Portable computerized device adapted for ad hoc security associations
Abstract
A portable computing device configured to provide secure data communications with a network via a network communications interface. In one embodiment, the portable computing device includes a network security apparatus configured to communicate data with other network security apparatus over the network via the establishment of an association, the establishment of the association between the network security apparatus and the other network security apparatus resultant in the execution of a key generation algorithm configured to cause the network security apparatus and the other network security apparatus to exchange information utilized in the generation of cryptogaphic keys.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 - 52 . (canceled)
53 . A portable computing device configured to provide secure data communications with a network via a network communications interface, the device comprising:
a host computer; and a network security apparatus configured to communicate data with other network security apparatus over the network via the establishment of an association, the establishment of the association between the network security apparatus and the other network security apparatus resultant in the execution of a key generation algorithm configured to cause the network security apparatus and the other network security apparatus to exchange information utilized in the generation of cryptographic keys; the network security apparatus further configured to:
determine whether an association between the network security apparatus and the other network security apparatus in communication with the network exists;
receive a message sent from a higher layer process in the host computer for transmission over the network;
convert at least a portion of the received message to a format utilized by the network; and
transmit the message received from the higher layer process to the other network security apparatus when the association does exist;
wherein the network security apparatus comprises an encryption algorithm that is initialized at least in part to utilize an initialization vector (IV), the encryption algorithm configured so that the encryption of data using the same cryptographic key, but a different IV, will produce a different ciphered output.
54 . The device of claim 53 , wherein the portable computing device further comprises a network protocol used to resolve an IP address from a given hardware address.
55 . The device of claim 54 , wherein the network security apparatus is further configured to authenticate at least one other computing device or other network security apparatus associated with the at least one other computing device that requests to form an association that utilizes at least one other key generation algorithm.
56 . The device of claim 54 , wherein the network security apparatus is further configured to authenticate at least one other computing device or other network security apparatus associated with the at least one other computing device from which the network security apparatus has first requested authentication.
57 . The device of claim 53 , wherein the network security apparatus is disposed substantially within a software stack above the Physical Layer thereof.
58 . The device of claim 57 , wherein the network security apparatus is disposed substantially within a software stack below the Network Layer thereof
59 . The device of claim 57 , wherein the network security apparatus is disposed substantially within a software stack below the Transport Layer thereof.
60 . The device of claim 53 , wherein the association comprises a non-permanent trusted communications channel between and unique to the network security apparatus and the other network security apparatus.
61 . The device of claim 53 , wherein the network security apparatus is configured to dynamically generate at least one encryption key for each association, the act of generating not requiring either: (i) intervention by a network administrator; or (ii) intervention by a user of the portable computing device.
62 . A portable computing device configured to provide secure data communications with a network via a network communications interface, the device comprising:
a host computer; and a network security module comprising:
an association determination process configured to determine whether an association exists between the network security module and another network security module in communication with the network;
an association manager process configured to establish an association with one or more other network security modules, the act of establishing the association resulting in the authentication of the one or more other network security modules as well as the authentication of the portable computing device to the one or more other network security modules;
an interface configured to receive a message sent from a higher layer process, where the message is intended for transmission over the network; and
a management process in communication with the network communications interface and configured to transmit the message to the network when the association exists;
wherein at least a portion of the message is configured to be evaluated by the another network security module that utilizes a first cryptographic residue generated at the another network security module using at least locally stored information, and a second residue of the transmitted at least a portion of the message.
63 . The device of claim 62 , wherein the network security module is further configured to dynamically generate at least one encryption key for each association, the act of generating not requiring either: (i) intervention by a network administrator; or (ii) intervention by a user of the portable computing device.
64 . The device of claim 62 , wherein at least one encryption key is dynamically generated by the network security module pursuant to the establishment of the association with the one or more other network security modules.
65 . The device of claim 64 , wherein the at least one encryption key is specific to a particular session between the network security module and the one or more other network security modules.
66 . The device of claim 65 , wherein the network security module is further configured to encrypt at least portions of the message using a block cipher.
67 . The device of claim 62 , wherein the network security module comprises an encryption algorithm that is initialized at least in part using an initialization vector (IV).
68 . The device of claim 67 , wherein the encryption algorithm is configured so that encrypting data using the same encryption key, but different IVs, will produce different ciphered output.
69 . The device of claim 67 , wherein the network security module is configured to generate a new IV for each encryption event.
70 . A portable computing device configured to provide secure data communications with a network via a network communications interface, the device comprising:
a host computer; and a network security module, comprising:
an association determination process configured to determine whether an association exists between the network security module and another network security module in communication with the network;
an association manager process configured to establish an association with one or more other network security modules if the association is determined to not exist, the act of establishing an association resulting in the authentication of the one or more other network security modules as well as the authentication of the portable computing device to the one or more other network security modules;
an interface configured to receive a message sent from a higher layer process, wherein the message is intended for transmission over the network; and
a management process in communication with the interface and the network communications interface, the management process configured to transmit the message towards the network if the association determination process determines that the association exists;
wherein the network security module operates according to a trusted session-based protocol, the trusted session-based protocol configured to generate one or more encryption keys in response to the act of establishing an association, the one or more encryption keys being substantially unique to the association; and
wherein the trusted session-based protocol provides at least one mechanism to verify that at least a portion of the message is unaltered during transmission to the network, the at least one mechanism configured to verify that the at least a portion of the message is unaltered during transmission to the network comprising a cryptographic residue.
71 . The device of claim 70 , wherein at least one of the one or more encryption keys comprises a symmetric encryption key.
72 . The device of claim 70 , wherein at least one of the one or more encryption keys provides confidentiality, integrity and authentication of one or more user datagrams during a particular session or association between the network security module and the another network security module.
73 . The device of claim 70 , wherein the network security module, as part of the establishment of the association, generates random data that is transmitted to the another network security module.
74 . The device of claim 73 , wherein the transmission of the random data is associated with a procedure that permits both the network security module and the another network security module to generate encryption keys that permit the two network security modules to decrypt encrypted data sent by the other.
75 . The device of claim 70 , wherein at least a portion of the transmitted message is evaluated by the another network security module using a first cryptographic residue generated at the another network security module using at least locally stored information, and a second residue of the transmitted message.
76 . The device of claim 75 , wherein the evaluation of the first and second residues comprises a comparison of the residues to see if they match.Join the waitlist — get patent alerts
Track US2015143121A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.