Device authentication
Abstract
A method for authenticating a first device capable of operating according to a wireless communications protocol, the method comprising: at a second device, receiving a first message comprising an identifier for the first device and an authorisation code associated with the first device, the first message not being received from the first device in accordance with the wireless communications protocol; at the second device, receiving a second message comprising a value, the second message being sent from the first device in accordance with the wireless communications protocol; and authenticating the first device if the authorisation code received via the first message relates, according to a predetermined algorithm, to the received value.
Claims
exact text as granted — not AI-modified1 . A method for authenticating a first device capable of operating according to a wireless communications protocol, the method comprising:
at a second device, receiving a database identifier and sending a request message comprising the database identifier to a computer, the database identifier not being received from the first device in accordance with the wireless communications protocol; at the second device, receiving a response message from the computer comprising an identifier for the first device and an authorisation code associated with the first device; at the second device, receiving a second message comprising a value, the second message being sent from the first device in accordance with the wireless communications protocol; and authenticating the first device if the authorisation code received via the response message relates, according to a predetermined algorithm, to the received value.
2 . A method as claimed in claim 1 , further comprising: at the second device and in response to authenticating the first device, sending an association message to the first device, the association message comprising an encrypted network key by means of which the first device can access a network comprising the second device.
3 . A method as claimed in claim 2 , further comprising, at the second device:
receiving a public key from the first device; and calculating an encryption key in dependence the received public key and a private key stored at the second device, the network key being encrypted using the encryption key.
4 . A method as claimed in claim 3 , said calculation being in accordance with a Diffie-Hellman-Merkle key exchange.
5 . A method as claimed in claim 1 , the database identifier being received via an analysis of an image.
6 . A method as claimed in claim 5 , the image being a QR-Code, barcode or text representing the database identifier.
7 . A method as claimed in claim 5 further comprising, at the second device:
scanning the image, the image representing the database identifier,
sending the request message, via the internet; and
in response to the request, receiving the response message, via the internet.
8 . A method as claimed in claim 7 , the response message comprising one or more further identifiers and identification codes associated with respective one or more further devices.
9 . A method as claimed in claim 1 , the value being dependent on an authorisation code stored at the first device.
10 . A method as claimed in claim 1 , the value being different to the authorisation code.
11 . A method as claimed in claim 1 , the value being calculated using the predetermined algorithm having as inputs: the authorisation code stored at the first device, a public key of the first device and a random number generated by the first device.
12 . A method as claimed in claim 11 , said authenticating step comprising:
receiving the random number from the first device; from the value, authorisation code and the public key, calculating a number according to the predetermined algorithm; and comparing said calculated number with the received random number and, if said numbers match, authenticating the first device.
13 . A method as claimed in claim 1 , further comprising: at the first device, broadcasting the identifier for the first device in accordance with the communications protocol.
14 . A method as claimed in claim 1 , the second message being received via a third device capable of operating according to the communications protocol.
15 . A method as claimed in claim 1 , the second device being capable of communicating in a mesh network.
16 . A method as claimed in claim 1 , wherein the wireless communications protocol is Bluetooth Low Energy protocol.
17 . A method as claimed in claim 1 , the wireless communications protocol defining a broadcast packet type, said second message being received via a packet of the broadcast packet type.
18 . A wireless communications device capable of operating according to a wireless communications protocol, the wireless communications device comprising:
an input configured to receive a database identifier, the database identifier not being received from the first device in accordance with the wireless communications protocol; an interface configured to send a request message comprising the database identifier to a computer and to receive a response message from the computer comprising an identifier for a first device and an authorisation code associated with the first device; a transceiver capable of operating according to the wireless communications protocol and configured to receive a second message comprising a value, the second message being sent from the first device in accordance with the wireless communications protocol; and a controller configured to authenticate the first device if the authorisation code received via the response message relates, according to a predetermined algorithm, to the received value.
19 . A wireless communications device as claimed in claim 18 , the input being a camera or barcode reader configured to analyse an image.
20 . A wireless communications device capable of operating according to a wireless communications protocol, the wireless communications device comprising:
a transceiver configured to broadcast an identifier for the device in accordance with the communications protocol, wherein the identifier is associated with a database identifier; a memory configured to store an authorisation code, the transceiver being further configured to:
send a first message comprising a value, the value being related, according to a predetermined algorithm, to the authorisation code; and
in response to sending the first message, receive a second message comprising an encrypted network key; and
a controller configured to decrypt the encrypted network key by means of which the device can access a network, wherein the device is configured to not send and not display the authorisation code unencrypted.Join the waitlist — get patent alerts
Track US2015245204A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.