US2015143121A1PendingUtilityA1

Portable computerized device adapted for ad hoc security associations

Assignee: ROUND ROCK RES LLCPriority: Jul 30, 1996Filed: Oct 24, 2014Published: May 21, 2015
Est. expiryJul 30, 2016(expired)· nominal 20-yr term from priority
G06F 2221/2153H04L 9/3247H04L 63/14G06F 2221/2141G06F 2211/001H04L 63/0442G06F 2221/2149H04L 63/126H04L 63/061H04L 63/0869G06F 2211/009G06F 21/85H04L 2209/76H04L 63/0218G06F 2211/005H04L 9/3273G06F 2211/007G06F 21/31H04L 9/3268H04L 63/101H04L 63/02H04L 67/141H04L 63/105G06F 2221/2101G06F 21/606H04L 9/0861H04L 63/16H04L 63/08H04L 9/40H04L 67/563H04W 12/069
64
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A portable computing device configured to provide secure data communications with a network via a network communications interface. In one embodiment, the portable computing device includes a network security apparatus configured to communicate data with other network security apparatus over the network via the establishment of an association, the establishment of the association between the network security apparatus and the other network security apparatus resultant in the execution of a key generation algorithm configured to cause the network security apparatus and the other network security apparatus to exchange information utilized in the generation of cryptogaphic keys.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 - 52 . (canceled) 
     
     
         53 . A portable computing device configured to provide secure data communications with a network via a network communications interface, the device comprising:
 a host computer; and   a network security apparatus configured to communicate data with other network security apparatus over the network via the establishment of an association, the establishment of the association between the network security apparatus and the other network security apparatus resultant in the execution of a key generation algorithm configured to cause the network security apparatus and the other network security apparatus to exchange information utilized in the generation of cryptographic keys;   the network security apparatus further configured to:
 determine whether an association between the network security apparatus and the other network security apparatus in communication with the network exists; 
 receive a message sent from a higher layer process in the host computer for transmission over the network; 
 convert at least a portion of the received message to a format utilized by the network; and 
 transmit the message received from the higher layer process to the other network security apparatus when the association does exist; 
 wherein the network security apparatus comprises an encryption algorithm that is initialized at least in part to utilize an initialization vector (IV), the encryption algorithm configured so that the encryption of data using the same cryptographic key, but a different IV, will produce a different ciphered output. 
   
     
     
         54 . The device of  claim 53 , wherein the portable computing device further comprises a network protocol used to resolve an IP address from a given hardware address. 
     
     
         55 . The device of  claim 54 , wherein the network security apparatus is further configured to authenticate at least one other computing device or other network security apparatus associated with the at least one other computing device that requests to form an association that utilizes at least one other key generation algorithm. 
     
     
         56 . The device of  claim 54 , wherein the network security apparatus is further configured to authenticate at least one other computing device or other network security apparatus associated with the at least one other computing device from which the network security apparatus has first requested authentication. 
     
     
         57 . The device of  claim 53 , wherein the network security apparatus is disposed substantially within a software stack above the Physical Layer thereof. 
     
     
         58 . The device of  claim 57 , wherein the network security apparatus is disposed substantially within a software stack below the Network Layer thereof 
     
     
         59 . The device of  claim 57 , wherein the network security apparatus is disposed substantially within a software stack below the Transport Layer thereof. 
     
     
         60 . The device of  claim 53 , wherein the association comprises a non-permanent trusted communications channel between and unique to the network security apparatus and the other network security apparatus. 
     
     
         61 . The device of  claim 53 , wherein the network security apparatus is configured to dynamically generate at least one encryption key for each association, the act of generating not requiring either: (i) intervention by a network administrator; or (ii) intervention by a user of the portable computing device. 
     
     
         62 . A portable computing device configured to provide secure data communications with a network via a network communications interface, the device comprising:
 a host computer; and   a network security module comprising:
 an association determination process configured to determine whether an association exists between the network security module and another network security module in communication with the network; 
 an association manager process configured to establish an association with one or more other network security modules, the act of establishing the association resulting in the authentication of the one or more other network security modules as well as the authentication of the portable computing device to the one or more other network security modules; 
 an interface configured to receive a message sent from a higher layer process, where the message is intended for transmission over the network; and 
 a management process in communication with the network communications interface and configured to transmit the message to the network when the association exists; 
 wherein at least a portion of the message is configured to be evaluated by the another network security module that utilizes a first cryptographic residue generated at the another network security module using at least locally stored information, and a second residue of the transmitted at least a portion of the message. 
   
     
     
         63 . The device of  claim 62 , wherein the network security module is further configured to dynamically generate at least one encryption key for each association, the act of generating not requiring either: (i) intervention by a network administrator; or (ii) intervention by a user of the portable computing device. 
     
     
         64 . The device of  claim 62 , wherein at least one encryption key is dynamically generated by the network security module pursuant to the establishment of the association with the one or more other network security modules. 
     
     
         65 . The device of  claim 64 , wherein the at least one encryption key is specific to a particular session between the network security module and the one or more other network security modules. 
     
     
         66 . The device of  claim 65 , wherein the network security module is further configured to encrypt at least portions of the message using a block cipher. 
     
     
         67 . The device of  claim 62 , wherein the network security module comprises an encryption algorithm that is initialized at least in part using an initialization vector (IV). 
     
     
         68 . The device of  claim 67 , wherein the encryption algorithm is configured so that encrypting data using the same encryption key, but different IVs, will produce different ciphered output. 
     
     
         69 . The device of  claim 67 , wherein the network security module is configured to generate a new IV for each encryption event. 
     
     
         70 . A portable computing device configured to provide secure data communications with a network via a network communications interface, the device comprising:
 a host computer; and   a network security module, comprising:
 an association determination process configured to determine whether an association exists between the network security module and another network security module in communication with the network; 
 an association manager process configured to establish an association with one or more other network security modules if the association is determined to not exist, the act of establishing an association resulting in the authentication of the one or more other network security modules as well as the authentication of the portable computing device to the one or more other network security modules; 
 an interface configured to receive a message sent from a higher layer process, wherein the message is intended for transmission over the network; and 
 a management process in communication with the interface and the network communications interface, the management process configured to transmit the message towards the network if the association determination process determines that the association exists; 
 wherein the network security module operates according to a trusted session-based protocol, the trusted session-based protocol configured to generate one or more encryption keys in response to the act of establishing an association, the one or more encryption keys being substantially unique to the association; and 
 wherein the trusted session-based protocol provides at least one mechanism to verify that at least a portion of the message is unaltered during transmission to the network, the at least one mechanism configured to verify that the at least a portion of the message is unaltered during transmission to the network comprising a cryptographic residue. 
   
     
     
         71 . The device of  claim 70 , wherein at least one of the one or more encryption keys comprises a symmetric encryption key. 
     
     
         72 . The device of  claim 70 , wherein at least one of the one or more encryption keys provides confidentiality, integrity and authentication of one or more user datagrams during a particular session or association between the network security module and the another network security module. 
     
     
         73 . The device of  claim 70 , wherein the network security module, as part of the establishment of the association, generates random data that is transmitted to the another network security module. 
     
     
         74 . The device of  claim 73 , wherein the transmission of the random data is associated with a procedure that permits both the network security module and the another network security module to generate encryption keys that permit the two network security modules to decrypt encrypted data sent by the other. 
     
     
         75 . The device of  claim 70 , wherein at least a portion of the transmitted message is evaluated by the another network security module using a first cryptographic residue generated at the another network security module using at least locally stored information, and a second residue of the transmitted message. 
     
     
         76 . The device of  claim 75 , wherein the evaluation of the first and second residues comprises a comparison of the residues to see if they match.

Join the waitlist — get patent alerts

Track US2015143121A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.