Dual-Mode Peer Devices for Mesh Network Redundancy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional mesh networks have a single failure point due to reliance on an authenticator module and key server, leading to temporary MACsec outages and network unavailability during temporary outages or changes in group membership.

Innovation Solution

Implementing a large-scale Ethernet mesh network with dual-mode peer devices that can operate as both supplicants and authenticators, enabling authenticator redundancy and failover, and using a shared group encryption key for secure data exchange, with mechanisms for key server election and distribution to maintain continuous MACsec service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single authenticator module and key server are used in conventional mesh networks, then device complexity is reduced, but network reliability deteriorates due to single failure points causing MACsec outages

Engineering Contradiction:
Improveauthentication structureVSAvoidnetwork availability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

Each peer device in the mesh network is configured to simultaneously operate as both an authenticator and a supplicant. This merging of roles eliminates the need for separate dedicated authenticator modules and key servers, thereby reducing device complexity while simultaneously providing redundancy to eliminate single failure points, thus improving network reliability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Peer devices are designed with multi-functionality, capable of performing both authentication (authenticator mode) and being authenticated (supplicant mode). This universal design allows any peer device to take on either role as needed, providing fault tolerance and continuous network availability while maintaining relatively simple device structures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If dual-mode peer devices are implemented with both supplicant and authenticator capabilities, then network reliability is improved through redundancy, but device complexity increases

Engineering Contradiction:
Improvenetwork availabilityVSAvoidpeer device functionality
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines supplicant and authenticator functionalities into a single peer device. By merging these previously separate functions into one unified device architecture, the patent achieves redundancy and eliminates single failure points without proportionally increasing overall system complexity, as the same hardware platform performs both roles.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Peer devices are designed as universal nodes capable of operating in multiple modes (supplicant mode and authenticator mode). This multi-functionality is achieved through a unified device structure that can dynamically switch between roles, providing high reliability while keeping individual device complexity manageable through shared components and protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If IEEE 802.1X-2010 protocol is used in mesh networks, then authentication security is maintained, but network scale is limited to 30 nodes

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork scale
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic key distribution and authentication mechanisms that allow the mesh network to scale beyond the 30-node limitation of IEEE 802.1X-2010. Peer devices can dynamically assume authenticator and key server roles, enabling the network to adapt to varying scales while maintaining security through the same cryptographic protocols, thus increasing adaptability without compromising authentication security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11962685B2High availability secure network including dual mode authentication
Publication Date: 2024.04.16 RAYTHEON CO
  • US11962685B2 patent drawing
  • US11962685B2 patent drawing
  • US11962685B2 patent drawing

AI summary

A large-scale Ethernet mesh network including a plurality of dual-mode peer devices in signal communication with one another so as to establish a group connectivity association (CA). Each dual-mode peer device simultaneously operates in a supplicant mode and authenticator mode. Each of dual-mode peer device encrypts data using a shared group encryption key (SAK), and exchanges the encrypted data with peer devices in the group CA.