the group of devices. 4. The method of claim 1, further comprising: updating the first group security configuration and the second group security configuration based at least in part on a quantity of devices that change their group connection status exceeding a threshold quantity of devices. 5. The method of claim 4, further comprising: providing the updated first group security configuration to the first device using a first secure unicast channel;and providing the updated second group security configuration to the second device using a second secure unicast channel. 6. The method of claim 4, wherein the updating comprises: changing the group security parameter, the device-specific security parameter associated with the first device, or the device-specific security parameter associated with the second device, or a combination thereof. 7. The method of claim 4, wherein the updating comprises: selecting a group identifier providing an index to an updated group security parameter, an updated device-specific security parameter associated with the first device, or an updated device-specific security parameter associated with the second device, or a combination thereof;and providing the selected group identifier to the first device, or the second device, or both the first device and the second device. 8. The method of claim 4, wherein a device changing its group connection status comprises the device being identified as a compromised device, a periodic security configuration update, the device departing from the group of devices, or the device joining the group of devices, or a combination thereof. 9. The method of claim 1, wherein the group of devices comprise a group of sensor nodes, a group of wireless devices forming a wireless peer-to-peer (P2P) network, a group of wireless devices forming a mesh network, or a group of devices forming an infrastructure-less network, or a combination thereof. 10. A method of wireless communication comprising: receiving, at a first device of a group of devices, a first group security configuration from a managing device, the first group security configuration comprising a group security parameter associated with the group of devices and a device-specific security parameter associated with the first device;and establishing a secure connection for communications with a second device of the group of devices based at least in part on the first group security configuration and a second group security configuration provided to the second device, the second group security configuration comprising the group security parameter and a device-specific security parameter associated with the second device. 11. The method of claim 10, wherein the secure connection is established without additional communications with the managing device during the establishment of the secure connection. 12. The method of claim 10, further comprising: generating, based at least in part on the first group security configuration and the second group security configuration, a pairwise key to establish the secure connection, the pairwise key being symmetric between the first device and the second device. 13. The method of claim 10, further comprising: determining, at the first device, the device-specific security parameter associated with the second device, wherein establishing the secure connection is based at least in part on the device-specific security parameter associated with the second device as determined at the first device. 14. The method of claim 13, wherein determining the device-specific security parameter associated with the second device comprises: receiving a broadcast message from the second device, the broadcast message comprising the device-specific security parameter associated with the second device. 15. The method of claim 10, further comprising: receiving an updated first group security configuration;and reestablishing the secure connection for communications with the second device based at least in part on the updated first group security configuration. 16. An apparatus for wireless communication, comprising: means for creating a first group security configuration for a first device of a group of devices, the first group security configuration comprising a group security parameter associated with the group of devices and a device-specific security parameter associated with the first device;means for creating a second group security configuration for a second device of the group of devices, the second group security configuration comprising the group security parameter and a device-specific security parameter associated with the second device;and means for providing the first group security configuration to the first device and the second group security configuration to the second device, wherein the first group security configuration and the second group security configuration are configured to be used to establish a secure connection for communications between the first device and the second device. 17. The apparatus of claim 16 wherein the first group security configuration and the second group security configuration are configured to be used to establish the secure connection without additional communications with the apparatus during the establishment of the secure connection. 18. The apparatus of claim 16, further comprising: means for determining a group security level for the group of devices based at least in part on a maximum number of devices in the group of devices. 19. The apparatus of claim 16, further comprising: means for updating the first group security configuration and the second group security configuration based at least in part on a quantity of devices that change their group connection status exceeding a threshold quantity of devices. 20. The apparatus of claim 19, further comprising: means for providing the updated first group security configuration to the first device using a first secure unicast channel;and means for providing the updated second group security configuration to the second device using a second secure unicast channel. 21. The apparatus of claim 19, wherein the means for updating the first group security configuration and the second group security configuration further comprise: means for changing the group security parameter, the device-specific security parameter associated with the first device, or the device-specific security parameter associated with the second device, or a combination thereof. 22. The apparatus of claim 19, wherein the means for updating the first group security configuration and the second group security configuration further comprise: means for selecting a group identifier providing an index to an updated group security parameter, an updated device-specific security parameter associated with the first device, or an updated device-specific security parameter associated with the second device, or a combination thereof;and means for providing the selected group identifier to the first device, or the second device, or both the first device and the second device. 23. The apparatus of claim 19, wherein a device changing its group connection status comprises the device being identified as a compromised device, a periodic security configuration update, the device departing from the group of devices, or the device joining the group of devices, or a combination thereof. 24. The apparatus of claim 16, wherein the group of devices comprise a group of sensor nodes, a group of wireless devices forming a wireless peer-to-peer (P2P) network, a group of wireless devices forming a mesh network, or a group of devices forming an infrastructure-less network, or a combination thereof. 25. An apparatus for wireless communication, comprising: means for receiving a first group security configuration from a managing device, the first group security configuration comprising a group security parameter associated with the group of devices and a device-specific security parameter associated with the apparatus;and means for establishing a secure connection for communications with a second device of a group of devices based at least in part on the first group security configuration and a second group security configuration provided to the second device, the second group security configuration comprising the group security parameter and a device-specific security parameter associated with the second device. 26. The apparatus of claim 25, wherein the secure connection is established without additional communications with the managing device during the establishment of the secure connection. 27. The apparatus of claim 25, further comprising: means for generating, based at least in part on the first group security configuration and the second group security configuration, a pairwise key to establish the secure connection, the pairwise key being symmetric between the apparatus and the second device. 28. The apparatus of claim 25, further comprising: means for determining the device-specific security parameter associated with the second device, wherein establishing the secure connection is based at least in part on the device-specific security parameter associated with the second device as determined at the apparatus. 29. The apparatus of claim 28, wherein the means for determining the device-specific security parameter associated with the second device further comprise: means for receiving a broadcast message from the second device, the broadcast message comprising the device-specific security parameter associated with the second device. 30. The apparatus of claim 25, further comprise: means for receiving an updated first group security configuration;and means for reestablishing the secure connection for communications with the second device based at least in part on the updated first group security configuration.