Patents by Inventor Stephen M. Orr

Stephen M. Orr has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20260203391
    Abstract: Simultaneous Authentication of Equals (SAE) password identifiers privacy protection may be provided. A client device may receive a set of password Identifiers (IDs) over an Out-of-Band (OOB) connection. Next the computing device may select, from the set of password IDs, a password ID to be seen by an authenticator, and to be applied to an SAE exchange. The computing device may then rotate across the set of password IDs for subsequent SAE exchanges.
    Type: Application
    Filed: January 13, 2026
    Publication date: July 16, 2026
    Applicant: Cisco Technology, Inc.
    Inventors: Javier Contreras Albesa, Stephen M. Orr
  • Publication number: 20260205271
    Abstract: Secure communication with a Backscatter Device (BKD) may be provided. A temporal key may be created. The temporal key and a network Identifier (ID) may be encrypted with a public key of a public private key pair associated with the BKD. An excitation frame including the encrypted temporal key and the encrypted network ID may be transmitted to the BKD. The AMP BKD may include a sensor. A BKD frame may be received from the BKD in response to the excitation frame. The BKD frame may include a sensor data encoded with the temporal key and the network ID as a target destination. The BKD frame may be signed using a private key of the public private key pair.
    Type: Application
    Filed: December 22, 2025
    Publication date: July 16, 2026
    Applicant: Cisco Technology, Inc.
    Inventors: Jerome Henry, Stephen M. Orr, Robert E. Barton, Indermeet S. Gandhi
  • Publication number: 20260197634
    Abstract: Validation of privacy requests for mutual Access Point (AP) and client device protection may be provided. A first computing device may accept association with a second computing device. Then the first computing device may receive frame anonymization parameters associated with a parameter rotation from the second computing device. Next, the first computing device may determine to one of: i) accept the parameter rotation based on the frame anonymization parameters; and ii) reject the parameter rotation based on the frame anonymization parameters.
    Type: Application
    Filed: February 25, 2026
    Publication date: July 9, 2026
    Applicant: Cisco Technology, Inc.
    Inventors: Domenico Ficara, Stephen M. Orr, Jerome Henry, Ugo Mario Campiglio, Javier Contreras
  • Publication number: 20260180678
    Abstract: Backscatter Device (BKD) onboarding may be provided. BKD onboarding may begin with an AP receiving an identifier associated with a BKD. The AP may determine to onboard the BKD and transmit to the BKD an onboarding excitation signal to request data from a memory bank of the BKD. The AP may then receive a response to the onboarding excitation signal from the BKD. The AP may verify the BKD is valid based on the identifier and the response. Finally, the AP may onboard the BKD based on verifying the BKD is valid.
    Type: Application
    Filed: December 2, 2025
    Publication date: June 25, 2026
    Applicant: Cisco Technology, Inc.
    Inventors: Jerome Henry, Juan Carlos Zuniga, Stephen M. Orr
  • Publication number: 20260164226
    Abstract: A seamless mobility domain (SMD) is described where a PTK for a wireless device is pre-computed or pre-generated before the client roams from a serving AP to a target AP in the SMD. The pre-computed PTK can be distributed (i.e., pushed) to one or more target APs before the wireless device roams, or the PTK can be stored in a key stored and then retrieved from the key store by a target AP once the wireless device roams to the target AP. In another embodiment, the PMK and/or PTK keys are generated using a SMD identifier, such as a SMD MAC address or a special ID for the SMD.
    Type: Application
    Filed: November 25, 2025
    Publication date: June 11, 2026
    Inventors: Binita GUPTA, Stephen M. ORR, Brian D. HART
  • Publication number: 20260149705
    Abstract: Prescriptive advertising of valid security combinations within a Service Set Identifier (SSID) may be provided. A computing device may determine supported security combinations that are supported by the computing device. Next, the computing device may indicate the supported security combinations in an information element. Then the computing device may advertise the information element.
    Type: Application
    Filed: November 21, 2025
    Publication date: May 28, 2026
    Applicant: Cisco Technology, Inc.
    Inventors: Anuj Dharap, Stephen M. Orr
  • Publication number: 20260136189
    Abstract: Fine Time Measurement (FTM) Location Configuration Information (LCI) protection and, specifically, FTM LCI protection with authentication and selective client enablement may be provided. To perform FTM LCI protection, a controller may first obtain a key-pair including a public key and a private key from a Certificate Authority (CA). The controller my determine a venue location where an Access Point (AP) is located. The controller may send a Certificate Signing Request (CSR) with the venue location to the CA. In response to sending the CSR, the controller may receive a public key certificate from the CA, wherein the public key certificate includes the venue location. The AP may receive a request for Location Configuration Information (LCI) from a Station (STA), wherein the LCI includes an AP location. The AP creates a hash of LCI of the AP using the private key and sends the LCI and the hash to the STA.
    Type: Application
    Filed: January 6, 2026
    Publication date: May 14, 2026
    Applicant: Cisco Technology, Inc.
    Inventors: Jerome Henry, Brian D. Hart, Peiman Amini, Stephen M. Orr, Sudhir K. Jain
  • Publication number: 20260135694
    Abstract: A system and method are provided for generating group encryption keys for a global group and a private group to encrypt wireless messages between an access point and a station. The private group key is based on a unique private group identifier. The global group key and the private group key are sent from the access point to one or more stations via an M3 message as part of a 4-way handshake or as part of a 2-way group key handshake. The global group key is used for encrypted broadcast or multicast messages with an entire group, whereas the private group key is used for encrypted broadcast or multicast messages with a private group that is a subset of the entire group.
    Type: Application
    Filed: January 9, 2026
    Publication date: May 14, 2026
    Inventors: Stephen M. Orr, Shree Narasimha Murthy
  • Publication number: 20260136257
    Abstract: A converged Seamless Mobility Domain (SMD) architecture enabling different SMD modes may be provided. A request to roam may be received from a non-Access Point (AP) Multi-Link Device (MLD) to roam from a first AP MLD to a second AP MLD of the converged SMD architecture. The converged SMD architecture can selectively be configured in one of: a distributed SMD mode and a centralized SMD mode. It may be determined that the converged SMD architecture is configured in the distributed SMD mode. An uplink data path to a distribution system for the non-AP MLD through the first AP MLD may be paused during a roaming transition. The non-AP MLD may be connected to the distribution system through first AP MLD. During the roaming transition, the uplink data path to the distribution system for the non-AP MLD may be changed from through the first AP MLD to through the second AP MLD.
    Type: Application
    Filed: July 25, 2025
    Publication date: May 14, 2026
    Applicant: Cisco Technology, Inc.
    Inventors: Binita Gupta, Brian D. Hart, Malcolm Muir Smith, Stephen M. Orr, Sudhir Kumar Jain
  • Publication number: 20260129424
    Abstract: In a mobility domain (e.g., a seamless mobility domain), a roaming counter value is provided to a target access point (AP) which the target AP can use to generate a nonce for encrypting data transmitted to a roaming non-AP multi-link device (MLD). That is, the non-AP MLD may be roaming from a current (or serving) AP to the target AP. The roaming counter is incremented each time the non-AP MLD roams in the mobility domain. Thus, each time the non-AP MLD roams, the updated roaming counter is provided to the new target AP MLD. Because the roaming counter is incremented each times there is a roam, even in a buggy implementation where the same PN is reused, the nonce will be different due to the roaming counter being different.
    Type: Application
    Filed: November 4, 2025
    Publication date: May 7, 2026
    Inventors: Binita GUPTA, Brian D. HART, Stephen M. ORR
  • Publication number: 20260129452
    Abstract: Detection of rogue access points (APs) through an AP that is associated with a mobility domain in a network. Unvalidated APs that attempt to join the network may be validated by another AP that is associated with the network. The unvalidated and associated APs may exchange signatures to determine if the unvalidated AP knows a key associated with the network. If the unvalidated AP does not know the key, the unvalidated AP is not validated for the network. The AP that was doing the validation may transmit a message to devices on the network indicating a rogue AP, the unvalidated AP, is attempting to join the network.
    Type: Application
    Filed: June 18, 2025
    Publication date: May 7, 2026
    Inventors: Binita GUPTA, Brian D. HART, Stephen M. ORR, Malcolm M. SMITH, Indermeet S. GANDHI
  • Publication number: 20260129453
    Abstract: The present disclosure provides techniques for mitigating Man-in-the-Middle (MITM) and replay attack within a mobility domain. An access point (AP) within a seamless mobility domain (SMD), generates a frame comprising an SMD signature, an SMD identifier, and a replay protection value, where the SMD signature is generated by signing a data structure comprising the SMD identifier and the replay protection value using a private key associated with the SMD. The AP transmits the frame to a station (STA) for verification.
    Type: Application
    Filed: October 2, 2025
    Publication date: May 7, 2026
    Inventors: Binita GUPTA, Brian D. HART, Stephen M. ORR, Malcolm M. SMITH, Indermeet S. GANDHI
  • Publication number: 20260113630
    Abstract: Transmission of a signal from an access point on a mobility domain to a client device. The signal indicates that the client device should perform an authentication process before joining the mobility domain. By authenticating the mobility domain, the client device ensures that it is not joining a rogue access point mimicking an access point of the mobility domain.
    Type: Application
    Filed: May 19, 2025
    Publication date: April 23, 2026
    Inventors: Binita GUPTA, Stephen M. ORR, Brian D. HART
  • Publication number: 20260075402
    Abstract: A seamless mobility domain (SMD) is described where a PTK for a wireless device is pre-computed or pre-generated before the client roams from a serving AP to a target AP in the SMD. The pre-computed PTK can be distributed (i.e., pushed) to one or more target APs before the wireless device roams, or the PTK can be stored in a key stored and then retrieved from the key store by a target AP once the wireless device roams to the target AP. In another embodiment, the PMK and/or PTK keys are generated using a SMD identifier, such as a SMD MAC address or a special ID for the SMD.
    Type: Application
    Filed: November 14, 2025
    Publication date: March 12, 2026
    Inventors: Binita GUPTA, Stephen M. ORR, Brian D. HART
  • Publication number: 20260067667
    Abstract: The present disclosure provides techniques for mitigating replay attacks during roaming with a shared pairwise transient key (PTK). A first access point (AP) receives a first roaming request from a station (STA), where the first roaming request comprises a first packet number (PN). In response to determining that the first PN is less than or equal to a last known PN maintained by the first AP, the first AP discards the roaming request.
    Type: Application
    Filed: July 26, 2025
    Publication date: March 5, 2026
    Inventors: Binita GUPTA, Brian D. HART, Malcolm M. SMITH, Stephen M. ORR
  • Publication number: 20260067086
    Abstract: The present disclosure provides techniques for device authorization using a per-device identifier. A network device authenticates a client device using simultaneous authentication of equals (SAE) with a shared passphrase. After completing association, the network device sends a first message to the client device, comprising an access point (AP)-generated random value to the client device. The network device receives a second message from the client device, comprising a station (STA)-generated random value and an authorization identifier. The network device decrypts the authorization identifier using a session key. In response to determining that the authorization identifier matches an entry in the authorization database, the network device sends a third message confirming authorization of the client device as a trusted entity. The network device receives a fourth message confirming completion of a security key exchange.
    Type: Application
    Filed: May 30, 2025
    Publication date: March 5, 2026
    Inventors: Ugo M. CAMPIGLIO, Stephen M. ORR, Domenico FICARA, Javier I. CONTRERAS ALBESA, Jerome HENRY, Federico LOVISON, Juan Carlos ZUNIGA
  • Publication number: 20260052380
    Abstract: A wireless device comprising one or more memories and one or more processors communicatively coupled to the one or more memories. The one or more processors are configured, individually or collectively, to perform an operation. The operation comprises initiating a roam between a first access point (AP) and a second AP. After the roam, the operation further comprises detecting that the first AP reused a packet number (PN) that the second AP had used, and based on detecting that the first AP reused the PN, establishing a new pairwise transient key (PTK) with the first AP.
    Type: Application
    Filed: July 26, 2025
    Publication date: February 19, 2026
    Inventors: Brian D. HART, Binita GUPTA, Stephen M. ORR
  • Publication number: 20260019808
    Abstract: Techniques are described for securely transmitting diagnostic data between a STA and an AP before the STA has successfully been on boarded at the AP. In the embodiments herein, the STA can use a key (e.g., a long-term key) to encrypt diagnostic data transmitted to the AP when the STA has not been on boarded by the AP. This key can be provided to the STA several different ways such as when the STA was provisioned to connect to a service set identifier (SSID) supported by the AP, or the STA may have previously associated with the SSID (e.g., by connecting to the same or another AP supporting the SSID during a previous session) and received or generated the key.
    Type: Application
    Filed: July 14, 2025
    Publication date: January 15, 2026
    Inventors: Javier I. CONTRERAS ALBESA, Jerome HENRY, Stephen M. ORR, Domenico FICARA, Brian D. HART
  • Patent number: 12526282
    Abstract: Group identity assignment and policy enforcement may be provided. A User Defined Network Identifier (UDN ID) defining a group of client devices may be received. Next, a client identifier (ID) associated with a source client device that is associated with the group of client devices may be received. The UDN ID and the client ID may be encoded in an Extended Local Identifier (ELI) Media Access Control (MAC) address associated with the source client device. A source MAC address of a packet received from the source client device may then be substituted with the ELI MAC address. Then the packet may be forwarded.
    Type: Grant
    Filed: December 16, 2021
    Date of Patent: January 13, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Roberto Muccifora, Domenico Ficara, Amine Choukir, Ugo Mario Campiglio, Shree Murthy, Stephen M. Orr
  • Patent number: 12520145
    Abstract: Fine Time Measurement (FTM) Location Configuration Information (LCI) protection and, specifically, FTM LCI protection with authentication and selective client enablement may be provided. To perform FTM LCI protection, a controller may first obtain a key-pair including a public key and a private key from a Certificate Authority (CA). The controller my determine a venue location where an Access Point (AP) is located. The controller may send a Certificate Signing Request (CSR) with the venue location to the CA. In response to sending the CSR, the controller may receive a public key certificate from the CA, wherein the public key certificate includes the venue location. The AP may receive a request for Location Configuration Information (LCI) from a Station (STA), wherein the LCI includes an AP location. The AP creates a hash of LCI of the AP using the private key and sends the LCI and the hash to the STA.
    Type: Grant
    Filed: October 26, 2023
    Date of Patent: January 6, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Jerome Henry, Brian D. Hart, Peiman Amini, Stephen M. Orr, Sudhir K. Jain