Dual-Mode Peer Devices for Mesh Network Redundancy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional mesh networks have a single failure point due to reliance on an authenticator module and key server, leading to temporary MACsec outages and network unavailability during temporary outages or changes in group membership.
Innovation Solution
Implementing a large-scale Ethernet mesh network with dual-mode peer devices that can operate as both supplicants and authenticators, enabling authenticator redundancy and failover, and using a shared group encryption key for secure data exchange, with mechanisms for key server election and distribution to maintain continuous MACsec service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single authenticator module and key server are used in conventional mesh networks, then device complexity is reduced, but network reliability deteriorates due to single failure points causing MACsec outages
Solution Approach 1:
Each peer device in the mesh network is configured to simultaneously operate as both an authenticator and a supplicant. This merging of roles eliminates the need for separate dedicated authenticator modules and key servers, thereby reducing device complexity while simultaneously providing redundancy to eliminate single failure points, thus improving network reliability.
Solution Approach 2:
Peer devices are designed with multi-functionality, capable of performing both authentication (authenticator mode) and being authenticated (supplicant mode). This universal design allows any peer device to take on either role as needed, providing fault tolerance and continuous network availability while maintaining relatively simple device structures.
2Reliability
If dual-mode peer devices are implemented with both supplicant and authenticator capabilities, then network reliability is improved through redundancy, but device complexity increases
Solution Approach 1:
The patent combines supplicant and authenticator functionalities into a single peer device. By merging these previously separate functions into one unified device architecture, the patent achieves redundancy and eliminates single failure points without proportionally increasing overall system complexity, as the same hardware platform performs both roles.
Solution Approach 2:
Peer devices are designed as universal nodes capable of operating in multiple modes (supplicant mode and authenticator mode). This multi-functionality is achieved through a unified device structure that can dynamically switch between roles, providing high reliability while keeping individual device complexity manageable through shared components and protocols.
3Reliability
If IEEE 802.1X-2010 protocol is used in mesh networks, then authentication security is maintained, but network scale is limited to 30 nodes
Solution Approach 1:
The patent implements dynamic key distribution and authentication mechanisms that allow the mesh network to scale beyond the 30-node limitation of IEEE 802.1X-2010. Peer devices can dynamically assume authenticator and key server roles, enabling the network to adapt to varying scales while maintaining security through the same cryptographic protocols, thus increasing adaptability without compromising authentication security.
Data Source
AI summary
A large-scale Ethernet mesh network including a plurality of dual-mode peer devices in signal communication with one another so as to establish a group connectivity association (CA). Each dual-mode peer device simultaneously operates in a supplicant mode and authenticator mode. Each of dual-mode peer device encrypts data using a shared group encryption key (SAK), and exchanges the encrypted data with peer devices in the group CA.


