Dual Beacon Wireless Mesh Authentication Without Provisioning Network

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless mesh network communication standards, such as IEEE 802.15.4e-2012, require a provisioning network for connection authentication of new nodes, which can compromise security and efficiency, especially when overlapping wireless coverage is needed.

Innovation Solution

A communication apparatus employing two types of beacons with different security levels, where connected nodes use a first beacon encrypted with a common key, and unconnected nodes use a second beacon for authentication, allowing secure connection without a provisioning network by using distinct cryptographic keys and message authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a provisioning network is used for connection authentication, then new nodes can be authenticated to join the network, but security is compromised and efficiency is reduced

Engineering Contradiction:
Improveconnection authentication securityVSAvoidprovisioning network structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication function from the provisioning network infrastructure and implements it directly within the mesh network using two types of beacons. The first beacon (encrypted) handles secure authentication for connected nodes, while the second beacon (unencrypted) enables new nodes to join without requiring a separate provisioning network, thereby eliminating the security vulnerability and complexity of the provisioning network while maintaining authentication reliability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the beacon functionality into two distinct types: first beacons for authenticated communication and second beacons for unauthenticated joining. This segmentation allows the network to simultaneously maintain security for existing nodes while enabling easy joining for new nodes, resolving the contradiction between security and accessibility without requiring a provisioning network

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If overlapping wireless coverage is implemented for provisioning network and object network, then on-site join key acquisition is achieved, but security is compromised

Engineering Contradiction:
Improvejoin key acquisitionVSAvoidcommunication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by giving different security characteristics to different beacons transmitted by the same coordinator. The first beacon type provides encrypted, secure communication for authenticated nodes, while the second beacon type provides unencrypted, easily accessible information for new nodes to join. This allows the network to simultaneously provide easy join key acquisition and maintain communication security without requiring overlapping provisioning network coverage

Inventive Principle:
Principle #3Local quality

3Reliability

If a single common key is used for beacon encryption, then communication security is maintained for connected nodes, but new nodes cannot join without provisioning network

Engineering Contradiction:
Improvecommunication securityVSAvoidnode joining capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamics by allowing the coordinator to transmit two different types of beacons depending on the authentication state. The first beacon type (encrypted with common key) is used when nodes are authenticated, while the second beacon type (unencrypted or differently encrypted) is used to enable new nodes to join. This dynamic beacon transmission strategy allows the network to adapt between maintaining security and enabling joining capability without requiring a provisioning network

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The coordinator performs multiple functions by transmitting both first beacons (for secure authenticated communication) and second beacons (for enabling new node joining). This multi-functionality allows a single network infrastructure to simultaneously maintain security for connected nodes and provide joining capability for new nodes, eliminating the need for a separate provisioning network

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10506430B2Communication apparatus, communication method, and computer program product
Publication Date: 2019.12.10 KK TOSHIBA
  • US10506430B2 patent drawing
  • US10506430B2 patent drawing
  • US10506430B2 patent drawing

AI summary

According to an embodiment, a communication apparatus includes a receiver, a first beacon processor, a second beacon processor, and an authentication processor. The receiver receives a first beacon transmitted over a wireless network while being protected by a first common key and a second beacon transmitted over the wireless network while not being protected by the first common key. The first beacon processor accesses the wireless network using information contained in the first beacon when the first common key is provided. The second beacon processor accesses the wireless network using information contained in the second beacon when the first common key is not provided. The authentication processor performs connection authentication to the wireless network using information contained in the second beacon and acquires the first common key.